The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

46 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 9, 2020PIPEDA Findings #2020-003Indexed Jun 30, 2026

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Dell Inc.

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Jul 9, 2020PIPEDA Findings #2020-003
Adjudicator: Daniel Therrien
Plain-Language Summary

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Key Issues
  • Whether Dell adequately safeguarded personal information under its control while using a service provider (PIPEDA Principle 4.1.3 and 4.7).
  • Whether the personal information transferred to the service provider was sensitive enough to require a high degree of protection.
  • Whether Dell's access controls were sufficient to protect customer information.
  • Whether Dell's logging and monitoring practices were adequate to detect anomalous employee requests for customer information.
  • Whether Dell's technical measures, such as USB drive restrictions, were sufficient.
  • Whether Dell adequately investigated the circumstances and scope of the June 2017 breach.
  • Whether Dell adequately responded to customer complaints about potential privacy breaches (PIPEDA Principle 4.10.4).
  • Whether Dell remained responsible for personal information transferred to a third party for processing.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 16, 2019PIPEDA Findings #2019-003Indexed Jun 30, 2026

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Loblaw Companies Ltd.

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Oct 16, 2019PIPEDA Findings #2019-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Key Issues
  • Whether Loblaw collected more personal information than necessary for the Loblaw Card Program (Principle 4.4)
  • Whether Loblaw ensured a comparable level of protection for personal information transferred to a third party for processing (Principle 4.1.3)
  • Whether Loblaw was required to obtain additional consent for the transfer of personal information for processing (Principle 4.3)
  • Whether Loblaw was sufficiently open and transparent about its cross-border data transfers (Principle 4.8)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 8, 2018PIPEDA Report of Findings #2018-001Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

VTech Holdings Limited

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

Jan 8, 2018PIPEDA Report of Findings #2018-001
Adjudicator: Daniel Therrien
Plain-Language Summary

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Key Issues
  • Whether VTech Holdings Limited failed to adequately safeguard personal information under Principle 4.7 PIPEDA
  • Whether VTech's security safeguards were appropriate to the sensitivity of the information (Principle 4.7 PIPEDA)
  • Whether VTech's safeguards protected against unauthorized access, disclosure, copying, use, or modification (Principle 4.7.1 PIPEDA)
  • Whether the nature of VTech's safeguards varied depending on the sensitivity, amount, distribution, format, and storage method of the information (Principle 4.7.2 PIPEDA)
  • Whether VTech's methods of protection included physical, organizational, and technological measures (Principle 4.7.3 PIPEDA)
  • Whether VTech had adequate testing and maintenance protocols to identify and mitigate vulnerabilities
  • Whether VTech had adequate administrative access controls
  • Whether VTech had adequate cryptographic protection for personal information
  • Whether VTech had sufficient security monitoring and logging to detect threats
  • Whether VTech had a comprehensive security management program
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 29, 2017PIPEDA findings #2017-012Indexed Jun 30, 2026

PIPEDA findings #2017-012: Financial institution discloses too much information in response to production order

A financial institution

A complainant alleged that his financial institution improperly disclosed his personal information, specifically RESP account details from 1999, to a municipal police service. The financial institution claimed the disclosure was made under a production order or, alternatively, with the complainant's consent via its privacy policy. The OPC found that the disclosed 1999 RESP information fell outside the scope of the production order, which specified a different date range and nature of information. The OPC also rejected the financial institution's argument of consent, stating that the privacy policy's general language was insufficient for informed consent, especially for sensitive financial information. The financial institution agreed to review its procedures and provide training to ensure compliance with production orders. The complaint was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2017-012: Financial institution discloses too much information in response to production order

Aug 29, 2017PIPEDA findings #2017-012
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that his financial institution improperly disclosed his personal information, specifically RESP account details from 1999, to a municipal police service. The financial institution claimed the disclosure was made under a production order or, alternatively, with the complainant's consent via its privacy policy. The OPC found that the disclosed 1999 RESP information fell outside the scope of the production order, which specified a different date range and nature of information. The OPC also rejected the financial institution's argument of consent, stating that the privacy policy's general language was insufficient for informed consent, especially for sensitive financial information. The financial institution agreed to review its procedures and provide training to ensure compliance with production orders. The complaint was found to be well-founded and resolved.

