The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

172 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2016PIPEDA Case Summary #2016-012Indexed Jun 30, 2026

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

A bank associated with a retailer

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

Mar 31, 2016PIPEDA Case Summary #2016-012
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Key Issues
  • Whether the bank obtained valid consent for a credit card application and credit check under Principle 4.3
  • Whether the bank ensured the accuracy of personal information collected under Principle 4.6
  • Whether the bank had adequate procedures to give effect to PIPEDA principles under Principle 4.1.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 10, 2016PIPEDA Case Summary #2016-009Indexed Jun 30, 2026

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

An international trucking company

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

Mar 10, 2016PIPEDA Case Summary #2016-009
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Key Issues
  • Whether the disclosure of drug test results to the WCB without consent contravened PIPEDA Principles 4.3 and 4.5
  • Whether the employer had a legal obligation to disclose the drug test results to the WCB under the provincial Workers' Compensation Act, thereby qualifying for an exception to consent under paragraph 7(3)(i) of PIPEDA
  • Whether the employer disclosed the drug test results to co-workers without consent
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 24, 2016Incident Summary #12Indexed Jun 30, 2026

Incident Summary #12: Break with security procedures exposes financial planner’s client to privacy breach

A financial management firm

A financial management firm's employees breached internal security procedures by sending a client's detailed financial plan and federal income tax notice of assessment, containing sensitive personal information including her social insurance number, to her personal email account without secure messaging tools. The client's email account was subsequently hacked, and the alleged hacker used the obtained information to pose as the client and request a significant transfer from her investment account. An employee processed this transfer without following authentication procedures. Although the client's money was not stolen, the firm investigated the incident, advised the client to change passwords, informed the RCMP, and offered credit monitoring. The firm also took measures with the responsible employees, provided additional privacy training to staff, and reviewed its internal processes. The OPC considered the firm's response appropriate.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #12: Break with security procedures exposes financial planner’s client to privacy breach

Feb 24, 2016Incident Summary #12
Adjudicator: Daniel Therrien
Plain-Language Summary

A financial management firm's employees breached internal security procedures by sending a client's detailed financial plan and federal income tax notice of assessment, containing sensitive personal information including her social insurance number, to her personal email account without secure messaging tools. The client's email account was subsequently hacked, and the alleged hacker used the obtained information to pose as the client and request a significant transfer from her investment account. An employee processed this transfer without following authentication procedures. Although the client's money was not stolen, the firm investigated the incident, advised the client to change passwords, informed the RCMP, and offered credit monitoring. The firm also took measures with the responsible employees, provided additional privacy training to staff, and reviewed its internal processes. The OPC considered the firm's response appropriate.

Key Issues
  • Whether the firm adequately protected personal information by sending sensitive documents via unsecure email
  • Whether the firm had adequate procedures for authenticating clients for financial transactions
  • Whether the firm's response to the privacy breach was appropriate
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 19, 2016PIPEDA Report of Findings #2016-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

A property management company

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

Feb 19, 2016PIPEDA Report of Findings #2016-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Key Issues
  • Whether the collection, use, and disclosure of personal information for a "bad tenant list" was for purposes that a reasonable person would consider appropriate in the circumstances (s.5(3) PIPEDA)
  • Whether the property management company was acting as an unlicensed credit reporting agency under provincial legislation
  • Whether meaningful knowledge and consent of individuals were obtained for the collection, use, and disclosure of their personal information for the "bad tenant list" (Principle 4.3, 4.3.2 PIPEDA)
  • Whether the personal information on the "bad tenant list" was accurate, complete, and up-to-date (Principle 4.6, 4.6.1 PIPEDA)
  • Whether individuals had the ability to challenge the accuracy of information about them on the list (Principle 4.10 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 19, 2016Incident Summary #11Indexed Jun 30, 2026

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

A financial institution

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

Feb 19, 2016Incident Summary #11
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Key Issues
  • Whether the financial institution adequately safeguarded personal information during mass mail-outs
  • Whether the financial institution responded appropriately to a privacy breach involving misdirected mail
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 18, 2016Incident Summary #13Indexed Jun 30, 2026

