The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

75 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 30, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – RCMP

Royal Canadian Mounted Police (RCMP)

The complainant, an RCMP employee, alleged that the RCMP inappropriately used employees' personal information during a training course for Respectful Workplace Advisors on the National Administrative Records Management System (NARMS). During a data entry exercise, participants were given sheets containing real personal information of 91 employees, including names, ranks, and incident descriptions. The complainant raised concerns as participants were not advised real data would be used nor required to sign confidentiality agreements. The RCMP acknowledged that the use of this personal information for training purposes was not authorized under section 7 of the Privacy Act, as training was not a consistent use described in the applicable Personal Information Bank. The RCMP subsequently notified all 91 affected employees of the breach and took steps to prevent future occurrences. The OPC found the complaint to be well-founded.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – RCMP

Jul 30, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, an RCMP employee, alleged that the RCMP inappropriately used employees' personal information during a training course for Respectful Workplace Advisors on the National Administrative Records Management System (NARMS). During a data entry exercise, participants were given sheets containing real personal information of 91 employees, including names, ranks, and incident descriptions. The complainant raised concerns as participants were not advised real data would be used nor required to sign confidentiality agreements. The RCMP acknowledged that the use of this personal information for training purposes was not authorized under section 7 of the Privacy Act, as training was not a consistent use described in the applicable Personal Information Bank. The RCMP subsequently notified all 91 affected employees of the breach and took steps to prevent future occurrences. The OPC found the complaint to be well-founded.

Key Issues
  • Whether the use of employees' personal information for training purposes constituted an unauthorized use under section 7(a) of the Privacy Act
  • Whether training was a consistent use of personal information as described in the applicable Personal Information Bank (PIB PSU 915)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 28, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – Parole Board of Canada

Parole Board of Canada

The complaint alleged that the Parole Board of Canada (PBC) contravened the disclosure provisions of the Privacy Act when a human resources employee disclosed the complainant's medical information to individuals involved in a Public Service Staffing Tribunal (PSST) hearing. The PSST had specifically ordered the PBC to remove medical information from the material provided. The PBC acknowledged the disclosure, apologized to the complainant, and ensured the recipients disposed of the information. The OPC found that the complainant's medical information was disclosed without consent and not under any permitted disclosure provision of subsection 8(2) of the Act. Therefore, the OPC concluded that the complaint was well-founded.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – Parole Board of Canada

Jul 28, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint alleged that the Parole Board of Canada (PBC) contravened the disclosure provisions of the Privacy Act when a human resources employee disclosed the complainant's medical information to individuals involved in a Public Service Staffing Tribunal (PSST) hearing. The PSST had specifically ordered the PBC to remove medical information from the material provided. The PBC acknowledged the disclosure, apologized to the complainant, and ensured the recipients disposed of the information. The OPC found that the complainant's medical information was disclosed without consent and not under any permitted disclosure provision of subsection 8(2) of the Act. Therefore, the OPC concluded that the complaint was well-founded.

Key Issues
  • Whether the complainant's medical information constitutes personal information under s.3 of the Privacy Act
  • Whether the disclosure of the complainant's medical information by the PBC contravened s.8(1) of the Privacy Act
  • Whether the disclosure was in accordance with any of the permitted categories under s.8(2) of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 29, 2015Indexed Jun 30, 2026

Disclosure to Interpol raises concerns regarding electronic transmission of personal information

Canada Border Services Agency

The complainant alleged that the Canada Border Services Agency (CBSA) improperly disclosed his personal information, including a judgment from his country of origin, to the High Commission of Canada in Ghana and subsequently to Interpol, without his consent. This disclosure occurred during the verification of documents submitted for his refugee claim, which alleged persecution by the Nigerian government. The CBSA argued the disclosure was a consistent use under the Privacy Act for refugee determination and enforcement of the IRPA, necessary to verify the authenticity of the judgment after other documents were found fraudulent. The OPC found that the disclosure itself was permitted under paragraph 8(2)(a) of the Privacy Act as a consistent use for refugee determination purposes, thus concluding the primary complaint was "not well-founded." However, the OPC raised significant concerns regarding the CBSA's lack of established procedures for such verifications at the time, and the use of insecure commercial email (Yahoo!) for transmitting sensitive personal information of a refugee claimant. The OPC emphasized the inherent sensitivity of such information and the potential risk to claimants, recommending that CBSA review and strengthen its procedures, particularly concerning secure transmission methods and training. The OPC also noted it lacked jurisdiction over the actions of Interpol or Nigerian authorities.

