The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

364 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 12, 2018Indexed Jun 30, 2026

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Health Canada

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Quick view

Privacy ActWell-founded

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Mar 12, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Key Issues
  • Whether the information collected by Health Canada on Limited Use forms for drug benefits constitutes personal information under the Privacy Act
  • Whether Health Canada's collection of personal information on Limited Use forms relates directly to an operating program or activity of the institution as required by section 4 of the Privacy Act
  • Whether the specific data fields requesting detailed diagnostic information (e.g., exact number of swollen joints) are necessary for the adjudication of drug benefit claims under the NIHB Program
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 28, 2017PIPEDA Report of Findings #2017-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-002: Canadian adware developer Wajam Internet Technologies Inc. breaches multiple provisions of PIPEDA

Wajam Internet Technologies Inc.

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Wajam Internet Technologies Inc., an adware developer, regarding its software's installation, consent, uninstallation, and data handling practices. The software, Wajam or Social2Search, tracked online search queries, overlaid social media results, and displayed contextual ads. The OPC investigated whether Wajam obtained meaningful consent for installation, allowed users to withdraw consent, and adequately safeguarded personal information. The investigation found that Wajam lacked a privacy accountability framework, failed to obtain meaningful consent due to problematic third-party distribution methods and misleading information, indefinitely retained unencrypted raw user data, and had insufficient safeguards. All examined matters related to accountability, consent, limiting retention, safeguards, and openness were found to be well-founded. Wajam, having sold its assets to a Hong Kong-based company, IMTL, claimed it was unable to implement the OPC's recommendations, though it agreed to securely destroy Canadian user data. The OPC requested Wajam provide the report to IMTL and stated it would monitor the situation and engage international counterparts.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2017-002: Canadian adware developer Wajam Internet Technologies Inc. breaches multiple provisions of PIPEDA

Aug 28, 2017PIPEDA Report of Findings #2017-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Wajam Internet Technologies Inc., an adware developer, regarding its software's installation, consent, uninstallation, and data handling practices. The software, Wajam or Social2Search, tracked online search queries, overlaid social media results, and displayed contextual ads. The OPC investigated whether Wajam obtained meaningful consent for installation, allowed users to withdraw consent, and adequately safeguarded personal information. The investigation found that Wajam lacked a privacy accountability framework, failed to obtain meaningful consent due to problematic third-party distribution methods and misleading information, indefinitely retained unencrypted raw user data, and had insufficient safeguards. All examined matters related to accountability, consent, limiting retention, safeguards, and openness were found to be well-founded. Wajam, having sold its assets to a Hong Kong-based company, IMTL, claimed it was unable to implement the OPC's recommendations, though it agreed to securely destroy Canadian user data. The OPC requested Wajam provide the report to IMTL and stated it would monitor the situation and engage international counterparts.

Key Issues
  • Whether Wajam Internet Technologies Inc. had an adequate privacy accountability framework in place (Principle 4.1.4 PIPEDA)
  • Whether Wajam obtained meaningful consent from individuals for the installation and operation of its software (Principle 4.3, 4.3.2, 4.3.5 PIPEDA, s.6.1 PIPEDA)
  • Whether Wajam's third-party distribution model ensured meaningful consent for software installation
  • Whether Wajam's multiple-offer consent screens provided sufficient information for meaningful consent
  • Whether the information provided by Wajam about its software's functionality and privacy practices was accurate and complete (Principle 4.2, 4.3.2, 4.3.5 PIPEDA)
  • Whether Wajam permitted users to withdraw consent by making it difficult to uninstall its software (Principle 4.3.8 PIPEDA)
  • Whether Wajam was responsible for unsolicited ads and fake offers presented during the uninstallation process (Principle 4.3 PIPEDA)
  • Whether Wajam limited the retention of personal information to only as long as necessary for identified purposes (Principle 4.5, 4.5.2 PIPEDA)
  • Whether Wajam was open about its policies and practices relating to the management of personal information (Principle 4.8 PIPEDA)
  • Whether Wajam adequately safeguarded users' personal information against loss, theft, or unauthorized access, including during transmission and storage (Principle 4.7.1, 4.7.2, 4.7.3 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 17, 2017PIPEDA Report of Findings #2017-008Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-008: Jet Airways says possibility of litigation allows it to refuse access to personal information