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

A Canadian financial institution

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

Feb 18, 2016Incident Summary #13
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Key Issues
  • Whether the financial institution adequately protected customer personal information from unauthorized disclosure by a fraudster
  • Whether the financial institution took appropriate steps to mitigate the impact of the breach and prevent recurrence
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 12, 2016PIPEDA Report of Findings #2016-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

An insurance company

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

Feb 12, 2016PIPEDA Report of Findings #2016-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Key Issues
  • Whether the insurance company contravened Principles 4.9 and 4.9.1 by refusing access to personal information without severing third-party information
  • Whether the insurance company's internal ombudsman office constitutes a "formal dispute resolution process" under PIPEDA s.9(3)(d)
  • Whether the activities of the internal ombudsman office fall under the definition of "commercial activity" under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 9, 2016PIPEDA Case Summary #2016-007Indexed Jun 30, 2026

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

A collection agency

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

Feb 9, 2016PIPEDA Case Summary #2016-007
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the organization refused to provide access to personal information
  • Whether the organization responded to access requests within the required timeframe
  • Whether the organization followed its own privacy policies and procedures for access requests
  • Whether the organization maintained records of access request processing
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Jan 25, 2016Incident Summary #10Indexed Jun 30, 2026

Incident Summary #10: Cable provider removes personal information posted online of customers with overdue accounts

A cable provider

The OPC was alerted to a cable provider posting a list of customers with overdue accounts and the amounts owed on a municipal Facebook page. The cable provider believed this practice was permissible, citing municipal tax arrears publications as an example. The OPC informed the provider that publicly disseminating personal information for debt collection without consent is not permitted under PIPEDA, even though disclosure to a third-party debt collector may be. The cable provider subsequently removed the posting. The OPC also clarified with the NWT Commissioner that municipal tax arrears publications are mandated by territorial law, unlike the cable provider's actions. The OPC explained that PIPEDA's debt collection exemption does not authorize public disclosure.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #10: Cable provider removes personal information posted online of customers with overdue accounts

Jan 25, 2016Incident Summary #10
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC was alerted to a cable provider posting a list of customers with overdue accounts and the amounts owed on a municipal Facebook page. The cable provider believed this practice was permissible, citing municipal tax arrears publications as an example. The OPC informed the provider that publicly disseminating personal information for debt collection without consent is not permitted under PIPEDA, even though disclosure to a third-party debt collector may be. The cable provider subsequently removed the posting. The OPC also clarified with the NWT Commissioner that municipal tax arrears publications are mandated by territorial law, unlike the cable provider's actions. The OPC explained that PIPEDA's debt collection exemption does not authorize public disclosure.

Key Issues
  • Whether publicly posting customer debt information on social media is permissible under PIPEDA
  • Whether the debt collection exemption under paragraph 7(3)(b) of PIPEDA authorizes public dissemination of personal information
  • Whether municipal practices of publishing tax arrears are comparable to private organizations publishing customer debt under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 9, 2016PIPEDA Case Summary #2016-004Indexed Jun 30, 2026

PIPEDA Case Summary #2016-004: Retailer shares customer’s in-store behaviour with the customer’s employer

A retail store

A customer complained that a retail store employee disclosed his personal information to his employer, including his name, in-store behavior, and statements made to staff. The store argued the information was not personal because it was made publicly, and that it had implied consent for the disclosure. The OPC found that information overheard by others is still personal information under PIPEDA. The OPC also determined that implied consent was not appropriate given the sensitive nature of the information, which had the potential to negatively affect the customer's employment. The store's disclosure without knowledge or consent contravened Principle 4.3 of PIPEDA. The complaint was found to be well-founded and resolved after the store implemented the OPC's recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-004: Retailer shares customer’s in-store behaviour with the customer’s employer

Jan 9, 2016PIPEDA Case Summary #2016-004
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a retail store employee disclosed his personal information to his employer, including his name, in-store behavior, and statements made to staff. The store argued the information was not personal because it was made publicly, and that it had implied consent for the disclosure. The OPC found that information overheard by others is still personal information under PIPEDA. The OPC also determined that implied consent was not appropriate given the sensitive nature of the information, which had the potential to negatively affect the customer's employment. The store's disclosure without knowledge or consent contravened Principle 4.3 of PIPEDA. The complaint was found to be well-founded and resolved after the store implemented the OPC's recommendations.