Quick view

Privacy ActWell-founded

Disclosure to Interpol raises concerns regarding electronic transmission of personal information

Apr 29, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) improperly disclosed his personal information, including a judgment from his country of origin, to the High Commission of Canada in Ghana and subsequently to Interpol, without his consent. This disclosure occurred during the verification of documents submitted for his refugee claim, which alleged persecution by the Nigerian government. The CBSA argued the disclosure was a consistent use under the Privacy Act for refugee determination and enforcement of the IRPA, necessary to verify the authenticity of the judgment after other documents were found fraudulent. The OPC found that the disclosure itself was permitted under paragraph 8(2)(a) of the Privacy Act as a consistent use for refugee determination purposes, thus concluding the primary complaint was "not well-founded." However, the OPC raised significant concerns regarding the CBSA's lack of established procedures for such verifications at the time, and the use of insecure commercial email (Yahoo!) for transmitting sensitive personal information of a refugee claimant. The OPC emphasized the inherent sensitivity of such information and the potential risk to claimants, recommending that CBSA review and strengthen its procedures, particularly concerning secure transmission methods and training. The OPC also noted it lacked jurisdiction over the actions of Interpol or Nigerian authorities.

Key Issues
  • Whether the disclosure of the complainant's personal information (including the Judgment) by CBSA to the High Commission and Interpol without consent contravened section 8 of the Privacy Act.
  • Whether the disclosure was for a purpose consistent with the original collection under paragraph 8(2)(a) of the Privacy Act.
  • Whether CBSA's procedures for verifying documents with countries of origin and Interpol were sufficient at the time of disclosure.
  • Whether the electronic transmission of personal information via commercial email (Yahoo!) was secure and appropriate given the sensitivity.
  • Whether the OPC had jurisdiction over alleged secondary disclosures by Interpol or Nigerian authorities.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 16, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – Public Services and Procurement Canada

Public Services and Procurement Canada (PSPC)

An individual complained that Public Services and Procurement Canada (PSPC) mishandled her personal information by disclosing that she had filed a harassment complaint against her Director. The complainant alleged that the Director revealed this information during a management meeting. The investigation confirmed that the Director disclosed at a management meeting that the complainant had filed a complaint against her, as evidenced by meeting notes and confirmations from attendees. While the Director claimed the information was also her personal information, the OPC found no evidence that the employees present at the meeting needed to know the complainant's identity. The OPC concluded that PSPC did not reasonably consider the appropriateness of disclosing the complainant's identity without her consent, violating the Privacy Act.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – Public Services and Procurement Canada

Apr 16, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Public Services and Procurement Canada (PSPC) mishandled her personal information by disclosing that she had filed a harassment complaint against her Director. The complainant alleged that the Director revealed this information during a management meeting. The investigation confirmed that the Director disclosed at a management meeting that the complainant had filed a complaint against her, as evidenced by meeting notes and confirmations from attendees. While the Director claimed the information was also her personal information, the OPC found no evidence that the employees present at the meeting needed to know the complainant's identity. The OPC concluded that PSPC did not reasonably consider the appropriateness of disclosing the complainant's identity without her consent, violating the Privacy Act.

