The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

15 decisions matching
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Mar 31, 2020Indexed Jun 30, 2026

CBSA should only retain travellers’ digital device passcodes when necessary

Canada Border Services Agency (CBSA)

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Quick view

Privacy ActResolved

CBSA should only retain travellers’ digital device passcodes when necessary

Mar 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Key Issues
  • Whether the CBSA has the authority to require a traveller to provide a passcode to unlock a digital device for inspection purposes under the Customs Act
  • Whether the CBSA officer followed internal policies regarding the collection and retention of personal information (passcodes)
  • Whether the CBSA's retention of the passcode was necessary beyond the examination process when no further action was taken
  • Whether passcodes constitute sensitive personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Dec 27, 2017PIPEDA findings #2017-010Indexed Jun 30, 2026

PIPEDA findings #2017-010: Reasons for retaining customer credit card data explained

A retail store

A complainant objected to a retail store retaining records of her credit card transactions and refusing to delete them upon request. The store initially cited contractual obligations with credit card companies. During the OPC's investigation, the retail company provided a more detailed explanation, including its legal obligations under the Excise Tax Act to retain transactional data. The OPC relayed this information to the complainant, who was satisfied with the explanation and considered the matter resolved. The complainant noted that if this information had been provided initially, she would not have filed a complaint.

Quick view

Personal Information Protection and Electronic Documents ActResolved

PIPEDA findings #2017-010: Reasons for retaining customer credit card data explained

Dec 27, 2017PIPEDA findings #2017-010
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant objected to a retail store retaining records of her credit card transactions and refusing to delete them upon request. The store initially cited contractual obligations with credit card companies. During the OPC's investigation, the retail company provided a more detailed explanation, including its legal obligations under the Excise Tax Act to retain transactional data. The OPC relayed this information to the complainant, who was satisfied with the explanation and considered the matter resolved. The complainant noted that if this information had been provided initially, she would not have filed a complaint.

Key Issues
  • Whether a retail store's retention of credit card transaction records without deletion upon request violated PIPEDA's consent principle
  • Whether legal or contractual obligations justified the retention of personal information despite a withdrawal of consent
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 26, 2017Incident case summary #2017-001Indexed Jun 30, 2026

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Multiple organizations (Airline, Retailer, Digital media company)

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Apr 26, 2017Incident case summary #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Key Issues
  • Whether organizations adequately responded to breaches caused by password reuse
  • Whether organizations implemented appropriate safeguards to prevent recurrence of breaches due to password reuse
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 24, 2016Incident Summary #12Indexed Jun 30, 2026

Incident Summary #12: Break with security procedures exposes financial planner’s client to privacy breach

A financial management firm

A financial management firm's employees breached internal security procedures by sending a client's detailed financial plan and federal income tax notice of assessment, containing sensitive personal information including her social insurance number, to her personal email account without secure messaging tools. The client's email account was subsequently hacked, and the alleged hacker used the obtained information to pose as the client and request a significant transfer from her investment account. An employee processed this transfer without following authentication procedures. Although the client's money was not stolen, the firm investigated the incident, advised the client to change passwords, informed the RCMP, and offered credit monitoring. The firm also took measures with the responsible employees, provided additional privacy training to staff, and reviewed its internal processes. The OPC considered the firm's response appropriate.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #12: Break with security procedures exposes financial planner’s client to privacy breach

Feb 24, 2016Incident Summary #12
Adjudicator: Daniel Therrien
Plain-Language Summary

A financial management firm's employees breached internal security procedures by sending a client's detailed financial plan and federal income tax notice of assessment, containing sensitive personal information including her social insurance number, to her personal email account without secure messaging tools. The client's email account was subsequently hacked, and the alleged hacker used the obtained information to pose as the client and request a significant transfer from her investment account. An employee processed this transfer without following authentication procedures. Although the client's money was not stolen, the firm investigated the incident, advised the client to change passwords, informed the RCMP, and offered credit monitoring. The firm also took measures with the responsible employees, provided additional privacy training to staff, and reviewed its internal processes. The OPC considered the firm's response appropriate.

