The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

3 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 26, 2017Incident case summary #2017-001Indexed Jun 30, 2026

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Multiple organizations (Airline, Retailer, Digital media company)

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Apr 26, 2017Incident case summary #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Key Issues
  • Whether organizations adequately responded to breaches caused by password reuse
  • Whether organizations implemented appropriate safeguards to prevent recurrence of breaches due to password reuse
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 18, 2016Incident Summary #13Indexed Jun 30, 2026

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

A Canadian financial institution

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

Feb 18, 2016Incident Summary #13
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Key Issues
  • Whether the financial institution adequately protected customer personal information from unauthorized disclosure by a fraudster
  • Whether the financial institution took appropriate steps to mitigate the impact of the breach and prevent recurrence
Federal (Canada)Access to Information ActResolved
Federal (Canada) flag
May 14, 2015Indexed Jun 30, 2026

Investigation into an access to information request for the Long-gun Registry

Royal Canadian Mounted Police

The complainant requested access to the Firearms Registry database from the Royal Canadian Mounted Police (RCMP) on March 27, 2012, prior to the enactment of the Ending the Long-gun Registry Act. The complainant alleged that the RCMP provided an incomplete response, failed to justify the incompleteness, and obstructed the right of access by destroying responsive records. The investigation focused on whether the RCMP's actions, particularly the destruction of records, constituted an obstruction of the right of access under section 67.1 of the Access to Information Act. The Commissioner examined the circumstances surrounding the destruction of the Long-gun Registry data. The Commissioner found that the destruction of the records was carried out in accordance with a valid legislative process and did not constitute an obstruction of the right of access.

Quick view

Access to Information ActResolved

Investigation into an access to information request for the Long-gun Registry

May 14, 2015
Adjudicator: Suzanne Legault
Plain-Language Summary

The complainant requested access to the Firearms Registry database from the Royal Canadian Mounted Police (RCMP) on March 27, 2012, prior to the enactment of the Ending the Long-gun Registry Act. The complainant alleged that the RCMP provided an incomplete response, failed to justify the incompleteness, and obstructed the right of access by destroying responsive records. The investigation focused on whether the RCMP's actions, particularly the destruction of records, constituted an obstruction of the right of access under section 67.1 of the Access to Information Act. The Commissioner examined the circumstances surrounding the destruction of the Long-gun Registry data. The Commissioner found that the destruction of the records was carried out in accordance with a valid legislative process and did not constitute an obstruction of the right of access.

Key Issues
  • Whether the information provided was incomplete
  • Whether the RCMP justified the incomplete response
  • Whether the destruction of responsive records by the RCMP obstructed the right of access under section 67.1 of the Act