The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

5 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 20, 2018PIPEDA Report of Findings #2018-004Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-004: Microsoft to obtain opt-in consent, enhance transparency for Windows 10 privacy settings

Microsoft

An anonymous complainant raised concerns that Microsoft Windows 10 defaulted several privacy settings to "on" during installation, and these settings were difficult to understand and change. The OPC investigated whether Microsoft obtained valid consent for collecting, using, and disclosing personal information via these default settings. Initial concerns about clarity and consistency were shared with Microsoft regarding the original Windows 10 version. Following the Creators Update, the OPC identified further issues, particularly regarding the meaningfulness of consent for Location, Diagnostics, Tailored Experiences, Relevant Ads, and Speech Recognition settings, noting confusion caused by conflating related practices. Microsoft cooperated and committed to implementing changes, including obtaining opt-in consent for all installation privacy settings, enhancing transparency, and correcting the functioning of Speech Recognition. The OPC found the complaint well-founded and conditionally resolved, pending Microsoft's implementation of these commitments by the end of 2018.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-004: Microsoft to obtain opt-in consent, enhance transparency for Windows 10 privacy settings

Jun 20, 2018PIPEDA Report of Findings #2018-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant raised concerns that Microsoft Windows 10 defaulted several privacy settings to "on" during installation, and these settings were difficult to understand and change. The OPC investigated whether Microsoft obtained valid consent for collecting, using, and disclosing personal information via these default settings. Initial concerns about clarity and consistency were shared with Microsoft regarding the original Windows 10 version. Following the Creators Update, the OPC identified further issues, particularly regarding the meaningfulness of consent for Location, Diagnostics, Tailored Experiences, Relevant Ads, and Speech Recognition settings, noting confusion caused by conflating related practices. Microsoft cooperated and committed to implementing changes, including obtaining opt-in consent for all installation privacy settings, enhancing transparency, and correcting the functioning of Speech Recognition. The OPC found the complaint well-founded and conditionally resolved, pending Microsoft's implementation of these commitments by the end of 2018.

Key Issues
  • Whether Microsoft obtained valid and meaningful consent for the collection, use, and disclosure of personal information through Windows 10 default privacy settings.
  • Whether the initial Windows 10 (Version 1507) installation process provided sufficient prominence for customizing settings and adequate information via "Learn more" links.
  • Whether the explanations for Advertising ID and Diagnostics settings in Version 1507 were clear, consistent, and comprehensive.
  • Whether opt-out consent was appropriate for the Location setting in the Creators Update, and if Microsoft's explanations were sufficiently transparent regarding exceptions and the use of "de-identified location information."
  • Whether "Full" Diagnostics should be the default setting, and if Microsoft's transparency regarding data collected at this level was adequate for meaningful consent.
  • Whether Microsoft obtained valid consent for Tailored Experiences, particularly concerning the use of broad diagnostic data and the protection of sensitive information.
  • Whether Microsoft's practices for Tailored Experiences complied with accountability requirements under Principle 4.1.4.
  • Whether opt-out consent was appropriate for the Relevant Ads (Advertising ID) setting, and if Microsoft's communications clearly distinguished it from its own advertising program.
  • Whether opt-out consent was appropriate for the Speech Recognition setting, given the sensitivity of voice data and its cloud-based nature.
  • Whether Microsoft's explanations for Speech Recognition clearly distinguished between cloud-based and device-based functionality.
  • Whether Microsoft consistently respected user choices regarding the Speech Recognition setting, especially when conflicting with Cortana settings.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 24, 2018PIPEDA Report of Findings #2018-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-003: Facebook agrees to stop using non-users’ personal information in users’ address books

Facebook Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Facebook Inc. following a 2013 privacy breach where contact information, including that of non-users, was inadvertently disclosed via the 'Download Your Information' (DYI) tool. The investigation focused on Facebook's safeguards, consent practices for its 'matching across address books' process for both users and non-users, and the ability for individuals to access and correct their personal information. The OPC found Facebook's safeguards inadequate prior to the breach, but deemed the issue resolved after Facebook implemented a new Privacy Framework. While Facebook's use of user contact information for matching was found not to contravene consent principles, the OPC determined Facebook was not sufficiently open about these practices, an issue conditionally resolved by Facebook's commitment to revise its notices. The OPC also found Facebook used non-users' personal information for matching without meaningful consent, an issue resolved by Facebook's agreement to stop maintaining such data. Finally, Facebook was found not to be providing adequate access to and correction of matched data, which was resolved through an interim solution.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-003: Facebook agrees to stop using non-users’ personal information in users’ address books

May 24, 2018PIPEDA Report of Findings #2018-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Facebook Inc. following a 2013 privacy breach where contact information, including that of non-users, was inadvertently disclosed via the 'Download Your Information' (DYI) tool. The investigation focused on Facebook's safeguards, consent practices for its 'matching across address books' process for both users and non-users, and the ability for individuals to access and correct their personal information. The OPC found Facebook's safeguards inadequate prior to the breach, but deemed the issue resolved after Facebook implemented a new Privacy Framework. While Facebook's use of user contact information for matching was found not to contravene consent principles, the OPC determined Facebook was not sufficiently open about these practices, an issue conditionally resolved by Facebook's commitment to revise its notices. The OPC also found Facebook used non-users' personal information for matching without meaningful consent, an issue resolved by Facebook's agreement to stop maintaining such data. Finally, Facebook was found not to be providing adequate access to and correction of matched data, which was resolved through an interim solution.

