The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

172 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 4, 2006Incident Summary #3Indexed Jun 30, 2026

Incident Summary #3: Misdirected faxes - December 4, 2006

Two Canadian banks

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #3: Misdirected faxes - December 4, 2006

Dec 4, 2006Incident Summary #3
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Key Issues
  • Whether organizations adequately safeguard personal information to prevent inappropriate disclosure (Principle 4.7 PIPEDA)
  • Whether organizations implement effective policies and procedures to give effect to fair information practices (Principle 4.1 PIPEDA)
  • Whether employees are attuned to privacy issues and can respond to problems when they arise
  • Whether organizations notify affected customers of privacy breaches
  • Whether organizations have processes for confirming correct fax transmission
  • Whether organizations have measures to recover erroneously transmitted customer information
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Oct 2, 2006Settled Case summary #22Indexed Jun 30, 2026

Settled case summary #22 — A counselling firm and An emergency services organization

A counselling firm and an emergency services organization

A complainant alleged that a counselling firm, part of her employer's Employee Assistance Program (EAP), improperly disclosed sensitive personal information to her employer and others. The firm revealed she was using counselling services and believed she was a danger to herself, which the complainant disputed as a misinterpretation. The OPC's investigation found that a miscommunication occurred during a phone call between the complainant and her counsellor regarding the meaning of "having a plan." The counsellor, believing the complainant was suicidal, contacted emergency services, including the complainant's workplace. The police later concluded the complainant posed no danger. The counselling firm and the complainant reached a private settlement with the OPC's involvement. The firm subsequently revised its policies on disclosing personal information, emphasizing detailed case notes and limiting information shared with emergency services.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #22 — A counselling firm and An emergency services organization

Oct 2, 2006Settled Case summary #22
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a counselling firm, part of her employer's Employee Assistance Program (EAP), improperly disclosed sensitive personal information to her employer and others. The firm revealed she was using counselling services and believed she was a danger to herself, which the complainant disputed as a misinterpretation. The OPC's investigation found that a miscommunication occurred during a phone call between the complainant and her counsellor regarding the meaning of "having a plan." The counsellor, believing the complainant was suicidal, contacted emergency services, including the complainant's workplace. The police later concluded the complainant posed no danger. The counselling firm and the complainant reached a private settlement with the OPC's involvement. The firm subsequently revised its policies on disclosing personal information, emphasizing detailed case notes and limiting information shared with emergency services.

Key Issues
  • Whether the counselling firm improperly disclosed personal information about the complainant to her employer and others
  • Whether the information disclosed by the counselling firm was inaccurate
  • Whether the counsellor misconstrued the complainant's statements during a telephone conversation
  • Whether the counselling firm's disclosure of personal information was justified under circumstances of perceived imminent danger
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jul 24, 2006Settled Case summary #21Indexed Jun 30, 2026

Settled case summary #21 — A loyalty program

A loyalty program

An individual complained that a loyalty program shared his children's names and addresses with partner credit card companies, resulting in marketing materials being sent to the minors. The loyalty program stated it does not market to minors or share their information with partners. However, due to telephone account openings where birth dates were not mandatory, the children were not identified as minors in their profiles. This led to their information being shared for marketing purposes. The program acknowledged an overly long delay in correcting the issue, partly due to marketing lists being generated weeks in advance. The loyalty program sent an apology letter, and the mailings to the children ceased. The complaint was considered settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #21 — A loyalty program

Jul 24, 2006Settled Case summary #21
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a loyalty program shared his children's names and addresses with partner credit card companies, resulting in marketing materials being sent to the minors. The loyalty program stated it does not market to minors or share their information with partners. However, due to telephone account openings where birth dates were not mandatory, the children were not identified as minors in their profiles. This led to their information being shared for marketing purposes. The program acknowledged an overly long delay in correcting the issue, partly due to marketing lists being generated weeks in advance. The loyalty program sent an apology letter, and the mailings to the children ceased. The complaint was considered settled.

