The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

35 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 21, 2016PIPEDA Report of Findings #2016-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Compu-Finder (3510395 Canada Inc.)

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Apr 21, 2016PIPEDA Report of Findings #2016-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Key Issues
  • Whether Compu-Finder's collection and use of email addresses constituted "personal information" under PIPEDA.
  • Whether the business contact information carve-out under s. 4.01 PIPEDA applied to Compu-Finder's activities.
  • Whether Compu-Finder obtained meaningful express consent for collecting email addresses via telemarketing (Principles 4.2, 4.3, 4.3.2).
  • Whether Compu-Finder collected personal information by fair and lawful means (Principle 4.4).
  • Whether Compu-Finder obtained meaningful implied consent for collecting email addresses from publicly available sources (Principle 4.3.6).
  • Whether the "publicly available information" exemption (s. 7(1)(d), 7(2)(c.1) PIPEDA and s. 1 of the Regulations) applied to Compu-Finder's collection and use of email addresses.
  • Whether the address harvesting provisions (s. 7.1(2) PIPEDA) prohibited the use of email addresses collected via software before the provision came into force.
  • Whether Compu-Finder had a designated individual accountable for PIPEDA compliance (Principle 4.1).
  • Whether Compu-Finder implemented policies and practices to give effect to PIPEDA principles (Principle 4.1.4).
  • Whether Compu-Finder was open about its personal information management policies and practices (Principles 4.8.1, 4.8.2).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 15, 2015PIPEDA Case Summary #2015-014Indexed Jun 30, 2026

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

A pension and benefit provider

An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

Dec 15, 2015PIPEDA Case Summary #2015-014
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.

Key Issues
  • Whether the provider disclosed the complainant's unique identifier to a third party without consent (Principle 4.3 PIPEDA)
  • Whether the provider failed to keep the complainant's address information accurate (Principle 4.6 PIPEDA)
  • Whether the provider failed to implement appropriate safeguards to protect personal information from unauthorized disclosure and modification (Principle 4.7 PIPEDA)
  • Whether proper authentication of the caller took place before the complainant's ID number was given out (Principle 4.7.1 PIPEDA)
  • Whether the provider's failure to detect and correct the erroneous address sooner constituted a contravention of Principle 4.6.1 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

An organization

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Key Issues
  • Whether the disclosed leave information constituted personal information under PIPEDA
  • Whether the organization's purposes for disclosing employee leave information to other employees were appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the disclosure of leave type was necessary for the organization to meet its employee schedule management needs
  • Whether the benefits of the leave exchange system were proportional to the loss of privacy experienced by employees
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apple Canada Inc.

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Key Issues
  • Whether Apple's privacy policy adequately identified the purposes for collecting date of birth information for authentication (Principle 4.2 PIPEDA)
  • Whether Apple's collection of date of birth was limited to what was necessary for identified purposes (Principle 4.4 PIPEDA)
  • Whether Apple made information about its policies and practices concerning the collection of credit card information readily available to individuals (Principle 4.8 PIPEDA)
  • Whether Apple's practices resulted in the over-collection of sensitive payment information (Principle 4.4 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 14, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-001Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-001: Use of sensitive health information for targeting of Google ads raises privacy concerns

Google Inc.

A complainant alleged that Google's AdSense service displayed targeted advertisements for sleep apnea devices on unrelated websites after he searched for medical devices online. He viewed his online activities related to sleep apnea as sensitive information requiring express consent for targeted advertising. The OPC's technical analysis confirmed that Google was delivering these ads through online behavioural advertising (OBA) and that they persisted over time. Google initially attributed this to a technical issue but later confirmed it was due to 'remarketed ads,' a form of interest-based advertising. The OPC found that Google's practice of delivering tailored ads based on sensitive health information without express consent contravened PIPEDA Principles 4.3 and 4.3.6. Google committed to several remedial measures, including rejecting relevant remarketing campaigns, revising its policies, developing new internal training, and increasing monitoring.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Report of Findings #2014-001: Use of sensitive health information for targeting of Google ads raises privacy concerns

Jan 14, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-001
Adjudicator: Chantal Bernier
Plain-Language Summary

A complainant alleged that Google's AdSense service displayed targeted advertisements for sleep apnea devices on unrelated websites after he searched for medical devices online. He viewed his online activities related to sleep apnea as sensitive information requiring express consent for targeted advertising. The OPC's technical analysis confirmed that Google was delivering these ads through online behavioural advertising (OBA) and that they persisted over time. Google initially attributed this to a technical issue but later confirmed it was due to 'remarketed ads,' a form of interest-based advertising. The OPC found that Google's practice of delivering tailored ads based on sensitive health information without express consent contravened PIPEDA Principles 4.3 and 4.3.6. Google committed to several remedial measures, including rejecting relevant remarketing campaigns, revising its policies, developing new internal training, and increasing monitoring.

Key Issues
  • Whether the delivery of targeted advertisements based on online searches for medical devices constitutes online behavioural advertising (OBA)
  • Whether information related to online searches for medical devices is sensitive personal information
  • Whether express consent is required for the collection and use of sensitive personal health information for OBA purposes
  • Whether Google obtained appropriate consent under Principle 4.3 and 4.3.6 for the use of sensitive health information for targeted advertising
  • Whether Google's privacy policy accurately reflected its practices regarding sensitive categories in tailored ads
  • Whether Google's monitoring tools for preventing policy abuses were scalable and effective