The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

75 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 21, 2019Indexed Jun 30, 2026

Crossing the line? The CBSA’s examination of digital devices at the border

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Quick view

Privacy ActWell-founded

Crossing the line? The CBSA’s examination of digital devices at the border

Oct 21, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Key Issues
  • Whether CBSA's collection of personal information via digital device searches contravened section 4 of the Privacy Act.
  • Whether the definition of "goods" under the Customs Act extends to electronic documents on digital devices.
  • Whether CBSA's authority to search digital devices is limited to information stored on the device.
  • Whether Border Services Officers (BSOs) complied with CBSA's internal policy (Operational Bulletin PRG-2015-31) regarding digital device examinations (e.g., airplane mode, note-taking, search threshold).
  • Whether the copying of content from a digital device by a BSO was consistent with CBSA's legal authority and policy.
  • Whether the CBSA complied with its obligations under subsection 6(1) of the Privacy Act to retain personal information used for administrative purposes.
  • Whether the CBSA's practices regarding training, awareness, and accountability mechanisms for digital device searches were adequate.
  • Whether the Customs Act requires amendment to include a clear legal framework and a higher threshold for digital device examinations.
  • Whether the threshold for digital device examinations should be "reasonable grounds to suspect".
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 29, 2019Indexed Jun 30, 2026

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Global Affairs Canada

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Quick view

Privacy ActWell-founded

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Mar 29, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Key Issues
  • Whether the information in the diplomatic passport constitutes personal information under s.3 of the Privacy Act
  • Whether Global Affairs Canada's request for the diplomatic passport constituted a collection of personal information
  • Whether Global Affairs Canada demonstrated its authority to collect the personal travel information under s.4 of the Privacy Act
  • Whether the collection of personal travel information related directly to an operating program or activity of Global Affairs Canada
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 28, 2019Indexed Jun 30, 2026

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Employment and Social Development Canada (ESDC)

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Quick view

Privacy ActWell-founded

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Mar 28, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Key Issues
  • Whether the complainant's name, telephone number, and email address constitute personal information under the Act
  • Whether ESDC was required to collect personal information directly from the complainant under section 5 of the Act
  • Whether ESDC complied with section 4 of the Act regarding the collection of personal information
  • Whether ESDC adequately ensured Grey House Publishing Canada complied with consent requirements as per their contract
  • Whether ESDC improperly collected the complainant's information after he requested removal from the distribution list
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 11, 2019Indexed Jun 30, 2026

The name of an individual is considered personal information if it is accompanied by information that is about the individual

Canadian Transportation Agency (CTA)

The complainant, an air passenger rights advocate, requested access to all records about himself held by the Canadian Transportation Agency (CTA). The CTA initially withheld 760 pages, arguing that most references to the complainant's name were not personal information because he was acting on behalf of an organization. The OPC found that the information was indeed personal information, as the organization was not a separate legal entity and the records contained views and information directly about the complainant. The OPC also found that the CTA incorrectly applied exemptions under section 26 (third-party personal information) and subsection 70(1) (cabinet confidences) in some instances, and over-redacted under section 27 (solicitor-client privilege). The complaint was found to be well-founded, and the CTA agreed to implement the OPC's recommendations to disclose the withheld information.

Quick view

Privacy ActWell-founded

The name of an individual is considered personal information if it is accompanied by information that is about the individual

Feb 11, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, an air passenger rights advocate, requested access to all records about himself held by the Canadian Transportation Agency (CTA). The CTA initially withheld 760 pages, arguing that most references to the complainant's name were not personal information because he was acting on behalf of an organization. The OPC found that the information was indeed personal information, as the organization was not a separate legal entity and the records contained views and information directly about the complainant. The OPC also found that the CTA incorrectly applied exemptions under section 26 (third-party personal information) and subsection 70(1) (cabinet confidences) in some instances, and over-redacted under section 27 (solicitor-client privilege). The complaint was found to be well-founded, and the CTA agreed to implement the OPC's recommendations to disclose the withheld information.

Key Issues
  • Whether information relating to the complainant's advocacy activities, where his name appears, constitutes personal information under section 3 of the Privacy Act
  • Whether the CTA correctly invoked paragraph 12(1)(b) to deny access to information it deemed not to be personal information
  • Whether the CTA correctly withheld third-party personal information under section 26 of the Privacy Act
  • Whether the CTA correctly withheld information under section 27 of the Privacy Act (solicitor-client privilege)
  • Whether the CTA correctly withheld information under subsection 70(1) of the Privacy Act (cabinet confidences)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 20, 2018Indexed Jun 30, 2026

Innovation, Science and Economic Development Canada fails to ensure that the information it used to staff a position was accurate

Innovation, Science and Economic Development Canada (ISED)

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) used inaccurate personal information about him when staffing a position. ISED acknowledged that its Human Resources officials mistakenly selected the complainant's profile in the MyGCHR system instead of another individual with the same name, leading to the complainant being 'hired' by ISED and 'terminated' from his position at Public Services and Procurement Canada (PSPC). This error caused the complainant to miss pay periods. The OPC found that ISED did not take all reasonable steps to ensure the accuracy of the personal information, as officials only used first and last names for the search and did not verify with additional identifiers like a Personal Record Identifier (PRI) or date of birth. The complaint was found to be well-founded, but ISED has since implemented a new policy requiring staff to validate identities using multiple data fields.

Quick view

Privacy ActWell-founded

Innovation, Science and Economic Development Canada fails to ensure that the information it used to staff a position was accurate

Aug 20, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) used inaccurate personal information about him when staffing a position. ISED acknowledged that its Human Resources officials mistakenly selected the complainant's profile in the MyGCHR system instead of another individual with the same name, leading to the complainant being 'hired' by ISED and 'terminated' from his position at Public Services and Procurement Canada (PSPC). This error caused the complainant to miss pay periods. The OPC found that ISED did not take all reasonable steps to ensure the accuracy of the personal information, as officials only used first and last names for the search and did not verify with additional identifiers like a Personal Record Identifier (PRI) or date of birth. The complaint was found to be well-founded, but ISED has since implemented a new policy requiring staff to validate identities using multiple data fields.

Key Issues
  • Whether the information at issue constituted personal information under section 3 of the Privacy Act
  • Whether ISED took all reasonable steps to ensure that the personal information it used for an administrative purpose was as accurate, up-to-date and complete as possible, as required by subsection 6(2) of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 12, 2018Repeat offenderIndexed Jun 30, 2026

Repeat offender: CSC unlawfully denies complainant access to his personal information a second time

Correctional Service Canada (CSC)

A federal inmate complained that Correctional Service Canada (CSC) repeatedly denied him access to his personal information, specifically video and audio recordings, in contravention of the Privacy Act. This complaint followed a similar investigation in 2012 where the OPC found serious deficiencies in CSC's handling of the complainant's requests, including failure to retain video recordings before destruction. In the current investigation, the OPC found that CSC again failed to retrieve and retain requested video recordings within their short retention period in two cases, and failed to respond to four other requests for grievance-related records. The OPC concluded that CSC contravened subsection 12(1) of the Privacy Act by denying the complainant access to his personal information. CSC accepted the OPC's recommendations to improve its processes for handling access requests for records with short retention periods and to respond to outstanding requests.

Quick view

Privacy ActWell-founded

Repeat offender: CSC unlawfully denies complainant access to his personal information a second time

Jun 12, 2018Repeat offender
Adjudicator: Daniel Therrien
Plain-Language Summary

A federal inmate complained that Correctional Service Canada (CSC) repeatedly denied him access to his personal information, specifically video and audio recordings, in contravention of the Privacy Act. This complaint followed a similar investigation in 2012 where the OPC found serious deficiencies in CSC's handling of the complainant's requests, including failure to retain video recordings before destruction. In the current investigation, the OPC found that CSC again failed to retrieve and retain requested video recordings within their short retention period in two cases, and failed to respond to four other requests for grievance-related records. The OPC concluded that CSC contravened subsection 12(1) of the Privacy Act by denying the complainant access to his personal information. CSC accepted the OPC's recommendations to improve its processes for handling access requests for records with short retention periods and to respond to outstanding requests.

Key Issues
  • Whether CSC contravened subsection 6(1) of the Privacy Act by failing to retain personal information for a prescribed period
  • Whether CSC contravened subsection 12(1) of the Privacy Act by failing to provide access to personal information
  • Whether CSC contravened subsection 16(3) of the Privacy Act by failing to respond to access requests within statutory time limits
  • Whether CSC appropriately applied paragraph 22(1)(c) of the Privacy Act to withhold video recordings
  • Whether CSC appropriately applied section 26 of the Privacy Act to withhold video recordings
  • Whether CSC made reasonable efforts to secure video recordings before destruction as per previous OPC recommendations
  • Whether CSC's processes for handling access requests for records with short retention periods are adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 4, 2018Indexed Jun 30, 2026

Employee text messages intercepted without authorization at the Warkworth Institution

Correctional Service Canada (CSC)

The OPC received complaints alleging that Correctional Service Canada (CSC) contravened the Privacy Act by intercepting cell phone conversations and text messages near Warkworth Institution. CSC confirmed intercepting six text messages but denied recording conversations, stating it did not intend to collect text messages. The investigation found that CSC used a cell-site simulator, operated by a contractor, to detect unauthorized cell phone use by inmates. While the collection of metadata was deemed consistent with the Act due to security concerns, the interception of text message content was not authorized. The OPC concluded that CSC was responsible for the contractor's actions and that the collection of text messages contravened the Privacy Act. The complaints were found to be well-founded.

