The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

5 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 21, 2023Indexed Jun 30, 2026

Investigation into IRCC’s search for records using modified wording

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) failed to disclose all information sought under the Privacy Act, specifically regarding the cancellation and reissuing of visas for the complainant and her children. The investigation found that IRCC initially narrowed the scope of the request without the complainant's approval and did not conduct a sufficiently broad search for records. The OPC determined that IRCC did not initially conduct a reasonable search for records. However, during the investigation, IRCC expanded its search to include additional offices and a specific former employee's correspondence. Although no additional records were found, IRCC's subsequent efforts satisfied the OPC that it had met its obligations under the Act.

Quick view

Privacy ActWell-founded

Investigation into IRCC’s search for records using modified wording

Sep 21, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) failed to disclose all information sought under the Privacy Act, specifically regarding the cancellation and reissuing of visas for the complainant and her children. The investigation found that IRCC initially narrowed the scope of the request without the complainant's approval and did not conduct a sufficiently broad search for records. The OPC determined that IRCC did not initially conduct a reasonable search for records. However, during the investigation, IRCC expanded its search to include additional offices and a specific former employee's correspondence. Although no additional records were found, IRCC's subsequent efforts satisfied the OPC that it had met its obligations under the Act.

Key Issues
  • Whether IRCC conducted a reasonable search for records responsive to the access request
  • Whether IRCC improperly reduced the scope of the request without the complainant's approval
  • Whether IRCC tasked all appropriate Offices of Primary Interest (OPIs) in its initial search
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 19, 2023Indexed Jun 30, 2026

Canada Post’s collection and use of personal information for marketing purposes not compliant with the Act

Canada Post

An individual complained that Canada Post (CPC) was using personal information gathered from the outside of delivered envelopes and parcels to create mail marketing lists, which it then rented to the private sector. The Office of the Privacy Commissioner (OPC) investigated whether CPC's Smartmail Marketing Program (SMM Program) complied with the Privacy Act. The OPC found that CPC's collection of personal information for the SMM Program was directly related to an operating program (s.4) and that its use and disclosure were for an original purpose of collection (s.7 and s.8), thus compliant with these sections. However, the OPC determined that the SMM Program constituted an "administrative purpose" under the Act, and CPC had failed to obtain individuals' authorization for the indirect collection of their personal information, contravening section 5. CPC disagreed with this finding and refused to implement the OPC's recommendation to cease the practice without authorization, proposing only enhanced transparency measures which the OPC deemed insufficient. Consequently, the complaint was found to be well-founded and not resolved.

Quick view

Privacy ActWell-founded

Canada Post’s collection and use of personal information for marketing purposes not compliant with the Act

Sep 19, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that Canada Post (CPC) was using personal information gathered from the outside of delivered envelopes and parcels to create mail marketing lists, which it then rented to the private sector. The Office of the Privacy Commissioner (OPC) investigated whether CPC's Smartmail Marketing Program (SMM Program) complied with the Privacy Act. The OPC found that CPC's collection of personal information for the SMM Program was directly related to an operating program (s.4) and that its use and disclosure were for an original purpose of collection (s.7 and s.8), thus compliant with these sections. However, the OPC determined that the SMM Program constituted an "administrative purpose" under the Act, and CPC had failed to obtain individuals' authorization for the indirect collection of their personal information, contravening section 5. CPC disagreed with this finding and refused to implement the OPC's recommendation to cease the practice without authorization, proposing only enhanced transparency measures which the OPC deemed insufficient. Consequently, the complaint was found to be well-founded and not resolved.

Key Issues
  • Whether Canada Post's collection of personal information for marketing mail list services complies with section 4 of the Privacy Act (related directly to an operating program or activity).
  • Whether Canada Post's use and disclosure of personal information for marketing mail list services complies with sections 7 and 8 of the Privacy Act (for the purpose obtained or consistent use, or with consent).
  • Whether Canada Post's collection of personal information for marketing mail list services complies with section 5 of the Privacy Act (direct collection for administrative purpose, or with authorization).
  • Whether the use of an individual's information to provide mail marketing services constitutes an "administrative purpose" under section 3 of the Privacy Act.
  • Whether individuals implicitly authorized Canada Post to indirectly collect their personal information for the SMM Program by accepting mail delivery or through the availability of an opt-out mechanism.
  • Whether the exceptions under subsection 5(3) of the Privacy Act apply.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Erroneous quarantine notifications from ArriveCAN

