The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

35 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 14, 2020PIPEDA Findings #2020-005Indexed Jun 30, 2026

PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019

Desjardins

The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019

Dec 14, 2020PIPEDA Findings #2020-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.

Key Issues
  • Whether personal information held by Desjardins was protected throughout its life cycle by security safeguards appropriate to the sensitivity of the information as required by PIPEDA Safeguards Principle 4.7.
  • Whether Desjardins fulfilled its responsibilities to implement procedures to protect personal information and train its staff, as set out in Accountability Principle 4.1.
  • Whether the personal information of individuals was handled in accordance with the retention and destruction requirements as set out in PIPEDA Principle 4.5, limiting use, disclosure and retention.
  • Whether the mitigation measures offered by Desjardins to affected individuals were adequate to protect their personal information from unauthorized use, such as future identity theft, in accordance with PIPEDA Safeguards Principle 4.7.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 30, 2020PIPEDA Findings #2020-002Indexed Jun 30, 2026

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

RateMDs.com

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

Jun 30, 2020PIPEDA Findings #2020-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Key Issues
  • Whether RateMDs collected, used, or disclosed the complainant's business contact information without consent (Principle 4.3)
  • Whether the business contact information exemption under s.4.01 of PIPEDA applied to RateMDs' use of the complainant's business contact information
  • Whether the complainant's business contact information was publicly available under s.7(1)(d), 7(2)(c.1), and 7(3)(h.1) of PIPEDA and its Regulations
  • Whether the reviews and ratings posted on RateMDs constituted the complainant's personal information
  • Whether the reviews and ratings also constituted the personal information of the users who posted them
  • Whether RateMDs required the complainant's consent to publish the reviews and ratings about her (Principle 4.3)
  • Whether a balancing of interests was required when the privacy rights of multiple individuals conflicted regarding the same personal information
  • Whether RateMDs ensured the accuracy of information and provided a fair and accessible process for health professionals to challenge and correct inaccurate information (Principle 4.6, 4.9.5)
  • Whether RateMDs made readily available specific information about its policies and practices relating to the management of personal information, particularly regarding review removal and correction (Principle 4.8)
  • Whether RateMDs' "pay-for-takedown" service, allowing subscribers to hide negative reviews for a fee, constituted an appropriate purpose for collecting, using, or disclosing personal information under s.5(3) of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Nov 26, 2019PIPEDA Findings #2019-004Indexed Jun 30, 2026

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

AggregateIQ Data Services Ltd.

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Nov 26, 2019PIPEDA Findings #2019-004
Adjudicator: Daniel Therrien
Plain-Language Summary

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Key Issues
  • Whether AIQ was compliant with consent requirements for the collection, use, or disclosure of personal information under PIPEDA and PIPA.
  • Whether AIQ could rely on consent obtained by its clients for its own collection, use, and disclosure of personal information.
  • Whether consent was adequate for specific uses, such as disclosing personal information to Facebook for "custom audiences" and "lookalike audiences."
  • Whether consent was adequate for sensitive personal information, such as political opinions or psychographic profiles.
  • Whether AIQ took reasonable security measures to protect the personal information in its custody or control under PIPEDA and PIPA.
  • Whether the security breach involving the GitLab repository constituted a failure of reasonable security measures.
  • Whether personal information collected from public telephone directories required consent.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 9, 2019PIPEDA Findings #2019-001Indexed Jun 30, 2026

PIPEDA Findings #2019-001: Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information

Equifax Canada Co.

The Office of the Privacy Commissioner of Canada (OPC) investigated a 2017 data breach that compromised the personal information of approximately 19,000 Canadians held by Equifax Inc., the US parent company of Equifax Canada Co. The investigation examined the adequacy of security safeguards by both entities, Equifax Canada's accountability for data processed by Equifax Inc., the validity of consent obtained for data transfers, retention practices, and the sufficiency of post-breach mitigation measures. The OPC concluded that both Equifax Inc. and Equifax Canada contravened PIPEDA in all these areas, citing inadequate vulnerability management, network segregation, basic information security practices, and oversight. Equifax Canada signed a compliance agreement, committing to corrective measures for most findings, which were deemed well-founded and conditionally resolved. However, the finding regarding post-breach safeguards was only partially resolved, as Equifax Canada committed to extended credit monitoring but not a free credit freeze product.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-001: Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information