Key Issues
  • Whether the firm adequately protected personal information by sending sensitive documents via unsecure email
  • Whether the firm had adequate procedures for authenticating clients for financial transactions
  • Whether the firm's response to the privacy breach was appropriate
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 19, 2016Incident Summary #11Indexed Jun 30, 2026

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

A financial institution

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

Feb 19, 2016Incident Summary #11
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Key Issues
  • Whether the financial institution adequately safeguarded personal information during mass mail-outs
  • Whether the financial institution responded appropriately to a privacy breach involving misdirected mail
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 18, 2016Incident Summary #13Indexed Jun 30, 2026

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

A Canadian financial institution

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

Feb 18, 2016Incident Summary #13
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Key Issues
  • Whether the financial institution adequately protected customer personal information from unauthorized disclosure by a fraudster
  • Whether the financial institution took appropriate steps to mitigate the impact of the breach and prevent recurrence
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Jan 25, 2016Incident Summary #10Indexed Jun 30, 2026

Incident Summary #10: Cable provider removes personal information posted online of customers with overdue accounts

A cable provider

The OPC was alerted to a cable provider posting a list of customers with overdue accounts and the amounts owed on a municipal Facebook page. The cable provider believed this practice was permissible, citing municipal tax arrears publications as an example. The OPC informed the provider that publicly disseminating personal information for debt collection without consent is not permitted under PIPEDA, even though disclosure to a third-party debt collector may be. The cable provider subsequently removed the posting. The OPC also clarified with the NWT Commissioner that municipal tax arrears publications are mandated by territorial law, unlike the cable provider's actions. The OPC explained that PIPEDA's debt collection exemption does not authorize public disclosure.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #10: Cable provider removes personal information posted online of customers with overdue accounts

Jan 25, 2016Incident Summary #10
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC was alerted to a cable provider posting a list of customers with overdue accounts and the amounts owed on a municipal Facebook page. The cable provider believed this practice was permissible, citing municipal tax arrears publications as an example. The OPC informed the provider that publicly disseminating personal information for debt collection without consent is not permitted under PIPEDA, even though disclosure to a third-party debt collector may be. The cable provider subsequently removed the posting. The OPC also clarified with the NWT Commissioner that municipal tax arrears publications are mandated by territorial law, unlike the cable provider's actions. The OPC explained that PIPEDA's debt collection exemption does not authorize public disclosure.

Key Issues
  • Whether publicly posting customer debt information on social media is permissible under PIPEDA
  • Whether the debt collection exemption under paragraph 7(3)(b) of PIPEDA authorizes public dissemination of personal information
  • Whether municipal practices of publishing tax arrears are comparable to private organizations publishing customer debt under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Jul 22, 2015PIPEDA findings #2015-019Indexed Jun 30, 2026

PIPEDA findings #2015-019: OPC complaint prompts telecom’s fraud investigation

A telecommunications company

A complainant reported a fraudulent telecommunications account causing a false debt statement on their credit report. The complainant alleged they never lived at the address associated with the debt, and the telecommunications company initially refused to correct the debt or provide proof of account opening. The credit-reporting agency had validated the debt with the telecom company. Upon the OPC's intervention, the telecommunications company's fraud team reviewed the file and determined the account was fraudulent. The company then cancelled the fraudulent account and updated the credit-reporting agency with accurate information. The complainant was satisfied with these actions, leading to an early resolution.

Quick view

Personal Information Protection and Electronic Documents ActResolved

PIPEDA findings #2015-019: OPC complaint prompts telecom’s fraud investigation

Jul 22, 2015PIPEDA findings #2015-019
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant reported a fraudulent telecommunications account causing a false debt statement on their credit report. The complainant alleged they never lived at the address associated with the debt, and the telecommunications company initially refused to correct the debt or provide proof of account opening. The credit-reporting agency had validated the debt with the telecom company. Upon the OPC's intervention, the telecommunications company's fraud team reviewed the file and determined the account was fraudulent. The company then cancelled the fraudulent account and updated the credit-reporting agency with accurate information. The complainant was satisfied with these actions, leading to an early resolution.