Jet Airways

The complainant alleged that Jet Airways failed to provide complete access to her personal information related to an incident where she and her companion were removed from a flight. Jet Airways initially failed to respond to the access request within the 30-day timeframe, citing potential litigation and staff medical leave. While Jet Airways eventually provided the Passenger Name Record, it withheld other documents, claiming solicitor-client privilege (including litigation privilege) and that the information was generated during a formal dispute resolution process. The OPC found that Jet Airways contravened its obligations regarding timely response and proper policies for handling access requests and applying exemptions. However, due to binding court decisions, the OPC could not make a finding on the specific application of solicitor-client/litigation privilege to the withheld documents, leading to an impasse on that issue. The OPC recommended that Jet Airways implement proper access request procedures and review its policies for applying exemptions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2017-008: Jet Airways says possibility of litigation allows it to refuse access to personal information

Aug 17, 2017PIPEDA Report of Findings #2017-008
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Jet Airways failed to provide complete access to her personal information related to an incident where she and her companion were removed from a flight. Jet Airways initially failed to respond to the access request within the 30-day timeframe, citing potential litigation and staff medical leave. While Jet Airways eventually provided the Passenger Name Record, it withheld other documents, claiming solicitor-client privilege (including litigation privilege) and that the information was generated during a formal dispute resolution process. The OPC found that Jet Airways contravened its obligations regarding timely response and proper policies for handling access requests and applying exemptions. However, due to binding court decisions, the OPC could not make a finding on the specific application of solicitor-client/litigation privilege to the withheld documents, leading to an impasse on that issue. The OPC recommended that Jet Airways implement proper access request procedures and review its policies for applying exemptions.

Key Issues
  • Whether Jet Airways responded to the access request within the prescribed 30-day time period under subsection 8(3) of PIPEDA
  • Whether Jet Airways had appropriate policies and practices to give effect to Principle 4.1.4 of Schedule 1 of PIPEDA
  • Whether the withheld information was protected by solicitor-client privilege or litigation privilege under paragraph 9(3)(a) of PIPEDA
  • Whether the withheld information was generated in the course of a formal dispute resolution process under paragraph 9(3)(d) of PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 16, 2017Indexed Jun 30, 2026

Cell site simulators used by RCMP not capable of intercepting private communication

Royal Canadian Mounted Police (RCMP)

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Quick view

Privacy ActWell-founded

Cell site simulators used by RCMP not capable of intercepting private communication

Aug 16, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Key Issues
  • Whether RCMP uses cell site simulators (MDIs)
  • Whether RCMP's MDIs are capable of intercepting private communications (voice, text, email, encryption keys)
  • Whether RCMP's collection of personal information using MDIs relates directly to an operating program or activity (s.4 Privacy Act)
  • Whether RCMP's collection of personal information using MDIs was lawful and Charter-compliant, specifically regarding prior judicial authorization
  • Whether exigent circumstances justified warrantless MDI deployments in certain cases
  • Whether RCMP's collection of personal information using MDIs complied with direct collection and notification requirements (s.5 Privacy Act)
  • Whether the RCMP adequately handles, retains, and disposes of third-party personal information (IMSI/IMEI numbers) collected by MDIs
  • Whether the wording in warrants and policies provides adequate protection for collected personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 8, 2017PIPEDA Report of Findings #2017-007Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-007: Operator of website that shamed debtors for profit takes down website after OPC takes the matter to Federal Court