Apr 9, 2019PIPEDA Findings #2019-001
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a 2017 data breach that compromised the personal information of approximately 19,000 Canadians held by Equifax Inc., the US parent company of Equifax Canada Co. The investigation examined the adequacy of security safeguards by both entities, Equifax Canada's accountability for data processed by Equifax Inc., the validity of consent obtained for data transfers, retention practices, and the sufficiency of post-breach mitigation measures. The OPC concluded that both Equifax Inc. and Equifax Canada contravened PIPEDA in all these areas, citing inadequate vulnerability management, network segregation, basic information security practices, and oversight. Equifax Canada signed a compliance agreement, committing to corrective measures for most findings, which were deemed well-founded and conditionally resolved. However, the finding regarding post-breach safeguards was only partially resolved, as Equifax Canada committed to extended credit monitoring but not a free credit freeze product.

Key Issues
  • Whether Equifax Inc.'s security safeguards were appropriate to the sensitivity of the information as required by PIPEDA Safeguards Principle 4.7.
  • Whether Equifax Inc.'s retention and destruction practices for Canadian personal information complied with PIPEDA Principle 4.5.
  • Whether Equifax Canada demonstrated adequate accountability for protecting Canadian personal information handled by Equifax Inc. as required under PIPEDA Principle 4.1.
  • Whether there was adequate consent from Canadians for the collection of their personal information by Equifax Inc. and disclosure to Equifax Inc. by Equifax Canada, as required under PIPEDA Principle 4.3 and s.6.1.
  • Whether Equifax Canada's security safeguards for personal information it held directly were appropriate as required by PIPEDA Safeguards Principle 4.7.
  • Whether the post-breach mitigation measures offered by Equifax Canada were adequate to protect against unauthorized use of compromised personal information as required by PIPEDA Safeguards Principle 4.7.1.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2019PIPEDA Case Summary #2019-006Indexed Jun 30, 2026

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Grey House Publishing Canada

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Mar 28, 2019PIPEDA Case Summary #2019-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Key Issues
  • Whether the complainant's contact information constituted 'personal information' under PIPEDA
  • Whether Grey House Publishing Canada was engaged in 'commercial activity' under PIPEDA
  • Whether Grey House obtained adequate consent for the collection, use, and disclosure of the complainant's personal information
  • Whether the 'publicly available information' exceptions to consent applied
  • Whether Grey House's privacy statement met the 'openness' principle under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 25, 2019PIPEDA Findings #2019-005Indexed Jun 30, 2026

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

411Numbers

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

Mar 25, 2019PIPEDA Findings #2019-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Key Issues
  • Whether the OPC had jurisdiction over 411Numbers, a Hong Kong-incorporated company with servers outside Canada, due to a 'real and substantial connection' to Canada.
  • Whether 411Numbers collected, used, and disclosed the complainant's personal information (unlisted phone number, name, address) without knowledge and consent, contravening Principle 4.3.
  • Whether information associated with unlisted telephone numbers constitutes 'publicly available' information under paragraph 1(a) of the Regulations Specifying Publicly Available Information.
  • Whether 411Numbers exercised due diligence to ensure its databases did not include unlisted numbers.
  • Whether publishing personal information for the purpose of encouraging individuals to pay to have it removed constitutes an inappropriate purpose under s. 5(3) of PIPEDA.
  • Whether 411Numbers required individuals to provide more information than necessary for removal services, contravening Principle 4.3.3.
  • Whether 411Numbers met its obligations regarding accountability under Principles 4.1, 4.1.2, and 4.1.4.
  • Whether 411Numbers met its obligations regarding openness under Principle 4.8 and 4.8.3.
  • Whether 411Numbers met its obligations regarding challenging compliance under Principle 4.10.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 20, 2018PIPEDA Report of Findings #2018-004Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-004: Microsoft to obtain opt-in consent, enhance transparency for Windows 10 privacy settings

Microsoft

An anonymous complainant raised concerns that Microsoft Windows 10 defaulted several privacy settings to "on" during installation, and these settings were difficult to understand and change. The OPC investigated whether Microsoft obtained valid consent for collecting, using, and disclosing personal information via these default settings. Initial concerns about clarity and consistency were shared with Microsoft regarding the original Windows 10 version. Following the Creators Update, the OPC identified further issues, particularly regarding the meaningfulness of consent for Location, Diagnostics, Tailored Experiences, Relevant Ads, and Speech Recognition settings, noting confusion caused by conflating related practices. Microsoft cooperated and committed to implementing changes, including obtaining opt-in consent for all installation privacy settings, enhancing transparency, and correcting the functioning of Speech Recognition. The OPC found the complaint well-founded and conditionally resolved, pending Microsoft's implementation of these commitments by the end of 2018.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-004: Microsoft to obtain opt-in consent, enhance transparency for Windows 10 privacy settings

Jun 20, 2018PIPEDA Report of Findings #2018-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant raised concerns that Microsoft Windows 10 defaulted several privacy settings to "on" during installation, and these settings were difficult to understand and change. The OPC investigated whether Microsoft obtained valid consent for collecting, using, and disclosing personal information via these default settings. Initial concerns about clarity and consistency were shared with Microsoft regarding the original Windows 10 version. Following the Creators Update, the OPC identified further issues, particularly regarding the meaningfulness of consent for Location, Diagnostics, Tailored Experiences, Relevant Ads, and Speech Recognition settings, noting confusion caused by conflating related practices. Microsoft cooperated and committed to implementing changes, including obtaining opt-in consent for all installation privacy settings, enhancing transparency, and correcting the functioning of Speech Recognition. The OPC found the complaint well-founded and conditionally resolved, pending Microsoft's implementation of these commitments by the end of 2018.

Key Issues
  • Whether Microsoft obtained valid and meaningful consent for the collection, use, and disclosure of personal information through Windows 10 default privacy settings.
  • Whether the initial Windows 10 (Version 1507) installation process provided sufficient prominence for customizing settings and adequate information via "Learn more" links.
  • Whether the explanations for Advertising ID and Diagnostics settings in Version 1507 were clear, consistent, and comprehensive.
  • Whether opt-out consent was appropriate for the Location setting in the Creators Update, and if Microsoft's explanations were sufficiently transparent regarding exceptions and the use of "de-identified location information."
  • Whether "Full" Diagnostics should be the default setting, and if Microsoft's transparency regarding data collected at this level was adequate for meaningful consent.
  • Whether Microsoft obtained valid consent for Tailored Experiences, particularly concerning the use of broad diagnostic data and the protection of sensitive information.
  • Whether Microsoft's practices for Tailored Experiences complied with accountability requirements under Principle 4.1.4.
  • Whether opt-out consent was appropriate for the Relevant Ads (Advertising ID) setting, and if Microsoft's communications clearly distinguished it from its own advertising program.
  • Whether opt-out consent was appropriate for the Speech Recognition setting, given the sensitivity of voice data and its cloud-based nature.
  • Whether Microsoft's explanations for Speech Recognition clearly distinguished between cloud-based and device-based functionality.
  • Whether Microsoft consistently respected user choices regarding the Speech Recognition setting, especially when conflicting with Cortana settings.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 24, 2018PIPEDA Report of Findings #2018-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-003: Facebook agrees to stop using non-users’ personal information in users’ address books

Facebook Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Facebook Inc. following a 2013 privacy breach where contact information, including that of non-users, was inadvertently disclosed via the 'Download Your Information' (DYI) tool. The investigation focused on Facebook's safeguards, consent practices for its 'matching across address books' process for both users and non-users, and the ability for individuals to access and correct their personal information. The OPC found Facebook's safeguards inadequate prior to the breach, but deemed the issue resolved after Facebook implemented a new Privacy Framework. While Facebook's use of user contact information for matching was found not to contravene consent principles, the OPC determined Facebook was not sufficiently open about these practices, an issue conditionally resolved by Facebook's commitment to revise its notices. The OPC also found Facebook used non-users' personal information for matching without meaningful consent, an issue resolved by Facebook's agreement to stop maintaining such data. Finally, Facebook was found not to be providing adequate access to and correction of matched data, which was resolved through an interim solution.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-003: Facebook agrees to stop using non-users’ personal information in users’ address books

May 24, 2018PIPEDA Report of Findings #2018-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Facebook Inc. following a 2013 privacy breach where contact information, including that of non-users, was inadvertently disclosed via the 'Download Your Information' (DYI) tool. The investigation focused on Facebook's safeguards, consent practices for its 'matching across address books' process for both users and non-users, and the ability for individuals to access and correct their personal information. The OPC found Facebook's safeguards inadequate prior to the breach, but deemed the issue resolved after Facebook implemented a new Privacy Framework. While Facebook's use of user contact information for matching was found not to contravene consent principles, the OPC determined Facebook was not sufficiently open about these practices, an issue conditionally resolved by Facebook's commitment to revise its notices. The OPC also found Facebook used non-users' personal information for matching without meaningful consent, an issue resolved by Facebook's agreement to stop maintaining such data. Finally, Facebook was found not to be providing adequate access to and correction of matched data, which was resolved through an interim solution.

Key Issues
  • Whether FB had appropriate safeguards in place prior to the breach to protect contact information of users and non-users.
  • Whether FB implemented appropriate safeguards after the breach.
  • Whether FB was using the personal information of users and non-users during the process of matching across address books.
  • Whether FB was obtaining meaningful consent from users for the use of personal information during the matching process.
  • Whether FB was meeting its obligation to be open about its policies and practices regarding the matching process for users.
  • Whether FB was obtaining meaningful consent from non-users for the use of personal information during the matching process.
  • Whether FB was providing users and non-users the ability to obtain access to their personal information/data.
  • Whether FB was providing users and non-users the ability to correct their personal information/data.
  • Whether the breach resulted in unauthorized disclosure of personal information.
  • Whether the testing conducted by FB for the DYI tool was adequate.
  • Whether the notice provided to non-users in email invitations was consistent with PIPEDA s.6.1 and Principles 4.3 and 4.8.
  • Whether providing access to matched data would likely reveal personal information about a third party under PIPEDA s.9(1).
  • Whether providing access to matched data would raise safety and security concerns.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 29, 2018PIPEDA Case Summary #2018-005Indexed Jun 30, 2026

PIPEDA Case Summary #2018-005: Courier company discontinues practice of delivery to a neighbour

A courier company

A complainant alleged that a courier company disclosed her personal information without consent by delivering a package containing financial documents to her neighbour. The courier company's policy allowed drivers to deliver packages to neighbours if the addressee was not home, a practice the complainant was unaware of as she was not expecting the package. The OPC found that the courier company contravened Principle 4.3 of PIPEDA by failing to obtain consent for this practice, either directly from the complainant or by ensuring the shipper had obtained it. The OPC noted that the sensitivity of the package's contents and the complainant's unlisted phone number on the label heightened the need for express consent. The courier company committed to ending the 'delivery to a neighbour' practice in response to the OPC's recommendations. The OPC later confirmed the practice had ceased.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2018-005: Courier company discontinues practice of delivery to a neighbour

Mar 29, 2018PIPEDA Case Summary #2018-005
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a courier company disclosed her personal information without consent by delivering a package containing financial documents to her neighbour. The courier company's policy allowed drivers to deliver packages to neighbours if the addressee was not home, a practice the complainant was unaware of as she was not expecting the package. The OPC found that the courier company contravened Principle 4.3 of PIPEDA by failing to obtain consent for this practice, either directly from the complainant or by ensuring the shipper had obtained it. The OPC noted that the sensitivity of the package's contents and the complainant's unlisted phone number on the label heightened the need for express consent. The courier company committed to ending the 'delivery to a neighbour' practice in response to the OPC's recommendations. The OPC later confirmed the practice had ceased.

Key Issues
  • Whether the courier company obtained valid consent for delivering a package to a neighbour
  • Whether the courier company exercised due diligence to ensure the shipper obtained consent for 'delivery to a neighbour'
  • Whether the information disclosed (name, address, unlisted telephone number, and package contents) was sensitive in context
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 7, 2018PIPEDA Report of Findings #2018-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-006: Breach of the World Anti-Doping database

World Anti-Doping Agency (WADA)

The Office of the Privacy Commissioner of Canada (OPC) initiated an investigation into the World Anti-Doping Agency (WADA) following a 2016 data breach of its Anti-Doping Administration and Management System (ADAMS) by the "Fancy Bear" hacking group. The breach led to the public disclosure of highly sensitive personal and health information of 127 athletes, with 11,837 athletes' data potentially accessible. The OPC examined whether WADA had sufficient security safeguards under PIPEDA Principles 4.1.4, 4.7, 4.7.1, 4.7.2, and 4.7.3. The investigation found WADA's safeguards to be insufficient, particularly concerning access controls, monitoring, policies, and encryption, given the sensitivity of the data and the sophisticated nature of the attack. WADA agreed to implement most of the OPC's recommendations, including developing a comprehensive information security framework, strengthening access controls, and employing encryption at rest. The OPC accepted WADA's proposal for optional two-factor authentication for athletes, provided WADA actively promotes its use. Consequently, the matter was concluded as well-founded and conditionally resolved, with the OPC entering into a compliance agreement to monitor WADA's implementation.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-006: Breach of the World Anti-Doping database