Key Issues
  • Whether the loyalty program inappropriately disclosed personal information of minors to partner companies for marketing purposes
  • Whether the loyalty program adequately protected the personal information of minor members
  • Whether the loyalty program took appropriate and timely steps to resolve the complaint
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jul 21, 2006Settled Case summary #24Indexed Jun 30, 2026

Settled case summary #24 — A web-based company

A web-based company

An individual complained that a web-based company retained his personal information for too long after he cancelled his free trial membership. He also alleged that the company lacked accountability under PIPEDA, as it did not fully answer his privacy questions and had no designated privacy officer. The company explained that it retained personal information, including credit card details, to process rental requests, ship items, and prevent fraud, particularly to track individuals attempting to obtain multiple free trials. As a result of the complaint, the company revised its privacy policy to clarify retention purposes and periods for different types of information. It also trained its customer service staff and designated a privacy officer. The complainant was satisfied with these changes.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #24 — A web-based company

Jul 21, 2006Settled Case summary #24
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a web-based company retained his personal information for too long after he cancelled his free trial membership. He also alleged that the company lacked accountability under PIPEDA, as it did not fully answer his privacy questions and had no designated privacy officer. The company explained that it retained personal information, including credit card details, to process rental requests, ship items, and prevent fraud, particularly to track individuals attempting to obtain multiple free trials. As a result of the complaint, the company revised its privacy policy to clarify retention purposes and periods for different types of information. It also trained its customer service staff and designated a privacy officer. The complainant was satisfied with these changes.

Key Issues
  • Whether the web-based company retained personal information for too long after a free trial cancellation
  • Whether the web-based company was fully accountable under PIPEDA
  • Whether the web-based company adequately answered privacy-related questions
  • Whether the web-based company had a designated person responsible for handling privacy issues
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jun 12, 2006Settled Case summary #23Indexed Jun 30, 2026

Settled case summary #23 — A building management firm

A building management firm

A tenant complained that the caretaker of his apartment building disclosed to other tenants that his rent cheque had bounced. The building management firm initially did not take the issue seriously, prompting the tenant to complain to the OPC. While the caretaker and his wife denied the disclosure, another tenant confirmed that the caretaker's wife had indeed shared this information, along with other tenants' rent details. The complainant sought a letter of apology from the building management firm. The firm provided the apology and also reminded the caretaker and his wife about their obligation not to discuss tenants' personal information. The OPC further advised the firm to create a privacy policy in compliance with PIPEDA. The matter was ultimately settled to the satisfaction of both the OPC and the complainant.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #23 — A building management firm

Jun 12, 2006Settled Case summary #23
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A tenant complained that the caretaker of his apartment building disclosed to other tenants that his rent cheque had bounced. The building management firm initially did not take the issue seriously, prompting the tenant to complain to the OPC. While the caretaker and his wife denied the disclosure, another tenant confirmed that the caretaker's wife had indeed shared this information, along with other tenants' rent details. The complainant sought a letter of apology from the building management firm. The firm provided the apology and also reminded the caretaker and his wife about their obligation not to discuss tenants' personal information. The OPC further advised the firm to create a privacy policy in compliance with PIPEDA. The matter was ultimately settled to the satisfaction of both the OPC and the complainant.

Key Issues
  • Whether a building caretaker disclosed a tenant's personal information without consent
  • Whether the building management firm adequately protected personal information
  • Whether the building management firm had appropriate privacy policies in place
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
May 16, 2006Settled Case summary #27Indexed Jun 30, 2026

Settled case summary #27 — A dental clinic

A dental clinic

An individual complained that her dental clinic disclosed information about her overdue account to the person who had referred her to the clinic. The complainant had been in hospital and respite care, missing invoices. The clinic, seeking her whereabouts, disclosed to the referrer that her bill was overdue, the amount owing, and that it would go to collections. The clinic acknowledged this violated its privacy policy, stating it should have only requested contact information. During the investigation, the clinic and complainant reached a monetary settlement, including an apology letter. The OPC and complainant agreed the matter was settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #27 — A dental clinic

May 16, 2006Settled Case summary #27
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that her dental clinic disclosed information about her overdue account to the person who had referred her to the clinic. The complainant had been in hospital and respite care, missing invoices. The clinic, seeking her whereabouts, disclosed to the referrer that her bill was overdue, the amount owing, and that it would go to collections. The clinic acknowledged this violated its privacy policy, stating it should have only requested contact information. During the investigation, the clinic and complainant reached a monetary settlement, including an apology letter. The OPC and complainant agreed the matter was settled.

