The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

5 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 16, 2017Indexed Jun 30, 2026

Cell site simulators used by RCMP not capable of intercepting private communication

Royal Canadian Mounted Police (RCMP)

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Quick view

Privacy ActWell-founded

Cell site simulators used by RCMP not capable of intercepting private communication

Aug 16, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Key Issues
  • Whether RCMP uses cell site simulators (MDIs)
  • Whether RCMP's MDIs are capable of intercepting private communications (voice, text, email, encryption keys)
  • Whether RCMP's collection of personal information using MDIs relates directly to an operating program or activity (s.4 Privacy Act)
  • Whether RCMP's collection of personal information using MDIs was lawful and Charter-compliant, specifically regarding prior judicial authorization
  • Whether exigent circumstances justified warrantless MDI deployments in certain cases
  • Whether RCMP's collection of personal information using MDIs complied with direct collection and notification requirements (s.5 Privacy Act)
  • Whether the RCMP adequately handles, retains, and disposes of third-party personal information (IMSI/IMEI numbers) collected by MDIs
  • Whether the wording in warrants and policies provides adequate protection for collected personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 19, 2017Indexed Jun 30, 2026

MyDemocracy website not designed in a privacy sensitive way

Privy Council Office

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Quick view

Privacy ActWell-founded

MyDemocracy website not designed in a privacy sensitive way

Jul 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Key Issues
  • Whether the MyDemocracy.ca website's design led to the disclosure of personal information to third parties (Facebook, Google Analytics) without consent.
  • Whether IP addresses, browser characteristics, and unique URLs constitute "personal information" under section 3 of the Privacy Act.
  • Whether the Privy Council Office (PCO) met its obligations under section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether PCO's amendments to the website and privacy policy were sufficient to obtain meaningful consent for data disclosure.
  • Whether PCO should have conducted a Privacy Impact Assessment (PIA) for the MyDemocracy.ca initiative.
  • Whether the collection of demographic information was justified and compliant with relevant standards.
  • Whether the use of Google Analytics complied with the Treasury Board of Canada Secretariat's (TBS) Standard on Privacy and Web Analytics.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Phoenix pay system compromised Public Servants’ privacy

Public Services and Procurement Canada

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Quick view

Privacy ActWell-founded

Phoenix pay system compromised Public Servants’ privacy

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Key Issues
  • Whether personal information was at issue in the reported incidents
  • Whether the personal information at issue was improperly disclosed
  • What was the scope of the improper disclosure
  • Whether the personal information that was improperly disclosed was misused
  • Whether PSPC was aware of potential privacy issues with Phoenix before the launch
  • What kind of harm could result from the unauthorized disclosure of the personal information at issue
  • Whether PSPC resolved all of the vulnerabilities within Phoenix
  • Whether PSPC provided individuals with timely information regarding the breaches and vulnerabilities
  • Whether PSPC developed and implemented controls to monitor and document access to personal information held in Phoenix (Recommendation 1)
  • Whether PSPC developed more robust testing and response procedures (Recommendation 2)
  • Whether PSPC conducted necessary assessments to identify potential risks and vulnerabilities in Phoenix (Recommendation 3)
  • Whether PSPC took measures to mitigate the increased vulnerability of information used by employees in call centres (Recommendation 4)
  • Whether PSPC reviewed its breach notification practices and provided notification of the extent of the Phoenix breaches (Recommendation 5)
  • Whether PSPC completed the review of pages with row-level security (Recommendation 6)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Health Canada

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Quick view

Privacy ActWell-founded

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Key Issues
  • Whether diagnostic information about individual patients constitutes 'personal information' under s.3 of the Privacy Act
  • Whether Health Canada contravened s.4 of the Privacy Act by collecting diagnostic information about patients seeking medical transportation and specialist services that was not directly related to an operating program or activity
  • Whether the collection of diagnostic information was demonstrably necessary to achieve a specific and legitimate purpose
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 19, 2017Indexed Jun 30, 2026

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Royal Canadian Mounted Police (RCMP)

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Quick view

Privacy ActWell-founded

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Apr 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Key Issues
  • Whether the RCMP inappropriately disclosed the complainant's personal information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(f) of the Privacy Act.
  • Whether CBP's use of the complainant's personal information for an admissibility assessment constituted "criminal justice purposes" or "law enforcement" as defined in the Memorandum of Cooperation (MOC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(a) of the Privacy Act as a "consistent use."
  • Whether the CPIC policies in effect at the time provided sufficient clarity to guard against unauthorized disclosure of sensitive personal information.
  • Whether the revised CPIC policies, including the "SHARE US A" feature and "SIP-OB" entries, adequately protect against unauthorized disclosure of attempted suicide information.
  • Whether the default setting of the "SHARE US A" feature in CPIC should suppress the sharing of SIP-OB entries relating to threatened or attempted suicides with US border officials.
  • Whether CPIC policies should be revised to provide clear guidance for sharing attempted suicide information with US border officials only where an individual presents an ongoing risk to others.