The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

2 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 7, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Canada Revenue Agency

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

May 7, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Key Issues
  • Whether the CRA adequately protected personal information against unauthorized disclosure and modification
  • Whether the CRA contravened subsection 6(2) of the Privacy Act regarding accuracy of personal information
  • Whether the CRA contravened subsection 8(2) of the Privacy Act regarding disclosure of personal information
  • Whether the CRA's prevention measures were adequate
  • Whether the CRA implemented mandatory multi-factor authentication (MFA) in a timely manner and with sufficient strength
  • Whether the CRA's authentication processes by phone were strong enough
  • Whether the CRA considered and integrated a zero-trust approach into its security measures
  • Whether the CRA had sufficient visibility over its attack surface and managed it effectively
  • Whether the CRA's vetting, training, and awareness tools were effective for employees and third parties
  • Whether the CRA's monitoring and detection approach was tailored to the threats and risks leading to Unauthorized Use of Taxpayer Information by a Third Party (UUTP)
  • Whether the CRA's remediation efforts for individual UUTPs were adequate, including root cause analysis
  • Whether the CRA's governance processes for addressing UUTPs were coordinated, comprehensive, and efficient
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 3, 2026Indexed Jun 30, 2026

Correctional Service of Canada Deleted Video

Correctional Service of Canada (CSC)

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Correctional Service of Canada Deleted Video

Mar 3, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether CSC failed to retain personal information used for an administrative purpose as required by Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations
  • Whether the complainant was denied a reasonable opportunity to obtain access to their personal information due to non-retention