The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

38 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 15, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-002Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-002: Bank misinformed client of purpose of requesting personal information for picking up credit card

A Canadian bank

A bank customer complained after being asked to provide his driver's license to pick up a replacement credit card, despite having other identification on file and being known to staff. The bank initially cited anti-money laundering regulations (PCMLTFA) but later admitted this rationale was incorrect. The OPC investigated two issues: whether the bank improperly demanded to record information (collection) and whether it could explain the purpose of collection. Since the customer refused to provide his driver's license, no actual collection occurred, so that aspect of the complaint was not well-founded. However, the bank's inaccurate explanation for requesting the information contravened Principle 4.2.5. The bank revised its procedures and circulated new guidelines to staff, leading to a well-founded and resolved outcome for the latter issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-002: Bank misinformed client of purpose of requesting personal information for picking up credit card

Apr 15, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-002
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A bank customer complained after being asked to provide his driver's license to pick up a replacement credit card, despite having other identification on file and being known to staff. The bank initially cited anti-money laundering regulations (PCMLTFA) but later admitted this rationale was incorrect. The OPC investigated two issues: whether the bank improperly demanded to record information (collection) and whether it could explain the purpose of collection. Since the customer refused to provide his driver's license, no actual collection occurred, so that aspect of the complaint was not well-founded. However, the bank's inaccurate explanation for requesting the information contravened Principle 4.2.5. The bank revised its procedures and circulated new guidelines to staff, leading to a well-founded and resolved outcome for the latter issue.

Key Issues
  • Whether the bank limited its collection of personal information to that which was necessary for the purposes identified by the organization (Principle 4.4 PIPEDA)
  • Whether the bank ensured its employees were able to explain the purposes for which personal information was being collected (Principle 4.2.5 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 22, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-004Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account

A cellular-telephone service provider

An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account

Aug 22, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-004
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.

Key Issues
  • Whether the cellular service provider disclosed personal information without consent to an imposter, contravening Principle 4.3 PIPEDA
  • Whether the cellular service provider adequately responded to the complainant's access request for personal information under Principle 4.9 PIPEDA
  • Whether the cellular service provider responded to the access request within the 30-day timeframe as per s.8(3) PIPEDA
  • Whether the redaction of the CSR's name from the transcript was permissible under s.9(1) PIPEDA
  • Whether the company was required to provide an audio recording of the conversation in addition to a transcript under s.10 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 14, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-010Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings # 2012-010: Telecommunications firm adopts additional accountability measures to ensure a consistent approach in handling access requests

A telecommunications firm

A complainant alleged that a telecommunications firm failed to provide her with access to her personal information, specifically notes and transcripts of recorded conversations related to an account dispute. The firm acknowledged receiving the access request but mistakenly believed it was not necessary to provide the information due to ongoing settlement negotiations. The OPC found that the firm failed to respond to the access request within 30 days and did not issue an extension notice, thus contravening PIPEDA subsections 8(3), 8(4), and 8(5). Furthermore, the firm purged the requested audio records, violating subsection 8(8) and Principles 4.9 and 4.9.4. The firm's internal policies were found to be unclear and staff training inadequate, leading to the erroneous deletion of records. The OPC made several recommendations, which the firm accepted and implemented, including amending policies and providing staff training. As a result, the complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings # 2012-010: Telecommunications firm adopts additional accountability measures to ensure a consistent approach in handling access requests

Aug 14, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a telecommunications firm failed to provide her with access to her personal information, specifically notes and transcripts of recorded conversations related to an account dispute. The firm acknowledged receiving the access request but mistakenly believed it was not necessary to provide the information due to ongoing settlement negotiations. The OPC found that the firm failed to respond to the access request within 30 days and did not issue an extension notice, thus contravening PIPEDA subsections 8(3), 8(4), and 8(5). Furthermore, the firm purged the requested audio records, violating subsection 8(8) and Principles 4.9 and 4.9.4. The firm's internal policies were found to be unclear and staff training inadequate, leading to the erroneous deletion of records. The OPC made several recommendations, which the firm accepted and implemented, including amending policies and providing staff training. As a result, the complaint was deemed well-founded and resolved.

Key Issues
  • Whether the telecommunications firm responded to the access request within the 30-day time limit under subsection 8(3) PIPEDA
  • Whether the telecommunications firm issued a notice of extension for the access request under subsection 8(4) PIPEDA
  • Whether the telecommunications firm was deemed to have refused the access request under subsection 8(5) PIPEDA
  • Whether the telecommunications firm provided access to personal information as required by Principle 4.9 PIPEDA
  • Whether the telecommunications firm responded to the access request within a reasonable time and at minimal or no cost under Principle 4.9.4 PIPEDA
  • Whether the telecommunications firm retained personal information that was the subject of an access request for as long as necessary to allow the individual to exhaust any recourse under subsection 8(8) PIPEDA
  • Whether the telecommunications firm implemented policies and practices to give effect to the principles, including training staff and communicating policies and practices under Principle 4.1.4(c) PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 21, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-024Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2009-024: Bank Disclosed Personal Information without Consent

