The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

172 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Feb 27, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #7 — A national transportation company

A national transportation company

An employee of a national transportation company complained about the security of personal information in an automated crew management system. The complainant was concerned that unauthorized personnel, particularly union representatives, could access sensitive data like date of birth, social insurance number, wage rates, and vacation eligibility. While some information was not accessible to union representatives, the company agreed to modify the system. The adjustments ensured that screens would no longer display Social Insurance Numbers, birth dates, and health information. As the complainant's concerns were addressed, the case was considered settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #7 — A national transportation company

Feb 27, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An employee of a national transportation company complained about the security of personal information in an automated crew management system. The complainant was concerned that unauthorized personnel, particularly union representatives, could access sensitive data like date of birth, social insurance number, wage rates, and vacation eligibility. While some information was not accessible to union representatives, the company agreed to modify the system. The adjustments ensured that screens would no longer display Social Insurance Numbers, birth dates, and health information. As the complainant's concerns were addressed, the case was considered settled.

Key Issues
  • Whether employee personal information in an automated crew management system was adequately protected from unauthorized access
  • Whether union representatives had unauthorized access to sensitive employee personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Nov 7, 2003PIPEDA Case Summary #2003-244Indexed Jun 30, 2026

PIPEDA Case Summary #2003-244 — Telecommunications company "A"

Telecommunications company "A"

An individual complained that a telecommunications company failed to obtain proper consent for the collection, use, and disclosure of personal information for secondary marketing purposes. The complainant alleged that the company did not adequately inform customers of these practices or provide an easy opt-out mechanism. The investigation found that while the company had a privacy policy available online and in booklets, it did not actively bring these practices to the attention of new customers during the service application process. The Assistant Commissioner determined that the company's practices did not meet the reasonable expectations of its customers and thus contravened several PIPEDA principles. The complaint was found to be well-founded, and the Assistant Commissioner recommended that the company draw customers' attention to its privacy policy and options at the time of collection.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Case Summary #2003-244 — Telecommunications company "A"

Nov 7, 2003PIPEDA Case Summary #2003-244
Adjudicator: Robert Marleau
Plain-Language Summary

An individual complained that a telecommunications company failed to obtain proper consent for the collection, use, and disclosure of personal information for secondary marketing purposes. The complainant alleged that the company did not adequately inform customers of these practices or provide an easy opt-out mechanism. The investigation found that while the company had a privacy policy available online and in booklets, it did not actively bring these practices to the attention of new customers during the service application process. The Assistant Commissioner determined that the company's practices did not meet the reasonable expectations of its customers and thus contravened several PIPEDA principles. The complaint was found to be well-founded, and the Assistant Commissioner recommended that the company draw customers' attention to its privacy policy and options at the time of collection.

Key Issues
  • Whether the telecommunications company obtained adequate knowledge and consent for secondary marketing purposes under Principle 4.3
  • Whether the company specified identified purposes at or before the time of collection under Principle 4.2.3
  • Whether the company made reasonable efforts to ensure individuals were advised of the purposes for which information would be used, as required by Principle 4.3.2
  • Whether the company's consent practices met the reasonable expectations of the individual under Principle 4.3.5
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Nov 7, 2003PIPEDA Case Summary #2003-243Indexed Jun 30, 2026

PIPEDA Case Summary #2003-243 — telecommunications company "B"

telecommunications company "B"

An individual complained that a telecommunications company failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the company did not adequately inform customers about its practice of sharing data with affiliates for marketing, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The company maintained that its privacy policy, code, and activation process provided a sufficient basis for customer knowledge and consent, and that it complied with CRTC restrictions on disclosing personal information. The investigation found that the company's privacy documents and activation process constituted a reasonable effort to advise individuals of secondary purposes and that customers could refuse or withdraw consent. The Assistant Commissioner concluded that the company was in compliance with PIPEDA.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Case Summary #2003-243 — telecommunications company "B"

Nov 7, 2003PIPEDA Case Summary #2003-243
Adjudicator: Robert Marleau
Plain-Language Summary

An individual complained that a telecommunications company failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the company did not adequately inform customers about its practice of sharing data with affiliates for marketing, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The company maintained that its privacy policy, code, and activation process provided a sufficient basis for customer knowledge and consent, and that it complied with CRTC restrictions on disclosing personal information. The investigation found that the company's privacy documents and activation process constituted a reasonable effort to advise individuals of secondary purposes and that customers could refuse or withdraw consent. The Assistant Commissioner concluded that the company was in compliance with PIPEDA.

