The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

46 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 6, 2015PIPEDA Case Summary #2015-010Indexed Jun 30, 2026

PIPEDA Case Summary #2015-010: Customer’s emails sent to her acquaintance following a telecom employee’s attempt to fix a problem with the customer’s email service

A telecommunications provider

An individual complained that her telecommunications provider disclosed her personal information without consent. A technical support representative, while attempting to fix her email service, inadvertently configured her email application to automatically forward her emails, including one containing a temporary password, to an acquaintance. The OPC found that this constituted a disclosure of personal information without consent, contravening Principle 4.3. The telecom provider initially provided inaccurate information to the OPC regarding corrective measures taken, but later clarified its existing measures. The complaint was found to be well-founded and resolved, as the provider had some measures in place to prevent recurrence, despite the initial misrepresentations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2015-010: Customer’s emails sent to her acquaintance following a telecom employee’s attempt to fix a problem with the customer’s email service

Jul 6, 2015PIPEDA Case Summary #2015-010
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that her telecommunications provider disclosed her personal information without consent. A technical support representative, while attempting to fix her email service, inadvertently configured her email application to automatically forward her emails, including one containing a temporary password, to an acquaintance. The OPC found that this constituted a disclosure of personal information without consent, contravening Principle 4.3. The telecom provider initially provided inaccurate information to the OPC regarding corrective measures taken, but later clarified its existing measures. The complaint was found to be well-founded and resolved, as the provider had some measures in place to prevent recurrence, despite the initial misrepresentations.

Key Issues
  • Whether the telecommunications provider disclosed the individual's personal information without consent
  • Whether the disclosure contravened Principle 4.3 of PIPEDA
  • Whether the telecommunications provider provided accurate information to the OPC during the investigation
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 13, 2015PIPEDA Report of Findings #2015-007Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-007: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Peoples Trust

The OPC initiated an investigation into Peoples Trust following a data breach that compromised sensitive personal information of approximately 12,000 customers. The investigation found that Peoples Trust failed to implement adequate technological and organizational safeguards, including using an outdated and vulnerable web editor and lacking ongoing monitoring. Additionally, the organization unnecessarily stored duplicate, unencrypted customer information on a web server for longer than required, contravening its retention policies. Following the OPC's intervention, Peoples Trust implemented comprehensive remedial measures, such as redesigning its web portal, enhancing monitoring, and developing a new Information Security Policy. As a result, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2015-007: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 13, 2015PIPEDA Report of Findings #2015-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated an investigation into Peoples Trust following a data breach that compromised sensitive personal information of approximately 12,000 customers. The investigation found that Peoples Trust failed to implement adequate technological and organizational safeguards, including using an outdated and vulnerable web editor and lacking ongoing monitoring. Additionally, the organization unnecessarily stored duplicate, unencrypted customer information on a web server for longer than required, contravening its retention policies. Following the OPC's intervention, Peoples Trust implemented comprehensive remedial measures, such as redesigning its web portal, enhancing monitoring, and developing a new Information Security Policy. As a result, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether Peoples Trust implemented adequate technological and organizational safeguards appropriate to the sensitivity of the information, as per Principle 4.7 and 4.1.4(a) PIPEDA
  • Whether Peoples Trust retained personal information for longer than necessary to fulfill its purposes, as per Principle 4.5 PIPEDA
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Employment and Social Development Canada (ESDC)

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Quick view

Privacy ActWell-founded & resolved

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Key Issues
  • Whether Employment and Social Development Canada (ESDC) adequately protected personal information on a lost USB key
  • Whether Justice Canada adequately protected personal information on a lost USB key while in its custody
  • Whether physical controls for personal information were adequate
  • Whether technological controls (encryption, password protection) for personal information were adequate
  • Whether administrative controls for personal information were adequate
  • Whether personnel controls for personal information were adequate
  • Whether ESDC translated its privacy and security policies into meaningful business practices
  • Whether Justice Canada translated its privacy and security policies into meaningful business practices
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
May 22, 2014PIPEDA findings #2014-020Indexed Jun 30, 2026

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

A videographer

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

May 22, 2014PIPEDA findings #2014-020
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Key Issues
  • Whether the use of personal information constituted commercial activity
  • Whether the videographer had consent for this use
  • Whether the videographer needed consent for this use
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014Indexed Jun 30, 2026