Quick view

Privacy ActWell-founded

Employee text messages intercepted without authorization at the Warkworth Institution

Jun 4, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC received complaints alleging that Correctional Service Canada (CSC) contravened the Privacy Act by intercepting cell phone conversations and text messages near Warkworth Institution. CSC confirmed intercepting six text messages but denied recording conversations, stating it did not intend to collect text messages. The investigation found that CSC used a cell-site simulator, operated by a contractor, to detect unauthorized cell phone use by inmates. While the collection of metadata was deemed consistent with the Act due to security concerns, the interception of text message content was not authorized. The OPC concluded that CSC was responsible for the contractor's actions and that the collection of text messages contravened the Privacy Act. The complaints were found to be well-founded.

Key Issues
  • Whether cell phone metadata constitutes personal information under the Privacy Act
  • Whether text messages constitute personal information under the Privacy Act
  • Whether the collection of cell phone metadata by CSC was consistent with section 4 of the Privacy Act
  • Whether the interception and collection of text message content by CSC was consistent with section 4 of the Privacy Act
  • Whether CSC is responsible for the actions of its contractor in collecting personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 12, 2018Indexed Jun 30, 2026

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Health Canada

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Quick view

Privacy ActWell-founded

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Mar 12, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Key Issues
  • Whether the information collected by Health Canada on Limited Use forms for drug benefits constitutes personal information under the Privacy Act
  • Whether Health Canada's collection of personal information on Limited Use forms relates directly to an operating program or activity of the institution as required by section 4 of the Privacy Act
  • Whether the specific data fields requesting detailed diagnostic information (e.g., exact number of swollen joints) are necessary for the adjudication of drug benefit claims under the NIHB Program
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 16, 2017Indexed Jun 30, 2026

Cell site simulators used by RCMP not capable of intercepting private communication

Royal Canadian Mounted Police (RCMP)

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Quick view

Privacy ActWell-founded

Cell site simulators used by RCMP not capable of intercepting private communication

Aug 16, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Key Issues
  • Whether RCMP uses cell site simulators (MDIs)
  • Whether RCMP's MDIs are capable of intercepting private communications (voice, text, email, encryption keys)
  • Whether RCMP's collection of personal information using MDIs relates directly to an operating program or activity (s.4 Privacy Act)
  • Whether RCMP's collection of personal information using MDIs was lawful and Charter-compliant, specifically regarding prior judicial authorization
  • Whether exigent circumstances justified warrantless MDI deployments in certain cases
  • Whether RCMP's collection of personal information using MDIs complied with direct collection and notification requirements (s.5 Privacy Act)
  • Whether the RCMP adequately handles, retains, and disposes of third-party personal information (IMSI/IMEI numbers) collected by MDIs
  • Whether the wording in warrants and policies provides adequate protection for collected personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 19, 2017Indexed Jun 30, 2026

MyDemocracy website not designed in a privacy sensitive way

Privy Council Office

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Quick view

Privacy ActWell-founded

MyDemocracy website not designed in a privacy sensitive way

Jul 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Key Issues
  • Whether the MyDemocracy.ca website's design led to the disclosure of personal information to third parties (Facebook, Google Analytics) without consent.
  • Whether IP addresses, browser characteristics, and unique URLs constitute "personal information" under section 3 of the Privacy Act.
  • Whether the Privy Council Office (PCO) met its obligations under section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether PCO's amendments to the website and privacy policy were sufficient to obtain meaningful consent for data disclosure.
  • Whether PCO should have conducted a Privacy Impact Assessment (PIA) for the MyDemocracy.ca initiative.
  • Whether the collection of demographic information was justified and compliant with relevant standards.
  • Whether the use of Google Analytics complied with the Treasury Board of Canada Secretariat's (TBS) Standard on Privacy and Web Analytics.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Phoenix pay system compromised Public Servants’ privacy