Key Issues
  • Whether the dental clinic disclosed personal information without consent
  • Whether the disclosure of overdue bill details, amount owing, and collection threat to a third party was appropriate
  • Whether the clinic's actions violated its own privacy policy
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Mar 28, 2006Settled Case summary #26Indexed Jun 30, 2026

Settled Case summary #26: Department store's credit card application form appropriate (March 28, 2006)

A department store

An individual complained after receiving promotional material and telemarketing calls following her application for a department store credit card, believing she had not consented to the use of her contact information for marketing. The department store asserted that her signature on the application form indicated agreement to its terms and conditions, which included marketing. The OPC found that the application form adequately explained how personal information would be used and provided an opt-out mechanism below the signature line. The OPC informed the complainant that this type of opt-out was permissible under PIPEDA. The complainant was satisfied with this explanation and requested removal from marketing lists, which the store completed. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #26: Department store's credit card application form appropriate (March 28, 2006)

Mar 28, 2006Settled Case summary #26
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained after receiving promotional material and telemarketing calls following her application for a department store credit card, believing she had not consented to the use of her contact information for marketing. The department store asserted that her signature on the application form indicated agreement to its terms and conditions, which included marketing. The OPC found that the application form adequately explained how personal information would be used and provided an opt-out mechanism below the signature line. The OPC informed the complainant that this type of opt-out was permissible under PIPEDA. The complainant was satisfied with this explanation and requested removal from marketing lists, which the store completed. The complaint was settled during the investigation.

Key Issues
  • Whether the department store obtained valid consent for using personal information for marketing purposes
  • Whether the opt-out mechanism provided by the department store was compliant with PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Mar 6, 2006Settled Case summary #18Indexed Jun 30, 2026

Settled Case summary #18: Business learns that it must have a privacy policy available to the public (March 6, 2006)

A business

An individual complained that a business withheld some of his personal information and its privacy policy. The business initially claimed the individual was not entitled to information predating January 1, 2004, when PIPEDA became applicable to it. After the complainant challenged this, the business provided the remaining personal information but still did not provide a privacy policy. The OPC discovered the business did not have a privacy policy. At the OPC's request, the business drafted a privacy policy and provided it to the complainant. The complainant considered the matter settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #18: Business learns that it must have a privacy policy available to the public (March 6, 2006)

Mar 6, 2006Settled Case summary #18
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a business withheld some of his personal information and its privacy policy. The business initially claimed the individual was not entitled to information predating January 1, 2004, when PIPEDA became applicable to it. After the complainant challenged this, the business provided the remaining personal information but still did not provide a privacy policy. The OPC discovered the business did not have a privacy policy. At the OPC's request, the business drafted a privacy policy and provided it to the complainant. The complainant considered the matter settled.

Key Issues
  • Whether the business improperly withheld personal information requested by the individual
  • Whether the business failed to make its privacy policy publicly available as required by PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Mar 6, 2006Settled Case summary #20Indexed Jun 30, 2026

Settled case summary #20 — A condominium corporation

A condominium corporation

An individual complained that a condominium corporation disclosed personal information about her dispute with the corporation to all condominium owners. The corporation sent a letter detailing the alleged by-law contravention to all owners, posted it on a bulletin board, and included it in Board meeting minutes. The corporation initially believed only contact information, which it considered publicly available, was disclosed. However, the OPC clarified that the personal information at issue was the fact of the dispute itself. The corporation had disclosed this information without the complainant's consent. The matter was resolved when the condominium corporation sent the complainant a letter of apology.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #20 — A condominium corporation

Mar 6, 2006Settled Case summary #20
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a condominium corporation disclosed personal information about her dispute with the corporation to all condominium owners. The corporation sent a letter detailing the alleged by-law contravention to all owners, posted it on a bulletin board, and included it in Board meeting minutes. The corporation initially believed only contact information, which it considered publicly available, was disclosed. However, the OPC clarified that the personal information at issue was the fact of the dispute itself. The corporation had disclosed this information without the complainant's consent. The matter was resolved when the condominium corporation sent the complainant a letter of apology.

