The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

38 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 7, 2016PIPEDA Case Summary #2016-010Indexed Jun 30, 2026

PIPEDA Case Summary #2016-010: Credit reporting agency takes remedial action after failing to maintain accurate records

A credit reporting agency

An individual complained to the OPC after discovering inaccuracies in his credit file, including two unrecognized credit inquiries and a notation that his account had been automatically combined with others. The credit reporting agency acknowledged that his file had been manually combined with another individual's due to similar names and addresses. The OPC investigated two main issues: unauthorized use/disclosure and accuracy of personal information. The OPC found no unauthorized use or disclosure, as the inquiries occurred before the files were combined and only the other individual's information was used. However, the OPC determined that the agency failed to maintain accurate personal information, as combining files compromised accuracy and led to incorrect information being attributed to the complainant. The agency rectified the error by separating the files, notifying creditors of corrections, and committing to enhanced employee training. Consequently, the accuracy issue was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-010: Credit reporting agency takes remedial action after failing to maintain accurate records

Jul 7, 2016PIPEDA Case Summary #2016-010
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after discovering inaccuracies in his credit file, including two unrecognized credit inquiries and a notation that his account had been automatically combined with others. The credit reporting agency acknowledged that his file had been manually combined with another individual's due to similar names and addresses. The OPC investigated two main issues: unauthorized use/disclosure and accuracy of personal information. The OPC found no unauthorized use or disclosure, as the inquiries occurred before the files were combined and only the other individual's information was used. However, the OPC determined that the agency failed to maintain accurate personal information, as combining files compromised accuracy and led to incorrect information being attributed to the complainant. The agency rectified the error by separating the files, notifying creditors of corrections, and committing to enhanced employee training. Consequently, the accuracy issue was found to be well-founded and resolved.

Key Issues
  • Whether the credit reporting agency improperly disclosed the complainant's personal information without consent
  • Whether the credit reporting agency failed to maintain accurate personal information as required by PIPEDA Principle 4.6
  • Whether the credit reporting agency failed to maintain accurate personal information as required by PIPEDA Principle 4.6.3
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2016PIPEDA Case Summary #2016-012Indexed Jun 30, 2026

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

A bank associated with a retailer

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

Mar 31, 2016PIPEDA Case Summary #2016-012
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Key Issues
  • Whether the bank obtained valid consent for a credit card application and credit check under Principle 4.3
  • Whether the bank ensured the accuracy of personal information collected under Principle 4.6
  • Whether the bank had adequate procedures to give effect to PIPEDA principles under Principle 4.1.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 10, 2016PIPEDA Case Summary #2016-009Indexed Jun 30, 2026

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

An international trucking company

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

Mar 10, 2016PIPEDA Case Summary #2016-009
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Key Issues
  • Whether the disclosure of drug test results to the WCB without consent contravened PIPEDA Principles 4.3 and 4.5
  • Whether the employer had a legal obligation to disclose the drug test results to the WCB under the provincial Workers' Compensation Act, thereby qualifying for an exception to consent under paragraph 7(3)(i) of PIPEDA
  • Whether the employer disclosed the drug test results to co-workers without consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 19, 2016PIPEDA Report of Findings #2016-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

A property management company

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

Feb 19, 2016PIPEDA Report of Findings #2016-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Key Issues
  • Whether the collection, use, and disclosure of personal information for a "bad tenant list" was for purposes that a reasonable person would consider appropriate in the circumstances (s.5(3) PIPEDA)
  • Whether the property management company was acting as an unlicensed credit reporting agency under provincial legislation
  • Whether meaningful knowledge and consent of individuals were obtained for the collection, use, and disclosure of their personal information for the "bad tenant list" (Principle 4.3, 4.3.2 PIPEDA)
  • Whether the personal information on the "bad tenant list" was accurate, complete, and up-to-date (Principle 4.6, 4.6.1 PIPEDA)
  • Whether individuals had the ability to challenge the accuracy of information about them on the list (Principle 4.10 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 12, 2016PIPEDA Report of Findings #2016-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

