
Review of passport protection practices of four federal institutions
The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.
- 1Whether the institutions had adequate controls to prevent unauthorized disclosures of passports under s.8 of the Privacy Act
- 2Whether the institutions had adequate measures to detect potential unauthorized disclosures of passports
- 3Whether the institutions had adequate measures to remediate risks to individuals from unauthorized disclosures of passports
- 4Whether the institutions consistently and appropriately assessed the "materiality" of passport-related breaches
- 5Whether notifications to affected individuals regarding lost or stolen passports were timely
- 6Whether concrete assistance, such as credit monitoring, was offered to individuals affected by lost or stolen passports
- 7Whether incident assessment and investigation processes were robust enough to identify suspicious patterns and share lessons learned among relevant stakeholders
- Passport protection practices: Generally reasonable, but areas for improvement identified
- Incident detection: Improvements needed
- Remediation for individuals: Improvements needed
- Lesson-learning from breaches: Improvements needed
- Breach materiality assessment: Inconsistent assessments noted
- Notification of affected individuals: Delays noted
- Mitigation measures offered: Lack of concrete assistance noted
- Recommendations issued: All institutions agreed to implement
Recommendations made and agreed upon
The OPC found that while preventative measures were generally adequate, the institutions had deficiencies in detecting, remediating, and learning from unauthorized disclosures of passports, leading to recommendations that the institutions agreed to implement.
The OPC recommended that GAC, IRCC, and ESDC jointly establish and implement consistent written guidance on assessing materiality, reasonable service standards for timely notification, and include appropriate advice and offer mitigation measures like credit monitoring; and that IRCC ensure incident assessment and investigation processes are robust to identify patterns and share lessons learned.
- section 37 of the Privacy Act
- Section 8 of the Privacy Act
- Section 8(1) of the Privacy Act
- Section 8(2) of the Privacy Act
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro