
Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency
The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.
- 1Whether the CRA adequately protected personal information against unauthorized disclosure and modification
- 2Whether the CRA contravened subsection 6(2) of the Privacy Act regarding accuracy of personal information
- 3Whether the CRA contravened subsection 8(2) of the Privacy Act regarding disclosure of personal information
- 4Whether the CRA's prevention measures were adequate
- 5Whether the CRA implemented mandatory multi-factor authentication (MFA) in a timely manner and with sufficient strength
- 6Whether the CRA's authentication processes by phone were strong enough
- 7Whether the CRA considered and integrated a zero-trust approach into its security measures
- 8Whether the CRA had sufficient visibility over its attack surface and managed it effectively
- 9Whether the CRA's vetting, training, and awareness tools were effective for employees and third parties
- 10Whether the CRA's monitoring and detection approach was tailored to the threats and risks leading to Unauthorized Use of Taxpayer Information by a Third Party (UUTP)
- 11Whether the CRA's remediation efforts for individual UUTPs were adequate, including root cause analysis
- 12Whether the CRA's governance processes for addressing UUTPs were coordinated, comprehensive, and efficient
- Safeguards for personal information: CRA contravened Privacy Act subsections 6(2) and 8(2)
- Multi-factor authentication: Delayed implementation identified as weakness
- Breach tracking: Insufficient tracking identified as weakness
- Recommendations issued: Nine recommendations issued to CRA
- Recommendations accepted: CRA accepted eight recommendations in full and one in part
- Outcome of investigation: Investigation found well-founded and conditionally resolved
Complaint well-founded and conditionally resolved
The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to identified shortcomings in its security practices, but the CRA committed to implementing the OPC's recommendations to address these issues.
The Commissioner made nine recommendations to the CRA, which the Agency accepted eight in full and one in part, focusing on strengthening MFA, enhancing phone authentication, integrating zero-trust principles, improving attack surface management, assessing training and awareness, tailoring monitoring and detection, developing comprehensive breach tracking, and reviewing governance processes.
- s.6(2) Privacy Act
- s.8(2) Privacy Act
- s.39(1) Privacy Act
- s.40(1) Privacy Act
- TBS Policy on Privacy Protection
- TBS Policy on Government Security
- TBS Directive on Security Management
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro