
Protecting privacy in a pandemic
The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.
Ontario
British Columbia
Alberta
Saskatchewan
Manitoba
Quebec
Nova Scotia
New Brunswick
Prince Edward Island
Newfoundland and Labrador
Yukon
Northwest Territories
Nunavut