Public Executions Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Public Executions Inc., operator of publicexecutions.ca, a website that published personal information of judgment debtors for a fee. Complainants alleged their privacy rights under PIPEDA were breached by the website's practice of "naming and shaming" them into paying debts. The website owner argued PIPEDA did not apply, claiming it was not a commercial activity, was exempt as journalism, and that disclosures were permitted for debt collection. The OPC found that the website's fee-based service constituted a commercial activity under PIPEDA. It rejected the journalistic exemption, noting the lack of original production and journalistic discipline. The OPC concluded that broadly publicizing debtor information for financial gain and coercion was not an appropriate purpose under subsection 5(3) of PIPEDA, especially given existing legal mechanisms and regulations for debt collection. Furthermore, the OPC clarified that paragraph 7(3)(b) of PIPEDA, which allows disclosure for debt collection, does not permit indiscriminate disclosure to the public. Initially, the complaint was found well-founded and unresolved, as the website owner refused to comply with recommendations. However, after the OPC initiated Federal Court proceedings, the website was taken down, leading the OPC to discontinue its application.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2017-007: Operator of website that shamed debtors for profit takes down website after OPC takes the matter to Federal Court

Aug 8, 2017PIPEDA Report of Findings #2017-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Public Executions Inc., operator of publicexecutions.ca, a website that published personal information of judgment debtors for a fee. Complainants alleged their privacy rights under PIPEDA were breached by the website's practice of "naming and shaming" them into paying debts. The website owner argued PIPEDA did not apply, claiming it was not a commercial activity, was exempt as journalism, and that disclosures were permitted for debt collection. The OPC found that the website's fee-based service constituted a commercial activity under PIPEDA. It rejected the journalistic exemption, noting the lack of original production and journalistic discipline. The OPC concluded that broadly publicizing debtor information for financial gain and coercion was not an appropriate purpose under subsection 5(3) of PIPEDA, especially given existing legal mechanisms and regulations for debt collection. Furthermore, the OPC clarified that paragraph 7(3)(b) of PIPEDA, which allows disclosure for debt collection, does not permit indiscriminate disclosure to the public. Initially, the complaint was found well-founded and unresolved, as the website owner refused to comply with recommendations. However, after the OPC initiated Federal Court proceedings, the website was taken down, leading the OPC to discontinue its application.

Key Issues
  • Whether the website's activities constituted "commercial activity" under paragraph 4(1)(a) of PIPEDA.
  • Whether the website qualified for the "journalistic purposes" exemption under paragraph 4(2)(c) of PIPEDA.
  • Whether the collection, use, and disclosure of personal information by the website was for purposes that a reasonable person would consider "appropriate in the circumstances" under subsection 5(3) of PIPEDA.
  • Whether the disclosure of personal information was permitted without consent for the purpose of collecting a debt under paragraph 7(3)(b) of PIPEDA.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 19, 2017Indexed Jun 30, 2026

MyDemocracy website not designed in a privacy sensitive way

Privy Council Office

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Quick view

Privacy ActWell-founded

MyDemocracy website not designed in a privacy sensitive way

Jul 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Key Issues
  • Whether the MyDemocracy.ca website's design led to the disclosure of personal information to third parties (Facebook, Google Analytics) without consent.
  • Whether IP addresses, browser characteristics, and unique URLs constitute "personal information" under section 3 of the Privacy Act.
  • Whether the Privy Council Office (PCO) met its obligations under section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether PCO's amendments to the website and privacy policy were sufficient to obtain meaningful consent for data disclosure.
  • Whether PCO should have conducted a Privacy Impact Assessment (PIA) for the MyDemocracy.ca initiative.
  • Whether the collection of demographic information was justified and compliant with relevant standards.
  • Whether the use of Google Analytics complied with the Treasury Board of Canada Secretariat's (TBS) Standard on Privacy and Web Analytics.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Health Canada

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Quick view

Privacy ActWell-founded

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Key Issues
  • Whether diagnostic information about individual patients constitutes 'personal information' under s.3 of the Privacy Act
  • Whether Health Canada contravened s.4 of the Privacy Act by collecting diagnostic information about patients seeking medical transportation and specialist services that was not directly related to an operating program or activity
  • Whether the collection of diagnostic information was demonstrably necessary to achieve a specific and legitimate purpose
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Phoenix pay system compromised Public Servants’ privacy