An insurance company

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

Feb 12, 2016PIPEDA Report of Findings #2016-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Key Issues
  • Whether the insurance company contravened Principles 4.9 and 4.9.1 by refusing access to personal information without severing third-party information
  • Whether the insurance company's internal ombudsman office constitutes a "formal dispute resolution process" under PIPEDA s.9(3)(d)
  • Whether the activities of the internal ombudsman office fall under the definition of "commercial activity" under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 9, 2016PIPEDA Case Summary #2016-007Indexed Jun 30, 2026

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

A collection agency

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

Feb 9, 2016PIPEDA Case Summary #2016-007
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the organization refused to provide access to personal information
  • Whether the organization responded to access requests within the required timeframe
  • Whether the organization followed its own privacy policies and procedures for access requests
  • Whether the organization maintained records of access request processing
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 9, 2016PIPEDA Case Summary #2016-004Indexed Jun 30, 2026

PIPEDA Case Summary #2016-004: Retailer shares customer’s in-store behaviour with the customer’s employer

A retail store

A customer complained that a retail store employee disclosed his personal information to his employer, including his name, in-store behavior, and statements made to staff. The store argued the information was not personal because it was made publicly, and that it had implied consent for the disclosure. The OPC found that information overheard by others is still personal information under PIPEDA. The OPC also determined that implied consent was not appropriate given the sensitive nature of the information, which had the potential to negatively affect the customer's employment. The store's disclosure without knowledge or consent contravened Principle 4.3 of PIPEDA. The complaint was found to be well-founded and resolved after the store implemented the OPC's recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-004: Retailer shares customer’s in-store behaviour with the customer’s employer

Jan 9, 2016PIPEDA Case Summary #2016-004
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a retail store employee disclosed his personal information to his employer, including his name, in-store behavior, and statements made to staff. The store argued the information was not personal because it was made publicly, and that it had implied consent for the disclosure. The OPC found that information overheard by others is still personal information under PIPEDA. The OPC also determined that implied consent was not appropriate given the sensitive nature of the information, which had the potential to negatively affect the customer's employment. The store's disclosure without knowledge or consent contravened Principle 4.3 of PIPEDA. The complaint was found to be well-founded and resolved after the store implemented the OPC's recommendations.

Key Issues
  • Whether the information shared was personal information under PIPEDA
  • Whether the customer provided implied consent for the disclosure of his personal information
  • Whether the disclosed information was sensitive
  • Whether the customer had a reasonable expectation that his information would be shared with his employer
  • Whether the publicly available information exception to consent applied
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 10, 2015PIPEDA Case Summary #2015-015Indexed Jun 30, 2026

PIPEDA Case Summary #2015-015: Roofing company takes measures to ensure sub-contractors follow its privacy policy

A roofing company (the "second roofer")

An individual complained that an estimator working for a roofing company (the "second roofer") disclosed his personal financial situation and contractual history to a competitor (the "first roofer") without his consent. The individual had engaged the second roofer for an estimate to fix issues with work done by the first roofer, and later cancelled a contract with the second roofer. The OPC found that the estimator was acting as an agent for the second roofer, making the second roofer responsible for the estimator's actions. The OPC concluded that the disclosure of personal information without the individual's knowledge or consent contravened Principle 4.3 of PIPEDA. The second roofer subsequently implemented recommendations to establish agreements with sub-contractors to adhere to its privacy policy and provide training. As a result, the complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2015-015: Roofing company takes measures to ensure sub-contractors follow its privacy policy

Nov 10, 2015PIPEDA Case Summary #2015-015
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an estimator working for a roofing company (the "second roofer") disclosed his personal financial situation and contractual history to a competitor (the "first roofer") without his consent. The individual had engaged the second roofer for an estimate to fix issues with work done by the first roofer, and later cancelled a contract with the second roofer. The OPC found that the estimator was acting as an agent for the second roofer, making the second roofer responsible for the estimator's actions. The OPC concluded that the disclosure of personal information without the individual's knowledge or consent contravened Principle 4.3 of PIPEDA. The second roofer subsequently implemented recommendations to establish agreements with sub-contractors to adhere to its privacy policy and provide training. As a result, the complaint was deemed well-founded and resolved.