A Canadian bank

A married couple applied for a joint mortgage. The husband alleged that a bank mortgage specialist disclosed his account information to his wife without his consent during the application process. The bank argued there was implicit consent given the joint mortgage application. The Assistant Commissioner found that the bank did not make a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed to each other. Therefore, the bank did not have meaningful consent for the disclosure. Although the incident was a one-time error by an employee, the complaint was found to be well-founded and resolved as the bank had adopted reasonable practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Case Summary #2009-024: Bank Disclosed Personal Information without Consent

Dec 21, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-024
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A married couple applied for a joint mortgage. The husband alleged that a bank mortgage specialist disclosed his account information to his wife without his consent during the application process. The bank argued there was implicit consent given the joint mortgage application. The Assistant Commissioner found that the bank did not make a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed to each other. Therefore, the bank did not have meaningful consent for the disclosure. Although the incident was a one-time error by an employee, the complaint was found to be well-founded and resolved as the bank had adopted reasonable practices.

Key Issues
  • Whether the bank had the husband's implicit or explicit consent to disclose his account information to his wife
  • Whether the bank made a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed
  • Whether the bank's mortgage specialist followed the bank's usual practice for informing joint mortgage applicants
  • Whether the presumption of implied consent remained reasonable after the wife's reaction to the initial disclosure
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 16, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-008Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2009-008: Report of Findings: CIPPIC v. Facebook Inc.

Facebook Inc.

The Canadian Internet Policy and Public Interest Clinic (CIPPIC) filed a comprehensive complaint against Facebook Inc., alleging 24 contraventions of PIPEDA across 12 subjects, including default privacy settings, advertising practices, third-party applications, and the handling of personal information for deactivated, deceased, and non-users. The Office of the Privacy Commissioner (OPC) focused its investigation on meaningful consent, retention, and security safeguards. The Assistant Commissioner found several allegations to be 'not well-founded', such as those concerning new uses of information, collection from other sources, Facebook Mobile safeguards, and deception. Other allegations, including those related to date of birth collection, default privacy settings, advertising, and monitoring for anomalous activity, were found 'well-founded and resolved' due to Facebook's agreement to implement corrective measures. However, significant issues regarding third-party applications, indefinite retention of deactivated account data, inadequate notification for deceased users' accounts, and the collection/retention of non-users' personal information were found 'well-founded' but remained unresolved, as Facebook declined to implement key recommendations. The OPC indicated it would follow up on all recommendations and consider further action for unresolved issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Case Summary #2009-008: Report of Findings: CIPPIC v. Facebook Inc.

Jul 16, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-008
Adjudicator: Elizabeth Denham
Plain-Language Summary

The Canadian Internet Policy and Public Interest Clinic (CIPPIC) filed a comprehensive complaint against Facebook Inc., alleging 24 contraventions of PIPEDA across 12 subjects, including default privacy settings, advertising practices, third-party applications, and the handling of personal information for deactivated, deceased, and non-users. The Office of the Privacy Commissioner (OPC) focused its investigation on meaningful consent, retention, and security safeguards. The Assistant Commissioner found several allegations to be 'not well-founded', such as those concerning new uses of information, collection from other sources, Facebook Mobile safeguards, and deception. Other allegations, including those related to date of birth collection, default privacy settings, advertising, and monitoring for anomalous activity, were found 'well-founded and resolved' due to Facebook's agreement to implement corrective measures. However, significant issues regarding third-party applications, indefinite retention of deactivated account data, inadequate notification for deceased users' accounts, and the collection/retention of non-users' personal information were found 'well-founded' but remained unresolved, as Facebook declined to implement key recommendations. The OPC indicated it would follow up on all recommendations and consider further action for unresolved issues.

