
TBS email breach illustrates the importance of considering context when assessing impact of a breach
Twenty complainants, current or former federal government employees, alleged that the Treasury Board of Canada Secretariat (TBS) improperly disclosed their personal information. TBS mistakenly sent two emails to 400 applicants for the Severe Phoenix Impacts program using the 'cc' field instead of 'bcc', revealing email addresses (some with names) and the fact they had filed a claim for Phoenix-related damages. The OPC found that the disclosure was not authorized under the Privacy Act, making the complaints well-founded. While TBS acknowledged the error, it initially deemed the breach non-material, a conclusion the OPC disagreed with, emphasizing the importance of contextual factors in assessing harm. TBS agreed to implement two of the OPC's three recommendations, but not the one concerning incorporating the findings on materiality into its policy instruments. The OPC concluded the complaints were well-founded and conditionally resolved in part, expressing ongoing concern about TBS's assessment of breach materiality.
- 1Whether the disclosure of personal information via email was authorized under the Privacy Act
- 2Whether the privacy breach was 'material' in nature according to TBS's guidelines
- 3Whether TBS's assessment of the breach's materiality was appropriate
- 4Whether the context of the personal information disclosed should be considered when assessing the risk of injury or harm
- Disclosure of personal information: Disclosure was unauthorized
- Breach materiality assessment: Institution's assessment was incorrect
- Recommendations implementation: Institution partially agreed to recommendations
- Complaint outcome: Complaints well-founded and conditionally resolved in part
Complaint well-founded and conditionally resolved in part
The OPC found that TBS contravened section 8 of the Privacy Act by disclosing personal information without authorization. The resolution is conditional because TBS agreed to implement some, but not all, of the OPC's recommendations, particularly regarding the assessment of breach materiality.
The OPC recommended that TBS share the final report with staff, remind them of their responsibilities, raise awareness about breach causes, incorporate findings into policy instruments for consistent harm assessment, and explore more secure communication means. TBS agreed to implement the first and third recommendations.
- s.3 Privacy Act
- s.8 Privacy Act
- s.8(1) Privacy Act
- s.8(2) Privacy Act
This summary is for informational purposes only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro