The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

172 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Feb 2, 2021PIPEDA Findings #2021-001Indexed Jun 30, 2026

PIPEDA Findings #2021-001: Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta

Clearview AI, Inc.

A joint investigation by Canadian privacy commissioners examined Clearview AI's facial recognition tool, which scraped billions of images from public websites to create a database for law enforcement and other users. Clearview argued that Canadian privacy laws did not apply due to a lack of jurisdiction and that the information was "publicly available," thus exempt from consent requirements. The Offices asserted jurisdiction, finding a real and substantial connection to Canada through Clearview's marketing and use by Canadian entities. They determined Clearview failed to obtain requisite consent, as the "publicly available" exception did not apply to sensitive biometric data scraped from social media for unrelated purposes. Furthermore, Clearview's mass collection and use of sensitive facial biometric information for commercial purposes were deemed inappropriate. In Quebec, Clearview also failed to report its biometric database and obtain express consent as required by law. The matter was found to be well-founded, with recommendations for Clearview to cease operations in Canada and delete Canadian data, which Clearview did not commit to implementing.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2021-001: Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta

Feb 2, 2021PIPEDA Findings #2021-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A joint investigation by Canadian privacy commissioners examined Clearview AI's facial recognition tool, which scraped billions of images from public websites to create a database for law enforcement and other users. Clearview argued that Canadian privacy laws did not apply due to a lack of jurisdiction and that the information was "publicly available," thus exempt from consent requirements. The Offices asserted jurisdiction, finding a real and substantial connection to Canada through Clearview's marketing and use by Canadian entities. They determined Clearview failed to obtain requisite consent, as the "publicly available" exception did not apply to sensitive biometric data scraped from social media for unrelated purposes. Furthermore, Clearview's mass collection and use of sensitive facial biometric information for commercial purposes were deemed inappropriate. In Quebec, Clearview also failed to report its biometric database and obtain express consent as required by law. The matter was found to be well-founded, with recommendations for Clearview to cease operations in Canada and delete Canadian data, which Clearview did not commit to implementing.

Key Issues
  • Whether the Canadian privacy commissioners had jurisdiction over Clearview AI's activities.
  • Whether Clearview AI obtained requisite consent for its collection, use, and disclosure of personal information under PIPEDA, PIPA AB, PIPA BC, and Quebec's Private Sector Act.
  • Whether the "publicly available" information exception applied to Clearview AI's collection of images from public websites.
  • Whether Clearview AI's collection, use, and disclosure of personal information was for an appropriate purpose under PIPEDA, PIPA AB, PIPA BC, and Quebec's Private Sector Act.
  • Whether Clearview AI satisfied its biometric obligations in Quebec, specifically regarding reporting the creation of a biometric database and obtaining express consent under the LCCJTI.
  • Whether Clearview AI's activities were protected by freedom of expression under the Canadian Charter of Rights and Freedoms.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 14, 2020PIPEDA Findings #2020-005Indexed Jun 30, 2026

PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019

Desjardins

The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019

Dec 14, 2020PIPEDA Findings #2020-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.

Key Issues
  • Whether personal information held by Desjardins was protected throughout its life cycle by security safeguards appropriate to the sensitivity of the information as required by PIPEDA Safeguards Principle 4.7.
  • Whether Desjardins fulfilled its responsibilities to implement procedures to protect personal information and train its staff, as set out in Accountability Principle 4.1.
  • Whether the personal information of individuals was handled in accordance with the retention and destruction requirements as set out in PIPEDA Principle 4.5, limiting use, disclosure and retention.
  • Whether the mitigation measures offered by Desjardins to affected individuals were adequate to protect their personal information from unauthorized use, such as future identity theft, in accordance with PIPEDA Safeguards Principle 4.7.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 28, 2020PIPEDA Findings #2020-004Indexed Jun 30, 2026

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

The Cadillac Fairview Corporation Limited

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

Oct 28, 2020PIPEDA Findings #2020-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Key Issues
  • Whether CFCL’s use of Anonymous Video Analytics (AVA) technology, via in-mall directories, resulted in the collection, use, and/or disclosure of personal information.
  • Whether images of individual faces captured by AVA technology constitute personal information.
  • Whether numerical representations of faces (biometric information) generated by AVA technology constitute personal information.
  • Whether age range and gender assessments, combined with other data, constitute personal information.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via AVA technology.
  • Whether CFCL retained personal information collected via AVA technology longer than necessary.
  • Whether CFCL’s use of mobile device geolocation technologies (Anonymous Shopper Journey) resulted in the collection, use, and/or disclosure of personal information.
  • Whether hashed and randomized MAC addresses, combined with non-granular zone geolocation, constitute personal information in the context of anonymous shopper tracking.
  • Whether CFCL’s use of mobile device geolocation technologies (Logged In Shopper Journey) resulted in the collection, use, and/or disclosure of personal information linked to identifiable individuals.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via mobile device geolocation technologies (Logged In Shopper Journey).
  • Whether CFCL's privacy policy and signage provided sufficient notice and obtained valid consent for its data collection practices.
  • Whether the "serious possibility" threshold for identifying individuals was met for anonymous shopper journey data.
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Aug 4, 2020PIPEDA Findings #2020-001Indexed Jun 30, 2026

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

TD Canada Trust

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

Aug 4, 2020PIPEDA Findings #2020-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Key Issues
  • Whether TD was required to obtain additional consent for transferring personal information to a third-party service provider in India for fraud claims processing (Principle 4.3 PIPEDA)
  • Whether TD was required to offer customers an opt-out for the transfer of personal information to a third-party service provider in India for fraud claims processing
  • Whether TD was sufficiently open about its practice of transferring personal information to a third-party service provider in a foreign jurisdiction for processing (Principle 4.8 PIPEDA)
  • Whether TD ensured a comparable level of protection for personal information processed by the third-party service provider in India (Principle 4.1.3 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 9, 2020PIPEDA Findings #2020-003Indexed Jun 30, 2026

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Dell Inc.

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Jul 9, 2020PIPEDA Findings #2020-003
Adjudicator: Daniel Therrien
Plain-Language Summary

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Key Issues
  • Whether Dell adequately safeguarded personal information under its control while using a service provider (PIPEDA Principle 4.1.3 and 4.7).
  • Whether the personal information transferred to the service provider was sensitive enough to require a high degree of protection.
  • Whether Dell's access controls were sufficient to protect customer information.
  • Whether Dell's logging and monitoring practices were adequate to detect anomalous employee requests for customer information.
  • Whether Dell's technical measures, such as USB drive restrictions, were sufficient.
  • Whether Dell adequately investigated the circumstances and scope of the June 2017 breach.
  • Whether Dell adequately responded to customer complaints about potential privacy breaches (PIPEDA Principle 4.10.4).
  • Whether Dell remained responsible for personal information transferred to a third party for processing.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 30, 2020PIPEDA Findings #2020-002Indexed Jun 30, 2026

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

RateMDs.com

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

Jun 30, 2020PIPEDA Findings #2020-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Key Issues
  • Whether RateMDs collected, used, or disclosed the complainant's business contact information without consent (Principle 4.3)
  • Whether the business contact information exemption under s.4.01 of PIPEDA applied to RateMDs' use of the complainant's business contact information
  • Whether the complainant's business contact information was publicly available under s.7(1)(d), 7(2)(c.1), and 7(3)(h.1) of PIPEDA and its Regulations
  • Whether the reviews and ratings posted on RateMDs constituted the complainant's personal information
  • Whether the reviews and ratings also constituted the personal information of the users who posted them
  • Whether RateMDs required the complainant's consent to publish the reviews and ratings about her (Principle 4.3)
  • Whether a balancing of interests was required when the privacy rights of multiple individuals conflicted regarding the same personal information
  • Whether RateMDs ensured the accuracy of information and provided a fair and accessible process for health professionals to challenge and correct inaccurate information (Principle 4.6, 4.9.5)
  • Whether RateMDs made readily available specific information about its policies and practices relating to the management of personal information, particularly regarding review removal and correction (Principle 4.8)
  • Whether RateMDs' "pay-for-takedown" service, allowing subscribers to hide negative reviews for a fee, constituted an appropriate purpose for collecting, using, or disclosing personal information under s.5(3) of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Dec 9, 2019PIPEDA Findings #2019-007Indexed Jun 30, 2026

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Trans Union of Canada, Inc.

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Dec 9, 2019PIPEDA Findings #2019-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Key Issues
  • Whether TransUnion disclosed the complainant's credit file information to Statistics Canada without requisite consent
  • Whether TransUnion was authorized to disclose personal information without consent under PIPEDA subparagraph 7(3)(c.1)(iii)
  • Whether Statistics Canada identified its lawful authority to obtain the information
  • Whether the disclosure was requested to administer a law of Canada (the Statistics Act)
  • Whether Statistics Canada subsequently disclosed the complainant's credit file information to other government institutions for debt collection
  • Whether there was sufficient evidence to support the allegation of information misuse for debt collection
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Nov 26, 2019PIPEDA Findings #2019-004Indexed Jun 30, 2026

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

AggregateIQ Data Services Ltd.

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Nov 26, 2019PIPEDA Findings #2019-004
Adjudicator: Daniel Therrien
Plain-Language Summary

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Key Issues
  • Whether AIQ was compliant with consent requirements for the collection, use, or disclosure of personal information under PIPEDA and PIPA.
  • Whether AIQ could rely on consent obtained by its clients for its own collection, use, and disclosure of personal information.
  • Whether consent was adequate for specific uses, such as disclosing personal information to Facebook for "custom audiences" and "lookalike audiences."
  • Whether consent was adequate for sensitive personal information, such as political opinions or psychographic profiles.
  • Whether AIQ took reasonable security measures to protect the personal information in its custody or control under PIPEDA and PIPA.
  • Whether the security breach involving the GitLab repository constituted a failure of reasonable security measures.
  • Whether personal information collected from public telephone directories required consent.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 16, 2019PIPEDA Findings #2019-003Indexed Jun 30, 2026

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Loblaw Companies Ltd.

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Oct 16, 2019PIPEDA Findings #2019-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Key Issues
  • Whether Loblaw collected more personal information than necessary for the Loblaw Card Program (Principle 4.4)
  • Whether Loblaw ensured a comparable level of protection for personal information transferred to a third party for processing (Principle 4.1.3)
  • Whether Loblaw was required to obtain additional consent for the transfer of personal information for processing (Principle 4.3)
  • Whether Loblaw was sufficiently open and transparent about its cross-border data transfers (Principle 4.8)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Apr 25, 2019PIPEDA Findings #2019-002Indexed Jun 30, 2026

PIPEDA Findings #2019-002: Joint investigation of Facebook, Inc. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Facebook, Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) conducted a joint investigation into Facebook, Inc.'s compliance with PIPEDA and PIPA following revelations about the "thisisyourdigitallife" (TYDL) app and its data sharing with Cambridge Analytica. The investigation focused on Facebook's consent practices for both installing users and their friends, its data safeguards, and its overall accountability. The OPC found that Facebook failed to obtain meaningful consent from users for the disclosure of their personal information to third-party apps, including the TYDL app, and that its safeguards against unauthorized access and use were inadequate. Furthermore, Facebook was deemed to have abdicated its responsibility for user information, demonstrating a lack of accountability. Despite recommendations from the OPC, Facebook rejected or refused to implement them, leading to a finding that the complaint was well-founded and remains unresolved. The OPC stated it would pursue further action under its authorities.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2019-002: Joint investigation of Facebook, Inc. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Apr 25, 2019PIPEDA Findings #2019-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) conducted a joint investigation into Facebook, Inc.'s compliance with PIPEDA and PIPA following revelations about the "thisisyourdigitallife" (TYDL) app and its data sharing with Cambridge Analytica. The investigation focused on Facebook's consent practices for both installing users and their friends, its data safeguards, and its overall accountability. The OPC found that Facebook failed to obtain meaningful consent from users for the disclosure of their personal information to third-party apps, including the TYDL app, and that its safeguards against unauthorized access and use were inadequate. Furthermore, Facebook was deemed to have abdicated its responsibility for user information, demonstrating a lack of accountability. Despite recommendations from the OPC, Facebook rejected or refused to implement them, leading to a finding that the complaint was well-founded and remains unresolved. The OPC stated it would pursue further action under its authorities.

Key Issues
  • Whether the OPC and OIPC BC had jurisdiction to investigate the matter.
  • Whether Facebook's provision of access to personal information via its Graph API constitutes a "disclosure" under PIPEDA.
  • Whether Facebook obtained valid and meaningful consent from installing users for the disclosure of their personal information to third-party apps, including the TYDL App.
  • Whether Facebook made reasonable efforts to ensure third-party apps obtained meaningful consent from installing users.
  • Whether Facebook's reliance on overbroad and conflicting language in its privacy communications was sufficient for meaningful consent from installing users.
  • Whether Facebook obtained meaningful consent from friends of installing users (Affected Users) for the disclosure of their personal information to third-party apps.
  • Whether Facebook had adequate safeguards to protect user information against unauthorized access, use, and disclosure by apps.
  • Whether Facebook's monitoring and enforcement of its Platform Policy were adequate.
  • Whether Facebook's implementation of Graph v2 and App Review adequately addressed safeguard concerns for ongoing compliance.
  • Whether Facebook was accountable for the user information under its control.
  • Whether Facebook's policies and practices gave effect to the privacy principles under PIPEDA and PIPA.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 9, 2019PIPEDA Findings #2019-001Indexed Jun 30, 2026

PIPEDA Findings #2019-001: Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information

Equifax Canada Co.

The Office of the Privacy Commissioner of Canada (OPC) investigated a 2017 data breach that compromised the personal information of approximately 19,000 Canadians held by Equifax Inc., the US parent company of Equifax Canada Co. The investigation examined the adequacy of security safeguards by both entities, Equifax Canada's accountability for data processed by Equifax Inc., the validity of consent obtained for data transfers, retention practices, and the sufficiency of post-breach mitigation measures. The OPC concluded that both Equifax Inc. and Equifax Canada contravened PIPEDA in all these areas, citing inadequate vulnerability management, network segregation, basic information security practices, and oversight. Equifax Canada signed a compliance agreement, committing to corrective measures for most findings, which were deemed well-founded and conditionally resolved. However, the finding regarding post-breach safeguards was only partially resolved, as Equifax Canada committed to extended credit monitoring but not a free credit freeze product.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-001: Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information

Apr 9, 2019PIPEDA Findings #2019-001
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a 2017 data breach that compromised the personal information of approximately 19,000 Canadians held by Equifax Inc., the US parent company of Equifax Canada Co. The investigation examined the adequacy of security safeguards by both entities, Equifax Canada's accountability for data processed by Equifax Inc., the validity of consent obtained for data transfers, retention practices, and the sufficiency of post-breach mitigation measures. The OPC concluded that both Equifax Inc. and Equifax Canada contravened PIPEDA in all these areas, citing inadequate vulnerability management, network segregation, basic information security practices, and oversight. Equifax Canada signed a compliance agreement, committing to corrective measures for most findings, which were deemed well-founded and conditionally resolved. However, the finding regarding post-breach safeguards was only partially resolved, as Equifax Canada committed to extended credit monitoring but not a free credit freeze product.

Key Issues
  • Whether Equifax Inc.'s security safeguards were appropriate to the sensitivity of the information as required by PIPEDA Safeguards Principle 4.7.
  • Whether Equifax Inc.'s retention and destruction practices for Canadian personal information complied with PIPEDA Principle 4.5.
  • Whether Equifax Canada demonstrated adequate accountability for protecting Canadian personal information handled by Equifax Inc. as required under PIPEDA Principle 4.1.
  • Whether there was adequate consent from Canadians for the collection of their personal information by Equifax Inc. and disclosure to Equifax Inc. by Equifax Canada, as required under PIPEDA Principle 4.3 and s.6.1.
  • Whether Equifax Canada's security safeguards for personal information it held directly were appropriate as required by PIPEDA Safeguards Principle 4.7.
  • Whether the post-breach mitigation measures offered by Equifax Canada were adequate to protect against unauthorized use of compromised personal information as required by PIPEDA Safeguards Principle 4.7.1.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2019PIPEDA Case Summary #2019-006Indexed Jun 30, 2026

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Grey House Publishing Canada