Key Issues
  • Whether FB had appropriate safeguards in place prior to the breach to protect contact information of users and non-users.
  • Whether FB implemented appropriate safeguards after the breach.
  • Whether FB was using the personal information of users and non-users during the process of matching across address books.
  • Whether FB was obtaining meaningful consent from users for the use of personal information during the matching process.
  • Whether FB was meeting its obligation to be open about its policies and practices regarding the matching process for users.
  • Whether FB was obtaining meaningful consent from non-users for the use of personal information during the matching process.
  • Whether FB was providing users and non-users the ability to obtain access to their personal information/data.
  • Whether FB was providing users and non-users the ability to correct their personal information/data.
  • Whether the breach resulted in unauthorized disclosure of personal information.
  • Whether the testing conducted by FB for the DYI tool was adequate.
  • Whether the notice provided to non-users in email invitations was consistent with PIPEDA s.6.1 and Principles 4.3 and 4.8.
  • Whether providing access to matched data would likely reveal personal information about a third party under PIPEDA s.9(1).
  • Whether providing access to matched data would raise safety and security concerns.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 29, 2018PIPEDA Case Summary #2018-005Indexed Jun 30, 2026

PIPEDA Case Summary #2018-005: Courier company discontinues practice of delivery to a neighbour

A courier company

A complainant alleged that a courier company disclosed her personal information without consent by delivering a package containing financial documents to her neighbour. The courier company's policy allowed drivers to deliver packages to neighbours if the addressee was not home, a practice the complainant was unaware of as she was not expecting the package. The OPC found that the courier company contravened Principle 4.3 of PIPEDA by failing to obtain consent for this practice, either directly from the complainant or by ensuring the shipper had obtained it. The OPC noted that the sensitivity of the package's contents and the complainant's unlisted phone number on the label heightened the need for express consent. The courier company committed to ending the 'delivery to a neighbour' practice in response to the OPC's recommendations. The OPC later confirmed the practice had ceased.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2018-005: Courier company discontinues practice of delivery to a neighbour

Mar 29, 2018PIPEDA Case Summary #2018-005
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a courier company disclosed her personal information without consent by delivering a package containing financial documents to her neighbour. The courier company's policy allowed drivers to deliver packages to neighbours if the addressee was not home, a practice the complainant was unaware of as she was not expecting the package. The OPC found that the courier company contravened Principle 4.3 of PIPEDA by failing to obtain consent for this practice, either directly from the complainant or by ensuring the shipper had obtained it. The OPC noted that the sensitivity of the package's contents and the complainant's unlisted phone number on the label heightened the need for express consent. The courier company committed to ending the 'delivery to a neighbour' practice in response to the OPC's recommendations. The OPC later confirmed the practice had ceased.

Key Issues
  • Whether the courier company obtained valid consent for delivering a package to a neighbour
  • Whether the courier company exercised due diligence to ensure the shipper obtained consent for 'delivery to a neighbour'
  • Whether the information disclosed (name, address, unlisted telephone number, and package contents) was sensitive in context
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 7, 2018PIPEDA Report of Findings #2018-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-006: Breach of the World Anti-Doping database

World Anti-Doping Agency (WADA)

The Office of the Privacy Commissioner of Canada (OPC) initiated an investigation into the World Anti-Doping Agency (WADA) following a 2016 data breach of its Anti-Doping Administration and Management System (ADAMS) by the "Fancy Bear" hacking group. The breach led to the public disclosure of highly sensitive personal and health information of 127 athletes, with 11,837 athletes' data potentially accessible. The OPC examined whether WADA had sufficient security safeguards under PIPEDA Principles 4.1.4, 4.7, 4.7.1, 4.7.2, and 4.7.3. The investigation found WADA's safeguards to be insufficient, particularly concerning access controls, monitoring, policies, and encryption, given the sensitivity of the data and the sophisticated nature of the attack. WADA agreed to implement most of the OPC's recommendations, including developing a comprehensive information security framework, strengthening access controls, and employing encryption at rest. The OPC accepted WADA's proposal for optional two-factor authentication for athletes, provided WADA actively promotes its use. Consequently, the matter was concluded as well-founded and conditionally resolved, with the OPC entering into a compliance agreement to monitor WADA's implementation.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-006: Breach of the World Anti-Doping database