Key Issues
  • Whether the telecommunications company obtained adequate knowledge and consent for the collection, use, or disclosure of personal information for secondary marketing purposes under Principle 4.3
  • Whether the company specified identified purposes at or before the time of collection as per Principle 4.2.3
  • Whether the company made a reasonable effort to ensure individuals were advised of the purposes for which information would be used, as required by Principle 4.3.2
  • Whether the form of consent sought by the organization was appropriate given the circumstances and type of information, considering Principle 4.3.4
  • Whether the reasonable expectations of the individual were considered in obtaining consent, as per Principle 4.3.5
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Oct 16, 2002PIPEDA Case Summary #2002-82Indexed Jun 30, 2026

PIPEDA Case Summary #2002-82: Alleged disclosure of personal information without consent for secondary marketing purposes by a bank

A bank

An individual complained that a bank failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the bank did not adequately inform customers of its data sharing practices with affiliates, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The OPC investigated the bank's privacy materials and processes, finding that the bank provided two privacy documents to customers and had a detailed privacy code available online or in paper format. The bank also had a process where representatives drew attention to privacy policies and recorded customer preferences regarding disclosure to affiliates. The Commissioner found that the bank's materials and processes constituted a reasonable effort to inform individuals and allow them to refuse or withdraw consent. The complaint was therefore found to be not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Case Summary #2002-82: Alleged disclosure of personal information without consent for secondary marketing purposes by a bank

Oct 16, 2002PIPEDA Case Summary #2002-82
Adjudicator: George Radwanski
Plain-Language Summary

An individual complained that a bank failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the bank did not adequately inform customers of its data sharing practices with affiliates, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The OPC investigated the bank's privacy materials and processes, finding that the bank provided two privacy documents to customers and had a detailed privacy code available online or in paper format. The bank also had a process where representatives drew attention to privacy policies and recorded customer preferences regarding disclosure to affiliates. The Commissioner found that the bank's materials and processes constituted a reasonable effort to inform individuals and allow them to refuse or withdraw consent. The complaint was therefore found to be not well-founded.

Key Issues
  • Whether the bank obtained adequate knowledge and consent for secondary marketing purposes under Principle 4.3
  • Whether the bank made a reasonable effort to advise individuals of the purposes for which information would be used, as required by Principle 4.3.2
  • Whether the purposes were stated in a manner that individuals could reasonably understand, as per Principle 4.3.2
  • Whether the bank considered the reasonable expectations of the individual in obtaining consent, as per Principle 4.3.5
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Sep 17, 2001IncidentIndexed Jun 30, 2026

Incident: Web site broadcasts cell phone conversations

An Ottawa-based Web site / Internet Service Provider

The OPC initiated an investigation after a news report revealed an Ottawa-based website was streaming live cell phone conversations. The website was using a scanner to intercept cellular telephone traffic and broadcasting it online. During the investigation, the Internet Service Provider (ISP) hosting the website shut it down due to bandwidth issues. The ISP also terminated an employee who was responsible for the unauthorized data forwarding. The website reportedly moved to a New York server under new management. Given the shutdown of the Ottawa-based site, the OPC discontinued its investigation.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Incident: Web site broadcasts cell phone conversations

Sep 17, 2001Incident
Adjudicator: George Radwanski
Plain-Language Summary

The OPC initiated an investigation after a news report revealed an Ottawa-based website was streaming live cell phone conversations. The website was using a scanner to intercept cellular telephone traffic and broadcasting it online. During the investigation, the Internet Service Provider (ISP) hosting the website shut it down due to bandwidth issues. The ISP also terminated an employee who was responsible for the unauthorized data forwarding. The website reportedly moved to a New York server under new management. Given the shutdown of the Ottawa-based site, the OPC discontinued its investigation.