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Mar 28, 2019PIPEDA Case Summary #2019-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Key Issues
  • Whether the complainant's contact information constituted 'personal information' under PIPEDA
  • Whether Grey House Publishing Canada was engaged in 'commercial activity' under PIPEDA
  • Whether Grey House obtained adequate consent for the collection, use, and disclosure of the complainant's personal information
  • Whether the 'publicly available information' exceptions to consent applied
  • Whether Grey House's privacy statement met the 'openness' principle under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 25, 2019PIPEDA Findings #2019-005Indexed Jun 30, 2026

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

411Numbers

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

Mar 25, 2019PIPEDA Findings #2019-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Key Issues
  • Whether the OPC had jurisdiction over 411Numbers, a Hong Kong-incorporated company with servers outside Canada, due to a 'real and substantial connection' to Canada.
  • Whether 411Numbers collected, used, and disclosed the complainant's personal information (unlisted phone number, name, address) without knowledge and consent, contravening Principle 4.3.
  • Whether information associated with unlisted telephone numbers constitutes 'publicly available' information under paragraph 1(a) of the Regulations Specifying Publicly Available Information.
  • Whether 411Numbers exercised due diligence to ensure its databases did not include unlisted numbers.
  • Whether publishing personal information for the purpose of encouraging individuals to pay to have it removed constitutes an inappropriate purpose under s. 5(3) of PIPEDA.
  • Whether 411Numbers required individuals to provide more information than necessary for removal services, contravening Principle 4.3.3.
  • Whether 411Numbers met its obligations regarding accountability under Principles 4.1, 4.1.2, and 4.1.4.
  • Whether 411Numbers met its obligations regarding openness under Principle 4.8 and 4.8.3.
  • Whether 411Numbers met its obligations regarding challenging compliance under Principle 4.10.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 20, 2018PIPEDA Report of Findings #2018-004Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-004: Microsoft to obtain opt-in consent, enhance transparency for Windows 10 privacy settings

Microsoft

An anonymous complainant raised concerns that Microsoft Windows 10 defaulted several privacy settings to "on" during installation, and these settings were difficult to understand and change. The OPC investigated whether Microsoft obtained valid consent for collecting, using, and disclosing personal information via these default settings. Initial concerns about clarity and consistency were shared with Microsoft regarding the original Windows 10 version. Following the Creators Update, the OPC identified further issues, particularly regarding the meaningfulness of consent for Location, Diagnostics, Tailored Experiences, Relevant Ads, and Speech Recognition settings, noting confusion caused by conflating related practices. Microsoft cooperated and committed to implementing changes, including obtaining opt-in consent for all installation privacy settings, enhancing transparency, and correcting the functioning of Speech Recognition. The OPC found the complaint well-founded and conditionally resolved, pending Microsoft's implementation of these commitments by the end of 2018.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-004: Microsoft to obtain opt-in consent, enhance transparency for Windows 10 privacy settings

Jun 20, 2018PIPEDA Report of Findings #2018-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant raised concerns that Microsoft Windows 10 defaulted several privacy settings to "on" during installation, and these settings were difficult to understand and change. The OPC investigated whether Microsoft obtained valid consent for collecting, using, and disclosing personal information via these default settings. Initial concerns about clarity and consistency were shared with Microsoft regarding the original Windows 10 version. Following the Creators Update, the OPC identified further issues, particularly regarding the meaningfulness of consent for Location, Diagnostics, Tailored Experiences, Relevant Ads, and Speech Recognition settings, noting confusion caused by conflating related practices. Microsoft cooperated and committed to implementing changes, including obtaining opt-in consent for all installation privacy settings, enhancing transparency, and correcting the functioning of Speech Recognition. The OPC found the complaint well-founded and conditionally resolved, pending Microsoft's implementation of these commitments by the end of 2018.