Key Issues
  • Whether the telecommunications company failed to ensure the accuracy of personal information
  • Whether the telecommunications company failed to correct inaccurate personal information
  • Whether the credit-reporting agency failed to ensure the accuracy of personal information
Federal (Canada)Access to Information ActResolved
Federal (Canada) flag
May 14, 2015Indexed Jun 30, 2026

Investigation into an access to information request for the Long-gun Registry

Royal Canadian Mounted Police

The complainant requested access to the Firearms Registry database from the Royal Canadian Mounted Police (RCMP) on March 27, 2012, prior to the enactment of the Ending the Long-gun Registry Act. The complainant alleged that the RCMP provided an incomplete response, failed to justify the incompleteness, and obstructed the right of access by destroying responsive records. The investigation focused on whether the RCMP's actions, particularly the destruction of records, constituted an obstruction of the right of access under section 67.1 of the Access to Information Act. The Commissioner examined the circumstances surrounding the destruction of the Long-gun Registry data. The Commissioner found that the destruction of the records was carried out in accordance with a valid legislative process and did not constitute an obstruction of the right of access.

Quick view

Access to Information ActResolved

Investigation into an access to information request for the Long-gun Registry

May 14, 2015
Adjudicator: Suzanne Legault
Plain-Language Summary

The complainant requested access to the Firearms Registry database from the Royal Canadian Mounted Police (RCMP) on March 27, 2012, prior to the enactment of the Ending the Long-gun Registry Act. The complainant alleged that the RCMP provided an incomplete response, failed to justify the incompleteness, and obstructed the right of access by destroying responsive records. The investigation focused on whether the RCMP's actions, particularly the destruction of records, constituted an obstruction of the right of access under section 67.1 of the Access to Information Act. The Commissioner examined the circumstances surrounding the destruction of the Long-gun Registry data. The Commissioner found that the destruction of the records was carried out in accordance with a valid legislative process and did not constitute an obstruction of the right of access.

Key Issues
  • Whether the information provided was incomplete
  • Whether the RCMP justified the incomplete response
  • Whether the destruction of responsive records by the RCMP obstructed the right of access under section 67.1 of the Act
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Nov 13, 2014Indexed Jun 30, 2026

Video surveillance of employees vs. right to privacy - a delicate balance - November 13, 2014

Canada Border Services Agency (CBSA)

An employee of the Canada Border Services Agency (CBSA) complained on behalf of colleagues that the CBSA was using video monitoring to collect personal information for the purpose of monitoring employee conduct and performance, beyond the original safety and security purposes. The complainant also alleged insufficient signage. The OPC found the signage issue was resolved early in the investigation as the CBSA added more signs. Regarding the use of video for monitoring conduct and performance, the CBSA updated its policy to clarify that video technology would not be used for performance monitoring. The OPC accepted the CBSA's rationale for using video recordings to investigate serious misconduct, finding it met the standard for collection under section 4 of the Privacy Act. However, the resolution was conditional on the CBSA providing updated guidelines for implementing its policy.

Quick view

Privacy ActResolved

Video surveillance of employees vs. right to privacy - a delicate balance - November 13, 2014

Nov 13, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee of the Canada Border Services Agency (CBSA) complained on behalf of colleagues that the CBSA was using video monitoring to collect personal information for the purpose of monitoring employee conduct and performance, beyond the original safety and security purposes. The complainant also alleged insufficient signage. The OPC found the signage issue was resolved early in the investigation as the CBSA added more signs. Regarding the use of video for monitoring conduct and performance, the CBSA updated its policy to clarify that video technology would not be used for performance monitoring. The OPC accepted the CBSA's rationale for using video recordings to investigate serious misconduct, finding it met the standard for collection under section 4 of the Privacy Act. However, the resolution was conditional on the CBSA providing updated guidelines for implementing its policy.