Key Issues
  • Whether requiring date of birth as a condition of registration contravened Principle 4.3.3
  • Whether Facebook adequately explained the purposes for collecting and using date of birth under Principle 4.3.2
  • Whether default privacy settings constituted improper opt-out consent for sensitive information under Principle 4.3.6
  • Whether Facebook made reasonable efforts to advise users of purposes and extent of information use/disclosure via default settings under Principles 4.2.3 and 4.3.2
  • Whether default settings for photo albums met users' reasonable expectations under Principle 4.3.5
  • Whether default settings for public search listings met users' reasonable expectations under Principle 4.3.5
  • Whether Facebook made reasonable efforts to notify users of advertising purposes under Principle 4.3.2
  • Whether Social Ads improperly used opt-out consent for sensitive information under Principle 4.3.6
  • Whether users could opt out of Facebook Ads under Principle 4.3.8
  • Whether requiring consent to Facebook Ads as a condition of service violated Principle 4.3.3
  • Whether Facebook adequately informed users of the purpose for disclosing personal information to third-party application developers under Principles 4.2.2 and 4.2.5
  • Whether Facebook provided third-party application developers with access to personal information beyond what was necessary under Principle 4.4.1
  • Whether Facebook required consent to disclosure beyond what was necessary to run an application under Principle 4.3.3
  • Whether Facebook adequately safeguarded personal information transferred to third-party applications under Principle 4.7
  • Whether Facebook obtained meaningful consent for disclosure of personal information to application developers when users or their friends added applications under Principles 4.2, 4.2.3, 4.3.2, 4.3.4, 4.3.5, 4.3.6, and subsection 5(3)
  • Whether Facebook failed to notify users of new purposes for collecting, using, or disclosing personal information under Principle 4.2.4
  • Whether Facebook failed to provide specific information and obtain meaningful consent for collecting personal information from sources outside Facebook under Principle 4.3
  • Whether Facebook inappropriately deprived users of a means to delete all personal information from the site
  • Whether Facebook's indefinite retention of personal information in deactivated accounts contravened Principles 4.5 and 4.5.3
  • Whether Facebook obtained meaningful consent for memorializing deceased users' profiles under Principle 4.3.3
  • Whether memorializing profiles was an unnecessary condition of service under Principle 4.3.3
  • Whether Facebook adequately informed users of its practice of account memorialization under Principles 4.2.1, 4.2.3, 4.3.2, and 4.8
  • Whether Facebook obtained consent from non-users for uploading their personal information (e.g., tagging, invitations) under Principle 4.3
  • Whether Facebook's retention of non-users' email addresses beyond the initial purpose contravened Principle 4.5
  • Whether Facebook Mobile's use of a persistent cookie constituted inadequate safeguarding of personal information under Principles 4.7, 4.7.1, and 4.7.3
  • Whether Facebook adequately informed users of its practice of monitoring for anomalous activity under Principle 4.8
  • Whether Facebook misrepresented its purpose or users' control over personal information under Principles 4.3.2 and 4.4.2
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 4, 2006Incident Summary #3Indexed Jun 30, 2026

Incident Summary #3: Misdirected faxes - December 4, 2006

Two Canadian banks

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #3: Misdirected faxes - December 4, 2006

Dec 4, 2006Incident Summary #3
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Key Issues
  • Whether organizations adequately safeguard personal information to prevent inappropriate disclosure (Principle 4.7 PIPEDA)
  • Whether organizations implement effective policies and procedures to give effect to fair information practices (Principle 4.1 PIPEDA)
  • Whether employees are attuned to privacy issues and can respond to problems when they arise
  • Whether organizations notify affected customers of privacy breaches
  • Whether organizations have processes for confirming correct fax transmission
  • Whether organizations have measures to recover erroneously transmitted customer information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 18, 2005Incident Summary #2Indexed Jun 30, 2026

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

CIBC

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

Apr 18, 2005Incident Summary #2
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Key Issues
  • Whether CIBC's privacy practices adequately protected personal information from misdirected faxes
  • Whether CIBC effectively responded to notifications of misdirected faxes
  • Whether CIBC appropriately recovered misdirected personal information
  • Whether CIBC adequately notified affected customers of privacy breaches
  • Whether CIBC employees recognized misdirected faxes as privacy issues
  • Whether CIBC's internal privacy management structure was sufficient to address breaches
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 21, 2004Incident Summary #1Indexed Jun 30, 2026

Incident Summary #1: Misdirected faxes containing health information end up in apartment managers' hands

Dynacare and Viewpoint

This incident summary details two separate investigations into misdirected faxes containing personal health information. In both cases, faxes from Dynacare and Viewpoint were erroneously sent to apartment managers. The OPC found that both companies disclosed personal information without consent, contravening PIPEDA. Dynacare implemented an electronic auto-fax function and revised policies, while Viewpoint committed to retrieving misdirected faxes and verifying numbers. The Assistant Commissioner recommended both organizations implement OPC faxing guidelines, notify affected individuals, and annually update employee confidentiality agreements.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #1: Misdirected faxes containing health information end up in apartment managers' hands

Dec 21, 2004Incident Summary #1
Adjudicator: Jennifer Stoddart
Plain-Language Summary

This incident summary details two separate investigations into misdirected faxes containing personal health information. In both cases, faxes from Dynacare and Viewpoint were erroneously sent to apartment managers. The OPC found that both companies disclosed personal information without consent, contravening PIPEDA. Dynacare implemented an electronic auto-fax function and revised policies, while Viewpoint committed to retrieving misdirected faxes and verifying numbers. The Assistant Commissioner recommended both organizations implement OPC faxing guidelines, notify affected individuals, and annually update employee confidentiality agreements.

Key Issues
  • Whether Dynacare disclosed personal information without consent, contrary to PIPEDA
  • Whether Viewpoint disclosed personal information without consent, contrary to PIPEDA
  • Whether Dynacare's security safeguards were adequate to prevent misdirected faxes
  • Whether Viewpoint's security safeguards were adequate to prevent misdirected faxes
  • Whether Dynacare should notify the affected individual
  • Whether Viewpoint should notify the affected individual