Key Issues
  • Whether the fact of an individual's dispute with a condominium corporation constitutes personal information under PIPEDA
  • Whether the condominium corporation disclosed personal information without consent
  • Whether the personal information was publicly available
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Feb 3, 2006Settled Case summary #19Indexed Jun 30, 2026

Settled Case summary #19: SIN not required when signing apartment lease (February 3, 2006)

A property management firm

A student complained that a property management firm required his Social Insurance Number (SIN) to rent an apartment. The firm stated it needed the SIN for identity verification, credit checks, and collections. The OPC noted that while no legislation prevents organizations from asking for SINs for identification, organizations subject to PIPEDA must inform individuals that providing a SIN for identification is optional and not a condition of service. As a result of the complaint, the property manager revised the lease agreement to only require a driver's license for identification and stopped requesting SINs from potential renters. The student and the OPC considered the matter settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #19: SIN not required when signing apartment lease (February 3, 2006)

Feb 3, 2006Settled Case summary #19
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A student complained that a property management firm required his Social Insurance Number (SIN) to rent an apartment. The firm stated it needed the SIN for identity verification, credit checks, and collections. The OPC noted that while no legislation prevents organizations from asking for SINs for identification, organizations subject to PIPEDA must inform individuals that providing a SIN for identification is optional and not a condition of service. As a result of the complaint, the property manager revised the lease agreement to only require a driver's license for identification and stopped requesting SINs from potential renters. The student and the OPC considered the matter settled.

Key Issues
  • Whether requiring a SIN for an apartment lease is permissible under PIPEDA
  • Whether organizations must inform individuals that providing a SIN for identification is optional
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jan 27, 2006Settled Case summary #25Indexed Jun 30, 2026

Settled case summary #25 — A restaurant

A restaurant

An individual complained that a restaurant's credit card receipts displayed her name, full credit card number, and expiry date, arguing this information should be masked. The restaurant used electronic processing equipment that did not mask this information. The OPC found that the personal information was collected, used, and stored in a manner consistent with PIPEDA principles, and there was no unauthorized disclosure. However, the OPC noted that technology for masking credit card information on receipts exists and that industry representatives indicated all equipment would mask this information by 2007. The complainant was satisfied with this information and the restaurant owner's awareness of privacy legislation. The matter was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #25 — A restaurant

Jan 27, 2006Settled Case summary #25
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a restaurant's credit card receipts displayed her name, full credit card number, and expiry date, arguing this information should be masked. The restaurant used electronic processing equipment that did not mask this information. The OPC found that the personal information was collected, used, and stored in a manner consistent with PIPEDA principles, and there was no unauthorized disclosure. However, the OPC noted that technology for masking credit card information on receipts exists and that industry representatives indicated all equipment would mask this information by 2007. The complainant was satisfied with this information and the restaurant owner's awareness of privacy legislation. The matter was settled during the investigation.

Key Issues
  • Whether the display of full credit card details on receipts constituted a contravention of PIPEDA
  • Whether the collection, use, and storage of personal information on credit card receipts was consistent with PIPEDA principles
  • Whether there was unauthorized disclosure of personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Dec 16, 2005Settled Case summary #17Indexed Jun 30, 2026

Settled case summary #17 — A not-for-profit association

A not-for-profit association

A member of a not-for-profit association complained that the association required a second piece of identification, in addition to his membership card, to obtain member discounts. The complainant believed his membership card should be sufficient and that collecting further personal information was unwarranted. The association explained that it had legal agreements with vendors requiring it to sell discounted products only to current members. Due to some members loaning their cards to non-members, which caused legal and revenue issues, the association implemented the supplementary identification requirement to confirm identity and prevent misuse. The association also noted that members could choose their secondary identification and that this information was not recorded. The complainant was satisfied with this explanation, and the complaint was settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #17 — A not-for-profit association

Dec 16, 2005Settled Case summary #17
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A member of a not-for-profit association complained that the association required a second piece of identification, in addition to his membership card, to obtain member discounts. The complainant believed his membership card should be sufficient and that collecting further personal information was unwarranted. The association explained that it had legal agreements with vendors requiring it to sell discounted products only to current members. Due to some members loaning their cards to non-members, which caused legal and revenue issues, the association implemented the supplementary identification requirement to confirm identity and prevent misuse. The association also noted that members could choose their secondary identification and that this information was not recorded. The complainant was satisfied with this explanation, and the complaint was settled.