Key Issues
  • Whether the CBSA's use of video monitoring for employee conduct and performance monitoring contravened the Privacy Act
  • Whether the collection of personal information via video technology was necessary and related directly to an operating program or activity of the institution under section 4 of the Privacy Act
  • Whether the CBSA had sufficient signage to inform employees of video monitoring
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Mar 21, 2014Incident Summary #5Indexed Jun 30, 2026

Incident Summary #5: Life insurance company employs best practices in responding to mass mailing error that risked exposing personal information - March 21, 2014

A life insurance company

A life insurance company discovered that a mass mailing error risked exposing the personal information of 53 pension plan members. The new window envelopes used were larger, potentially revealing certificate numbers, SINs, dates of birth, spouse's names, and beneficiaries if statements shifted. Upon discovering the incident, the company promptly notified affected individuals, apologized, explained the incident, and offered a free one-year credit monitoring service. They also advised members to take harm-reducing steps and ceased using the problematic envelopes. The company informed the OPC about the incident and its response. The OPC concluded that the company demonstrated best practices in its incident response.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #5: Life insurance company employs best practices in responding to mass mailing error that risked exposing personal information - March 21, 2014

Mar 21, 2014Incident Summary #5
Adjudicator: Chantal Bernier
Plain-Language Summary

A life insurance company discovered that a mass mailing error risked exposing the personal information of 53 pension plan members. The new window envelopes used were larger, potentially revealing certificate numbers, SINs, dates of birth, spouse's names, and beneficiaries if statements shifted. Upon discovering the incident, the company promptly notified affected individuals, apologized, explained the incident, and offered a free one-year credit monitoring service. They also advised members to take harm-reducing steps and ceased using the problematic envelopes. The company informed the OPC about the incident and its response. The OPC concluded that the company demonstrated best practices in its incident response.

Key Issues
  • Whether a mass mailing error led to the potential exposure of personal information
  • Whether the life insurance company's response to the incident constituted best practices
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 20, 2014Early resolved case summary #10Indexed Jun 30, 2026

Early resolved case summary #10: Bank improves its credit card account verification practices after challenge from customer - February 20, 2014

A financial institution

An individual complained that her bank required the last six digits of her Social Insurance Number (SIN) to set up a "verified credit account" for online purchases. She believed this practice was inappropriate and that an alternative method not requiring SIN information should be available. The bank initially stated an alternative existed through commercial websites, but the complainant noted this was not clearly communicated. The OPC highlighted a comparable case where a lack of transparency regarding authentication alternatives was found. Following this, the bank decided to discontinue the SIN-based authentication method entirely and update its website. The complainant was satisfied with this resolution, and the OPC confirmed the website changes.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Early resolved case summary #10: Bank improves its credit card account verification practices after challenge from customer - February 20, 2014

Feb 20, 2014Early resolved case summary #10
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that her bank required the last six digits of her Social Insurance Number (SIN) to set up a "verified credit account" for online purchases. She believed this practice was inappropriate and that an alternative method not requiring SIN information should be available. The bank initially stated an alternative existed through commercial websites, but the complainant noted this was not clearly communicated. The OPC highlighted a comparable case where a lack of transparency regarding authentication alternatives was found. Following this, the bank decided to discontinue the SIN-based authentication method entirely and update its website. The complainant was satisfied with this resolution, and the OPC confirmed the website changes.

Key Issues
  • Whether collecting a partial SIN for credit card account verification was appropriate under PIPEDA
  • Whether the bank provided adequate transparency regarding alternative verification methods
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Correctional Service of Canada initially denies access to full report in favour of giving the “gist”

Correctional Service of Canada (CSC)

A complainant alleged that the Correctional Service of Canada (CSC) denied him full access to a report concerning his treatment and supervision. The complainant initially received a three-page summary, but later learned the full report was ten pages with more findings. The OPC's investigation confirmed the existence of the longer report. CSC stated they provided a condensed version because the full report was based on informal interviews. The OPC found that providing an abbreviated version misrepresented the information and was contrary to CSC's obligations under the Privacy Act to process all relevant information. After negotiations, CSC provided the full report with third-party personal information redacted and committed to reviewing its access request handling and educating staff on Privacy Act obligations.

