The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

5 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 20, 2018Indexed Jun 30, 2026

Innovation, Science and Economic Development Canada fails to ensure that the information it used to staff a position was accurate

Innovation, Science and Economic Development Canada (ISED)

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) used inaccurate personal information about him when staffing a position. ISED acknowledged that its Human Resources officials mistakenly selected the complainant's profile in the MyGCHR system instead of another individual with the same name, leading to the complainant being 'hired' by ISED and 'terminated' from his position at Public Services and Procurement Canada (PSPC). This error caused the complainant to miss pay periods. The OPC found that ISED did not take all reasonable steps to ensure the accuracy of the personal information, as officials only used first and last names for the search and did not verify with additional identifiers like a Personal Record Identifier (PRI) or date of birth. The complaint was found to be well-founded, but ISED has since implemented a new policy requiring staff to validate identities using multiple data fields.

Quick view

Privacy ActWell-founded

Innovation, Science and Economic Development Canada fails to ensure that the information it used to staff a position was accurate

Aug 20, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) used inaccurate personal information about him when staffing a position. ISED acknowledged that its Human Resources officials mistakenly selected the complainant's profile in the MyGCHR system instead of another individual with the same name, leading to the complainant being 'hired' by ISED and 'terminated' from his position at Public Services and Procurement Canada (PSPC). This error caused the complainant to miss pay periods. The OPC found that ISED did not take all reasonable steps to ensure the accuracy of the personal information, as officials only used first and last names for the search and did not verify with additional identifiers like a Personal Record Identifier (PRI) or date of birth. The complaint was found to be well-founded, but ISED has since implemented a new policy requiring staff to validate identities using multiple data fields.

Key Issues
  • Whether the information at issue constituted personal information under section 3 of the Privacy Act
  • Whether ISED took all reasonable steps to ensure that the personal information it used for an administrative purpose was as accurate, up-to-date and complete as possible, as required by subsection 6(2) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 12, 2018PIPEDA Report of Findings #2018-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-002: Company’s re-use of millions of Canadian Facebook user profiles violated privacy law

Profile Technology Ltd.

Multiple complainants alleged that Profile Technology Ltd. copied their personal information from Facebook profiles and groups without consent and posted it on its social networking website, making removal difficult, and indefinitely retaining helpdesk information. The OPC asserted jurisdiction over the New Zealand-based company due to a real and substantial connection to Canada. The OPC found that the information was not "publicly available" under PIPEDA's Regulations, and Profile Technology failed to obtain valid consent for its new purpose of operating a social networking site. Furthermore, the OPC determined that using this information for such a purpose was not appropriate in the circumstances and that the indefinite retention of helpdesk ticket information violated retention principles. Profile Technology refused to implement recommendations for deletion and a retention policy. Although the company later removed profiles from its website, it uploaded much of the data to the Internet Archive, which the OPC found did not resolve the contraventions and created new privacy risks. The matter was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2018-002: Company’s re-use of millions of Canadian Facebook user profiles violated privacy law

Jun 12, 2018PIPEDA Report of Findings #2018-002
Adjudicator: Daniel Therrien
Plain-Language Summary

Multiple complainants alleged that Profile Technology Ltd. copied their personal information from Facebook profiles and groups without consent and posted it on its social networking website, making removal difficult, and indefinitely retaining helpdesk information. The OPC asserted jurisdiction over the New Zealand-based company due to a real and substantial connection to Canada. The OPC found that the information was not "publicly available" under PIPEDA's Regulations, and Profile Technology failed to obtain valid consent for its new purpose of operating a social networking site. Furthermore, the OPC determined that using this information for such a purpose was not appropriate in the circumstances and that the indefinite retention of helpdesk ticket information violated retention principles. Profile Technology refused to implement recommendations for deletion and a retention policy. Although the company later removed profiles from its website, it uploaded much of the data to the Internet Archive, which the OPC found did not resolve the contraventions and created new privacy risks. The matter was found to be well-founded.

Key Issues
  • Whether the OPC had jurisdiction to investigate a New Zealand-based company's activities affecting Canadians.
  • Whether the investigation was time-barred under subsection 13(1) of PIPEDA.
  • Whether PIPEDA's application to commercial activity is constitutionally valid under the federal Trade and Commerce power.
  • Whether personal information copied from Facebook profiles was "publicly available" under PIPEDA's Regulations Specifying Publicly Available Information.
  • Whether Facebook profiles constitute a "publication" for the purposes of the Regulations.
  • Whether Profile Technology obtained valid knowledge and consent (Principle 4.3 PIPEDA) for the collection, use, and disclosure of personal information for its social networking website.
  • Whether consent obtained by Facebook was sufficient for Profile Technology's subsequent use of the data.
  • Whether opt-out consent would be an appropriate form of consent in this context (Principle 4.3.4 PIPEDA).
  • Whether Profile Technology's use of Facebook profile information for its social networking site was for purposes a reasonable person would consider "appropriate in the circumstances" (subsection 5(3) PIPEDA).
  • Whether Profile Technology retained personal information (helpdesk tickets) longer than necessary (Principle 4.5 PIPEDA).
  • Whether Profile Technology was responsible for personal information held by its third-party helpdesk service provider.
  • Whether Profile Technology's actions of removing profiles from its website and uploading data to the Internet Archive resolved the identified contraventions.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 12, 2018Repeat offenderIndexed Jun 30, 2026