Feb 7, 2018PIPEDA Report of Findings #2018-006
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated an investigation into the World Anti-Doping Agency (WADA) following a 2016 data breach of its Anti-Doping Administration and Management System (ADAMS) by the "Fancy Bear" hacking group. The breach led to the public disclosure of highly sensitive personal and health information of 127 athletes, with 11,837 athletes' data potentially accessible. The OPC examined whether WADA had sufficient security safeguards under PIPEDA Principles 4.1.4, 4.7, 4.7.1, 4.7.2, and 4.7.3. The investigation found WADA's safeguards to be insufficient, particularly concerning access controls, monitoring, policies, and encryption, given the sensitivity of the data and the sophisticated nature of the attack. WADA agreed to implement most of the OPC's recommendations, including developing a comprehensive information security framework, strengthening access controls, and employing encryption at rest. The OPC accepted WADA's proposal for optional two-factor authentication for athletes, provided WADA actively promotes its use. Consequently, the matter was concluded as well-founded and conditionally resolved, with the OPC entering into a compliance agreement to monitor WADA's implementation.

Key Issues
  • Whether WADA's security safeguards were appropriate to the sensitivity of the personal information in ADAMS, as required by PIPEDA Principles 4.7, 4.7.1, 4.7.2, and 4.7.3.
  • Whether WADA had implemented adequate policies and practices to give effect to PIPEDA principles, including procedures for protecting personal information, staff training, and policy documentation, under Principle 4.1.4.
  • Whether WADA's access controls, including password management, multi-factor authentication, and oversight of administrative accounts granted to Anti-Doping Organizations (ADOs), were sufficiently robust.
  • Whether WADA's monitoring and logging capabilities were adequate to detect and respond to security anomalies and intrusions.
  • Whether WADA had a proper incident response plan and a documented risk-management framework.
  • Whether WADA employed encryption for data at rest in the ADAMS database.
  • Whether WADA provided sufficient security awareness training to its staff and ADAMS stakeholders.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 9, 2018PIPEDA findings #2018-007Indexed Jun 30, 2026

PIPEDA findings #2018-007: Online marketplace needs consent from members before contacting them to join advocacy network

online marketplace

An anonymous complainant challenged an online marketplace's privacy practices after receiving an advocacy email without explicit consent. The complaint alleged unauthorized use of personal information for lobbying, inadequate handling of her privacy complaint, and unnecessary retention of data. The OPC found that the retention allegation was not well-founded. However, the OPC determined that the online marketplace failed to obtain adequate consent for sending advocacy emails and mishandled the complainant's privacy concerns, contravening PIPEDA Principles 4.3 and 4.10 respectively. The organization initially committed to corrective measures, including updating its privacy policy, providing an opt-out for advocacy messages, and improving its complaint handling process. Following the successful implementation of these recommendations, the OPC deemed the consent and challenging compliance matters well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA findings #2018-007: Online marketplace needs consent from members before contacting them to join advocacy network

Jan 9, 2018PIPEDA findings #2018-007
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant challenged an online marketplace's privacy practices after receiving an advocacy email without explicit consent. The complaint alleged unauthorized use of personal information for lobbying, inadequate handling of her privacy complaint, and unnecessary retention of data. The OPC found that the retention allegation was not well-founded. However, the OPC determined that the online marketplace failed to obtain adequate consent for sending advocacy emails and mishandled the complainant's privacy concerns, contravening PIPEDA Principles 4.3 and 4.10 respectively. The organization initially committed to corrective measures, including updating its privacy policy, providing an opt-out for advocacy messages, and improving its complaint handling process. Following the successful implementation of these recommendations, the OPC deemed the consent and challenging compliance matters well-founded and resolved.

