The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

75 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 25, 2026Indexed Jun 30, 2026

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Immigration, Refugees and Citizenship Canada (IRCC)

The OPC investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding its systematic practice of withholding access to certain personal information in its Global Case Management System (GCMS). IRCC's policy was to retrieve and process only a "Short Form" GCMS Report in response to access requests, even when individuals requested their entire file or specific content found in the "Long Form." The OPC found that the "History Section" of the GCMS file, which is part of the Long Form, contained the complainant's personal information and that IRCC's practice contravened Section 12 of the Privacy Act. While IRCC eventually provided the complainant with the requested Long Form, it did not agree to update its procedures to systematically retrieve and process the Long Form for all future requests. Consequently, the OPC found the complaint well-founded but not resolved, as IRCC had not committed to addressing the systemic issue.

Quick view

Privacy ActWell-founded

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding its systematic practice of withholding access to certain personal information in its Global Case Management System (GCMS). IRCC's policy was to retrieve and process only a "Short Form" GCMS Report in response to access requests, even when individuals requested their entire file or specific content found in the "Long Form." The OPC found that the "History Section" of the GCMS file, which is part of the Long Form, contained the complainant's personal information and that IRCC's practice contravened Section 12 of the Privacy Act. While IRCC eventually provided the complainant with the requested Long Form, it did not agree to update its procedures to systematically retrieve and process the Long Form for all future requests. Consequently, the OPC found the complaint well-founded but not resolved, as IRCC had not committed to addressing the systemic issue.

Key Issues
  • Whether IRCC's practice of providing only a "Short Form" GCMS Report in response to access requests contravenes Section 12 of the Privacy Act
  • Whether the "History Section" of the GCMS file contains personal information
  • Whether information in the "Long Form" GCMS Report is always exempt from disclosure
  • Whether IRCC has an obligation to retrieve and process all records responsive to a Privacy Act request
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2026Indexed Jun 30, 2026

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Canada Border Services Agency (CBSA)

An employee of the Canada Border Services Agency (CBSA) filed a complaint after their personal information, including sensitive details about an accommodation request, was inadvertently made accessible to other CBSA employees through the Apollo information management system. The issue stemmed from improperly set permissions on an old ATIP file folder, which allowed document titles and sometimes the first line of emails containing personal information to be visible via Apollo's search function. The OPC found that the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority. While the CBSA corrected the specific permissions and committed to broader reviews and improved naming conventions, it did not agree to implement mandatory and trackable training for employees on Apollo permissions management. Consequently, the OPC found the complaint well-founded but unresolved, as it was not satisfied that sufficient safeguards were in place to prevent recurrence.

Quick view

Privacy ActWell-founded

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Mar 24, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee of the Canada Border Services Agency (CBSA) filed a complaint after their personal information, including sensitive details about an accommodation request, was inadvertently made accessible to other CBSA employees through the Apollo information management system. The issue stemmed from improperly set permissions on an old ATIP file folder, which allowed document titles and sometimes the first line of emails containing personal information to be visible via Apollo's search function. The OPC found that the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority. While the CBSA corrected the specific permissions and committed to broader reviews and improved naming conventions, it did not agree to implement mandatory and trackable training for employees on Apollo permissions management. Consequently, the OPC found the complaint well-founded but unresolved, as it was not satisfied that sufficient safeguards were in place to prevent recurrence.

Key Issues
  • Whether the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority
  • Whether the CBSA appropriately responded to the unauthorized disclosure
  • Whether the CBSA's proposed measures, without mandatory and trackable training, are sufficient to prevent future unauthorized disclosures
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 27, 2025Indexed Jun 30, 2026

Investigation into the disclosure of an adopted child’s name to their biological mother by the Canada Revenue Agency

Canada Revenue Agency (CRA)

A complainant alleged that the Canada Revenue Agency (CRA) inappropriately disclosed her adoptive child's name and her personal information to the child's biological mother, contravening section 8 of the Privacy Act. The child's name had been changed for safety reasons after a closed adoption. The OPC found that, on the balance of probabilities, the CRA likely disclosed the child's adoptive name to the biological mother, leading to significant negative impacts on the family. The investigation also revealed deficiencies in the CRA's internal procedures for safeguarding adopted children's personal information. The OPC issued recommendations to revise procedures, provide comprehensive training, and implement oversight measures. The CRA agreed to implement two of the three recommendations, but declined the oversight measure, leading to a "well-founded and not resolved" finding.