Key Issues
  • Whether the estimator was acting as an agent of the second roofer
  • Whether the second roofer was responsible for the personal information handling practices of its estimator
  • Whether personal information was disclosed without the individual's knowledge or consent
  • Whether the disclosure contravened Principle 4.3 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 6, 2015PIPEDA Case Summary #2015-010Indexed Jun 30, 2026

PIPEDA Case Summary #2015-010: Customer’s emails sent to her acquaintance following a telecom employee’s attempt to fix a problem with the customer’s email service

A telecommunications provider

An individual complained that her telecommunications provider disclosed her personal information without consent. A technical support representative, while attempting to fix her email service, inadvertently configured her email application to automatically forward her emails, including one containing a temporary password, to an acquaintance. The OPC found that this constituted a disclosure of personal information without consent, contravening Principle 4.3. The telecom provider initially provided inaccurate information to the OPC regarding corrective measures taken, but later clarified its existing measures. The complaint was found to be well-founded and resolved, as the provider had some measures in place to prevent recurrence, despite the initial misrepresentations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2015-010: Customer’s emails sent to her acquaintance following a telecom employee’s attempt to fix a problem with the customer’s email service

Jul 6, 2015PIPEDA Case Summary #2015-010
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that her telecommunications provider disclosed her personal information without consent. A technical support representative, while attempting to fix her email service, inadvertently configured her email application to automatically forward her emails, including one containing a temporary password, to an acquaintance. The OPC found that this constituted a disclosure of personal information without consent, contravening Principle 4.3. The telecom provider initially provided inaccurate information to the OPC regarding corrective measures taken, but later clarified its existing measures. The complaint was found to be well-founded and resolved, as the provider had some measures in place to prevent recurrence, despite the initial misrepresentations.

Key Issues
  • Whether the telecommunications provider disclosed the individual's personal information without consent
  • Whether the disclosure contravened Principle 4.3 of PIPEDA
  • Whether the telecommunications provider provided accurate information to the OPC during the investigation
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 13, 2015PIPEDA Report of Findings #2015-007Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-007: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Peoples Trust

The OPC initiated an investigation into Peoples Trust following a data breach that compromised sensitive personal information of approximately 12,000 customers. The investigation found that Peoples Trust failed to implement adequate technological and organizational safeguards, including using an outdated and vulnerable web editor and lacking ongoing monitoring. Additionally, the organization unnecessarily stored duplicate, unencrypted customer information on a web server for longer than required, contravening its retention policies. Following the OPC's intervention, Peoples Trust implemented comprehensive remedial measures, such as redesigning its web portal, enhancing monitoring, and developing a new Information Security Policy. As a result, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2015-007: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 13, 2015PIPEDA Report of Findings #2015-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated an investigation into Peoples Trust following a data breach that compromised sensitive personal information of approximately 12,000 customers. The investigation found that Peoples Trust failed to implement adequate technological and organizational safeguards, including using an outdated and vulnerable web editor and lacking ongoing monitoring. Additionally, the organization unnecessarily stored duplicate, unencrypted customer information on a web server for longer than required, contravening its retention policies. Following the OPC's intervention, Peoples Trust implemented comprehensive remedial measures, such as redesigning its web portal, enhancing monitoring, and developing a new Information Security Policy. As a result, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether Peoples Trust implemented adequate technological and organizational safeguards appropriate to the sensitivity of the information, as per Principle 4.7 and 4.1.4(a) PIPEDA
  • Whether Peoples Trust retained personal information for longer than necessary to fulfill its purposes, as per Principle 4.5 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
May 22, 2014PIPEDA findings #2014-020Indexed Jun 30, 2026

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

A videographer

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

May 22, 2014PIPEDA findings #2014-020
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Key Issues
  • Whether the use of personal information constituted commercial activity
  • Whether the videographer had consent for this use
  • Whether the videographer needed consent for this use
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014Indexed Jun 30, 2026