Key Issues
  • Whether the disclosure of RESP account information from 1999 was justified under paragraph 7(3)(c) of PIPEDA as being required by a production order
  • Whether the financial institution could rely on the complainant's consent, as stipulated in its privacy policy, for the disclosure of personal information to law enforcement
  • Whether the RESP account information constituted sensitive personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 28, 2017PIPEDA Report of Findings #2017-001Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-001: Drug activity history in property reports deemed not publicly available

A property report provider

A complainant alleged that a company selling "home history reports" collected, used, and disclosed personal information without consent, specifically sales history, drug activity, and insurance claims. The OPC found that sales history was no longer included in reports and insurance claims information, as clarified by the respondent, related to property damage paid to third parties, not individuals, thus not constituting personal information. However, information about drug activity was deemed personal information because it could be linked to identifiable individuals and suggested their involvement in drug activity. The OPC concluded that this drug activity information was not "publicly available" under PIPEDA Regulations, requiring consent for its use. The respondent agreed to cease including drug activity details in its reports, leading to a well-founded and resolved outcome.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2017-001: Drug activity history in property reports deemed not publicly available

Aug 28, 2017PIPEDA Report of Findings #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a company selling "home history reports" collected, used, and disclosed personal information without consent, specifically sales history, drug activity, and insurance claims. The OPC found that sales history was no longer included in reports and insurance claims information, as clarified by the respondent, related to property damage paid to third parties, not individuals, thus not constituting personal information. However, information about drug activity was deemed personal information because it could be linked to identifiable individuals and suggested their involvement in drug activity. The OPC concluded that this drug activity information was not "publicly available" under PIPEDA Regulations, requiring consent for its use. The respondent agreed to cease including drug activity details in its reports, leading to a well-founded and resolved outcome.

Key Issues
  • Whether sales history information constituted personal information and was collected, used, or disclosed without consent
  • Whether insurance claims information constituted personal information
  • Whether drug activity information constituted personal information
  • Whether drug activity information was "publicly available" under the Regulations Specifying Publicly Available Information
  • Whether the respondent obtained adequate consent for the collection, use, and disclosure of personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2017PIPEDA findings #2017-011Indexed Jun 30, 2026

PIPEDA findings #2017-011: Financial institution originally misuses confidential commercial information exemption to withhold personal information

A financial institution

A complainant alleged that a financial institution refused to respond to his access to personal information request related to a disputed credit card transaction. Initially, the financial institution withheld documents, claiming they contained confidential commercial information under PIPEDA s.9(3)(b). The OPC found this exemption was inappropriately applied and that the financial institution failed to respond within the statutory 30-day timeframe. Following the OPC's preliminary report, the financial institution provided further clarification, leading the OPC to determine that the information in question was not the complainant's personal information and was correctly redacted under s.9(1) as third-party information. Although the complainant eventually received all personal information he was entitled to, the OPC criticized the financial institution's delay and initial misuse of the exemption. The complaint was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2017-011: Financial institution originally misuses confidential commercial information exemption to withhold personal information

Mar 31, 2017PIPEDA findings #2017-011
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a financial institution refused to respond to his access to personal information request related to a disputed credit card transaction. Initially, the financial institution withheld documents, claiming they contained confidential commercial information under PIPEDA s.9(3)(b). The OPC found this exemption was inappropriately applied and that the financial institution failed to respond within the statutory 30-day timeframe. Following the OPC's preliminary report, the financial institution provided further clarification, leading the OPC to determine that the information in question was not the complainant's personal information and was correctly redacted under s.9(1) as third-party information. Although the complainant eventually received all personal information he was entitled to, the OPC criticized the financial institution's delay and initial misuse of the exemption. The complaint was found to be well-founded and resolved.

Key Issues
  • Whether the financial institution responded to the access request within the 30-day time limit required by PIPEDA s.8(3)
  • Whether the financial institution sent a notice of extension within 30 days of the request as required by PIPEDA s.8(4)
  • Whether the financial institution appropriately applied the confidential commercial information exemption under PIPEDA s.9(3)(b) to withhold documents
  • Whether the withheld information constituted the complainant's personal information
  • Whether the information was properly redacted as third-party information under PIPEDA s.9(1)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 14, 2016PIPEDA Case Summary #2016-008Indexed Jun 30, 2026

PIPEDA Case Summary #2016-008: Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties

A telecommunications company

An individual complained that a telecommunications company (telco) provided an incomplete response to her access request for information about disclosures of her personal information to other parties, including law enforcement. The telco initially responded by stating it was in compliance with specific PIPEDA subsections, without confirming or denying disclosures. The OPC found that the telco's response did not meet its obligation under Principle 4.9 of PIPEDA, which requires organizations to inform individuals of the existence, use, and disclosure of their personal information. The OPC clarified that an organization must provide a clear 'yes' or 'no' answer regarding disclosures, unless a government institution objects to such disclosure under PIPEDA s.9(2.4). Following the OPC's recommendation, the telco provided a complete response to the complainant and updated its policy for handling future access requests. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-008: Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties

Jul 14, 2016PIPEDA Case Summary #2016-008
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a telecommunications company (telco) provided an incomplete response to her access request for information about disclosures of her personal information to other parties, including law enforcement. The telco initially responded by stating it was in compliance with specific PIPEDA subsections, without confirming or denying disclosures. The OPC found that the telco's response did not meet its obligation under Principle 4.9 of PIPEDA, which requires organizations to inform individuals of the existence, use, and disclosure of their personal information. The OPC clarified that an organization must provide a clear 'yes' or 'no' answer regarding disclosures, unless a government institution objects to such disclosure under PIPEDA s.9(2.4). Following the OPC's recommendation, the telco provided a complete response to the complainant and updated its policy for handling future access requests. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the telco's initial response to an access request for disclosure information met its obligations under Principle 4.9 of PIPEDA
  • Whether the telco's practice of stating compliance with PIPEDA s.9(2.1)-(2.4) was sufficient for access requests
  • Whether the telco had an obligation to provide a 'yes' or 'no' answer regarding disclosures to all third parties, including those not covered by PIPEDA s.9(2.1)-(2.4)
  • How an organization should respond to an access request for disclosure information when a government institution objects under PIPEDA s.9(2.4)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 7, 2016PIPEDA Case Summary #2016-010Indexed Jun 30, 2026

PIPEDA Case Summary #2016-010: Credit reporting agency takes remedial action after failing to maintain accurate records

A credit reporting agency

An individual complained to the OPC after discovering inaccuracies in his credit file, including two unrecognized credit inquiries and a notation that his account had been automatically combined with others. The credit reporting agency acknowledged that his file had been manually combined with another individual's due to similar names and addresses. The OPC investigated two main issues: unauthorized use/disclosure and accuracy of personal information. The OPC found no unauthorized use or disclosure, as the inquiries occurred before the files were combined and only the other individual's information was used. However, the OPC determined that the agency failed to maintain accurate personal information, as combining files compromised accuracy and led to incorrect information being attributed to the complainant. The agency rectified the error by separating the files, notifying creditors of corrections, and committing to enhanced employee training. Consequently, the accuracy issue was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-010: Credit reporting agency takes remedial action after failing to maintain accurate records

Jul 7, 2016PIPEDA Case Summary #2016-010
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after discovering inaccuracies in his credit file, including two unrecognized credit inquiries and a notation that his account had been automatically combined with others. The credit reporting agency acknowledged that his file had been manually combined with another individual's due to similar names and addresses. The OPC investigated two main issues: unauthorized use/disclosure and accuracy of personal information. The OPC found no unauthorized use or disclosure, as the inquiries occurred before the files were combined and only the other individual's information was used. However, the OPC determined that the agency failed to maintain accurate personal information, as combining files compromised accuracy and led to incorrect information being attributed to the complainant. The agency rectified the error by separating the files, notifying creditors of corrections, and committing to enhanced employee training. Consequently, the accuracy issue was found to be well-founded and resolved.

Key Issues
  • Whether the credit reporting agency improperly disclosed the complainant's personal information without consent
  • Whether the credit reporting agency failed to maintain accurate personal information as required by PIPEDA Principle 4.6
  • Whether the credit reporting agency failed to maintain accurate personal information as required by PIPEDA Principle 4.6.3
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2016PIPEDA Case Summary #2016-012Indexed Jun 30, 2026

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

A bank associated with a retailer

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

Mar 31, 2016PIPEDA Case Summary #2016-012
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Key Issues
  • Whether the bank obtained valid consent for a credit card application and credit check under Principle 4.3
  • Whether the bank ensured the accuracy of personal information collected under Principle 4.6
  • Whether the bank had adequate procedures to give effect to PIPEDA principles under Principle 4.1.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 10, 2016PIPEDA Case Summary #2016-009Indexed Jun 30, 2026

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

An international trucking company

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

Mar 10, 2016PIPEDA Case Summary #2016-009
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Key Issues
  • Whether the disclosure of drug test results to the WCB without consent contravened PIPEDA Principles 4.3 and 4.5
  • Whether the employer had a legal obligation to disclose the drug test results to the WCB under the provincial Workers' Compensation Act, thereby qualifying for an exception to consent under paragraph 7(3)(i) of PIPEDA
  • Whether the employer disclosed the drug test results to co-workers without consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 19, 2016PIPEDA Report of Findings #2016-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

A property management company

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

Feb 19, 2016PIPEDA Report of Findings #2016-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Key Issues
  • Whether the collection, use, and disclosure of personal information for a "bad tenant list" was for purposes that a reasonable person would consider appropriate in the circumstances (s.5(3) PIPEDA)
  • Whether the property management company was acting as an unlicensed credit reporting agency under provincial legislation
  • Whether meaningful knowledge and consent of individuals were obtained for the collection, use, and disclosure of their personal information for the "bad tenant list" (Principle 4.3, 4.3.2 PIPEDA)
  • Whether the personal information on the "bad tenant list" was accurate, complete, and up-to-date (Principle 4.6, 4.6.1 PIPEDA)
  • Whether individuals had the ability to challenge the accuracy of information about them on the list (Principle 4.10 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 12, 2016PIPEDA Report of Findings #2016-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