Key Issues
  • Whether the disclosure of the complainant's identity as having filed a harassment complaint constituted personal information under s.3 of the Privacy Act
  • Whether the disclosure of the complainant's identity was made without her consent
  • Whether the disclosure was for a purpose consistent with the purpose for which the information was obtained or compiled, as per s.8(2)(a) of the Privacy Act
  • Whether the employees present at the meeting needed to know the complainant's identity
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 3, 2015Indexed Jun 30, 2026

Accidental disclosure by Health Canada - March 3, 2015

Health Canada

The Office of the Privacy Commissioner (OPC) initiated a complaint against Health Canada (HC) after HC sent 41,514 letters to "Marihuana Medical Access Program" (MMAP) clients in windowed envelopes that allowed the program name to be openly visible. The OPC also received 339 individual complaints regarding this incident. Complainants were concerned that the visible program name revealed their association with MMAP to Canada Post employees and the public, potentially impacting their careers, reputation, and safety due to the stigma associated with marihuana. HC argued that the disclosure was implicitly consented to, was a consistent use of information, or was not an unlawful disclosure by HC. The OPC found that the combination of the MMAP name and the individual's name and address constituted sensitive personal information. HC failed to demonstrate appropriate consent or that any permissible disclosures under section 8(2) of the Privacy Act applied. The OPC concluded that HC contravened the Privacy Act.

Quick view

Privacy ActWell-founded

Accidental disclosure by Health Canada - March 3, 2015

Mar 3, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) initiated a complaint against Health Canada (HC) after HC sent 41,514 letters to "Marihuana Medical Access Program" (MMAP) clients in windowed envelopes that allowed the program name to be openly visible. The OPC also received 339 individual complaints regarding this incident. Complainants were concerned that the visible program name revealed their association with MMAP to Canada Post employees and the public, potentially impacting their careers, reputation, and safety due to the stigma associated with marihuana. HC argued that the disclosure was implicitly consented to, was a consistent use of information, or was not an unlawful disclosure by HC. The OPC found that the combination of the MMAP name and the individual's name and address constituted sensitive personal information. HC failed to demonstrate appropriate consent or that any permissible disclosures under section 8(2) of the Privacy Act applied. The OPC concluded that HC contravened the Privacy Act.

Key Issues
  • Whether the phrase "Marihuana Medical Access Program" combined with an individual's name and address constitutes personal information under section 3 of the Privacy Act
  • Whether subsequent actions by individuals (e.g., media communication) alter Health Canada's obligations under the Privacy Act
  • Whether mail recipients implicitly consented to the disclosure of their personal information under section 8(1) of the Privacy Act
  • Whether the disclosure was a "consistent use" under section 8(2)(a) of the Privacy Act
  • Whether limiting information on return address blocks would have broad implications for government communication
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 10, 2015Indexed Jun 30, 2026

Records deemed 'transitory' prematurely destroyed - February 10, 2015

Department of National Defence (DND)

A former Canadian Forces member complained that the Department of National Defence (DND) prematurely destroyed an audio recording of his Progress Review Board (PRB) hearing, thereby contravening the retention and disposal provisions of the Privacy Act. The complainant argued that the recording was personal information used for an administrative purpose and should have been retained for a reasonable period to allow him access. DND contended the recording was a "transitory" record, destroyed after minutes were drafted, and that the complainant had implicitly consented to its disposal by signing the minutes. The OPC found that the audio recording contained personal information used for an administrative purpose and that the complainant had not consented to its disposal. Therefore, DND was obligated to retain the recording for at least two years.

Quick view

Privacy ActWell-founded

Records deemed 'transitory' prematurely destroyed - February 10, 2015

Feb 10, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

A former Canadian Forces member complained that the Department of National Defence (DND) prematurely destroyed an audio recording of his Progress Review Board (PRB) hearing, thereby contravening the retention and disposal provisions of the Privacy Act. The complainant argued that the recording was personal information used for an administrative purpose and should have been retained for a reasonable period to allow him access. DND contended the recording was a "transitory" record, destroyed after minutes were drafted, and that the complainant had implicitly consented to its disposal by signing the minutes. The OPC found that the audio recording contained personal information used for an administrative purpose and that the complainant had not consented to its disposal. Therefore, DND was obligated to retain the recording for at least two years.