Public Services and Procurement Canada

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Quick view

Privacy ActWell-founded

Phoenix pay system compromised Public Servants’ privacy

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Key Issues
  • Whether personal information was at issue in the reported incidents
  • Whether the personal information at issue was improperly disclosed
  • What was the scope of the improper disclosure
  • Whether the personal information that was improperly disclosed was misused
  • Whether PSPC was aware of potential privacy issues with Phoenix before the launch
  • What kind of harm could result from the unauthorized disclosure of the personal information at issue
  • Whether PSPC resolved all of the vulnerabilities within Phoenix
  • Whether PSPC provided individuals with timely information regarding the breaches and vulnerabilities
  • Whether PSPC developed and implemented controls to monitor and document access to personal information held in Phoenix (Recommendation 1)
  • Whether PSPC developed more robust testing and response procedures (Recommendation 2)
  • Whether PSPC conducted necessary assessments to identify potential risks and vulnerabilities in Phoenix (Recommendation 3)
  • Whether PSPC took measures to mitigate the increased vulnerability of information used by employees in call centres (Recommendation 4)
  • Whether PSPC reviewed its breach notification practices and provided notification of the extent of the Phoenix breaches (Recommendation 5)
  • Whether PSPC completed the review of pages with row-level security (Recommendation 6)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 19, 2017Indexed Jun 30, 2026

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Royal Canadian Mounted Police (RCMP)

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Quick view

Privacy ActWell-founded

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Apr 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Key Issues
  • Whether the RCMP inappropriately disclosed the complainant's personal information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(f) of the Privacy Act.
  • Whether CBP's use of the complainant's personal information for an admissibility assessment constituted "criminal justice purposes" or "law enforcement" as defined in the Memorandum of Cooperation (MOC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(a) of the Privacy Act as a "consistent use."
  • Whether the CPIC policies in effect at the time provided sufficient clarity to guard against unauthorized disclosure of sensitive personal information.
  • Whether the revised CPIC policies, including the "SHARE US A" feature and "SIP-OB" entries, adequately protect against unauthorized disclosure of attempted suicide information.
  • Whether the default setting of the "SHARE US A" feature in CPIC should suppress the sharing of SIP-OB entries relating to threatened or attempted suicides with US border officials.
  • Whether CPIC policies should be revised to provide clear guidance for sharing attempted suicide information with US border officials only where an individual presents an ongoing risk to others.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Dec 29, 2016PIPEDA findings #2016-013Indexed Jun 30, 2026

PIPEDA findings #2016-013: Company’s disclosure of information about a debt owed is not covered under exemption to consent

A sports facilities company

An individual complained that a sports facilities company disclosed his personal information, specifically details about an outstanding debt, to a related sports association on two occasions without his consent. The company did not deny the disclosures but argued they were made in response to direct questions and with an expectation of privacy. The OPC found that information about a debt owed by an identifiable individual is personal and sensitive, requiring consent for disclosure unless a specific exemption applies. The OPC determined that the disclosures were not for the purpose of collecting the debt, thus the exemption under paragraph 7(3)(b) of PIPEDA did not apply. The company's reliance on an 'expectation of privacy' or being asked directly was not a valid substitute for obtaining consent. The complaint was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA findings #2016-013: Company’s disclosure of information about a debt owed is not covered under exemption to consent

Dec 29, 2016PIPEDA findings #2016-013
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a sports facilities company disclosed his personal information, specifically details about an outstanding debt, to a related sports association on two occasions without his consent. The company did not deny the disclosures but argued they were made in response to direct questions and with an expectation of privacy. The OPC found that information about a debt owed by an identifiable individual is personal and sensitive, requiring consent for disclosure unless a specific exemption applies. The OPC determined that the disclosures were not for the purpose of collecting the debt, thus the exemption under paragraph 7(3)(b) of PIPEDA did not apply. The company's reliance on an 'expectation of privacy' or being asked directly was not a valid substitute for obtaining consent. The complaint was found to be well-founded.

