The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

2 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 25, 2026Indexed Jun 30, 2026

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Immigration, Refugees and Citizenship Canada (IRCC)

The OPC investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding its systematic practice of withholding access to certain personal information in its Global Case Management System (GCMS). IRCC's policy was to retrieve and process only a "Short Form" GCMS Report in response to access requests, even when individuals requested their entire file or specific content found in the "Long Form." The OPC found that the "History Section" of the GCMS file, which is part of the Long Form, contained the complainant's personal information and that IRCC's practice contravened Section 12 of the Privacy Act. While IRCC eventually provided the complainant with the requested Long Form, it did not agree to update its procedures to systematically retrieve and process the Long Form for all future requests. Consequently, the OPC found the complaint well-founded but not resolved, as IRCC had not committed to addressing the systemic issue.

Quick view

Privacy ActWell-founded

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding its systematic practice of withholding access to certain personal information in its Global Case Management System (GCMS). IRCC's policy was to retrieve and process only a "Short Form" GCMS Report in response to access requests, even when individuals requested their entire file or specific content found in the "Long Form." The OPC found that the "History Section" of the GCMS file, which is part of the Long Form, contained the complainant's personal information and that IRCC's practice contravened Section 12 of the Privacy Act. While IRCC eventually provided the complainant with the requested Long Form, it did not agree to update its procedures to systematically retrieve and process the Long Form for all future requests. Consequently, the OPC found the complaint well-founded but not resolved, as IRCC had not committed to addressing the systemic issue.

Key Issues
  • Whether IRCC's practice of providing only a "Short Form" GCMS Report in response to access requests contravenes Section 12 of the Privacy Act
  • Whether the "History Section" of the GCMS file contains personal information
  • Whether information in the "Long Form" GCMS Report is always exempt from disclosure
  • Whether IRCC has an obligation to retrieve and process all records responsive to a Privacy Act request
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2026Indexed Jun 30, 2026

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Canada Border Services Agency (CBSA)

An employee of the Canada Border Services Agency (CBSA) filed a complaint after their personal information, including sensitive details about an accommodation request, was inadvertently made accessible to other CBSA employees through the Apollo information management system. The issue stemmed from improperly set permissions on an old ATIP file folder, which allowed document titles and sometimes the first line of emails containing personal information to be visible via Apollo's search function. The OPC found that the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority. While the CBSA corrected the specific permissions and committed to broader reviews and improved naming conventions, it did not agree to implement mandatory and trackable training for employees on Apollo permissions management. Consequently, the OPC found the complaint well-founded but unresolved, as it was not satisfied that sufficient safeguards were in place to prevent recurrence.

Quick view

Privacy ActWell-founded

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Mar 24, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee of the Canada Border Services Agency (CBSA) filed a complaint after their personal information, including sensitive details about an accommodation request, was inadvertently made accessible to other CBSA employees through the Apollo information management system. The issue stemmed from improperly set permissions on an old ATIP file folder, which allowed document titles and sometimes the first line of emails containing personal information to be visible via Apollo's search function. The OPC found that the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority. While the CBSA corrected the specific permissions and committed to broader reviews and improved naming conventions, it did not agree to implement mandatory and trackable training for employees on Apollo permissions management. Consequently, the OPC found the complaint well-founded but unresolved, as it was not satisfied that sufficient safeguards were in place to prevent recurrence.

Key Issues
  • Whether the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority
  • Whether the CBSA appropriately responded to the unauthorized disclosure
  • Whether the CBSA's proposed measures, without mandatory and trackable training, are sufficient to prevent future unauthorized disclosures