Quick view

Privacy ActResolved

Correctional Service of Canada initially denies access to full report in favour of giving the “gist”

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that the Correctional Service of Canada (CSC) denied him full access to a report concerning his treatment and supervision. The complainant initially received a three-page summary, but later learned the full report was ten pages with more findings. The OPC's investigation confirmed the existence of the longer report. CSC stated they provided a condensed version because the full report was based on informal interviews. The OPC found that providing an abbreviated version misrepresented the information and was contrary to CSC's obligations under the Privacy Act to process all relevant information. After negotiations, CSC provided the full report with third-party personal information redacted and committed to reviewing its access request handling and educating staff on Privacy Act obligations.

Key Issues
  • Whether Correctional Service of Canada denied full access to a report
  • Whether providing a condensed version of a report constitutes a misrepresentation of information
  • Whether Correctional Service of Canada fulfilled its responsibility to identify and process all relevant information under the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 25, 2013Early resolved case summary #2013-01Indexed Jun 30, 2026

Early resolved case summary #2013-01: Property management company alters its rental application form to make clear that Social Insurance Number is optional

A property management company

An individual complained that a property management company was over-collecting personal information on rental application forms, specifically requesting Social Insurance Numbers (SINs), driver's licence information, and banking details as a condition of application. The complainant also noted the absence of a privacy policy on the company's website. The OPC contacted the company, which stated its website was under construction and would include a privacy policy. The company used third-party generated forms and believed SINs were necessary for credit checks, a point the OPC disputed. The OPC suggested marking SIN requests as 'optional' and advised against collecting unique driver's licence numbers. The company committed to updating its forms and website, satisfying the complainant. The OPC later confirmed these changes were implemented.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Early resolved case summary #2013-01: Property management company alters its rental application form to make clear that Social Insurance Number is optional

Apr 25, 2013Early resolved case summary #2013-01
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a property management company was over-collecting personal information on rental application forms, specifically requesting Social Insurance Numbers (SINs), driver's licence information, and banking details as a condition of application. The complainant also noted the absence of a privacy policy on the company's website. The OPC contacted the company, which stated its website was under construction and would include a privacy policy. The company used third-party generated forms and believed SINs were necessary for credit checks, a point the OPC disputed. The OPC suggested marking SIN requests as 'optional' and advised against collecting unique driver's licence numbers. The company committed to updating its forms and website, satisfying the complainant. The OPC later confirmed these changes were implemented.

Key Issues
  • Whether the collection of Social Insurance Numbers (SINs) was appropriate
  • Whether the collection of driver's licence numbers was appropriate
  • Whether the collection of banking information was appropriate
  • Whether the organization made its privacy policy readily available as required by PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 20, 2001IncidentIndexed Jun 30, 2026

Incident: Transportation company collects and discloses passengers' personal information

A transportation company

A complaint was made against a transportation company alleging that its sales agents were collecting passengers' date of birth and citizenship for Toronto-to-New York train bookings and disclosing this information to US Customs and US Naturalization and Immigration Service. The company confirmed this practice, stating it was an agreement with US authorities to minimize border delays. The OPC found that sales agents were representing the provision of this information as a requirement. The OPC advised the company to instruct its agents to present the provision of this information as voluntary and to seek consent after booking. The company issued a directive to its sales agents, and the OPC closed the file, subject to monitoring.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident: Transportation company collects and discloses passengers' personal information

Apr 20, 2001Incident
Adjudicator: George Radwanski
Plain-Language Summary

A complaint was made against a transportation company alleging that its sales agents were collecting passengers' date of birth and citizenship for Toronto-to-New York train bookings and disclosing this information to US Customs and US Naturalization and Immigration Service. The company confirmed this practice, stating it was an agreement with US authorities to minimize border delays. The OPC found that sales agents were representing the provision of this information as a requirement. The OPC advised the company to instruct its agents to present the provision of this information as voluntary and to seek consent after booking. The company issued a directive to its sales agents, and the OPC closed the file, subject to monitoring.

Key Issues
  • Whether the transportation company was collecting personal information without proper consent
  • Whether the transportation company was disclosing personal information without proper consent
  • Whether sales agents were misrepresenting the voluntary nature of providing personal information