Key Issues
  • Whether the disclosure of debt information without consent contravened Principle 4.3 of PIPEDA
  • Whether the disclosure was exempt from consent under paragraph 7(3)(b) of PIPEDA for debt collection purposes
  • Whether an 'expectation of privacy' or responding to a direct question constitutes a valid exception to consent requirements
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 20, 2016Indexed Jun 30, 2026

The PBC refuses to process requests for record suspension information

Parole Board of Canada

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Quick view

Privacy ActWell-founded

The PBC refuses to process requests for record suspension information

Dec 20, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Key Issues
  • Whether an individual can make a request under the Privacy Act to confirm that no personal information relating to record suspensions exists.
  • Whether the PBC properly applied the exemption under paragraph 22(1)(b) of the Privacy Act to refuse access requests for record suspension information.
  • Whether the disclosure of record suspension information under the Privacy Act would injure the enforcement of the Criminal Records Act.
  • Whether the PBC's requirement for additional identification (FPS number, PBC reference number, criminal record copy) is necessary to adequately identify a requester under the Privacy Act.
  • Whether the company's record suspension verification service circumvents the vulnerable sector verification process under the CRA.
  • Whether the consent obtained by the company for its service is valid.
  • Whether the proposed use of personal information by the company violates human rights legislation.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 6, 2016Indexed Jun 30, 2026

TV show raises numerous questions of consent

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Quick view

Privacy ActWell-founded

TV show raises numerous questions of consent

Jun 6, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Key Issues
  • Whether the CBSA, as a federal institution, could contract out of its obligations under the Privacy Act
  • Whether the CBSA's collection of personal information in connection with the TV Program related directly to an operating program or activity of the institution (s.4 Privacy Act)
  • Whether the CBSA was involved in the collection of personal information for the purposes of the TV Program
  • Whether there was a real-time disclosure of personal information by the CBSA to Force Four for the purpose of filming the TV Program
  • Whether the CBSA obtained valid, meaningful, and freely given consent from individuals, including the complainant, for the disclosure of their personal information to Force Four (s.8 Privacy Act)
  • Whether the "Voluntary Appearance Release Form" (Waiver) effectively waived individuals' rights under the Privacy Act
  • Whether the practice of "silent filming" by the production crew was consistent with obtaining valid consent
  • Whether the CBSA disclosed personal information of an intended subject to Force Four in advance of filming without authorization (s.8 Privacy Act)
  • Whether the personal information of the intended subject was publicly available at the time of disclosure
  • Whether the facial blurring and other identity concealment techniques used in the TV Program were sufficient to prevent the identification of individuals who had not provided written consent
  • Whether the CBSA demonstrated how the disclosure of personal information of individuals without written consent was consistent with section 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 30, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – RCMP

Royal Canadian Mounted Police (RCMP)

The complainant, an RCMP employee, alleged that the RCMP inappropriately used employees' personal information during a training course for Respectful Workplace Advisors on the National Administrative Records Management System (NARMS). During a data entry exercise, participants were given sheets containing real personal information of 91 employees, including names, ranks, and incident descriptions. The complainant raised concerns as participants were not advised real data would be used nor required to sign confidentiality agreements. The RCMP acknowledged that the use of this personal information for training purposes was not authorized under section 7 of the Privacy Act, as training was not a consistent use described in the applicable Personal Information Bank. The RCMP subsequently notified all 91 affected employees of the breach and took steps to prevent future occurrences. The OPC found the complaint to be well-founded.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – RCMP

Jul 30, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, an RCMP employee, alleged that the RCMP inappropriately used employees' personal information during a training course for Respectful Workplace Advisors on the National Administrative Records Management System (NARMS). During a data entry exercise, participants were given sheets containing real personal information of 91 employees, including names, ranks, and incident descriptions. The complainant raised concerns as participants were not advised real data would be used nor required to sign confidentiality agreements. The RCMP acknowledged that the use of this personal information for training purposes was not authorized under section 7 of the Privacy Act, as training was not a consistent use described in the applicable Personal Information Bank. The RCMP subsequently notified all 91 affected employees of the breach and took steps to prevent future occurrences. The OPC found the complaint to be well-founded.