Quick view

Privacy ActWell-founded

Investigation into the disclosure of an adopted child’s name to their biological mother by the Canada Revenue Agency

Feb 27, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

A complainant alleged that the Canada Revenue Agency (CRA) inappropriately disclosed her adoptive child's name and her personal information to the child's biological mother, contravening section 8 of the Privacy Act. The child's name had been changed for safety reasons after a closed adoption. The OPC found that, on the balance of probabilities, the CRA likely disclosed the child's adoptive name to the biological mother, leading to significant negative impacts on the family. The investigation also revealed deficiencies in the CRA's internal procedures for safeguarding adopted children's personal information. The OPC issued recommendations to revise procedures, provide comprehensive training, and implement oversight measures. The CRA agreed to implement two of the three recommendations, but declined the oversight measure, leading to a "well-founded and not resolved" finding.

Key Issues
  • Whether the CRA disclosed the child’s adoptive name to the biological mother in contravention of section 8 of the Privacy Act
  • Whether the CRA's internal procedures for safeguarding adopted children's personal information were adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 26, 2025Indexed Jun 30, 2026

Investigation into the Canada Revenue Agency’s application of paragraph 22(1)(b) to refuse access to personal information

Canada Revenue Agency (CRA)

The complainant alleged that the Canada Revenue Agency (CRA) improperly denied access to personal information related to five grievances, relying on exceptions in subsection 12(1), paragraph 22(1)(b), and section 26 of the Privacy Act. The OPC found that while the CRA conducted reasonable searches, it failed to substantiate its use of some exemptions, particularly paragraph 22(1)(b). The CRA did not demonstrate a clear and direct connection between disclosure and a risk of harm, instead relying on general assertions. The OPC concluded that the complainant did not receive all entitled personal information and found the complaint well-founded. The OPC recommended the CRA reassess its reliance on paragraph 22(1)(b) and disclose more information. However, the CRA maintained its position, leading the OPC to consider the complaint unresolved.

Quick view

Privacy ActWell-founded

Investigation into the Canada Revenue Agency’s application of paragraph 22(1)(b) to refuse access to personal information

Feb 26, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that the Canada Revenue Agency (CRA) improperly denied access to personal information related to five grievances, relying on exceptions in subsection 12(1), paragraph 22(1)(b), and section 26 of the Privacy Act. The OPC found that while the CRA conducted reasonable searches, it failed to substantiate its use of some exemptions, particularly paragraph 22(1)(b). The CRA did not demonstrate a clear and direct connection between disclosure and a risk of harm, instead relying on general assertions. The OPC concluded that the complainant did not receive all entitled personal information and found the complaint well-founded. The OPC recommended the CRA reassess its reliance on paragraph 22(1)(b) and disclose more information. However, the CRA maintained its position, leading the OPC to consider the complaint unresolved.

Key Issues
  • Whether the Canada Revenue Agency conducted reasonable searches for responsive records
  • Whether the Canada Revenue Agency properly applied subsection 12(1) of the Privacy Act to withhold information
  • Whether the Canada Revenue Agency properly applied paragraph 22(1)(b) of the Privacy Act to withhold information
  • Whether the Canada Revenue Agency properly applied section 26 of the Privacy Act to withhold information
  • Whether the Canada Revenue Agency demonstrated a clear and direct connection between disclosure and a risk of harm under paragraph 22(1)(b)
  • Whether general assertions of harm are sufficient to justify withholding information under paragraph 22(1)(b)
  • Whether the mere fact of an ongoing investigation meets the threshold for harm under paragraph 22(1)(b)
  • Whether the potential for strategic advantage is sufficient to justify withholding information under paragraph 22(1)(b)
  • Whether professional expertise alone is sufficient to substantiate an exemption claim under paragraph 22(1)(b)
  • Whether a case-by-case assessment is required for the application of paragraph 22(1)(b)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 24, 2025Indexed Jun 30, 2026