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint regarding erroneous quarantine notifications sent by the ArriveCAN application to approximately 10,200 Apple device users. These notifications, issued between June 28 and July 20, 2022, incorrectly instructed fully vaccinated travellers to quarantine due to a defect in ArriveCAN version 3.0. The OPC found that the Canada Border Services Agency (CBSA) failed to take all reasonable steps to ensure the accuracy of personal information used for an administrative purpose, as required by subsection 6(2) of the Privacy Act. Specifically, the OPC identified shortcomings in rigorous pre-release testing, effective human intervention, and timely correction and recourse for affected individuals. The CBSA disagreed with the finding and refused to implement the OPC's recommendation to correct the inaccurate "quarantine_exempted" value in its database. Consequently, the complaint was found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded

Erroneous quarantine notifications from ArriveCAN

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint regarding erroneous quarantine notifications sent by the ArriveCAN application to approximately 10,200 Apple device users. These notifications, issued between June 28 and July 20, 2022, incorrectly instructed fully vaccinated travellers to quarantine due to a defect in ArriveCAN version 3.0. The OPC found that the Canada Border Services Agency (CBSA) failed to take all reasonable steps to ensure the accuracy of personal information used for an administrative purpose, as required by subsection 6(2) of the Privacy Act. Specifically, the OPC identified shortcomings in rigorous pre-release testing, effective human intervention, and timely correction and recourse for affected individuals. The CBSA disagreed with the finding and refused to implement the OPC's recommendation to correct the inaccurate "quarantine_exempted" value in its database. Consequently, the complaint was found to be well-founded and unresolved.

Key Issues
  • Whether the Canada Border Services Agency (CBSA) took all reasonable steps to ensure that personal information used for an administrative decision was as accurate as possible under subsection 6(2) of the Privacy Act.
  • Whether the "quarantine_exempted" data field constituted personal information used for an administrative purpose by the CBSA.
  • Whether the CBSA conducted rigorous pre-release testing for issues that could lead to the highest negative impacts on individual users.
  • Whether the CBSA ensured effective human intervention with respect to high-impact decisions on individuals.
  • Whether the CBSA provided effective and timely correction and recourse for individuals affected by inaccurate information.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 24, 2023Indexed Jun 30, 2026

CBSA’s use of commercial genetic genealogy in a deportation case contravenes the Privacy Act

Canadian Border Services Agency (CBSA)

A former refugee complained that the Canadian Border Services Agency (CBSA) contravened his privacy rights by using commercial genetic genealogy (FamilyTreeDNA) to determine his nationality for deportation. He alleged lack of legal authority, unnecessary collection, invalid consent, deceptive practices, inadequate disclosure limitation, and insufficient Personal Information Bank (PIB) description. The Office of the Privacy Commissioner (OPC) found that while the collection was directly related to CBSA's program, the agency contravened section 5 of the Privacy Act by failing to obtain valid, informed authorization for indirect collection from FTDNA. CBSA also contravened section 8 by making incidental disclosures of the complainant's personal information to other FTDNA users, failing to monitor account settings, and not using a pseudonym. Furthermore, the CBSA's PIB descriptions were non-compliant with section 11, as they did not adequately describe the collection of genetic profiles of other FTDNA users. The OPC made several recommendations, which CBSA committed to implement for most parts, but two accounts remained open at the time of the report, leading to an ongoing, unresolved contravention. Consequently, the complaint was found well-founded in part and conditionally resolved in part.

Quick view

Privacy ActWell-founded

CBSA’s use of commercial genetic genealogy in a deportation case contravenes the Privacy Act

Apr 24, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

A former refugee complained that the Canadian Border Services Agency (CBSA) contravened his privacy rights by using commercial genetic genealogy (FamilyTreeDNA) to determine his nationality for deportation. He alleged lack of legal authority, unnecessary collection, invalid consent, deceptive practices, inadequate disclosure limitation, and insufficient Personal Information Bank (PIB) description. The Office of the Privacy Commissioner (OPC) found that while the collection was directly related to CBSA's program, the agency contravened section 5 of the Privacy Act by failing to obtain valid, informed authorization for indirect collection from FTDNA. CBSA also contravened section 8 by making incidental disclosures of the complainant's personal information to other FTDNA users, failing to monitor account settings, and not using a pseudonym. Furthermore, the CBSA's PIB descriptions were non-compliant with section 11, as they did not adequately describe the collection of genetic profiles of other FTDNA users. The OPC made several recommendations, which CBSA committed to implement for most parts, but two accounts remained open at the time of the report, leading to an ongoing, unresolved contravention. Consequently, the complaint was found well-founded in part and conditionally resolved in part.