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

An online dating service

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Key Issues
  • Whether the organization denied the complainant access to his personal information in violation of Principle 4.9
  • Whether the organization failed to respect the 30-day time limit for access requests under subsection 8(3)
  • Whether the organization contravened subsection 8(8) by destroying photographs, limiting the complainant's recourse
  • Whether the organization retained the complainant's information longer than necessary in contravention of Principle 4.5.3
  • Whether the organization continued to use the complainant's personal information for marketing after consent withdrawal, contravening Principle 4.3.8
  • Whether the organization lacked a privacy policy in contravention of Principle 4.1.4(d)
  • Whether the organization failed to safeguard the complainant's personal information as required by Principle 4.7.1
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 2, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-005Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-005: Beneficiary’s access to estate information is limited to his own personal information under PIPEDA

A legal firm

An individual, claiming to be a beneficiary of two estates, sought access under PIPEDA to estate information from a legal firm that had acted as an agent for another firm administering the estates. The complainant requested information pertaining to himself as a beneficiary and general beneficiary entitlements. The legal firm initially failed to respond to the access requests, leading to a complaint with the OPC. The firm later responded, stating it held no personal information about the complainant and that neither he nor the estates were clients. The OPC found that the firm contravened PIPEDA by not responding within the 30-day time limit. However, the OPC also determined that the complainant was only entitled to access information specifically about himself, not general estate information, and was satisfied that the firm had conducted a reasonable search for his personal information. The complaint was deemed well-founded and resolved due to the firm's initial failure to respond.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-005: Beneficiary’s access to estate information is limited to his own personal information under PIPEDA

Oct 2, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-005
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual, claiming to be a beneficiary of two estates, sought access under PIPEDA to estate information from a legal firm that had acted as an agent for another firm administering the estates. The complainant requested information pertaining to himself as a beneficiary and general beneficiary entitlements. The legal firm initially failed to respond to the access requests, leading to a complaint with the OPC. The firm later responded, stating it held no personal information about the complainant and that neither he nor the estates were clients. The OPC found that the firm contravened PIPEDA by not responding within the 30-day time limit. However, the OPC also determined that the complainant was only entitled to access information specifically about himself, not general estate information, and was satisfied that the firm had conducted a reasonable search for his personal information. The complaint was deemed well-founded and resolved due to the firm's initial failure to respond.

Key Issues
  • Whether a legal firm must respond to an access request within 30 days, even if it holds no personal information about the requester
  • Whether a beneficiary of an estate is entitled under PIPEDA to access general estate information
  • Whether the requested information (e.g., statements of accounts, money received, disbursements) constitutes the complainant's personal information under PIPEDA
  • Whether the legal firm conducted a reasonable search for the complainant's personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 11, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-003Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-003: Profiles on PositiveSingles.com dating website turn up on other affiliated dating websites

SuccessfulMatch Inc. (operating PositiveSingles.com)

Three individuals complained that their dating profiles, containing sensitive medical information, posted on PositiveSingles.com appeared on numerous other affiliated dating websites without their knowledge or consent. The complainants were assured of privacy but found their profiles on sites targeting different demographics, causing distress. The OPC's investigation found that PositiveSingles.com, operated by SuccessfulMatch Inc., used a single database across a network of affiliated sites, making profiles automatically available. The OPC concluded that the organization failed to obtain meaningful consent for this use, lacked openness about its network structure, and had inadequate safeguards, as some personal information was accessible via search engines. Following the OPC's recommendations, SuccessfulMatch revamped its website to provide explicit information about the network, ensure informed consent at registration, and improve safeguards. The complaint was found well-founded and resolved due to these corrective measures.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-003: Profiles on PositiveSingles.com dating website turn up on other affiliated dating websites

Jul 11, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-003
Adjudicator: Jennifer Stoddart
Plain-Language Summary

Three individuals complained that their dating profiles, containing sensitive medical information, posted on PositiveSingles.com appeared on numerous other affiliated dating websites without their knowledge or consent. The complainants were assured of privacy but found their profiles on sites targeting different demographics, causing distress. The OPC's investigation found that PositiveSingles.com, operated by SuccessfulMatch Inc., used a single database across a network of affiliated sites, making profiles automatically available. The OPC concluded that the organization failed to obtain meaningful consent for this use, lacked openness about its network structure, and had inadequate safeguards, as some personal information was accessible via search engines. Following the OPC's recommendations, SuccessfulMatch revamped its website to provide explicit information about the network, ensure informed consent at registration, and improve safeguards. The complaint was found well-founded and resolved due to these corrective measures.