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

An online dating service

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Key Issues
  • Whether the organization denied the complainant access to his personal information in violation of Principle 4.9
  • Whether the organization failed to respect the 30-day time limit for access requests under subsection 8(3)
  • Whether the organization contravened subsection 8(8) by destroying photographs, limiting the complainant's recourse
  • Whether the organization retained the complainant's information longer than necessary in contravention of Principle 4.5.3
  • Whether the organization continued to use the complainant's personal information for marketing after consent withdrawal, contravening Principle 4.3.8
  • Whether the organization lacked a privacy policy in contravention of Principle 4.1.4(d)
  • Whether the organization failed to safeguard the complainant's personal information as required by Principle 4.7.1
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 2, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-005Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-005: Beneficiary’s access to estate information is limited to his own personal information under PIPEDA

A legal firm

An individual, claiming to be a beneficiary of two estates, sought access under PIPEDA to estate information from a legal firm that had acted as an agent for another firm administering the estates. The complainant requested information pertaining to himself as a beneficiary and general beneficiary entitlements. The legal firm initially failed to respond to the access requests, leading to a complaint with the OPC. The firm later responded, stating it held no personal information about the complainant and that neither he nor the estates were clients. The OPC found that the firm contravened PIPEDA by not responding within the 30-day time limit. However, the OPC also determined that the complainant was only entitled to access information specifically about himself, not general estate information, and was satisfied that the firm had conducted a reasonable search for his personal information. The complaint was deemed well-founded and resolved due to the firm's initial failure to respond.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-005: Beneficiary’s access to estate information is limited to his own personal information under PIPEDA

Oct 2, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-005
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual, claiming to be a beneficiary of two estates, sought access under PIPEDA to estate information from a legal firm that had acted as an agent for another firm administering the estates. The complainant requested information pertaining to himself as a beneficiary and general beneficiary entitlements. The legal firm initially failed to respond to the access requests, leading to a complaint with the OPC. The firm later responded, stating it held no personal information about the complainant and that neither he nor the estates were clients. The OPC found that the firm contravened PIPEDA by not responding within the 30-day time limit. However, the OPC also determined that the complainant was only entitled to access information specifically about himself, not general estate information, and was satisfied that the firm had conducted a reasonable search for his personal information. The complaint was deemed well-founded and resolved due to the firm's initial failure to respond.

Key Issues
  • Whether a legal firm must respond to an access request within 30 days, even if it holds no personal information about the requester
  • Whether a beneficiary of an estate is entitled under PIPEDA to access general estate information
  • Whether the requested information (e.g., statements of accounts, money received, disbursements) constitutes the complainant's personal information under PIPEDA
  • Whether the legal firm conducted a reasonable search for the complainant's personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 11, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-003Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-003: Profiles on PositiveSingles.com dating website turn up on other affiliated dating websites

SuccessfulMatch Inc. (operating PositiveSingles.com)

Three individuals complained that their dating profiles, containing sensitive medical information, posted on PositiveSingles.com appeared on numerous other affiliated dating websites without their knowledge or consent. The complainants were assured of privacy but found their profiles on sites targeting different demographics, causing distress. The OPC's investigation found that PositiveSingles.com, operated by SuccessfulMatch Inc., used a single database across a network of affiliated sites, making profiles automatically available. The OPC concluded that the organization failed to obtain meaningful consent for this use, lacked openness about its network structure, and had inadequate safeguards, as some personal information was accessible via search engines. Following the OPC's recommendations, SuccessfulMatch revamped its website to provide explicit information about the network, ensure informed consent at registration, and improve safeguards. The complaint was found well-founded and resolved due to these corrective measures.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-003: Profiles on PositiveSingles.com dating website turn up on other affiliated dating websites

Jul 11, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-003
Adjudicator: Jennifer Stoddart
Plain-Language Summary

Three individuals complained that their dating profiles, containing sensitive medical information, posted on PositiveSingles.com appeared on numerous other affiliated dating websites without their knowledge or consent. The complainants were assured of privacy but found their profiles on sites targeting different demographics, causing distress. The OPC's investigation found that PositiveSingles.com, operated by SuccessfulMatch Inc., used a single database across a network of affiliated sites, making profiles automatically available. The OPC concluded that the organization failed to obtain meaningful consent for this use, lacked openness about its network structure, and had inadequate safeguards, as some personal information was accessible via search engines. Following the OPC's recommendations, SuccessfulMatch revamped its website to provide explicit information about the network, ensure informed consent at registration, and improve safeguards. The complaint was found well-founded and resolved due to these corrective measures.

