The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

3 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 18, 2026Indexed Jun 30, 2026

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Treasury Board of Canada Secretariat

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Treasury Board of Canada Secretariat (TBS) regarding its personal information practices for monitoring employee on-site presence under the federal government's hybrid work model. The complainant alleged invasive collection, use, and disclosure of personal information, questioning TBS's compliance with sections 4, 6, 7, and 8 of the Privacy Act, as well as transparency, necessity, proportionality, and Privacy Impact Assessment (PIA) requirements. The OPC found that TBS's collection of aggregated data for organizational compliance was for non-administrative purposes, authorized by existing statutes, and appropriately de-identified to fall outside the scope of the Act for disclosure. For individual compliance, managers primarily relied on observation and self-reporting, supported by internal guidance. While TBS's practices were largely compliant, the OPC encouraged TBS to update its Personal Information Bank (PIB) description for Physical Access Controls (PSU 907) to explicitly reflect the potential use of access logs in formal investigations and to clearly communicate this to employees. Overall, the OPC concluded that TBS's personal information handling practices were compliant with the Privacy Act.

Quick view

Privacy ActNot well-founded

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Mar 18, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Treasury Board of Canada Secretariat (TBS) regarding its personal information practices for monitoring employee on-site presence under the federal government's hybrid work model. The complainant alleged invasive collection, use, and disclosure of personal information, questioning TBS's compliance with sections 4, 6, 7, and 8 of the Privacy Act, as well as transparency, necessity, proportionality, and Privacy Impact Assessment (PIA) requirements. The OPC found that TBS's collection of aggregated data for organizational compliance was for non-administrative purposes, authorized by existing statutes, and appropriately de-identified to fall outside the scope of the Act for disclosure. For individual compliance, managers primarily relied on observation and self-reporting, supported by internal guidance. While TBS's practices were largely compliant, the OPC encouraged TBS to update its Personal Information Bank (PIB) description for Physical Access Controls (PSU 907) to explicitly reflect the potential use of access logs in formal investigations and to clearly communicate this to employees. Overall, the OPC concluded that TBS's personal information handling practices were compliant with the Privacy Act.

Key Issues
  • Whether the collection of employees' personal information for on-site presence monitoring was related directly to TBS's operating programs or activities under section 4 of the Privacy Act.
  • Whether TBS's retention and disposal practices for personal information collected for on-site presence monitoring complied with section 6 of the Privacy Act, specifically subsections 6(1) and 6(3).
  • Whether TBS's use of personal information for on-site presence monitoring was a 'consistent use' authorized under section 7(a) of the Privacy Act.
  • Whether TBS's disclosure of aggregated on-site presence data to senior management constituted personal information under section 3 of the Privacy Act and complied with section 8.
  • Whether TBS's transparency and openness related to its hybrid compliance monitoring approach, including standard Personal Information Banks (PIBs), was adequate under sections 10 and 11 of the Privacy Act.
  • Whether TBS's personal information practices for on-site presence monitoring complied with the necessity and proportionality data principles.
  • Whether TBS was required to complete a Privacy Impact Assessment (PIA) for its verification regime.
  • Whether managers' practices for monitoring individual compliance with the hybrid work model contravened the Privacy Act.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 12, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Quick view

Privacy ActNot well-founded

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Mar 12, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Key Issues
  • Whether the CBSA authorized contractors to access personal information collected through ArriveCAN without the required security clearance, in contravention of sections 7 and 8 of the Privacy Act
  • Whether ArriveCAN contracts and Task Authorizations (TAs) contained appropriate clauses to ensure the protection of travellers’ personal information that contractors had access to
  • Whether security requirements identified in contracts and TAs were accurate and specific
  • Whether the CBSA complied with organizational security screening requirements for vendors
  • Whether the CBSA complied with personnel security screening requirements for contractors
  • Whether the CBSA implemented adequate administrative safeguards to protect personal information accessed by contractors
  • Whether the CBSA implemented adequate technical safeguards to protect personal information accessed by contractors
  • Whether the CBSA restricted contractor permissions and access to personal information to what was strictly necessary
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Jan 8, 20265824-03656Indexed Jun 30, 2026

5824-03656 — Library and Archives Canada

Library and Archives Canada

The complainant alleged that Library and Archives Canada (LAC) failed to respond to an access request within the 30-day period stipulated by section 7 of the Access to Information Act. The request sought extensive information related to the Métis Nation, treaties, and the Native Women's Association of Canada, covering a broad historical period. LAC argued that the request was too broad and vague, lacking sufficient detail for experienced employees to identify specific records with reasonable effort, and that responding would require extensive historical and legal research beyond its mandate. The OIC determined that the request did not meet the requirements of section 6 of the Act, which mandates that requests provide enough detail for records to be identified with reasonable effort. Despite LAC's attempts to seek clarification and offer assistance through its reference services, the complainant did not provide further specifics. Consequently, the OIC concluded that LAC was not obligated to process the request and was not in deemed refusal. The complaint was found to be not well founded.

Quick view

Access to Information ActNot well-founded

5824-03656 — Library and Archives Canada

Jan 8, 20265824-03656
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Library and Archives Canada (LAC) failed to respond to an access request within the 30-day period stipulated by section 7 of the Access to Information Act. The request sought extensive information related to the Métis Nation, treaties, and the Native Women's Association of Canada, covering a broad historical period. LAC argued that the request was too broad and vague, lacking sufficient detail for experienced employees to identify specific records with reasonable effort, and that responding would require extensive historical and legal research beyond its mandate. The OIC determined that the request did not meet the requirements of section 6 of the Act, which mandates that requests provide enough detail for records to be identified with reasonable effort. Despite LAC's attempts to seek clarification and offer assistance through its reference services, the complainant did not provide further specifics. Consequently, the OIC concluded that LAC was not obligated to process the request and was not in deemed refusal. The complaint was found to be not well founded.

Key Issues
  • Whether Library and Archives Canada responded to the access request within the 30-day period
  • Whether the access request provided enough detail for experienced institutional employees to identify relevant records with a reasonable effort under section 6 of the ATIA
  • Whether the institution's efforts to seek clarification from the requester were reasonable
  • Whether the institution was in deemed refusal pursuant to subsection 10(3) of the ATIA