The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

2 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 22, 2016PIPEDA Report of Findings #2016-005Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Avid Life Media Inc. (ALM)

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Aug 22, 2016PIPEDA Report of Findings #2016-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Key Issues
  • Whether ALM's security safeguards were appropriate to the sensitivity of the information under PIPEDA Principle 4.7.
  • Whether ALM implemented policies and practices to give effect to the Principles, including procedures to protect personal information, under PIPEDA Principle 4.1.4.
  • Whether ALM's indefinite retention of personal information for deactivated or inactive accounts contravened PIPEDA Principle 4.5.
  • Whether ALM's failure to establish maximum retention periods for personal information contravened PIPEDA Principle 4.5.2.
  • Whether ALM's practice of charging a fee for the complete deletion of personal information contravened an individual's right to withdraw consent under PIPEDA Principle 4.3.8.
  • Whether ALM took reasonable steps to ensure personal information (email addresses) was accurate, complete, and up-to-date as necessary for its purposes, taking into account the interests of the individual, under PIPEDA Principle 4.6 and 4.6.1.
  • Whether ALM's consent for the collection, use, or disclosure of personal information was valid, given the nature, purpose, and consequences, under PIPEDA s.6.1 and Principle 4.3.
  • Whether ALM made information about its personal information handling policies and practices readily available and understandable, and did not obtain consent through deception, under PIPEDA Principle 4.8, 4.8.1, and 4.3.5.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 21, 2016PIPEDA Report of Findings #2016-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Compu-Finder (3510395 Canada Inc.)

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Apr 21, 2016PIPEDA Report of Findings #2016-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Key Issues
  • Whether Compu-Finder's collection and use of email addresses constituted "personal information" under PIPEDA.
  • Whether the business contact information carve-out under s. 4.01 PIPEDA applied to Compu-Finder's activities.
  • Whether Compu-Finder obtained meaningful express consent for collecting email addresses via telemarketing (Principles 4.2, 4.3, 4.3.2).
  • Whether Compu-Finder collected personal information by fair and lawful means (Principle 4.4).
  • Whether Compu-Finder obtained meaningful implied consent for collecting email addresses from publicly available sources (Principle 4.3.6).
  • Whether the "publicly available information" exemption (s. 7(1)(d), 7(2)(c.1) PIPEDA and s. 1 of the Regulations) applied to Compu-Finder's collection and use of email addresses.
  • Whether the address harvesting provisions (s. 7.1(2) PIPEDA) prohibited the use of email addresses collected via software before the provision came into force.
  • Whether Compu-Finder had a designated individual accountable for PIPEDA compliance (Principle 4.1).
  • Whether Compu-Finder implemented policies and practices to give effect to PIPEDA principles (Principle 4.1.4).
  • Whether Compu-Finder was open about its personal information management policies and practices (Principles 4.8.1, 4.8.2).