Measures to anonymize sensitive polygraph records mitigated privacy impacts of NSIRA review

NSIRA Secretariat

The Office of the Privacy Commissioner (OPC) investigated complaints against the NSIRA Secretariat regarding its access to sensitive polygraph records during a review of the Communications Security Establishment's (CSE) Internal Security Program. Complainants questioned whether the collection of personal information complied with section 4 of the Privacy Act and if the Secretariat met its Personal Information Bank (PIB) obligations under section 10. The OPC found that while some un-redacted elements in security screening files posed a re-identification risk, the polygraph recordings themselves were sufficiently anonymized. Given NSIRA's broad mandate and right of access, the OPC concluded the collection issue was not well-founded. However, the Secretariat's delay in requesting approval for PIB changes was found well-founded, though resolved by subsequent submission. The OPC recommended the Secretariat prioritize PIB approvals and publish its Info Source page for transparency. The Secretariat committed to these actions.

Quick view

Privacy ActWell-founded

Measures to anonymize sensitive polygraph records mitigated privacy impacts of NSIRA review

Jan 24, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated complaints against the NSIRA Secretariat regarding its access to sensitive polygraph records during a review of the Communications Security Establishment's (CSE) Internal Security Program. Complainants questioned whether the collection of personal information complied with section 4 of the Privacy Act and if the Secretariat met its Personal Information Bank (PIB) obligations under section 10. The OPC found that while some un-redacted elements in security screening files posed a re-identification risk, the polygraph recordings themselves were sufficiently anonymized. Given NSIRA's broad mandate and right of access, the OPC concluded the collection issue was not well-founded. However, the Secretariat's delay in requesting approval for PIB changes was found well-founded, though resolved by subsequent submission. The OPC recommended the Secretariat prioritize PIB approvals and publish its Info Source page for transparency. The Secretariat committed to these actions.

Key Issues
  • Whether the NSIRA Secretariat's collection of personal information (polygraph records) complied with section 4 of the Privacy Act.
  • Whether the anonymization measures applied to polygraph records were sufficient to prevent re-identification.
  • Whether the NSIRA Secretariat's viewing of personal information, even if not recorded, constituted a 'collection' under section 4.
  • Whether the NSIRA Secretariat met its obligations under section 10 of the Privacy Act regarding Personal Information Banks (PIBs).
  • Whether the NSIRA Secretariat's request for PIB approval was timely.
  • Whether the NSIRA Secretariat published its Info Source page as required by TBS policy.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 28, 2024Indexed Jun 30, 2026

Investigation into the treatment by a government institution of the personal information of two employees with the same name

A federal government institution

An employee complained that her personal information was repeatedly disclosed to another employee with the same name, and that numerous administrative errors occurred in their respective files. The OPC found that the government institution contravened section 8 of the Privacy Act by mistakenly disclosing the complainant's personal information, including her PRI, email, mailing address, and financial and health information. It also contravened subsection 6(2) of the Act by failing to ensure the accuracy of personal information used for administrative purposes, leading to errors in employee files. The OPC concluded that these issues were systemic due to human error and a lack of awareness among employees regarding privacy breach reporting procedures. The institution accepted the OPC's recommendations to prevent unauthorized disclosures and ensure data accuracy, leading to a conditionally resolved finding.