Key Issues
  • Whether the online marketplace obtained valid consent under PIPEDA Principle 4.3 for using email addresses to send advocacy emails.
  • Whether the online marketplace adequately explained the purposes for using personal information such that the individual could reasonably understand how it would be used (PIPEDA Principle 4.3.2).
  • Whether the form of consent obtained was appropriate given the reasonable expectations of the individual and the sensitivity of the information (PIPEDA Principles 4.3.4, 4.3.5, 4.3.6).
  • Whether the online marketplace enabled the complainant to address concerns to the designated individual accountable for PIPEDA compliance (PIPEDA Principle 4.10).
  • Whether the online marketplace implemented policies and practices to receive and respond to complaints and trained staff (PIPEDA Principles 4.1.4(b), 4.1.4(c)).
  • Whether the online marketplace retained personal information longer than necessary for the identified purpose (PIPEDA Principle 4.5).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 20, 2017PIPEDA Case Summary #2017-006Indexed Jun 30, 2026

PIPEDA Case Summary #2017-006: Using SIN for identity verification cannot be a condition of service

A financial institution

A complainant alleged that a financial institution required customers to provide their Social Insurance Number (SIN) to credit reporting agencies for identity verification when opening a savings account, even though the SIN was not needed for income reporting. The financial institution argued that using the SIN for identity verification was beneficial for maintaining data integrity and cited FINTRAC guidelines. The OPC reviewed FINTRAC and Employment and Social Development Canada (ESDC) guidelines and found no requirement or suggestion for using SINs for identity verification. The OPC concluded that requiring consent for this practice as a condition of service contravened Principle 4.3.3 of PIPEDA. The financial institution agreed to make the use of SIN for identity verification optional, and the complaint was deemed well-founded and conditionally resolved. A follow-up confirmed full compliance.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2017-006: Using SIN for identity verification cannot be a condition of service

Dec 20, 2017PIPEDA Case Summary #2017-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a financial institution required customers to provide their Social Insurance Number (SIN) to credit reporting agencies for identity verification when opening a savings account, even though the SIN was not needed for income reporting. The financial institution argued that using the SIN for identity verification was beneficial for maintaining data integrity and cited FINTRAC guidelines. The OPC reviewed FINTRAC and Employment and Social Development Canada (ESDC) guidelines and found no requirement or suggestion for using SINs for identity verification. The OPC concluded that requiring consent for this practice as a condition of service contravened Principle 4.3.3 of PIPEDA. The financial institution agreed to make the use of SIN for identity verification optional, and the complaint was deemed well-founded and conditionally resolved. A follow-up confirmed full compliance.

Key Issues
  • Whether requiring a SIN for identity verification as a condition of service contravenes Principle 4.3.3 of PIPEDA
  • Whether FINTRAC or ESDC guidelines require or suggest the use of SINs for identity verification
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 14, 2017PIPEDA Report of Findings #2017-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-003: Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process

An insurance company

An individual complained that an insurance company collected and used his credit score without meaningful consent during an auto insurance claims assessment, over-collected his credit file, and used the score for an inappropriate purpose. The OPC found that the insurance company failed to demonstrate that collecting and using credit scores for fraud detection in auto claims was an appropriate purpose under PIPEDA subsection 5(3) or a "direct business need" under Ontario's Consumer Reporting Act. The OPC also determined that the company did not obtain meaningful consent because it failed to clearly advise the complainant that providing his credit score was optional, contrary to Principle 4.3. Furthermore, the company was found not to be open about its practices regarding credit score collection and use, violating Principle 4.8.1, due to insufficient notifications and inaccurate employee scripts. The allegation of over-collection was not substantiated, as only the credit score was provided. In response to the OPC's preliminary report, the insurance company agreed to cease collecting credit scores for auto accident benefit claims and review its practices for other insurance types. The matter was concluded as well-founded and conditionally resolved, pending the full implementation of these agreed-upon changes.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2017-003: Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process

Mar 14, 2017PIPEDA Report of Findings #2017-003
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an insurance company collected and used his credit score without meaningful consent during an auto insurance claims assessment, over-collected his credit file, and used the score for an inappropriate purpose. The OPC found that the insurance company failed to demonstrate that collecting and using credit scores for fraud detection in auto claims was an appropriate purpose under PIPEDA subsection 5(3) or a "direct business need" under Ontario's Consumer Reporting Act. The OPC also determined that the company did not obtain meaningful consent because it failed to clearly advise the complainant that providing his credit score was optional, contrary to Principle 4.3. Furthermore, the company was found not to be open about its practices regarding credit score collection and use, violating Principle 4.8.1, due to insufficient notifications and inaccurate employee scripts. The allegation of over-collection was not substantiated, as only the credit score was provided. In response to the OPC's preliminary report, the insurance company agreed to cease collecting credit scores for auto accident benefit claims and review its practices for other insurance types. The matter was concluded as well-founded and conditionally resolved, pending the full implementation of these agreed-upon changes.