Key Issues
  • Whether PositiveSingles.com obtained meaningful consent for the use of personal information across its network of affiliated sites (Principle 4.3, 4.3.2, 4.3.5 PIPEDA)
  • Whether PositiveSingles.com was sufficiently open about its personal information management policies and practices, particularly regarding its network structure (Principle 4.8, 4.8.1 PIPEDA)
  • Whether PositiveSingles.com implemented adequate security safeguards to protect sensitive personal information from unauthorized access (Principle 4.7, 4.7.1 PIPEDA)
  • Whether PositiveSingles.com's use of cookies, potentially for online behavioral advertising, required express consent given the sensitive nature of the information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 28, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-017Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-017: Apple called upon to provide greater clarity on its use and disclosure of unique device identifiers for targeted advertising

Apple

An individual complained that Apple was using and sharing her unique device identifier (UDID) without her knowledge and consent for tracking and targeted advertising. The OPC determined that UDIDs, and later Advertising IDs (Ad IDs), constituted personal information because Apple could link them to identifiable individuals. While Apple's use of UDIDs for administrative purposes was deemed to have implied consent, the OPC initially found Apple's explanations for using and disclosing UDIDs for targeted advertising to be insufficient for meaningful consent. During the investigation, Apple phased out the use of UDIDs for advertising, introduced the resettable Ad ID, and improved its privacy policy explanations and opt-out mechanisms. Consequently, the OPC found that Apple's updated practices provided sufficient information for meaningful consent regarding the use and disclosure of Ad IDs for advertising. The complaint was found to be well-founded but resolved due to Apple's corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-017: Apple called upon to provide greater clarity on its use and disclosure of unique device identifiers for targeted advertising

Jun 28, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-017
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Apple was using and sharing her unique device identifier (UDID) without her knowledge and consent for tracking and targeted advertising. The OPC determined that UDIDs, and later Advertising IDs (Ad IDs), constituted personal information because Apple could link them to identifiable individuals. While Apple's use of UDIDs for administrative purposes was deemed to have implied consent, the OPC initially found Apple's explanations for using and disclosing UDIDs for targeted advertising to be insufficient for meaningful consent. During the investigation, Apple phased out the use of UDIDs for advertising, introduced the resettable Ad ID, and improved its privacy policy explanations and opt-out mechanisms. Consequently, the OPC found that Apple's updated practices provided sufficient information for meaningful consent regarding the use and disclosure of Ad IDs for advertising. The complaint was found to be well-founded but resolved due to Apple's corrective actions.

Key Issues
  • Whether Unique Device Identifiers (UDID) constitute personal information under PIPEDA.
  • Whether Advertising Identifiers (Ad ID) constitute personal information under PIPEDA.
  • Whether Apple obtained meaningful consent for its use of UDID for administration and maintenance purposes (Principle 4.3 PIPEDA).
  • Whether Apple obtained meaningful consent for its use of UDID and Ad ID for targeted advertising purposes (Principle 4.3 PIPEDA).
  • Whether Apple obtained meaningful consent for its disclosure of UDID and Ad ID to third-party app developers (Principle 4.3 PIPEDA).
  • Whether Apple's explanations regarding the use and disclosure of UDID and Ad ID were sufficiently clear and understandable to ensure meaningful consent (Principle 4.3.2 PIPEDA).
  • Whether the sensitivity of UDID and Ad ID in the context of user profiling and online behavioural advertising required express consent (Principle 4.3.6 PIPEDA).
  • Whether the reasonable expectations of the individual were met regarding the use and disclosure of UDID and Ad ID (Principle 4.3.5 PIPEDA).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 15, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-002Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-002: Bank misinformed client of purpose of requesting personal information for picking up credit card