Key Issues
  • Whether the use of employees' personal information for training purposes constituted an unauthorized use under section 7(a) of the Privacy Act
  • Whether training was a consistent use of personal information as described in the applicable Personal Information Bank (PIB PSU 915)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 28, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – Parole Board of Canada

Parole Board of Canada

The complaint alleged that the Parole Board of Canada (PBC) contravened the disclosure provisions of the Privacy Act when a human resources employee disclosed the complainant's medical information to individuals involved in a Public Service Staffing Tribunal (PSST) hearing. The PSST had specifically ordered the PBC to remove medical information from the material provided. The PBC acknowledged the disclosure, apologized to the complainant, and ensured the recipients disposed of the information. The OPC found that the complainant's medical information was disclosed without consent and not under any permitted disclosure provision of subsection 8(2) of the Act. Therefore, the OPC concluded that the complaint was well-founded.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – Parole Board of Canada

Jul 28, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint alleged that the Parole Board of Canada (PBC) contravened the disclosure provisions of the Privacy Act when a human resources employee disclosed the complainant's medical information to individuals involved in a Public Service Staffing Tribunal (PSST) hearing. The PSST had specifically ordered the PBC to remove medical information from the material provided. The PBC acknowledged the disclosure, apologized to the complainant, and ensured the recipients disposed of the information. The OPC found that the complainant's medical information was disclosed without consent and not under any permitted disclosure provision of subsection 8(2) of the Act. Therefore, the OPC concluded that the complaint was well-founded.

Key Issues
  • Whether the complainant's medical information constitutes personal information under s.3 of the Privacy Act
  • Whether the disclosure of the complainant's medical information by the PBC contravened s.8(1) of the Privacy Act
  • Whether the disclosure was in accordance with any of the permitted categories under s.8(2) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jul 28, 2015Discontinued Case Summary #2015-002Indexed Jun 30, 2026

Discontinued Case Summary #2015-002: OPC discontinues additional complaints against Globe24h.com following investigation into same privacy issues

Globe24h.com

Multiple complainants alleged that Globe24h.com collected, used, and disclosed their personal information without consent by republishing Canadian court and tribunal decisions and charging for removal. The OPC had previously investigated similar complaints against Globe24h.com and found them to be well-founded. Despite this, additional complaints continued to be received. The OPC decided to discontinue these new complaints under paragraph 12.2(1)(e) of PIPEDA, as the matter had already been the subject of a Commissioner's report. The OPC noted its continued interest in Globe24h.com's compliance and later participated in a Federal Court proceeding initiated by one of the original complainants. The Federal Court ultimately confirmed the OPC's findings and ordered Globe24h.com to remove the information and cease contravening PIPEDA, leading to the website's closure.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Discontinued Case Summary #2015-002: OPC discontinues additional complaints against Globe24h.com following investigation into same privacy issues

Jul 28, 2015Discontinued Case Summary #2015-002
Adjudicator: Daniel Therrien
Plain-Language Summary

Multiple complainants alleged that Globe24h.com collected, used, and disclosed their personal information without consent by republishing Canadian court and tribunal decisions and charging for removal. The OPC had previously investigated similar complaints against Globe24h.com and found them to be well-founded. Despite this, additional complaints continued to be received. The OPC decided to discontinue these new complaints under paragraph 12.2(1)(e) of PIPEDA, as the matter had already been the subject of a Commissioner's report. The OPC noted its continued interest in Globe24h.com's compliance and later participated in a Federal Court proceeding initiated by one of the original complainants. The Federal Court ultimately confirmed the OPC's findings and ordered Globe24h.com to remove the information and cease contravening PIPEDA, leading to the website's closure.

Key Issues
  • Whether Globe24h.com collected, used, and disclosed personal information without consent
  • Whether the Commissioner should discontinue investigation of additional complaints when the matter has already been reported on
  • Whether the practices of Globe24h.com contravened PIPEDA