Key Issues
  • Whether PositiveSingles.com obtained meaningful consent for the use of personal information across its network of affiliated sites (Principle 4.3, 4.3.2, 4.3.5 PIPEDA)
  • Whether PositiveSingles.com was sufficiently open about its personal information management policies and practices, particularly regarding its network structure (Principle 4.8, 4.8.1 PIPEDA)
  • Whether PositiveSingles.com implemented adequate security safeguards to protect sensitive personal information from unauthorized access (Principle 4.7, 4.7.1 PIPEDA)
  • Whether PositiveSingles.com's use of cookies, potentially for online behavioral advertising, required express consent given the sensitive nature of the information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 28, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-017Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-017: Apple called upon to provide greater clarity on its use and disclosure of unique device identifiers for targeted advertising

Apple

An individual complained that Apple was using and sharing her unique device identifier (UDID) without her knowledge and consent for tracking and targeted advertising. The OPC determined that UDIDs, and later Advertising IDs (Ad IDs), constituted personal information because Apple could link them to identifiable individuals. While Apple's use of UDIDs for administrative purposes was deemed to have implied consent, the OPC initially found Apple's explanations for using and disclosing UDIDs for targeted advertising to be insufficient for meaningful consent. During the investigation, Apple phased out the use of UDIDs for advertising, introduced the resettable Ad ID, and improved its privacy policy explanations and opt-out mechanisms. Consequently, the OPC found that Apple's updated practices provided sufficient information for meaningful consent regarding the use and disclosure of Ad IDs for advertising. The complaint was found to be well-founded but resolved due to Apple's corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-017: Apple called upon to provide greater clarity on its use and disclosure of unique device identifiers for targeted advertising

Jun 28, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-017
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Apple was using and sharing her unique device identifier (UDID) without her knowledge and consent for tracking and targeted advertising. The OPC determined that UDIDs, and later Advertising IDs (Ad IDs), constituted personal information because Apple could link them to identifiable individuals. While Apple's use of UDIDs for administrative purposes was deemed to have implied consent, the OPC initially found Apple's explanations for using and disclosing UDIDs for targeted advertising to be insufficient for meaningful consent. During the investigation, Apple phased out the use of UDIDs for advertising, introduced the resettable Ad ID, and improved its privacy policy explanations and opt-out mechanisms. Consequently, the OPC found that Apple's updated practices provided sufficient information for meaningful consent regarding the use and disclosure of Ad IDs for advertising. The complaint was found to be well-founded but resolved due to Apple's corrective actions.

Key Issues
  • Whether Unique Device Identifiers (UDID) constitute personal information under PIPEDA.
  • Whether Advertising Identifiers (Ad ID) constitute personal information under PIPEDA.
  • Whether Apple obtained meaningful consent for its use of UDID for administration and maintenance purposes (Principle 4.3 PIPEDA).
  • Whether Apple obtained meaningful consent for its use of UDID and Ad ID for targeted advertising purposes (Principle 4.3 PIPEDA).
  • Whether Apple obtained meaningful consent for its disclosure of UDID and Ad ID to third-party app developers (Principle 4.3 PIPEDA).
  • Whether Apple's explanations regarding the use and disclosure of UDID and Ad ID were sufficiently clear and understandable to ensure meaningful consent (Principle 4.3.2 PIPEDA).
  • Whether the sensitivity of UDID and Ad ID in the context of user profiling and online behavioural advertising required express consent (Principle 4.3.6 PIPEDA).
  • Whether the reasonable expectations of the individual were met regarding the use and disclosure of UDID and Ad ID (Principle 4.3.5 PIPEDA).