The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

5 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 6, 2010Indexed Jun 30, 2026

Veteran’s complaint highlights significant privacy issues - October 6, 2010

Veterans Affairs Canada

A veteran complained that Veterans Affairs Canada (VAC) inappropriately used his personal information by including excessive medical details in briefing notes for the Minister and by transferring his medical file to a hospital without consent. The OPC investigation found that briefing notes contained sensitive medical information far beyond what was necessary for their stated purpose and that this information was widely shared within VAC on a non-need-to-know basis. It also found that VAC transferred the complainant's medical file to a hospital it administered without obtaining his consent, despite departmental guidelines requiring it. The OPC concluded that VAC's actions violated section 7 of the Privacy Act, which governs the use of personal information. The complaint was found to be well-founded, and the OPC issued several recommendations to VAC, including developing an enhanced privacy policy framework, revising information-management practices, providing employee training, and reviewing consent procedures for information transfers.

Quick view

Privacy ActWell-founded

Veteran’s complaint highlights significant privacy issues - October 6, 2010

Oct 6, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A veteran complained that Veterans Affairs Canada (VAC) inappropriately used his personal information by including excessive medical details in briefing notes for the Minister and by transferring his medical file to a hospital without consent. The OPC investigation found that briefing notes contained sensitive medical information far beyond what was necessary for their stated purpose and that this information was widely shared within VAC on a non-need-to-know basis. It also found that VAC transferred the complainant's medical file to a hospital it administered without obtaining his consent, despite departmental guidelines requiring it. The OPC concluded that VAC's actions violated section 7 of the Privacy Act, which governs the use of personal information. The complaint was found to be well-founded, and the OPC issued several recommendations to VAC, including developing an enhanced privacy policy framework, revising information-management practices, providing employee training, and reviewing consent procedures for information transfers.

Key Issues
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by including excessive medical details in briefing notes for the Minister.
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by widely sharing sensitive personal information within the department on a non-need-to-know basis.
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by transferring his medical file to a hospital without obtaining his consent.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Internet posting highlights inappropriate access to tax records by CRA workers

Canada Revenue Agency (CRA)

The Commissioner initiated an investigation following media allegations that a Canada Revenue Agency (CRA) employee posted personal tax information of high-profile sports figures to an Internet chat group. The investigation confirmed that a former CRA employee had posted such information, and that other CRA employees had inappropriately accessed the tax information of these athletes, likely out of curiosity. While there was no evidence that these employees disclosed the information to outside sources, accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act. Consequently, the portion of the complaint concerning the improper use of personal information by CRA employees was found to be well-founded. The CRA took corrective measures, including suspending one employee, firing two others, and modernizing its audit trail system to monitor access to taxpayer information.

Quick view

Privacy ActWell-founded

Internet posting highlights inappropriate access to tax records by CRA workers

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Commissioner initiated an investigation following media allegations that a Canada Revenue Agency (CRA) employee posted personal tax information of high-profile sports figures to an Internet chat group. The investigation confirmed that a former CRA employee had posted such information, and that other CRA employees had inappropriately accessed the tax information of these athletes, likely out of curiosity. While there was no evidence that these employees disclosed the information to outside sources, accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act. Consequently, the portion of the complaint concerning the improper use of personal information by CRA employees was found to be well-founded. The CRA took corrective measures, including suspending one employee, firing two others, and modernizing its audit trail system to monitor access to taxpayer information.

Key Issues
  • Whether CRA employees inappropriately accessed personal tax information
  • Whether CRA employees disclosed personal tax information to outside sources
  • Whether accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Toronto Port Authority worker misuses personal data for political fundraiser

Toronto Port Authority

A Member of Parliament complained that an employee of the Toronto Port Authority (TPA) misused the organization's email database to invite people to a political fundraising event. The investigation found that a TPA employee sent an email to approximately 60 people, soliciting donations and inviting participation in a fundraiser for another MP. The employee obtained these email addresses from business cards collected by the TPA, including both business and personal addresses. The OPC determined that the employee used this personal information without the TPA's knowledge or authorization and for reasons unrelated to the organization's business activities. The complaint was found to be well-founded, but the TPA took corrective measures, including reminding employees of their responsibilities and pledging Privacy Act training.