A Canadian bank

A bank customer complained after being asked to provide his driver's license to pick up a replacement credit card, despite having other identification on file and being known to staff. The bank initially cited anti-money laundering regulations (PCMLTFA) but later admitted this rationale was incorrect. The OPC investigated two issues: whether the bank improperly demanded to record information (collection) and whether it could explain the purpose of collection. Since the customer refused to provide his driver's license, no actual collection occurred, so that aspect of the complaint was not well-founded. However, the bank's inaccurate explanation for requesting the information contravened Principle 4.2.5. The bank revised its procedures and circulated new guidelines to staff, leading to a well-founded and resolved outcome for the latter issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-002: Bank misinformed client of purpose of requesting personal information for picking up credit card

Apr 15, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-002
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A bank customer complained after being asked to provide his driver's license to pick up a replacement credit card, despite having other identification on file and being known to staff. The bank initially cited anti-money laundering regulations (PCMLTFA) but later admitted this rationale was incorrect. The OPC investigated two issues: whether the bank improperly demanded to record information (collection) and whether it could explain the purpose of collection. Since the customer refused to provide his driver's license, no actual collection occurred, so that aspect of the complaint was not well-founded. However, the bank's inaccurate explanation for requesting the information contravened Principle 4.2.5. The bank revised its procedures and circulated new guidelines to staff, leading to a well-founded and resolved outcome for the latter issue.

Key Issues
  • Whether the bank limited its collection of personal information to that which was necessary for the purposes identified by the organization (Principle 4.4 PIPEDA)
  • Whether the bank ensured its employees were able to explain the purposes for which personal information was being collected (Principle 4.2.5 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 22, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-004Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account

A cellular-telephone service provider

An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account

Aug 22, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-004
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.

Key Issues
  • Whether the cellular service provider disclosed personal information without consent to an imposter, contravening Principle 4.3 PIPEDA
  • Whether the cellular service provider adequately responded to the complainant's access request for personal information under Principle 4.9 PIPEDA
  • Whether the cellular service provider responded to the access request within the 30-day timeframe as per s.8(3) PIPEDA
  • Whether the redaction of the CSR's name from the transcript was permissible under s.9(1) PIPEDA
  • Whether the company was required to provide an audio recording of the conversation in addition to a transcript under s.10 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 14, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-010Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings # 2012-010: Telecommunications firm adopts additional accountability measures to ensure a consistent approach in handling access requests

A telecommunications firm

A complainant alleged that a telecommunications firm failed to provide her with access to her personal information, specifically notes and transcripts of recorded conversations related to an account dispute. The firm acknowledged receiving the access request but mistakenly believed it was not necessary to provide the information due to ongoing settlement negotiations. The OPC found that the firm failed to respond to the access request within 30 days and did not issue an extension notice, thus contravening PIPEDA subsections 8(3), 8(4), and 8(5). Furthermore, the firm purged the requested audio records, violating subsection 8(8) and Principles 4.9 and 4.9.4. The firm's internal policies were found to be unclear and staff training inadequate, leading to the erroneous deletion of records. The OPC made several recommendations, which the firm accepted and implemented, including amending policies and providing staff training. As a result, the complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings # 2012-010: Telecommunications firm adopts additional accountability measures to ensure a consistent approach in handling access requests

Aug 14, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a telecommunications firm failed to provide her with access to her personal information, specifically notes and transcripts of recorded conversations related to an account dispute. The firm acknowledged receiving the access request but mistakenly believed it was not necessary to provide the information due to ongoing settlement negotiations. The OPC found that the firm failed to respond to the access request within 30 days and did not issue an extension notice, thus contravening PIPEDA subsections 8(3), 8(4), and 8(5). Furthermore, the firm purged the requested audio records, violating subsection 8(8) and Principles 4.9 and 4.9.4. The firm's internal policies were found to be unclear and staff training inadequate, leading to the erroneous deletion of records. The OPC made several recommendations, which the firm accepted and implemented, including amending policies and providing staff training. As a result, the complaint was deemed well-founded and resolved.