Quick view

Privacy ActWell-founded

Investigation into the treatment by a government institution of the personal information of two employees with the same name

Mar 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee complained that her personal information was repeatedly disclosed to another employee with the same name, and that numerous administrative errors occurred in their respective files. The OPC found that the government institution contravened section 8 of the Privacy Act by mistakenly disclosing the complainant's personal information, including her PRI, email, mailing address, and financial and health information. It also contravened subsection 6(2) of the Act by failing to ensure the accuracy of personal information used for administrative purposes, leading to errors in employee files. The OPC concluded that these issues were systemic due to human error and a lack of awareness among employees regarding privacy breach reporting procedures. The institution accepted the OPC's recommendations to prevent unauthorized disclosures and ensure data accuracy, leading to a conditionally resolved finding.

Key Issues
  • Whether the government institution contravened section 8 of the Privacy Act by mistakenly disclosing the complainant’s personal information to another employee with the same name
  • Whether the government institution contravened subsection 6(2) of the Privacy Act by failing to ensure that personal information used for administrative purposes was accurate, up-to-date, and complete
  • Whether the repeated disclosures and inaccuracies constituted a systemic problem
  • Whether the institution's assessment of the sensitivity of the disclosed information was appropriate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP's collection of personal information via Social Studio complied with Section 4 of the Privacy Act.
  • Whether the RCMP's collection of personal information via Babel X complied with Section 4 of the Privacy Act.
  • Whether the RCMP conducted adequate due diligence on the lawfulness of collection practices of Babel X and its data providers.
  • Whether Section 4 of the Privacy Act permits the collection of personal information from a third-party agent that collected, used, or disclosed the information in contravention of a law that third party is subject to.
  • Whether the RCMP's publicly available descriptions of its open-source information gathering are granular enough to meet transparency obligations under Section 11 of the Privacy Act.
  • Whether the RCMP's published descriptions clarify limits on purposes for collection under Section 11 of the Privacy Act.
  • Whether the RCMP's descriptions of open-source information collection and related purposes are adequate under Section 11 of the Privacy Act.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 24, 2024Indexed Jun 30, 2026

Investigation into a privacy breach at Immigration, Refugees and Citizenship Canada

Immigration, Refugees and Citizenship Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach. IRCC inadvertently disclosed the personal information of 497 individuals when sending mass email notifications for a work permit extension program. An employee failed to apply a filter to the email address column in an Excel spreadsheet, causing email addresses to misalign with other personal data, leading to notifications being sent to incorrect recipients. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose and that its prevention measures were insufficient. While IRCC's mitigation efforts, including notifying affected individuals, were deemed adequate, the OPC recommended implementing robust procedural and administrative controls. IRCC accepted these recommendations, committing to measures such as a 'two pairs of eyes' rule, updated operating procedures, and data quality assurance checks. Consequently, the OPC considered the matter resolved.

Quick view

Privacy ActWell-founded

Investigation into a privacy breach at Immigration, Refugees and Citizenship Canada

Jan 24, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach. IRCC inadvertently disclosed the personal information of 497 individuals when sending mass email notifications for a work permit extension program. An employee failed to apply a filter to the email address column in an Excel spreadsheet, causing email addresses to misalign with other personal data, leading to notifications being sent to incorrect recipients. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose and that its prevention measures were insufficient. While IRCC's mitigation efforts, including notifying affected individuals, were deemed adequate, the OPC recommended implementing robust procedural and administrative controls. IRCC accepted these recommendations, committing to measures such as a 'two pairs of eyes' rule, updated operating procedures, and data quality assurance checks. Consequently, the OPC considered the matter resolved.

Key Issues
  • Whether IRCC's disclosure of personal information to unintended recipients contravened section 8 of the Privacy Act.
  • Whether IRCC had sufficient measures in place to prevent unauthorized disclosures of personal information of this nature.
  • Whether IRCC's response to mitigate the impact of the breach on affected individuals was adequate.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 21, 2023Indexed Jun 30, 2026

Investigation into IRCC’s search for records using modified wording

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) failed to disclose all information sought under the Privacy Act, specifically regarding the cancellation and reissuing of visas for the complainant and her children. The investigation found that IRCC initially narrowed the scope of the request without the complainant's approval and did not conduct a sufficiently broad search for records. The OPC determined that IRCC did not initially conduct a reasonable search for records. However, during the investigation, IRCC expanded its search to include additional offices and a specific former employee's correspondence. Although no additional records were found, IRCC's subsequent efforts satisfied the OPC that it had met its obligations under the Act.