Quick view

Privacy ActWell-founded

Toronto Port Authority worker misuses personal data for political fundraiser

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A Member of Parliament complained that an employee of the Toronto Port Authority (TPA) misused the organization's email database to invite people to a political fundraising event. The investigation found that a TPA employee sent an email to approximately 60 people, soliciting donations and inviting participation in a fundraiser for another MP. The employee obtained these email addresses from business cards collected by the TPA, including both business and personal addresses. The OPC determined that the employee used this personal information without the TPA's knowledge or authorization and for reasons unrelated to the organization's business activities. The complaint was found to be well-founded, but the TPA took corrective measures, including reminding employees of their responsibilities and pledging Privacy Act training.

Key Issues
  • Whether a Toronto Port Authority employee misused personal information for a political fundraiser
  • Whether email addresses obtained from business cards constitute personal information
  • Whether the use of personal information was without the knowledge or authorization of the institution
  • Whether the use of personal information was for reasons unrelated to the organization's business activities
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Mechanical malfunction, compounded by human error, leads to data spill

Human Resources and Skills Development Canada

In March 2009, Human Resources and Skills Development Canada (HRSDC) mailed 11,900 forms for the Guaranteed Income Supplement. Due to a mechanical malfunction and human error, some individuals received forms intended for others, containing names, addresses, and Social Insurance Numbers (SINs). The OPC initiated a complaint after HRSDC notified them of 44 reported cases of mix-ups. The investigation found that a technician failed to stop the mailing despite noticing errors and did not report the issue to management. The OPC determined the complaint was well-founded, highlighting both mechanical failure and human error. HRSDC conducted its own investigation, improved equipment, and strengthened quality control procedures. The OPC recommended better employee sensitization to privacy obligations, which HRSDC committed to implementing.

Quick view

Privacy ActWell-founded

Mechanical malfunction, compounded by human error, leads to data spill

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

In March 2009, Human Resources and Skills Development Canada (HRSDC) mailed 11,900 forms for the Guaranteed Income Supplement. Due to a mechanical malfunction and human error, some individuals received forms intended for others, containing names, addresses, and Social Insurance Numbers (SINs). The OPC initiated a complaint after HRSDC notified them of 44 reported cases of mix-ups. The investigation found that a technician failed to stop the mailing despite noticing errors and did not report the issue to management. The OPC determined the complaint was well-founded, highlighting both mechanical failure and human error. HRSDC conducted its own investigation, improved equipment, and strengthened quality control procedures. The OPC recommended better employee sensitization to privacy obligations, which HRSDC committed to implementing.

Key Issues
  • Whether personal information was inappropriately disclosed due to mechanical malfunction
  • Whether personal information was inappropriately disclosed due to human error
  • Whether the institution adequately safeguarded personal information during mass mailings
  • Whether employees were sufficiently sensitized to their obligations to safeguard personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Personal data of 191 EI claimants disclosed

Human Resources and Skills Development Canada

The Office of the Privacy Commissioner of Canada (OPC) received 82 complaints after Human Resources and Skills Development Canada (HRSDC) inadvertently disclosed the personal information of 191 Employment Insurance (EI) claimants to another individual. The disclosure occurred when an individual appealing an EI claim denial received an appeal docket that included names, dates of birth, employee identification numbers, and Social Insurance Numbers of 191 fellow employees, along with a second list of employment and leave statuses. The OPC's investigation confirmed that in 79 instances, the information was indeed released, leading to well-founded findings. HRSDC took immediate steps to retrieve the data, notify affected parties, and advise on identity theft prevention. They also implemented measures to prevent future recurrences, including reminding officials of proper procedures for protecting personal information during appeals.

Quick view

Privacy ActWell-founded

Personal data of 191 EI claimants disclosed

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) received 82 complaints after Human Resources and Skills Development Canada (HRSDC) inadvertently disclosed the personal information of 191 Employment Insurance (EI) claimants to another individual. The disclosure occurred when an individual appealing an EI claim denial received an appeal docket that included names, dates of birth, employee identification numbers, and Social Insurance Numbers of 191 fellow employees, along with a second list of employment and leave statuses. The OPC's investigation confirmed that in 79 instances, the information was indeed released, leading to well-founded findings. HRSDC took immediate steps to retrieve the data, notify affected parties, and advise on identity theft prevention. They also implemented measures to prevent future recurrences, including reminding officials of proper procedures for protecting personal information during appeals.

Key Issues
  • Whether Human Resources and Skills Development Canada inadvertently disclosed personal information of EI claimants
  • Whether the disclosure of names, dates of birth, employee identification numbers, and Social Insurance Numbers constituted a contravention of the Privacy Act
  • Whether the disclosure of employment and leave status constituted a contravention of the Privacy Act