The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

2 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Dec 27, 2017PIPEDA findings #2017-010Indexed Jun 30, 2026

PIPEDA findings #2017-010: Reasons for retaining customer credit card data explained

A retail store

A complainant objected to a retail store retaining records of her credit card transactions and refusing to delete them upon request. The store initially cited contractual obligations with credit card companies. During the OPC's investigation, the retail company provided a more detailed explanation, including its legal obligations under the Excise Tax Act to retain transactional data. The OPC relayed this information to the complainant, who was satisfied with the explanation and considered the matter resolved. The complainant noted that if this information had been provided initially, she would not have filed a complaint.

Quick view

Personal Information Protection and Electronic Documents ActResolved

PIPEDA findings #2017-010: Reasons for retaining customer credit card data explained

Dec 27, 2017PIPEDA findings #2017-010
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant objected to a retail store retaining records of her credit card transactions and refusing to delete them upon request. The store initially cited contractual obligations with credit card companies. During the OPC's investigation, the retail company provided a more detailed explanation, including its legal obligations under the Excise Tax Act to retain transactional data. The OPC relayed this information to the complainant, who was satisfied with the explanation and considered the matter resolved. The complainant noted that if this information had been provided initially, she would not have filed a complaint.

Key Issues
  • Whether a retail store's retention of credit card transaction records without deletion upon request violated PIPEDA's consent principle
  • Whether legal or contractual obligations justified the retention of personal information despite a withdrawal of consent
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 26, 2017Incident case summary #2017-001Indexed Jun 30, 2026

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Multiple organizations (Airline, Retailer, Digital media company)

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Apr 26, 2017Incident case summary #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Key Issues
  • Whether organizations adequately responded to breaches caused by password reuse
  • Whether organizations implemented appropriate safeguards to prevent recurrence of breaches due to password reuse