Quick view

Privacy ActWell-founded

Investigation into IRCC’s search for records using modified wording

Sep 21, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) failed to disclose all information sought under the Privacy Act, specifically regarding the cancellation and reissuing of visas for the complainant and her children. The investigation found that IRCC initially narrowed the scope of the request without the complainant's approval and did not conduct a sufficiently broad search for records. The OPC determined that IRCC did not initially conduct a reasonable search for records. However, during the investigation, IRCC expanded its search to include additional offices and a specific former employee's correspondence. Although no additional records were found, IRCC's subsequent efforts satisfied the OPC that it had met its obligations under the Act.

Key Issues
  • Whether IRCC conducted a reasonable search for records responsive to the access request
  • Whether IRCC improperly reduced the scope of the request without the complainant's approval
  • Whether IRCC tasked all appropriate Offices of Primary Interest (OPIs) in its initial search
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 19, 2023Indexed Jun 30, 2026

Canada Post’s collection and use of personal information for marketing purposes not compliant with the Act

Canada Post

An individual complained that Canada Post (CPC) was using personal information gathered from the outside of delivered envelopes and parcels to create mail marketing lists, which it then rented to the private sector. The Office of the Privacy Commissioner (OPC) investigated whether CPC's Smartmail Marketing Program (SMM Program) complied with the Privacy Act. The OPC found that CPC's collection of personal information for the SMM Program was directly related to an operating program (s.4) and that its use and disclosure were for an original purpose of collection (s.7 and s.8), thus compliant with these sections. However, the OPC determined that the SMM Program constituted an "administrative purpose" under the Act, and CPC had failed to obtain individuals' authorization for the indirect collection of their personal information, contravening section 5. CPC disagreed with this finding and refused to implement the OPC's recommendation to cease the practice without authorization, proposing only enhanced transparency measures which the OPC deemed insufficient. Consequently, the complaint was found to be well-founded and not resolved.

Quick view

Privacy ActWell-founded

Canada Post’s collection and use of personal information for marketing purposes not compliant with the Act

Sep 19, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that Canada Post (CPC) was using personal information gathered from the outside of delivered envelopes and parcels to create mail marketing lists, which it then rented to the private sector. The Office of the Privacy Commissioner (OPC) investigated whether CPC's Smartmail Marketing Program (SMM Program) complied with the Privacy Act. The OPC found that CPC's collection of personal information for the SMM Program was directly related to an operating program (s.4) and that its use and disclosure were for an original purpose of collection (s.7 and s.8), thus compliant with these sections. However, the OPC determined that the SMM Program constituted an "administrative purpose" under the Act, and CPC had failed to obtain individuals' authorization for the indirect collection of their personal information, contravening section 5. CPC disagreed with this finding and refused to implement the OPC's recommendation to cease the practice without authorization, proposing only enhanced transparency measures which the OPC deemed insufficient. Consequently, the complaint was found to be well-founded and not resolved.