Repeat offender: CSC unlawfully denies complainant access to his personal information a second time

Correctional Service Canada (CSC)

A federal inmate complained that Correctional Service Canada (CSC) repeatedly denied him access to his personal information, specifically video and audio recordings, in contravention of the Privacy Act. This complaint followed a similar investigation in 2012 where the OPC found serious deficiencies in CSC's handling of the complainant's requests, including failure to retain video recordings before destruction. In the current investigation, the OPC found that CSC again failed to retrieve and retain requested video recordings within their short retention period in two cases, and failed to respond to four other requests for grievance-related records. The OPC concluded that CSC contravened subsection 12(1) of the Privacy Act by denying the complainant access to his personal information. CSC accepted the OPC's recommendations to improve its processes for handling access requests for records with short retention periods and to respond to outstanding requests.

Quick view

Privacy ActWell-founded

Repeat offender: CSC unlawfully denies complainant access to his personal information a second time

Jun 12, 2018Repeat offender
Adjudicator: Daniel Therrien
Plain-Language Summary

A federal inmate complained that Correctional Service Canada (CSC) repeatedly denied him access to his personal information, specifically video and audio recordings, in contravention of the Privacy Act. This complaint followed a similar investigation in 2012 where the OPC found serious deficiencies in CSC's handling of the complainant's requests, including failure to retain video recordings before destruction. In the current investigation, the OPC found that CSC again failed to retrieve and retain requested video recordings within their short retention period in two cases, and failed to respond to four other requests for grievance-related records. The OPC concluded that CSC contravened subsection 12(1) of the Privacy Act by denying the complainant access to his personal information. CSC accepted the OPC's recommendations to improve its processes for handling access requests for records with short retention periods and to respond to outstanding requests.

Key Issues
  • Whether CSC contravened subsection 6(1) of the Privacy Act by failing to retain personal information for a prescribed period
  • Whether CSC contravened subsection 12(1) of the Privacy Act by failing to provide access to personal information
  • Whether CSC contravened subsection 16(3) of the Privacy Act by failing to respond to access requests within statutory time limits
  • Whether CSC appropriately applied paragraph 22(1)(c) of the Privacy Act to withhold video recordings
  • Whether CSC appropriately applied section 26 of the Privacy Act to withhold video recordings
  • Whether CSC made reasonable efforts to secure video recordings before destruction as per previous OPC recommendations
  • Whether CSC's processes for handling access requests for records with short retention periods are adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 4, 2018Indexed Jun 30, 2026

Employee text messages intercepted without authorization at the Warkworth Institution

Correctional Service Canada (CSC)

The OPC received complaints alleging that Correctional Service Canada (CSC) contravened the Privacy Act by intercepting cell phone conversations and text messages near Warkworth Institution. CSC confirmed intercepting six text messages but denied recording conversations, stating it did not intend to collect text messages. The investigation found that CSC used a cell-site simulator, operated by a contractor, to detect unauthorized cell phone use by inmates. While the collection of metadata was deemed consistent with the Act due to security concerns, the interception of text message content was not authorized. The OPC concluded that CSC was responsible for the contractor's actions and that the collection of text messages contravened the Privacy Act. The complaints were found to be well-founded.

Quick view

Privacy ActWell-founded

Employee text messages intercepted without authorization at the Warkworth Institution

Jun 4, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC received complaints alleging that Correctional Service Canada (CSC) contravened the Privacy Act by intercepting cell phone conversations and text messages near Warkworth Institution. CSC confirmed intercepting six text messages but denied recording conversations, stating it did not intend to collect text messages. The investigation found that CSC used a cell-site simulator, operated by a contractor, to detect unauthorized cell phone use by inmates. While the collection of metadata was deemed consistent with the Act due to security concerns, the interception of text message content was not authorized. The OPC concluded that CSC was responsible for the contractor's actions and that the collection of text messages contravened the Privacy Act. The complaints were found to be well-founded.

Key Issues
  • Whether cell phone metadata constitutes personal information under the Privacy Act
  • Whether text messages constitute personal information under the Privacy Act
  • Whether the collection of cell phone metadata by CSC was consistent with section 4 of the Privacy Act
  • Whether the interception and collection of text message content by CSC was consistent with section 4 of the Privacy Act
  • Whether CSC is responsible for the actions of its contractor in collecting personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 12, 2018Indexed Jun 30, 2026

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Health Canada

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Quick view

Privacy ActWell-founded

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Mar 12, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Key Issues
  • Whether the information collected by Health Canada on Limited Use forms for drug benefits constitutes personal information under the Privacy Act
  • Whether Health Canada's collection of personal information on Limited Use forms relates directly to an operating program or activity of the institution as required by section 4 of the Privacy Act
  • Whether the specific data fields requesting detailed diagnostic information (e.g., exact number of swollen joints) are necessary for the adjudication of drug benefit claims under the NIHB Program