The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

1 decision matching
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Feb 26, 2026Indexed Jun 30, 2026

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Canada Border Services Agency (CBSA)

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Quick view

Privacy ActWell-founded & resolved

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Feb 26, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Key Issues
  • Whether the CBSA's disclosure of employee personal information via spreadsheets contravened section 8 of the Privacy Act
  • Whether the inclusion of excess information in spreadsheets constituted unauthorized disclosure
  • Whether the use of personal email addresses for work-related data sharing contravened the Privacy Act
  • Whether the CBSA took adequate steps to address the incidents, including notification to affected individuals
  • Whether the CBSA's measures to reduce the risk of recurrence were reasonable