Key Issues
  • Whether broadcasting cell phone conversations without consent constitutes unauthorized collection, use, or disclosure of personal information under PIPEDA
  • Whether the OPC should continue an investigation when the alleged activity has ceased
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 15, 2001Indexed Jun 30, 2026

Letter of finding regarding the video surveillance issue

Centurion Security Services Co. Ltd.

The federal Privacy Commissioner investigated a complaint regarding Centurion Security Services' installation of surveillance cameras at a downtown Yellowknife intersection. The Commissioner found that both live and recorded video images of individuals constitute "personal information" under PIPEDA. Centurion Security Services, a private company, was monitoring public spaces for commercial purposes without the consent of individuals, which contravened Principle 4.3 of Schedule 1 and section 5(1) of the Act. Although the cameras were removed before the complaint was received, the Commissioner concluded that Centurion's intended future public video surveillance for commercial purposes would also be unlawful. The complaint was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Letter of finding regarding the video surveillance issue

Jun 15, 2001
Adjudicator: George Radwanski
Plain-Language Summary

The federal Privacy Commissioner investigated a complaint regarding Centurion Security Services' installation of surveillance cameras at a downtown Yellowknife intersection. The Commissioner found that both live and recorded video images of individuals constitute "personal information" under PIPEDA. Centurion Security Services, a private company, was monitoring public spaces for commercial purposes without the consent of individuals, which contravened Principle 4.3 of Schedule 1 and section 5(1) of the Act. Although the cameras were removed before the complaint was received, the Commissioner concluded that Centurion's intended future public video surveillance for commercial purposes would also be unlawful. The complaint was found to be well-founded.

Key Issues
  • Whether the subject matter falls within the Commissioner's jurisdiction under PIPEDA
  • Whether live video pictures of individuals constitute "personal information" under section 2 of PIPEDA
  • Whether the collection of personal information was in the course of a commercial activity under section 4 of PIPEDA
  • Whether Centurion Security Services collected personal information without consent in contravention of Principle 4.3 of Schedule 1 of PIPEDA
  • Whether the absence of recording (live feed only) affects the classification of information as personal information or the requirement for consent
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 20, 2001IncidentIndexed Jun 30, 2026

Incident: Transportation company collects and discloses passengers' personal information

A transportation company

A complaint was made against a transportation company alleging that its sales agents were collecting passengers' date of birth and citizenship for Toronto-to-New York train bookings and disclosing this information to US Customs and US Naturalization and Immigration Service. The company confirmed this practice, stating it was an agreement with US authorities to minimize border delays. The OPC found that sales agents were representing the provision of this information as a requirement. The OPC advised the company to instruct its agents to present the provision of this information as voluntary and to seek consent after booking. The company issued a directive to its sales agents, and the OPC closed the file, subject to monitoring.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident: Transportation company collects and discloses passengers' personal information

Apr 20, 2001Incident
Adjudicator: George Radwanski
Plain-Language Summary

A complaint was made against a transportation company alleging that its sales agents were collecting passengers' date of birth and citizenship for Toronto-to-New York train bookings and disclosing this information to US Customs and US Naturalization and Immigration Service. The company confirmed this practice, stating it was an agreement with US authorities to minimize border delays. The OPC found that sales agents were representing the provision of this information as a requirement. The OPC advised the company to instruct its agents to present the provision of this information as voluntary and to seek consent after booking. The company issued a directive to its sales agents, and the OPC closed the file, subject to monitoring.

Key Issues
  • Whether the transportation company was collecting personal information without proper consent
  • Whether the transportation company was disclosing personal information without proper consent
  • Whether sales agents were misrepresenting the voluntary nature of providing personal information