Key Issues
  • Whether CBSA's collection of genetic genealogy information was directly related to an operating program or activity under s.4 of the Privacy Act
  • Whether CBSA collected unnecessary information under s.4 of the Privacy Act
  • Whether CBSA obtained valid authorization from the complainant for the indirect collection of his personal information from FTDNA under s.5(1) of the Privacy Act
  • Whether the complainant's consent for indirect collection was voluntary and not given under duress
  • Whether the complainant was adequately informed about FTDNA's terms and his rights as a DNA donor for valid authorization
  • Whether CBSA acted deceptively in its collection via FTDNA
  • Whether the incidental indirect collection of genetic profile information of hundreds of other individuals contravened s.5(1) of the Privacy Act
  • Whether CBSA's incidental disclosures of the complainant's personal information contravened s.8 of the Privacy Act
  • Whether allowing potential disclosure of the complainant's personal information to other law enforcement bodies (via "law enforcement matching" opt-in) contravened s.8 of the Privacy Act
  • Whether the disclosure of ancillary personal information (ethnicity) to genetic matches contravened s.8 of the Privacy Act
  • Whether the disclosure of the complainant's identity to genetic matches (failure to use a pseudonym) contravened s.8 of the Privacy Act
  • Whether CBSA's Personal Information Bank (PIB) descriptions complied with the transparency obligations under s.11 of the Privacy Act
  • Whether the PIB adequately described the collection of biometric information for individuals subject to removal orders
  • Whether the PIB adequately described the collection of genetic profiles of other FTDNA users (relatives of individuals subject to removal orders)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 31, 2023Indexed Jun 30, 2026

Immigration and Refugee Board of Canada wrongly disclosed intimate and medical information to an employee’s management team via a fitness to work report

Immigration and Refugee Board of Canada (IRB)

An employee of the Immigration and Refugee Board of Canada (IRB) complained that their intimate personal and sensitive medical information, contained in a Fitness to Work (FTW) report, was disclosed to their management team without consent and for no reasonable purpose. The OPC investigated whether the IRB respected section 8 of the Privacy Act, specifically regarding consent and consistent use. The IRB argued the disclosure was a consistent use, but the OPC found that while some information disclosure was consistent, the highly intimate personal and sensitive medical information was not. The OPC concluded that the IRB contravened the Act by disclosing information internally that fell outside what is permissible. Despite some new processes, the IRB did not fully acknowledge wrongdoing or agree to all recommendations, leading to a well-founded and unresolved finding.

Quick view

Privacy ActWell-founded

Immigration and Refugee Board of Canada wrongly disclosed intimate and medical information to an employee’s management team via a fitness to work report

Mar 31, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee of the Immigration and Refugee Board of Canada (IRB) complained that their intimate personal and sensitive medical information, contained in a Fitness to Work (FTW) report, was disclosed to their management team without consent and for no reasonable purpose. The OPC investigated whether the IRB respected section 8 of the Privacy Act, specifically regarding consent and consistent use. The IRB argued the disclosure was a consistent use, but the OPC found that while some information disclosure was consistent, the highly intimate personal and sensitive medical information was not. The OPC concluded that the IRB contravened the Act by disclosing information internally that fell outside what is permissible. Despite some new processes, the IRB did not fully acknowledge wrongdoing or agree to all recommendations, leading to a well-founded and unresolved finding.

Key Issues
  • Whether the IRB obtained valid consent for the disclosure of the FTW report to the management team under section 8(1) of the Privacy Act
  • Whether the disclosure of intimate personal and sensitive medical information in the FTW report to the management team was a 'consistent use' under section 8(2)(a) of the Privacy Act
  • Whether the IRB adhered to the Treasury Board Secretariat's Occupational Health Evaluation Standard regarding disclosure of medical information to employers