Public Services and Procurement Canada

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Quick view

Privacy ActWell-founded

Phoenix pay system compromised Public Servants’ privacy

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Key Issues
  • Whether personal information was at issue in the reported incidents
  • Whether the personal information at issue was improperly disclosed
  • What was the scope of the improper disclosure
  • Whether the personal information that was improperly disclosed was misused
  • Whether PSPC was aware of potential privacy issues with Phoenix before the launch
  • What kind of harm could result from the unauthorized disclosure of the personal information at issue
  • Whether PSPC resolved all of the vulnerabilities within Phoenix
  • Whether PSPC provided individuals with timely information regarding the breaches and vulnerabilities
  • Whether PSPC developed and implemented controls to monitor and document access to personal information held in Phoenix (Recommendation 1)
  • Whether PSPC developed more robust testing and response procedures (Recommendation 2)
  • Whether PSPC conducted necessary assessments to identify potential risks and vulnerabilities in Phoenix (Recommendation 3)
  • Whether PSPC took measures to mitigate the increased vulnerability of information used by employees in call centres (Recommendation 4)
  • Whether PSPC reviewed its breach notification practices and provided notification of the extent of the Phoenix breaches (Recommendation 5)
  • Whether PSPC completed the review of pages with row-level security (Recommendation 6)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Health Canada

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Quick view

Privacy ActWell-founded

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Key Issues
  • Whether diagnostic information about individual patients constitutes 'personal information' under s.3 of the Privacy Act
  • Whether Health Canada contravened s.4 of the Privacy Act by collecting diagnostic information about patients seeking medical transportation and specialist services that was not directly related to an operating program or activity
  • Whether the collection of diagnostic information was demonstrably necessary to achieve a specific and legitimate purpose
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 19, 2017Indexed Jun 30, 2026

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Royal Canadian Mounted Police (RCMP)

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Quick view

Privacy ActWell-founded

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Apr 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Key Issues
  • Whether the RCMP inappropriately disclosed the complainant's personal information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(f) of the Privacy Act.
  • Whether CBP's use of the complainant's personal information for an admissibility assessment constituted "criminal justice purposes" or "law enforcement" as defined in the Memorandum of Cooperation (MOC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(a) of the Privacy Act as a "consistent use."
  • Whether the CPIC policies in effect at the time provided sufficient clarity to guard against unauthorized disclosure of sensitive personal information.
  • Whether the revised CPIC policies, including the "SHARE US A" feature and "SIP-OB" entries, adequately protect against unauthorized disclosure of attempted suicide information.
  • Whether the default setting of the "SHARE US A" feature in CPIC should suppress the sharing of SIP-OB entries relating to threatened or attempted suicides with US border officials.
  • Whether CPIC policies should be revised to provide clear guidance for sharing attempted suicide information with US border officials only where an individual presents an ongoing risk to others.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 20, 2016Indexed Jun 30, 2026

The PBC refuses to process requests for record suspension information

Parole Board of Canada

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Quick view

Privacy ActWell-founded

The PBC refuses to process requests for record suspension information

Dec 20, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Key Issues
  • Whether an individual can make a request under the Privacy Act to confirm that no personal information relating to record suspensions exists.
  • Whether the PBC properly applied the exemption under paragraph 22(1)(b) of the Privacy Act to refuse access requests for record suspension information.
  • Whether the disclosure of record suspension information under the Privacy Act would injure the enforcement of the Criminal Records Act.
  • Whether the PBC's requirement for additional identification (FPS number, PBC reference number, criminal record copy) is necessary to adequately identify a requester under the Privacy Act.
  • Whether the company's record suspension verification service circumvents the vulnerable sector verification process under the CRA.
  • Whether the consent obtained by the company for its service is valid.
  • Whether the proposed use of personal information by the company violates human rights legislation.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 6, 2016Indexed Jun 30, 2026

TV show raises numerous questions of consent

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Quick view

Privacy ActWell-founded

TV show raises numerous questions of consent

Jun 6, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Key Issues
  • Whether the CBSA, as a federal institution, could contract out of its obligations under the Privacy Act
  • Whether the CBSA's collection of personal information in connection with the TV Program related directly to an operating program or activity of the institution (s.4 Privacy Act)
  • Whether the CBSA was involved in the collection of personal information for the purposes of the TV Program
  • Whether there was a real-time disclosure of personal information by the CBSA to Force Four for the purpose of filming the TV Program
  • Whether the CBSA obtained valid, meaningful, and freely given consent from individuals, including the complainant, for the disclosure of their personal information to Force Four (s.8 Privacy Act)
  • Whether the "Voluntary Appearance Release Form" (Waiver) effectively waived individuals' rights under the Privacy Act
  • Whether the practice of "silent filming" by the production crew was consistent with obtaining valid consent
  • Whether the CBSA disclosed personal information of an intended subject to Force Four in advance of filming without authorization (s.8 Privacy Act)
  • Whether the personal information of the intended subject was publicly available at the time of disclosure
  • Whether the facial blurring and other identity concealment techniques used in the TV Program were sufficient to prevent the identification of individuals who had not provided written consent
  • Whether the CBSA demonstrated how the disclosure of personal information of individuals without written consent was consistent with section 8 of the Privacy Act