Key Issues
  • Whether Canada Post's collection of personal information for marketing mail list services complies with section 4 of the Privacy Act (related directly to an operating program or activity).
  • Whether Canada Post's use and disclosure of personal information for marketing mail list services complies with sections 7 and 8 of the Privacy Act (for the purpose obtained or consistent use, or with consent).
  • Whether Canada Post's collection of personal information for marketing mail list services complies with section 5 of the Privacy Act (direct collection for administrative purpose, or with authorization).
  • Whether the use of an individual's information to provide mail marketing services constitutes an "administrative purpose" under section 3 of the Privacy Act.
  • Whether individuals implicitly authorized Canada Post to indirectly collect their personal information for the SMM Program by accepting mail delivery or through the availability of an opt-out mechanism.
  • Whether the exceptions under subsection 5(3) of the Privacy Act apply.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Erroneous quarantine notifications from ArriveCAN

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint regarding erroneous quarantine notifications sent by the ArriveCAN application to approximately 10,200 Apple device users. These notifications, issued between June 28 and July 20, 2022, incorrectly instructed fully vaccinated travellers to quarantine due to a defect in ArriveCAN version 3.0. The OPC found that the Canada Border Services Agency (CBSA) failed to take all reasonable steps to ensure the accuracy of personal information used for an administrative purpose, as required by subsection 6(2) of the Privacy Act. Specifically, the OPC identified shortcomings in rigorous pre-release testing, effective human intervention, and timely correction and recourse for affected individuals. The CBSA disagreed with the finding and refused to implement the OPC's recommendation to correct the inaccurate "quarantine_exempted" value in its database. Consequently, the complaint was found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded

Erroneous quarantine notifications from ArriveCAN

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint regarding erroneous quarantine notifications sent by the ArriveCAN application to approximately 10,200 Apple device users. These notifications, issued between June 28 and July 20, 2022, incorrectly instructed fully vaccinated travellers to quarantine due to a defect in ArriveCAN version 3.0. The OPC found that the Canada Border Services Agency (CBSA) failed to take all reasonable steps to ensure the accuracy of personal information used for an administrative purpose, as required by subsection 6(2) of the Privacy Act. Specifically, the OPC identified shortcomings in rigorous pre-release testing, effective human intervention, and timely correction and recourse for affected individuals. The CBSA disagreed with the finding and refused to implement the OPC's recommendation to correct the inaccurate "quarantine_exempted" value in its database. Consequently, the complaint was found to be well-founded and unresolved.

Key Issues
  • Whether the Canada Border Services Agency (CBSA) took all reasonable steps to ensure that personal information used for an administrative decision was as accurate as possible under subsection 6(2) of the Privacy Act.
  • Whether the "quarantine_exempted" data field constituted personal information used for an administrative purpose by the CBSA.
  • Whether the CBSA conducted rigorous pre-release testing for issues that could lead to the highest negative impacts on individual users.
  • Whether the CBSA ensured effective human intervention with respect to high-impact decisions on individuals.
  • Whether the CBSA provided effective and timely correction and recourse for individuals affected by inaccurate information.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 24, 2023Indexed Jun 30, 2026

CBSA’s use of commercial genetic genealogy in a deportation case contravenes the Privacy Act

Canadian Border Services Agency (CBSA)

A former refugee complained that the Canadian Border Services Agency (CBSA) contravened his privacy rights by using commercial genetic genealogy (FamilyTreeDNA) to determine his nationality for deportation. He alleged lack of legal authority, unnecessary collection, invalid consent, deceptive practices, inadequate disclosure limitation, and insufficient Personal Information Bank (PIB) description. The Office of the Privacy Commissioner (OPC) found that while the collection was directly related to CBSA's program, the agency contravened section 5 of the Privacy Act by failing to obtain valid, informed authorization for indirect collection from FTDNA. CBSA also contravened section 8 by making incidental disclosures of the complainant's personal information to other FTDNA users, failing to monitor account settings, and not using a pseudonym. Furthermore, the CBSA's PIB descriptions were non-compliant with section 11, as they did not adequately describe the collection of genetic profiles of other FTDNA users. The OPC made several recommendations, which CBSA committed to implement for most parts, but two accounts remained open at the time of the report, leading to an ongoing, unresolved contravention. Consequently, the complaint was found well-founded in part and conditionally resolved in part.