Key Issues
  • Whether the audio recording contained the complainant's "personal information" as defined by the Act
  • Whether the personal information in the audio recording was used for an "administrative purpose"
  • Whether the complainant consented to the disposal of the information
  • Whether DND's classification of the recording as "transitory" exempted it from Privacy Act retention requirements
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 3, 2014Indexed Jun 30, 2026

Canada Revenue Agency and the Canadian Broadcasting Corporation (CRA) - 2015

Canada Revenue Agency

The Canada Revenue Agency (CRA) inadvertently mailed the personal information of approximately 1,000 individuals to a Canadian Broadcasting Corporation (CBC) journalist. This occurred due to an ATIP clerk mistakenly switching cover letters for two different response packages. The disclosed information included names, addresses, and details of donations. The CBC refused the CRA's requests to return the information, leading the CRA to initiate legal action. The OPC found that the CRA disclosed personal information without consent, contravening the Privacy Act. While the OPC noted the CRA's immediate remedial actions and action plan, it concluded that the disclosure did not meet the requirements of the Act.

Quick view

Privacy ActWell-founded

Canada Revenue Agency and the Canadian Broadcasting Corporation (CRA) - 2015

Dec 3, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canada Revenue Agency (CRA) inadvertently mailed the personal information of approximately 1,000 individuals to a Canadian Broadcasting Corporation (CBC) journalist. This occurred due to an ATIP clerk mistakenly switching cover letters for two different response packages. The disclosed information included names, addresses, and details of donations. The CBC refused the CRA's requests to return the information, leading the CRA to initiate legal action. The OPC found that the CRA disclosed personal information without consent, contravening the Privacy Act. While the OPC noted the CRA's immediate remedial actions and action plan, it concluded that the disclosure did not meet the requirements of the Act.

Key Issues
  • Whether the inadvertent mailing of personal information to a journalist constituted a disclosure without consent under the Privacy Act
  • Whether the information disclosed was 'personal information' as defined by section 3 of the Privacy Act
  • Whether the disclosure met the requirements of section 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2014Indexed Jun 30, 2026

Collection of RCMP member's health information unnecessary (RCMP) - November 17, 2014

Royal Canadian Mounted Police (RCMP)

A former RCMP member complained that the RCMP inappropriately collected her personal medical and financial information from Veterans Affairs Canada (VAC) after she was awarded a disability pension. The complainant alleged that the RCMP's National Compensation Policy Centre had no need for this sensitive information. The OPC found that the 2002 Memorandum of Understanding (MOU) between the RCMP and VAC transferred responsibility for pension administration to VAC, meaning the RCMP's National Compensation Policy Centre did not require the detailed medical diagnosis or financial information. The OPC concluded that the collection of this information by the RCMP was not for a purpose consistent with section 4 of the Privacy Act. The complaint was found to be well-founded, and the OPC recommended updating the MOU and reviewing RCMP's internal policies on access to medical records.

Quick view

Privacy ActWell-founded

Collection of RCMP member's health information unnecessary (RCMP) - November 17, 2014

Nov 17, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A former RCMP member complained that the RCMP inappropriately collected her personal medical and financial information from Veterans Affairs Canada (VAC) after she was awarded a disability pension. The complainant alleged that the RCMP's National Compensation Policy Centre had no need for this sensitive information. The OPC found that the 2002 Memorandum of Understanding (MOU) between the RCMP and VAC transferred responsibility for pension administration to VAC, meaning the RCMP's National Compensation Policy Centre did not require the detailed medical diagnosis or financial information. The OPC concluded that the collection of this information by the RCMP was not for a purpose consistent with section 4 of the Privacy Act. The complaint was found to be well-founded, and the OPC recommended updating the MOU and reviewing RCMP's internal policies on access to medical records.

Key Issues
  • Whether the collection of the complainant's financial information by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of the complainant's medical diagnosis/pensioned disability by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of the complainant's disability percentage by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of personal information by the RCMP's National Compensation Policy Centre was consistent with the RCMP's own internal policies restricting access to sensitive medical information
  • Whether the MOU between VAC and the RCMP adequately addressed information sharing practices for sensitive personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2014Indexed Jun 30, 2026

Collection of RCMP member's health information unnecessary (VAC) - November 17, 2014

Veterans Affairs Canada (VAC)

A former RCMP member complained that Veterans Affairs Canada (VAC) inappropriately disclosed her medical diagnosis, disability percentage, and financial information to the RCMP's National Compensation Policy Centre. VAC argued the disclosure was a 'consistent use' under the Privacy Act, citing the RCMP's responsibility for members' health services and an MOU between the two institutions. The OPC found that the information provided to the complainant at the time of application was inadequate to establish informed consent for such disclosure. Furthermore, the MOU did not explicitly authorize the sharing of detailed medical and financial information with the RCMP's National Compensation Policy Centre. The OPC concluded that the disclosure was not a consistent use and therefore contravened the Privacy Act, noting the systemic nature of this issue affecting many RCMP employees.