An insurance company

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

Feb 12, 2016PIPEDA Report of Findings #2016-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Key Issues
  • Whether the insurance company contravened Principles 4.9 and 4.9.1 by refusing access to personal information without severing third-party information
  • Whether the insurance company's internal ombudsman office constitutes a "formal dispute resolution process" under PIPEDA s.9(3)(d)
  • Whether the activities of the internal ombudsman office fall under the definition of "commercial activity" under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 9, 2016PIPEDA Case Summary #2016-007Indexed Jun 30, 2026

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

A collection agency

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

Feb 9, 2016PIPEDA Case Summary #2016-007
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the organization refused to provide access to personal information
  • Whether the organization responded to access requests within the required timeframe
  • Whether the organization followed its own privacy policies and procedures for access requests
  • Whether the organization maintained records of access request processing
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 9, 2016PIPEDA Case Summary #2016-004Indexed Jun 30, 2026

PIPEDA Case Summary #2016-004: Retailer shares customer’s in-store behaviour with the customer’s employer

A retail store

A customer complained that a retail store employee disclosed his personal information to his employer, including his name, in-store behavior, and statements made to staff. The store argued the information was not personal because it was made publicly, and that it had implied consent for the disclosure. The OPC found that information overheard by others is still personal information under PIPEDA. The OPC also determined that implied consent was not appropriate given the sensitive nature of the information, which had the potential to negatively affect the customer's employment. The store's disclosure without knowledge or consent contravened Principle 4.3 of PIPEDA. The complaint was found to be well-founded and resolved after the store implemented the OPC's recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-004: Retailer shares customer’s in-store behaviour with the customer’s employer

Jan 9, 2016PIPEDA Case Summary #2016-004
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a retail store employee disclosed his personal information to his employer, including his name, in-store behavior, and statements made to staff. The store argued the information was not personal because it was made publicly, and that it had implied consent for the disclosure. The OPC found that information overheard by others is still personal information under PIPEDA. The OPC also determined that implied consent was not appropriate given the sensitive nature of the information, which had the potential to negatively affect the customer's employment. The store's disclosure without knowledge or consent contravened Principle 4.3 of PIPEDA. The complaint was found to be well-founded and resolved after the store implemented the OPC's recommendations.

Key Issues
  • Whether the information shared was personal information under PIPEDA
  • Whether the customer provided implied consent for the disclosure of his personal information
  • Whether the disclosed information was sensitive
  • Whether the customer had a reasonable expectation that his information would be shared with his employer
  • Whether the publicly available information exception to consent applied
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 10, 2015PIPEDA Case Summary #2015-015Indexed Jun 30, 2026

PIPEDA Case Summary #2015-015: Roofing company takes measures to ensure sub-contractors follow its privacy policy

A roofing company (the "second roofer")

An individual complained that an estimator working for a roofing company (the "second roofer") disclosed his personal financial situation and contractual history to a competitor (the "first roofer") without his consent. The individual had engaged the second roofer for an estimate to fix issues with work done by the first roofer, and later cancelled a contract with the second roofer. The OPC found that the estimator was acting as an agent for the second roofer, making the second roofer responsible for the estimator's actions. The OPC concluded that the disclosure of personal information without the individual's knowledge or consent contravened Principle 4.3 of PIPEDA. The second roofer subsequently implemented recommendations to establish agreements with sub-contractors to adhere to its privacy policy and provide training. As a result, the complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2015-015: Roofing company takes measures to ensure sub-contractors follow its privacy policy

Nov 10, 2015PIPEDA Case Summary #2015-015
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an estimator working for a roofing company (the "second roofer") disclosed his personal financial situation and contractual history to a competitor (the "first roofer") without his consent. The individual had engaged the second roofer for an estimate to fix issues with work done by the first roofer, and later cancelled a contract with the second roofer. The OPC found that the estimator was acting as an agent for the second roofer, making the second roofer responsible for the estimator's actions. The OPC concluded that the disclosure of personal information without the individual's knowledge or consent contravened Principle 4.3 of PIPEDA. The second roofer subsequently implemented recommendations to establish agreements with sub-contractors to adhere to its privacy policy and provide training. As a result, the complaint was deemed well-founded and resolved.

Key Issues
  • Whether the estimator was acting as an agent of the second roofer
  • Whether the second roofer was responsible for the personal information handling practices of its estimator
  • Whether personal information was disclosed without the individual's knowledge or consent
  • Whether the disclosure contravened Principle 4.3 of PIPEDA