BreachOfPrivacy
Decisions/Federal (Canada)

Federal (Canada) Privacy Decisions

Browse privacy decisions from Federal (Canada) — with AI-generated plain-language summaries for every ruling.

2 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Dec 27, 2017PIPEDA findings #2017-010· Indexed Apr 12, 2026

PIPEDA findings #2017-010: Reasons for retaining customer credit card data explained

A retail store

A complainant objected to a retail store retaining records of her credit card transactions after she requested their deletion. The store initially cited contractual obligations to credit card companies, but later informed the OPC that the Excise Tax Act also legally required data retention. The OPC relayed this explanation to the complainant, who found it satisfactory, and the matter was resolved.

Quick View

Personal Information Protection and Electronic Documents ActResolved

PIPEDA findings #2017-010: Reasons for retaining customer credit card data explained

Dec 27, 2017PIPEDA findings #2017-010
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant objected to a retail store retaining records of her credit card transactions after she requested their deletion. The store initially cited contractual obligations to credit card companies, but later informed the OPC that the Excise Tax Act also legally required data retention. The OPC relayed this explanation to the complainant, who found it satisfactory, and the matter was resolved.

Key Issues
  • Right to withdraw consent vs. legal and contractual retention obligations
  • Adequacy of explanation provided to complainant
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Apr 26, 2017Incident case summary #2017-001· Indexed Apr 12, 2026

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Office of the Privacy Commissioner of Canada

This report details three incidents in 2017 where Canadian organizations experienced data breaches due to password reuse by their customers. In each case, attackers used login credentials obtained from unrelated breaches to access customer accounts. The Office of the Privacy Commissioner of Canada found the organizations' responses to be appropriate, including actions like password resets, enhanced security measures, and customer notifications, and encouraged other organizations to adopt similar preventative strategies.

Quick View

Personal Information Protection and Electronic Documents ActResolved

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Apr 26, 2017Incident case summary #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details three incidents in 2017 where Canadian organizations experienced data breaches due to password reuse by their customers. In each case, attackers used login credentials obtained from unrelated breaches to access customer accounts. The Office of the Privacy Commissioner of Canada found the organizations' responses to be appropriate, including actions like password resets, enhanced security measures, and customer notifications, and encouraged other organizations to adopt similar preventative strategies.

Key Issues
  • Impact of password reuse on personal information security
  • Adequacy of organizational responses to data breaches
  • Effectiveness of safeguards against unauthorized access
  • Communication and notification obligations to individuals