Quick view

Privacy ActWell-founded

Collection of RCMP member's health information unnecessary (VAC) - November 17, 2014

Nov 17, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A former RCMP member complained that Veterans Affairs Canada (VAC) inappropriately disclosed her medical diagnosis, disability percentage, and financial information to the RCMP's National Compensation Policy Centre. VAC argued the disclosure was a 'consistent use' under the Privacy Act, citing the RCMP's responsibility for members' health services and an MOU between the two institutions. The OPC found that the information provided to the complainant at the time of application was inadequate to establish informed consent for such disclosure. Furthermore, the MOU did not explicitly authorize the sharing of detailed medical and financial information with the RCMP's National Compensation Policy Centre. The OPC concluded that the disclosure was not a consistent use and therefore contravened the Privacy Act, noting the systemic nature of this issue affecting many RCMP employees.

Key Issues
  • Whether the disclosure of the complainant's medical and financial information by VAC to the RCMP was authorized by consent under subsection 8(1) of the Privacy Act
  • Whether the disclosure of the complainant's medical and financial information by VAC to the RCMP was for a consistent use under paragraph 8(2)(a) of the Privacy Act
  • Whether the information provided to disability pension applicants by VAC was sufficient to establish informed consent for disclosure to the RCMP
  • Whether the Memorandum of Understanding (MOU) between VAC and the RCMP authorized the detailed sharing of personal medical and financial information
  • Whether the RCMP's National Compensation Policy Centre had a 'need to know' the complainant's detailed medical and financial information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Woman fails in attempt to return personal information to Canada Revenue Agency

Canada Revenue Agency (CRA)

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Quick view

Privacy ActWell-founded

Woman fails in attempt to return personal information to Canada Revenue Agency

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Key Issues
  • Whether the Canada Revenue Agency breached the privacy rights of taxpayers by mistakenly sending confidential personal information to an unauthorized individual
  • Whether the Canada Revenue Agency's procedures for handling misdirected mail and breach reporting were adequate
  • Whether the Canada Revenue Agency's client service channels were accessible for reporting privacy breaches
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Wanted by the CBSA Program

Canada Border Services Agency (CBSA)

The Canadian Council for Refugees complained that the Canada Border Services Agency (CBSA) improperly disclosed an individual's personal information on its "Wanted by the CBSA" website. The program aimed to solicit public help in locating individuals with Canada-wide warrants for removal, including those accused of war crimes. The OPC found that while the disclosure of personal information was permissible under the Privacy Act as a consistent use for immigration law enforcement, the CBSA failed to ensure the information was accurate, up-to-date, and complete. Specifically, the website implied a conviction for war crimes when the individual was only deemed inadmissible under immigration law. This led to a well-founded finding regarding the accuracy of the information. The CBSA accepted five recommendations, including revisiting the amount of personal information disclosed, clarifying the distinction between criminal conviction and immigration determination, and improving the timely removal of profiles.

Quick view

Privacy ActWell-founded

Wanted by the CBSA Program

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canadian Council for Refugees complained that the Canada Border Services Agency (CBSA) improperly disclosed an individual's personal information on its "Wanted by the CBSA" website. The program aimed to solicit public help in locating individuals with Canada-wide warrants for removal, including those accused of war crimes. The OPC found that while the disclosure of personal information was permissible under the Privacy Act as a consistent use for immigration law enforcement, the CBSA failed to ensure the information was accurate, up-to-date, and complete. Specifically, the website implied a conviction for war crimes when the individual was only deemed inadmissible under immigration law. This led to a well-founded finding regarding the accuracy of the information. The CBSA accepted five recommendations, including revisiting the amount of personal information disclosed, clarifying the distinction between criminal conviction and immigration determination, and improving the timely removal of profiles.