Quick view

Privacy ActWell-founded

CBSA’s use of commercial genetic genealogy in a deportation case contravenes the Privacy Act

Apr 24, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

A former refugee complained that the Canadian Border Services Agency (CBSA) contravened his privacy rights by using commercial genetic genealogy (FamilyTreeDNA) to determine his nationality for deportation. He alleged lack of legal authority, unnecessary collection, invalid consent, deceptive practices, inadequate disclosure limitation, and insufficient Personal Information Bank (PIB) description. The Office of the Privacy Commissioner (OPC) found that while the collection was directly related to CBSA's program, the agency contravened section 5 of the Privacy Act by failing to obtain valid, informed authorization for indirect collection from FTDNA. CBSA also contravened section 8 by making incidental disclosures of the complainant's personal information to other FTDNA users, failing to monitor account settings, and not using a pseudonym. Furthermore, the CBSA's PIB descriptions were non-compliant with section 11, as they did not adequately describe the collection of genetic profiles of other FTDNA users. The OPC made several recommendations, which CBSA committed to implement for most parts, but two accounts remained open at the time of the report, leading to an ongoing, unresolved contravention. Consequently, the complaint was found well-founded in part and conditionally resolved in part.

Key Issues
  • Whether CBSA's collection of genetic genealogy information was directly related to an operating program or activity under s.4 of the Privacy Act
  • Whether CBSA collected unnecessary information under s.4 of the Privacy Act
  • Whether CBSA obtained valid authorization from the complainant for the indirect collection of his personal information from FTDNA under s.5(1) of the Privacy Act
  • Whether the complainant's consent for indirect collection was voluntary and not given under duress
  • Whether the complainant was adequately informed about FTDNA's terms and his rights as a DNA donor for valid authorization
  • Whether CBSA acted deceptively in its collection via FTDNA
  • Whether the incidental indirect collection of genetic profile information of hundreds of other individuals contravened s.5(1) of the Privacy Act
  • Whether CBSA's incidental disclosures of the complainant's personal information contravened s.8 of the Privacy Act
  • Whether allowing potential disclosure of the complainant's personal information to other law enforcement bodies (via "law enforcement matching" opt-in) contravened s.8 of the Privacy Act
  • Whether the disclosure of ancillary personal information (ethnicity) to genetic matches contravened s.8 of the Privacy Act
  • Whether the disclosure of the complainant's identity to genetic matches (failure to use a pseudonym) contravened s.8 of the Privacy Act
  • Whether CBSA's Personal Information Bank (PIB) descriptions complied with the transparency obligations under s.11 of the Privacy Act
  • Whether the PIB adequately described the collection of biometric information for individuals subject to removal orders
  • Whether the PIB adequately described the collection of genetic profiles of other FTDNA users (relatives of individuals subject to removal orders)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 31, 2023Indexed Jun 30, 2026

Immigration and Refugee Board of Canada wrongly disclosed intimate and medical information to an employee’s management team via a fitness to work report

Immigration and Refugee Board of Canada (IRB)

An employee of the Immigration and Refugee Board of Canada (IRB) complained that their intimate personal and sensitive medical information, contained in a Fitness to Work (FTW) report, was disclosed to their management team without consent and for no reasonable purpose. The OPC investigated whether the IRB respected section 8 of the Privacy Act, specifically regarding consent and consistent use. The IRB argued the disclosure was a consistent use, but the OPC found that while some information disclosure was consistent, the highly intimate personal and sensitive medical information was not. The OPC concluded that the IRB contravened the Act by disclosing information internally that fell outside what is permissible. Despite some new processes, the IRB did not fully acknowledge wrongdoing or agree to all recommendations, leading to a well-founded and unresolved finding.

Quick view

Privacy ActWell-founded

Immigration and Refugee Board of Canada wrongly disclosed intimate and medical information to an employee’s management team via a fitness to work report

Mar 31, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee of the Immigration and Refugee Board of Canada (IRB) complained that their intimate personal and sensitive medical information, contained in a Fitness to Work (FTW) report, was disclosed to their management team without consent and for no reasonable purpose. The OPC investigated whether the IRB respected section 8 of the Privacy Act, specifically regarding consent and consistent use. The IRB argued the disclosure was a consistent use, but the OPC found that while some information disclosure was consistent, the highly intimate personal and sensitive medical information was not. The OPC concluded that the IRB contravened the Act by disclosing information internally that fell outside what is permissible. Despite some new processes, the IRB did not fully acknowledge wrongdoing or agree to all recommendations, leading to a well-founded and unresolved finding.