Key Issues
  • Whether Microsoft obtained valid and meaningful consent for the collection, use, and disclosure of personal information through Windows 10 default privacy settings.
  • Whether the initial Windows 10 (Version 1507) installation process provided sufficient prominence for customizing settings and adequate information via "Learn more" links.
  • Whether the explanations for Advertising ID and Diagnostics settings in Version 1507 were clear, consistent, and comprehensive.
  • Whether opt-out consent was appropriate for the Location setting in the Creators Update, and if Microsoft's explanations were sufficiently transparent regarding exceptions and the use of "de-identified location information."
  • Whether "Full" Diagnostics should be the default setting, and if Microsoft's transparency regarding data collected at this level was adequate for meaningful consent.
  • Whether Microsoft obtained valid consent for Tailored Experiences, particularly concerning the use of broad diagnostic data and the protection of sensitive information.
  • Whether Microsoft's practices for Tailored Experiences complied with accountability requirements under Principle 4.1.4.
  • Whether opt-out consent was appropriate for the Relevant Ads (Advertising ID) setting, and if Microsoft's communications clearly distinguished it from its own advertising program.
  • Whether opt-out consent was appropriate for the Speech Recognition setting, given the sensitivity of voice data and its cloud-based nature.
  • Whether Microsoft's explanations for Speech Recognition clearly distinguished between cloud-based and device-based functionality.
  • Whether Microsoft consistently respected user choices regarding the Speech Recognition setting, especially when conflicting with Cortana settings.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 12, 2018PIPEDA Report of Findings #2018-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-002: Company’s re-use of millions of Canadian Facebook user profiles violated privacy law

Profile Technology Ltd.

Multiple complainants alleged that Profile Technology Ltd. copied their personal information from Facebook profiles and groups without consent and posted it on its social networking website, making removal difficult, and indefinitely retaining helpdesk information. The OPC asserted jurisdiction over the New Zealand-based company due to a real and substantial connection to Canada. The OPC found that the information was not "publicly available" under PIPEDA's Regulations, and Profile Technology failed to obtain valid consent for its new purpose of operating a social networking site. Furthermore, the OPC determined that using this information for such a purpose was not appropriate in the circumstances and that the indefinite retention of helpdesk ticket information violated retention principles. Profile Technology refused to implement recommendations for deletion and a retention policy. Although the company later removed profiles from its website, it uploaded much of the data to the Internet Archive, which the OPC found did not resolve the contraventions and created new privacy risks. The matter was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2018-002: Company’s re-use of millions of Canadian Facebook user profiles violated privacy law

Jun 12, 2018PIPEDA Report of Findings #2018-002
Adjudicator: Daniel Therrien
Plain-Language Summary

Multiple complainants alleged that Profile Technology Ltd. copied their personal information from Facebook profiles and groups without consent and posted it on its social networking website, making removal difficult, and indefinitely retaining helpdesk information. The OPC asserted jurisdiction over the New Zealand-based company due to a real and substantial connection to Canada. The OPC found that the information was not "publicly available" under PIPEDA's Regulations, and Profile Technology failed to obtain valid consent for its new purpose of operating a social networking site. Furthermore, the OPC determined that using this information for such a purpose was not appropriate in the circumstances and that the indefinite retention of helpdesk ticket information violated retention principles. Profile Technology refused to implement recommendations for deletion and a retention policy. Although the company later removed profiles from its website, it uploaded much of the data to the Internet Archive, which the OPC found did not resolve the contraventions and created new privacy risks. The matter was found to be well-founded.

Key Issues
  • Whether the OPC had jurisdiction to investigate a New Zealand-based company's activities affecting Canadians.
  • Whether the investigation was time-barred under subsection 13(1) of PIPEDA.
  • Whether PIPEDA's application to commercial activity is constitutionally valid under the federal Trade and Commerce power.
  • Whether personal information copied from Facebook profiles was "publicly available" under PIPEDA's Regulations Specifying Publicly Available Information.
  • Whether Facebook profiles constitute a "publication" for the purposes of the Regulations.
  • Whether Profile Technology obtained valid knowledge and consent (Principle 4.3 PIPEDA) for the collection, use, and disclosure of personal information for its social networking website.
  • Whether consent obtained by Facebook was sufficient for Profile Technology's subsequent use of the data.
  • Whether opt-out consent would be an appropriate form of consent in this context (Principle 4.3.4 PIPEDA).
  • Whether Profile Technology's use of Facebook profile information for its social networking site was for purposes a reasonable person would consider "appropriate in the circumstances" (subsection 5(3) PIPEDA).
  • Whether Profile Technology retained personal information (helpdesk tickets) longer than necessary (Principle 4.5 PIPEDA).
  • Whether Profile Technology was responsible for personal information held by its third-party helpdesk service provider.
  • Whether Profile Technology's actions of removing profiles from its website and uploading data to the Internet Archive resolved the identified contraventions.