Key Issues
  • Whether the disclosure of personal information on the "Wanted by the CBSA" website was permissible under the Privacy Act as a consistent use
  • Whether the CBSA took all reasonable steps to ensure the personal information was accurate, up-to-date, and complete as required by the Privacy Act
  • Whether the CBSA should have conducted a Privacy Impact Assessment before launching the program
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Public Service school called upon to better protect confidentiality

Canada School of Public Service

The Canada School of Public Service (the School) received a letter from the Public Sector Integrity Commissioner (PSIC) detailing allegations of wrongdoing against seven employees. The School then hand-delivered copies of this letter, which identified the seven individuals and the alleged wrongdoings, to each of the named employees. One of these employees complained to the OPC, alleging that the disclosure of his name via this letter violated the Privacy Act. The OPC found the complaint to be well-founded, concluding that the School had improperly disclosed personal information. Following the OPC's recommendations, the School developed new procedures to protect the confidentiality of information related to the Public Servants Disclosure Protection Act and a plan for addressing privacy breaches.

Quick view

Privacy ActWell-founded

Public Service school called upon to better protect confidentiality

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canada School of Public Service (the School) received a letter from the Public Sector Integrity Commissioner (PSIC) detailing allegations of wrongdoing against seven employees. The School then hand-delivered copies of this letter, which identified the seven individuals and the alleged wrongdoings, to each of the named employees. One of these employees complained to the OPC, alleging that the disclosure of his name via this letter violated the Privacy Act. The OPC found the complaint to be well-founded, concluding that the School had improperly disclosed personal information. Following the OPC's recommendations, the School developed new procedures to protect the confidentiality of information related to the Public Servants Disclosure Protection Act and a plan for addressing privacy breaches.

Key Issues
  • Whether the Canada School of Public Service disclosed personal information contrary to the Privacy Act by hand-delivering a letter from the Public Sector Integrity Commissioner to employees named in it
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 5, 2014Indexed Jun 30, 2026

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Aboriginal Affairs and Northern Development Canada (AANDC)

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Quick view

Privacy ActWell-founded

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Sep 5, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Key Issues
  • Whether the document contained personal information under s.3 of the Privacy Act
  • Whether all AANDC officials who accessed the document had a need-to-know the identity of the requesters under s.7(a) of the Privacy Act and TBS Policy on Access to Information s.6.2.3
  • Whether the disclosure of the information to La Presse constituted a contravention of s.8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 9, 2014Indexed Jun 30, 2026

Sharing of health information unjustified - July 9, 2014

Public Service Commission of Canada (PSC)

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Quick view

Privacy ActWell-founded

Sharing of health information unjustified - July 9, 2014

Jul 9, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Key Issues
  • Whether the disclosure of the complainant's medical information to witnesses was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the PSC's interpretation of "affected person" and the requirements of procedural fairness justified the disclosure of sensitive medical information to all witnesses
  • Whether the PSC contravened subsection 8(1) of the Privacy Act by disclosing personal information without consent or a valid exception
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2014Indexed Jun 30, 2026

IP54-56/2014 — Employment and Social Development Canada

Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Quick view

Privacy ActWell-founded

IP54-56/2014 — Employment and Social Development Canada

Mar 24, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Key Issues
  • Whether ESDC failed to implement adequate physical security controls for personal information stored on portable media.
  • Whether ESDC failed to implement adequate technical security controls, such as encryption and risk assessments, for personal information on portable media.
  • Whether ESDC failed to implement adequate administrative controls, including asset inventory, information classification, and lifecycle management, for personal information.
  • Whether ESDC failed to implement adequate personnel security controls, such as employee training, awareness, and accountability, regarding personal information.
  • Whether ESDC contravened subsection 6(3) of the Privacy Act by failing to properly dispose of personal information.
  • Whether ESDC contravened section 7 of the Privacy Act regarding the use of personal information.
  • Whether ESDC contravened section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether the delay in notifying affected individuals of the breach was reasonable.
  • Whether the scope of personal information reported to affected individuals in the notification letters was complete.