Key Issues
  • Whether requiring supplementary identification for member discounts was an unwarranted collection of personal information
  • Whether the membership card alone was sufficient identification
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 21, 2005Settled Case summary #16Indexed Jun 30, 2026

Settled Case summary #16: Personal information on receipts removed, information collected when goods returned is limited (November 21, 2005)

A retail chain

An individual complained about a retail chain's practice of printing personal information on receipts and collecting excessive information for returns. The complainant was concerned that the printing of name, credit card number, and expiry date on receipts, and the recording of driver's license and credit card information for refunds, constituted unnecessary collection of personal information. During the investigation, the company updated its point-of-sale equipment to mask personal information on receipts. For returns, the company committed to continuing to collect name, address, and telephone number, but would no longer record identification information, only asking to see it. Credit card information would only be requested if a credit card was used for the original purchase. The company also committed to training its employees on these new procedures. Both the complainant and the OPC were satisfied with these changes.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #16: Personal information on receipts removed, information collected when goods returned is limited (November 21, 2005)

Nov 21, 2005Settled Case summary #16
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained about a retail chain's practice of printing personal information on receipts and collecting excessive information for returns. The complainant was concerned that the printing of name, credit card number, and expiry date on receipts, and the recording of driver's license and credit card information for refunds, constituted unnecessary collection of personal information. During the investigation, the company updated its point-of-sale equipment to mask personal information on receipts. For returns, the company committed to continuing to collect name, address, and telephone number, but would no longer record identification information, only asking to see it. Credit card information would only be requested if a credit card was used for the original purchase. The company also committed to training its employees on these new procedures. Both the complainant and the OPC were satisfied with these changes.

Key Issues
  • Whether printing customer's name, credit card number, and expiry date on receipts constituted unnecessary collection of personal information under PIPEDA
  • Whether requiring and recording a driver's license and credit card for returns constituted unnecessary collection of personal information under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jul 29, 2005Settled Case summaryIndexed Jun 30, 2026

Settled Case summary: Disclosure of personal information to estranged spouse - July 29, 2005

A bank

An individual complained that a bank employee improperly disclosed her bank account balance to her estranged husband. The husband subsequently withheld a support payment, causing financial difficulty for the complainant. The bank apologized and acknowledged that its employee likely contravened Principle 4.3 of PIPEDA by disclosing personal information without consent. Although the employee denied the specific recollection, the bank found no evidence to suggest the allegations were false. The bank and the complainant reached a private settlement regarding compensation. The OPC concluded that there was no systemic problem, as the bank had adequate privacy policies and training in place.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary: Disclosure of personal information to estranged spouse - July 29, 2005

Jul 29, 2005Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a bank employee improperly disclosed her bank account balance to her estranged husband. The husband subsequently withheld a support payment, causing financial difficulty for the complainant. The bank apologized and acknowledged that its employee likely contravened Principle 4.3 of PIPEDA by disclosing personal information without consent. Although the employee denied the specific recollection, the bank found no evidence to suggest the allegations were false. The bank and the complainant reached a private settlement regarding compensation. The OPC concluded that there was no systemic problem, as the bank had adequate privacy policies and training in place.

Key Issues
  • Whether a bank employee disclosed personal information without consent
  • Whether the disclosure of a bank account balance to an estranged spouse contravened Principle 4.3 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jun 24, 2005Settled Case summary #15Indexed Jun 30, 2026

Settled case summary #15 — A retail store and A financial institution

A retail store and A financial institution

An individual complained that a retail store inappropriately collected her personal information and disclosed it to a financial institution, and that the financial institution used and disclosed her information without consent. The complainant provided her information for a credit application but decided not to proceed, tearing up the contract. However, due to a salesperson's error, her information was entered into the system before her signature, leading to a credit card being issued. The financial institution apologized, removed inquiries from her credit file, and purged her information. The retail store implemented new procedures to ensure signatures are obtained before data entry. Both the complainant and the OPC were satisfied with the corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #15 — A retail store and A financial institution

Jun 24, 2005Settled Case summary #15
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a retail store inappropriately collected her personal information and disclosed it to a financial institution, and that the financial institution used and disclosed her information without consent. The complainant provided her information for a credit application but decided not to proceed, tearing up the contract. However, due to a salesperson's error, her information was entered into the system before her signature, leading to a credit card being issued. The financial institution apologized, removed inquiries from her credit file, and purged her information. The retail store implemented new procedures to ensure signatures are obtained before data entry. Both the complainant and the OPC were satisfied with the corrective actions.

Key Issues
  • Whether the retail store inappropriately collected and disclosed personal information without consent
  • Whether the financial institution used and disclosed personal information without consent
  • Whether the salesperson followed proper procedure for credit applications