Key Issues
  • Whether collecting and using a credit score for fraud detection during auto insurance claims assessment is an appropriate purpose under subsection 5(3) of PIPEDA.
  • Whether the insurance company had a "direct business need" for credit scores under Ontario's Consumer Reporting Act (CRA) s.8(1)(d)(vi) for fraud detection in auto claims.
  • Whether the insurance company over-collected personal information by obtaining the complainant's entire credit file.
  • Whether the insurance company properly identified the purposes for collecting the complainant's credit score under Principle 4.2.
  • Whether the insurance company obtained meaningful consent for collecting the credit score, specifically if it advised the complainant that providing the information was optional, under Principle 4.3.
  • Whether the insurance company was open about its policies and practices regarding credit score collection and use under Principle 4.8.1.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 10, 2017PIPEDA Case Summary #2017-005Indexed Jun 30, 2026

PIPEDA Case Summary #2017-005: Insurance company required to delete individual’s personal information after individual withdraws consent

An insurance company

An individual complained that his former automobile insurance company refused to delete his personal information from its records and from third-party organizations. The company initially refused, citing the need to provide insurance history to other insurers. The OPC reframed the request as a withdrawal of consent, and the company subsequently agreed to delete the information from its own records, as there was no legal requirement to retain it. However, the OPC found that the company was not obligated to ensure deletion from third-party records if the information was lawfully disclosed. The investigation also revealed the company lacked clear documentation regarding its disclosure practices to third parties, contravening Principle 4.1.4(d). The company committed to developing a document to track disclosures, which it later provided to the OPC.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2017-005: Insurance company required to delete individual’s personal information after individual withdraws consent

Feb 10, 2017PIPEDA Case Summary #2017-005
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that his former automobile insurance company refused to delete his personal information from its records and from third-party organizations. The company initially refused, citing the need to provide insurance history to other insurers. The OPC reframed the request as a withdrawal of consent, and the company subsequently agreed to delete the information from its own records, as there was no legal requirement to retain it. However, the OPC found that the company was not obligated to ensure deletion from third-party records if the information was lawfully disclosed. The investigation also revealed the company lacked clear documentation regarding its disclosure practices to third parties, contravening Principle 4.1.4(d). The company committed to developing a document to track disclosures, which it later provided to the OPC.

Key Issues
  • Whether the insurance company was required to delete the individual's personal information from its own records upon withdrawal of consent
  • Whether the insurance company was required to ensure deletion of the individual's personal information from third-party organizations' records after lawful disclosure
  • Whether the insurance company contravened Principle 4.1.4(d) by lacking a clear explanation of its disclosure practices to third parties
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 22, 2016PIPEDA Report of Findings #2016-005Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Avid Life Media Inc. (ALM)

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Aug 22, 2016PIPEDA Report of Findings #2016-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Key Issues
  • Whether ALM's security safeguards were appropriate to the sensitivity of the information under PIPEDA Principle 4.7.
  • Whether ALM implemented policies and practices to give effect to the Principles, including procedures to protect personal information, under PIPEDA Principle 4.1.4.
  • Whether ALM's indefinite retention of personal information for deactivated or inactive accounts contravened PIPEDA Principle 4.5.
  • Whether ALM's failure to establish maximum retention periods for personal information contravened PIPEDA Principle 4.5.2.
  • Whether ALM's practice of charging a fee for the complete deletion of personal information contravened an individual's right to withdraw consent under PIPEDA Principle 4.3.8.
  • Whether ALM took reasonable steps to ensure personal information (email addresses) was accurate, complete, and up-to-date as necessary for its purposes, taking into account the interests of the individual, under PIPEDA Principle 4.6 and 4.6.1.
  • Whether ALM's consent for the collection, use, or disclosure of personal information was valid, given the nature, purpose, and consequences, under PIPEDA s.6.1 and Principle 4.3.
  • Whether ALM made information about its personal information handling policies and practices readily available and understandable, and did not obtain consent through deception, under PIPEDA Principle 4.8, 4.8.1, and 4.3.5.