Key Issues
  • Whether the IRB obtained valid consent for the disclosure of the FTW report to the management team under section 8(1) of the Privacy Act
  • Whether the disclosure of intimate personal and sensitive medical information in the FTW report to the management team was a 'consistent use' under section 8(2)(a) of the Privacy Act
  • Whether the IRB adhered to the Treasury Board Secretariat's Occupational Health Evaluation Standard regarding disclosure of medical information to employers
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 2, 2022Indexed Jun 30, 2026

Canada Border Services Agency over-discloses personal information to the Information Commissioner in relation to an ATIA request

Canada Border Services Agency (CBSA)

An individual complained that the Canada Border Services Agency (CBSA) over-disclosed their personal information to the Information Commissioner (IC) when seeking approval to decline two Access to Information Act (ATIA) requests. The CBSA provided not only information related to the ATIA requests but also a sensitive labour relations report about the complainant. The CBSA argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, as the information was collected in the context of workplace conflict and the disclosure was to determine how to handle the complainant's requests for their personal information. The OPC found that while information related to the ATIA requests was a consistent use, the disclosure of the labour relations report was not, as its original purpose (addressing workplace conflict) was distinct from responding to ATIA requests. The OPC concluded that the CBSA contravened section 8 of the Privacy Act and recommended the CBSA develop guidance for consistent use disclosures. The CBSA disagreed with the finding and declined to implement the recommendation, leading to a "well-founded and not resolved" outcome.

Quick view

Privacy ActWell-founded

Canada Border Services Agency over-discloses personal information to the Information Commissioner in relation to an ATIA request

Dec 2, 2022
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that the Canada Border Services Agency (CBSA) over-disclosed their personal information to the Information Commissioner (IC) when seeking approval to decline two Access to Information Act (ATIA) requests. The CBSA provided not only information related to the ATIA requests but also a sensitive labour relations report about the complainant. The CBSA argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, as the information was collected in the context of workplace conflict and the disclosure was to determine how to handle the complainant's requests for their personal information. The OPC found that while information related to the ATIA requests was a consistent use, the disclosure of the labour relations report was not, as its original purpose (addressing workplace conflict) was distinct from responding to ATIA requests. The OPC concluded that the CBSA contravened section 8 of the Privacy Act and recommended the CBSA develop guidance for consistent use disclosures. The CBSA disagreed with the finding and declined to implement the recommendation, leading to a "well-founded and not resolved" outcome.

Key Issues
  • Whether the disclosure of personal information to the Information Commissioner was for a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether information collected for administering ATIA requests can be disclosed to the IC as a consistent use
  • Whether a labour relations report, originally collected for addressing workplace conflict, can be disclosed to the IC as a consistent use in the context of ATIA requests
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 31, 2020Indexed Jun 30, 2026

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Employment and Social Development Canada (ESDC)

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Quick view

Privacy ActWell-founded

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Jan 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Key Issues
  • Whether the collection of video surveillance footage constituted personal information under s.3 of the Privacy Act
  • Whether the initial collection of video surveillance footage by ESDC was in compliance with s.4 of the Privacy Act
  • Whether ESDC informed individuals of the purpose for collecting personal information via video surveillance, as required by s.5 of the Privacy Act
  • Whether ESDC's use of video surveillance footage to monitor an employee's departure times was consistent with the purpose for which it was collected, as required by s.7(a) of the Privacy Act
  • Whether ESDC obtained consent for the use of video surveillance footage for purposes other than security, as required by s.7(a) of the Privacy Act