Feb 7, 2018PIPEDA Report of Findings #2018-006
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated an investigation into the World Anti-Doping Agency (WADA) following a 2016 data breach of its Anti-Doping Administration and Management System (ADAMS) by the "Fancy Bear" hacking group. The breach led to the public disclosure of highly sensitive personal and health information of 127 athletes, with 11,837 athletes' data potentially accessible. The OPC examined whether WADA had sufficient security safeguards under PIPEDA Principles 4.1.4, 4.7, 4.7.1, 4.7.2, and 4.7.3. The investigation found WADA's safeguards to be insufficient, particularly concerning access controls, monitoring, policies, and encryption, given the sensitivity of the data and the sophisticated nature of the attack. WADA agreed to implement most of the OPC's recommendations, including developing a comprehensive information security framework, strengthening access controls, and employing encryption at rest. The OPC accepted WADA's proposal for optional two-factor authentication for athletes, provided WADA actively promotes its use. Consequently, the matter was concluded as well-founded and conditionally resolved, with the OPC entering into a compliance agreement to monitor WADA's implementation.

Key Issues
  • Whether WADA's security safeguards were appropriate to the sensitivity of the personal information in ADAMS, as required by PIPEDA Principles 4.7, 4.7.1, 4.7.2, and 4.7.3.
  • Whether WADA had implemented adequate policies and practices to give effect to PIPEDA principles, including procedures for protecting personal information, staff training, and policy documentation, under Principle 4.1.4.
  • Whether WADA's access controls, including password management, multi-factor authentication, and oversight of administrative accounts granted to Anti-Doping Organizations (ADOs), were sufficiently robust.
  • Whether WADA's monitoring and logging capabilities were adequate to detect and respond to security anomalies and intrusions.
  • Whether WADA had a proper incident response plan and a documented risk-management framework.
  • Whether WADA employed encryption for data at rest in the ADAMS database.
  • Whether WADA provided sufficient security awareness training to its staff and ADAMS stakeholders.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 9, 2018PIPEDA findings #2018-007Indexed Jun 30, 2026

PIPEDA findings #2018-007: Online marketplace needs consent from members before contacting them to join advocacy network

online marketplace

An anonymous complainant challenged an online marketplace's privacy practices after receiving an advocacy email without explicit consent. The complaint alleged unauthorized use of personal information for lobbying, inadequate handling of her privacy complaint, and unnecessary retention of data. The OPC found that the retention allegation was not well-founded. However, the OPC determined that the online marketplace failed to obtain adequate consent for sending advocacy emails and mishandled the complainant's privacy concerns, contravening PIPEDA Principles 4.3 and 4.10 respectively. The organization initially committed to corrective measures, including updating its privacy policy, providing an opt-out for advocacy messages, and improving its complaint handling process. Following the successful implementation of these recommendations, the OPC deemed the consent and challenging compliance matters well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA findings #2018-007: Online marketplace needs consent from members before contacting them to join advocacy network

Jan 9, 2018PIPEDA findings #2018-007
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant challenged an online marketplace's privacy practices after receiving an advocacy email without explicit consent. The complaint alleged unauthorized use of personal information for lobbying, inadequate handling of her privacy complaint, and unnecessary retention of data. The OPC found that the retention allegation was not well-founded. However, the OPC determined that the online marketplace failed to obtain adequate consent for sending advocacy emails and mishandled the complainant's privacy concerns, contravening PIPEDA Principles 4.3 and 4.10 respectively. The organization initially committed to corrective measures, including updating its privacy policy, providing an opt-out for advocacy messages, and improving its complaint handling process. Following the successful implementation of these recommendations, the OPC deemed the consent and challenging compliance matters well-founded and resolved.

Key Issues
  • Whether the online marketplace obtained valid consent under PIPEDA Principle 4.3 for using email addresses to send advocacy emails.
  • Whether the online marketplace adequately explained the purposes for using personal information such that the individual could reasonably understand how it would be used (PIPEDA Principle 4.3.2).
  • Whether the form of consent obtained was appropriate given the reasonable expectations of the individual and the sensitivity of the information (PIPEDA Principles 4.3.4, 4.3.5, 4.3.6).
  • Whether the online marketplace enabled the complainant to address concerns to the designated individual accountable for PIPEDA compliance (PIPEDA Principle 4.10).
  • Whether the online marketplace implemented policies and practices to receive and respond to complaints and trained staff (PIPEDA Principles 4.1.4(b), 4.1.4(c)).
  • Whether the online marketplace retained personal information longer than necessary for the identified purpose (PIPEDA Principle 4.5).