Key Issues
  • Whether the information shared was personal information under PIPEDA
  • Whether the customer provided implied consent for the disclosure of his personal information
  • Whether the disclosed information was sensitive
  • Whether the customer had a reasonable expectation that his information would be shared with his employer
  • Whether the publicly available information exception to consent applied
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Dec 18, 2015PIPEDA findings #2015-021Indexed Jun 30, 2026

PIPEDA findings #2015-021: Telecom company responsible for erroneous debt collection calls

A telecommunications company

An individual complained that a telecommunications company continued to report a debt to a credit-reporting agency and that a collection agency was still contacting her, despite the debt being discharged in bankruptcy years prior. This inaccurate reporting was hindering her ability to rebuild her credit score. The telecommunications company investigated and found that an internal manual process error had caused the information to be overlooked. The company subsequently corrected its records, notified the credit-reporting agency of the updated information, and ensured that all collection activities against the complainant would cease. The complainant expressed satisfaction with the resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

PIPEDA findings #2015-021: Telecom company responsible for erroneous debt collection calls

Dec 18, 2015PIPEDA findings #2015-021
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a telecommunications company continued to report a debt to a credit-reporting agency and that a collection agency was still contacting her, despite the debt being discharged in bankruptcy years prior. This inaccurate reporting was hindering her ability to rebuild her credit score. The telecommunications company investigated and found that an internal manual process error had caused the information to be overlooked. The company subsequently corrected its records, notified the credit-reporting agency of the updated information, and ensured that all collection activities against the complainant would cease. The complainant expressed satisfaction with the resolution.

Key Issues
  • Whether the telecommunications company maintained sufficiently accurate personal information (Principle 4.6 PIPEDA)
  • Whether the telecommunications company appropriately disclosed accurate personal information to a third party (Principle 4.6 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 15, 2015PIPEDA Case Summary #2015-014Indexed Jun 30, 2026

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

A pension and benefit provider

An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

Dec 15, 2015PIPEDA Case Summary #2015-014
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.

Key Issues
  • Whether the provider disclosed the complainant's unique identifier to a third party without consent (Principle 4.3 PIPEDA)
  • Whether the provider failed to keep the complainant's address information accurate (Principle 4.6 PIPEDA)
  • Whether the provider failed to implement appropriate safeguards to protect personal information from unauthorized disclosure and modification (Principle 4.7 PIPEDA)
  • Whether proper authentication of the caller took place before the complainant's ID number was given out (Principle 4.7.1 PIPEDA)
  • Whether the provider's failure to detect and correct the erroneous address sooner constituted a contravention of Principle 4.6.1 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Dec 2, 2015Discontinued Case Summary #2015-001Indexed Jun 30, 2026

Discontinued Case Summary #2015-001: Real estate management company responds fairly and reasonably to surveillance camera concerns

A real estate management company

An individual complained that a real estate management company collected his personal information without consent through surveillance cameras. He alleged inadequate signage and over-collection when a camera was focused on him after a dispute about his service dog. The company responded by posting new, clearer signage about video surveillance at all entrances, including the one previously lacking. They also addressed the over-collection concern by explaining that a new security guard had mistakenly focused the camera, and provided additional training to staff regarding service animals. The OPC found the company's response to be fair and reasonable, addressing the complainant's concerns proactively. Consequently, the investigation was discontinued.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Discontinued Case Summary #2015-001: Real estate management company responds fairly and reasonably to surveillance camera concerns

Dec 2, 2015Discontinued Case Summary #2015-001
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a real estate management company collected his personal information without consent through surveillance cameras. He alleged inadequate signage and over-collection when a camera was focused on him after a dispute about his service dog. The company responded by posting new, clearer signage about video surveillance at all entrances, including the one previously lacking. They also addressed the over-collection concern by explaining that a new security guard had mistakenly focused the camera, and provided additional training to staff regarding service animals. The OPC found the company's response to be fair and reasonable, addressing the complainant's concerns proactively. Consequently, the investigation was discontinued.