Key Issues
  • Whether the telecommunications firm responded to the access request within the 30-day time limit under subsection 8(3) PIPEDA
  • Whether the telecommunications firm issued a notice of extension for the access request under subsection 8(4) PIPEDA
  • Whether the telecommunications firm was deemed to have refused the access request under subsection 8(5) PIPEDA
  • Whether the telecommunications firm provided access to personal information as required by Principle 4.9 PIPEDA
  • Whether the telecommunications firm responded to the access request within a reasonable time and at minimal or no cost under Principle 4.9.4 PIPEDA
  • Whether the telecommunications firm retained personal information that was the subject of an access request for as long as necessary to allow the individual to exhaust any recourse under subsection 8(8) PIPEDA
  • Whether the telecommunications firm implemented policies and practices to give effect to the principles, including training staff and communicating policies and practices under Principle 4.1.4(c) PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 21, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-024Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2009-024: Bank Disclosed Personal Information without Consent

A Canadian bank

A married couple applied for a joint mortgage. The husband alleged that a bank mortgage specialist disclosed his account information to his wife without his consent during the application process. The bank argued there was implicit consent given the joint mortgage application. The Assistant Commissioner found that the bank did not make a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed to each other. Therefore, the bank did not have meaningful consent for the disclosure. Although the incident was a one-time error by an employee, the complaint was found to be well-founded and resolved as the bank had adopted reasonable practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Case Summary #2009-024: Bank Disclosed Personal Information without Consent

Dec 21, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-024
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A married couple applied for a joint mortgage. The husband alleged that a bank mortgage specialist disclosed his account information to his wife without his consent during the application process. The bank argued there was implicit consent given the joint mortgage application. The Assistant Commissioner found that the bank did not make a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed to each other. Therefore, the bank did not have meaningful consent for the disclosure. Although the incident was a one-time error by an employee, the complaint was found to be well-founded and resolved as the bank had adopted reasonable practices.

Key Issues
  • Whether the bank had the husband's implicit or explicit consent to disclose his account information to his wife
  • Whether the bank made a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed
  • Whether the bank's mortgage specialist followed the bank's usual practice for informing joint mortgage applicants
  • Whether the presumption of implied consent remained reasonable after the wife's reaction to the initial disclosure
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 16, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-008Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2009-008: Report of Findings: CIPPIC v. Facebook Inc.

Facebook Inc.

The Canadian Internet Policy and Public Interest Clinic (CIPPIC) filed a comprehensive complaint against Facebook Inc., alleging 24 contraventions of PIPEDA across 12 subjects, including default privacy settings, advertising practices, third-party applications, and the handling of personal information for deactivated, deceased, and non-users. The Office of the Privacy Commissioner (OPC) focused its investigation on meaningful consent, retention, and security safeguards. The Assistant Commissioner found several allegations to be 'not well-founded', such as those concerning new uses of information, collection from other sources, Facebook Mobile safeguards, and deception. Other allegations, including those related to date of birth collection, default privacy settings, advertising, and monitoring for anomalous activity, were found 'well-founded and resolved' due to Facebook's agreement to implement corrective measures. However, significant issues regarding third-party applications, indefinite retention of deactivated account data, inadequate notification for deceased users' accounts, and the collection/retention of non-users' personal information were found 'well-founded' but remained unresolved, as Facebook declined to implement key recommendations. The OPC indicated it would follow up on all recommendations and consider further action for unresolved issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Case Summary #2009-008: Report of Findings: CIPPIC v. Facebook Inc.

Jul 16, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-008
Adjudicator: Elizabeth Denham
Plain-Language Summary

The Canadian Internet Policy and Public Interest Clinic (CIPPIC) filed a comprehensive complaint against Facebook Inc., alleging 24 contraventions of PIPEDA across 12 subjects, including default privacy settings, advertising practices, third-party applications, and the handling of personal information for deactivated, deceased, and non-users. The Office of the Privacy Commissioner (OPC) focused its investigation on meaningful consent, retention, and security safeguards. The Assistant Commissioner found several allegations to be 'not well-founded', such as those concerning new uses of information, collection from other sources, Facebook Mobile safeguards, and deception. Other allegations, including those related to date of birth collection, default privacy settings, advertising, and monitoring for anomalous activity, were found 'well-founded and resolved' due to Facebook's agreement to implement corrective measures. However, significant issues regarding third-party applications, indefinite retention of deactivated account data, inadequate notification for deceased users' accounts, and the collection/retention of non-users' personal information were found 'well-founded' but remained unresolved, as Facebook declined to implement key recommendations. The OPC indicated it would follow up on all recommendations and consider further action for unresolved issues.

