← Back to catalogue/Federal (Canada)Special report to Parliament
Federal (Canada)Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Organization: Canada Revenue AgencyComplainant: Anonymous applicant
Plain-language brief

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Key issues
  1. 1Whether the CRA adequately protected personal information against unauthorized disclosure and modification
  2. 2Whether the CRA contravened subsection 6(2) of the Privacy Act regarding accuracy of personal information
  3. 3Whether the CRA contravened subsection 8(2) of the Privacy Act regarding disclosure of personal information
  4. 4Whether the CRA's prevention measures were adequate
  5. 5Whether the CRA implemented mandatory multi-factor authentication (MFA) in a timely manner and with sufficient strength
  6. 6Whether the CRA's authentication processes by phone were strong enough
  7. 7Whether the CRA considered and integrated a zero-trust approach into its security measures
  8. 8Whether the CRA had sufficient visibility over its attack surface and managed it effectively
  9. 9Whether the CRA's vetting, training, and awareness tools were effective for employees and third parties
  10. 10Whether the CRA's monitoring and detection approach was tailored to the threats and risks leading to Unauthorized Use of Taxpayer Information by a Third Party (UUTP)
  11. 11Whether the CRA's remediation efforts for individual UUTPs were adequate, including root cause analysis
  12. 12Whether the CRA's governance processes for addressing UUTPs were coordinated, comprehensive, and efficient
Outcome breakdownFavours: Both, in part
  • Safeguards for personal information: CRA contravened Privacy Act subsections 6(2) and 8(2)
  • Multi-factor authentication: Delayed implementation identified as weakness
  • Breach tracking: Insufficient tracking identified as weakness
  • Recommendations issued: Nine recommendations issued to CRA
  • Recommendations accepted: CRA accepted eight recommendations in full and one in part
  • Outcome of investigation: Investigation found well-founded and conditionally resolved
Outcome

Complaint well-founded and conditionally resolved

Reasoning

The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to identified shortcomings in its security practices, but the CRA committed to implementing the OPC's recommendations to address these issues.

AI-generated summary for reference only. Always verify against the official decision ↗
Decision notes
Recommended action / remedy

The Commissioner made nine recommendations to the CRA, which the Agency accepted eight in full and one in part, focusing on strengthening MFA, enhancing phone authentication, integrating zero-trust principles, improving attack surface management, assessing training and awareness, tailoring monitoring and detection, developing comprehensive breach tracking, and reviewing governance processes.

Statutes considered
  • s.6(2) Privacy Act
  • s.8(2) Privacy Act
  • s.39(1) Privacy Act
  • s.40(1) Privacy Act
  • TBS Policy on Privacy Protection
  • TBS Policy on Government Security
  • TBS Directive on Security Management

This summary is informational only and not legal advice.

Pro · AI

Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.

Pro
Coverage — 13 of 14 jurisdictions searchable

Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.

Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).

Coming soon: Nunavut — being re-processed for AI search.

Find decisions like this one — by meaning, not keywords.

Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.

Upgrade to Pro