Key Issues
  • Whether the organization collected personal information without adequate signage for video surveillance
  • Whether the organization over-collected personal information by focusing a camera on the complainant
  • Whether the organization's response to the concerns was fair and reasonable under paragraph 12.2(1)(c) of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 10, 2015PIPEDA Case Summary #2015-015Indexed Jun 30, 2026

PIPEDA Case Summary #2015-015: Roofing company takes measures to ensure sub-contractors follow its privacy policy

A roofing company (the "second roofer")

An individual complained that an estimator working for a roofing company (the "second roofer") disclosed his personal financial situation and contractual history to a competitor (the "first roofer") without his consent. The individual had engaged the second roofer for an estimate to fix issues with work done by the first roofer, and later cancelled a contract with the second roofer. The OPC found that the estimator was acting as an agent for the second roofer, making the second roofer responsible for the estimator's actions. The OPC concluded that the disclosure of personal information without the individual's knowledge or consent contravened Principle 4.3 of PIPEDA. The second roofer subsequently implemented recommendations to establish agreements with sub-contractors to adhere to its privacy policy and provide training. As a result, the complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2015-015: Roofing company takes measures to ensure sub-contractors follow its privacy policy

Nov 10, 2015PIPEDA Case Summary #2015-015
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an estimator working for a roofing company (the "second roofer") disclosed his personal financial situation and contractual history to a competitor (the "first roofer") without his consent. The individual had engaged the second roofer for an estimate to fix issues with work done by the first roofer, and later cancelled a contract with the second roofer. The OPC found that the estimator was acting as an agent for the second roofer, making the second roofer responsible for the estimator's actions. The OPC concluded that the disclosure of personal information without the individual's knowledge or consent contravened Principle 4.3 of PIPEDA. The second roofer subsequently implemented recommendations to establish agreements with sub-contractors to adhere to its privacy policy and provide training. As a result, the complaint was deemed well-founded and resolved.

Key Issues
  • Whether the estimator was acting as an agent of the second roofer
  • Whether the second roofer was responsible for the personal information handling practices of its estimator
  • Whether personal information was disclosed without the individual's knowledge or consent
  • Whether the disclosure contravened Principle 4.3 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Oct 26, 2015Early resolved case summary #2015-02Indexed Jun 30, 2026

Early resolved case summary #2015-02: Retailer takes remedial actions after employee inappropriately texted customer

A retailer

An individual complained to the OPC after a retailer's delivery person inappropriately texted her using her phone number, which he had transferred from his faulty work phone to his personal device. The complainant also felt the retailer's management initially showed a lack of concern. The OPC's inquiries revealed the delivery person obtained the customer's number from his work phone. The retailer, disapproving of employees transferring customer information to personal devices, subsequently implemented a new policy requiring delivery employees with faulty work phones to return to the warehouse immediately. The retailer also took disciplinary action against the delivery person, provided mandatory privacy retraining to employees, and the company president met personally with the affected customer. The customer was satisfied with the actions taken by the retailer.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-02: Retailer takes remedial actions after employee inappropriately texted customer

Oct 26, 2015Early resolved case summary #2015-02
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after a retailer's delivery person inappropriately texted her using her phone number, which he had transferred from his faulty work phone to his personal device. The complainant also felt the retailer's management initially showed a lack of concern. The OPC's inquiries revealed the delivery person obtained the customer's number from his work phone. The retailer, disapproving of employees transferring customer information to personal devices, subsequently implemented a new policy requiring delivery employees with faulty work phones to return to the warehouse immediately. The retailer also took disciplinary action against the delivery person, provided mandatory privacy retraining to employees, and the company president met personally with the affected customer. The customer was satisfied with the actions taken by the retailer.

Key Issues
  • Whether the delivery person's use of customer information for personal communication was appropriate
  • Whether the retailer adequately protected customer personal information when work devices were faulty
  • Whether the retailer responded appropriately to the customer's complaint