Key Issues
  • Whether requiring date of birth as a condition of registration contravened Principle 4.3.3
  • Whether Facebook adequately explained the purposes for collecting and using date of birth under Principle 4.3.2
  • Whether default privacy settings constituted improper opt-out consent for sensitive information under Principle 4.3.6
  • Whether Facebook made reasonable efforts to advise users of purposes and extent of information use/disclosure via default settings under Principles 4.2.3 and 4.3.2
  • Whether default settings for photo albums met users' reasonable expectations under Principle 4.3.5
  • Whether default settings for public search listings met users' reasonable expectations under Principle 4.3.5
  • Whether Facebook made reasonable efforts to notify users of advertising purposes under Principle 4.3.2
  • Whether Social Ads improperly used opt-out consent for sensitive information under Principle 4.3.6
  • Whether users could opt out of Facebook Ads under Principle 4.3.8
  • Whether requiring consent to Facebook Ads as a condition of service violated Principle 4.3.3
  • Whether Facebook adequately informed users of the purpose for disclosing personal information to third-party application developers under Principles 4.2.2 and 4.2.5
  • Whether Facebook provided third-party application developers with access to personal information beyond what was necessary under Principle 4.4.1
  • Whether Facebook required consent to disclosure beyond what was necessary to run an application under Principle 4.3.3
  • Whether Facebook adequately safeguarded personal information transferred to third-party applications under Principle 4.7
  • Whether Facebook obtained meaningful consent for disclosure of personal information to application developers when users or their friends added applications under Principles 4.2, 4.2.3, 4.3.2, 4.3.4, 4.3.5, 4.3.6, and subsection 5(3)
  • Whether Facebook failed to notify users of new purposes for collecting, using, or disclosing personal information under Principle 4.2.4
  • Whether Facebook failed to provide specific information and obtain meaningful consent for collecting personal information from sources outside Facebook under Principle 4.3
  • Whether Facebook inappropriately deprived users of a means to delete all personal information from the site
  • Whether Facebook's indefinite retention of personal information in deactivated accounts contravened Principles 4.5 and 4.5.3
  • Whether Facebook obtained meaningful consent for memorializing deceased users' profiles under Principle 4.3.3
  • Whether memorializing profiles was an unnecessary condition of service under Principle 4.3.3
  • Whether Facebook adequately informed users of its practice of account memorialization under Principles 4.2.1, 4.2.3, 4.3.2, and 4.8
  • Whether Facebook obtained consent from non-users for uploading their personal information (e.g., tagging, invitations) under Principle 4.3
  • Whether Facebook's retention of non-users' email addresses beyond the initial purpose contravened Principle 4.5
  • Whether Facebook Mobile's use of a persistent cookie constituted inadequate safeguarding of personal information under Principles 4.7, 4.7.1, and 4.7.3
  • Whether Facebook adequately informed users of its practice of monitoring for anomalous activity under Principle 4.8
  • Whether Facebook misrepresented its purpose or users' control over personal information under Principles 4.3.2 and 4.4.2
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 4, 2006Incident Summary #3Indexed Jun 30, 2026

Incident Summary #3: Misdirected faxes - December 4, 2006

Two Canadian banks

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #3: Misdirected faxes - December 4, 2006

Dec 4, 2006Incident Summary #3
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Key Issues
  • Whether organizations adequately safeguard personal information to prevent inappropriate disclosure (Principle 4.7 PIPEDA)
  • Whether organizations implement effective policies and procedures to give effect to fair information practices (Principle 4.1 PIPEDA)
  • Whether employees are attuned to privacy issues and can respond to problems when they arise
  • Whether organizations notify affected customers of privacy breaches
  • Whether organizations have processes for confirming correct fax transmission
  • Whether organizations have measures to recover erroneously transmitted customer information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 18, 2005Incident Summary #2Indexed Jun 30, 2026

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

CIBC

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

Apr 18, 2005Incident Summary #2
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Key Issues
  • Whether CIBC's privacy practices adequately protected personal information from misdirected faxes
  • Whether CIBC effectively responded to notifications of misdirected faxes
  • Whether CIBC appropriately recovered misdirected personal information
  • Whether CIBC adequately notified affected customers of privacy breaches
  • Whether CIBC employees recognized misdirected faxes as privacy issues
  • Whether CIBC's internal privacy management structure was sufficient to address breaches