The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

153 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Mar 25, 2026Indexed Jun 30, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Nova Scotia Power

This document is a compliance letter from Nova Scotia Power to the OPC, outlining actions taken and commitments made following a significant data breach that occurred in March 2025. The breach, caused by malware, led to the exfiltration of personal information belonging to approximately 375,000 current and 540,000 former customers. The compromised data included names, contact information, financial details, driver's license numbers, and SINs. The OPC received numerous complaints regarding the breach, including concerns about the collection and retention of SINs and the timeliness and method of notification to affected individuals. Nova Scotia Power has committed to deleting customer SINs (subject to legal requirements) and undergoing an external security assessment by October 2026. Upon satisfactory fulfillment of these commitments, the OPC's investigation will be discontinued.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

This document is a compliance letter from Nova Scotia Power to the OPC, outlining actions taken and commitments made following a significant data breach that occurred in March 2025. The breach, caused by malware, led to the exfiltration of personal information belonging to approximately 375,000 current and 540,000 former customers. The compromised data included names, contact information, financial details, driver's license numbers, and SINs. The OPC received numerous complaints regarding the breach, including concerns about the collection and retention of SINs and the timeliness and method of notification to affected individuals. Nova Scotia Power has committed to deleting customer SINs (subject to legal requirements) and undergoing an external security assessment by October 2026. Upon satisfactory fulfillment of these commitments, the OPC's investigation will be discontinued.

Key Issues
  • Whether Nova Scotia Power's security safeguards were adequate to protect personal information
  • Whether Nova Scotia Power's collection and retention of Social Insurance Numbers (SINs) was appropriate
  • Whether Nova Scotia Power's notification of affected individuals was timely and appropriate
  • Whether Nova Scotia Power has taken sufficient corrective measures to address the breach and prevent future incidents
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 5, 2026PIPEDA Findings #2026-001Indexed Jun 30, 2026

PIPEDA Findings #2026-001: Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program

Loblaw Companies Ltd.

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Loblaw Companies Ltd. (Loblaw) regarding its PC Optimum Loyalty Program, focusing on the handling of privacy challenges and the retention of personal information. The investigation found that Loblaw contravened PIPEDA Principle 4.10 by failing to adequately address privacy challenges and respond to account deletion requests in a timely manner, though this issue was resolved during the investigation as Loblaw enhanced its procedures. The OPC also found that Loblaw contravened PIPEDA Principle 4.5.3 by not sufficiently anonymizing personal information retained from closed PC Optimum accounts, meaning there was a serious possibility of re-identification. Loblaw disagreed with this finding but agreed to engage an independent third party to assess its anonymization process and implement recommendations. A preliminary matter regarding requiring physical card holders to create an online account for deletion was found not well-founded. The overall outcome reflects a mix of resolved and conditionally resolved well-founded findings.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2026-001: Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program

Mar 5, 2026PIPEDA Findings #2026-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Loblaw Companies Ltd. (Loblaw) regarding its PC Optimum Loyalty Program, focusing on the handling of privacy challenges and the retention of personal information. The investigation found that Loblaw contravened PIPEDA Principle 4.10 by failing to adequately address privacy challenges and respond to account deletion requests in a timely manner, though this issue was resolved during the investigation as Loblaw enhanced its procedures. The OPC also found that Loblaw contravened PIPEDA Principle 4.5.3 by not sufficiently anonymizing personal information retained from closed PC Optimum accounts, meaning there was a serious possibility of re-identification. Loblaw disagreed with this finding but agreed to engage an independent third party to assess its anonymization process and implement recommendations. A preliminary matter regarding requiring physical card holders to create an online account for deletion was found not well-founded. The overall outcome reflects a mix of resolved and conditionally resolved well-founded findings.

Key Issues
  • Whether Loblaw adequately addresses privacy challenges raised by individuals concerning account deletion (PIPEDA Principle 4.10)
  • Whether Loblaw retains personal information of PC Optimum members for longer than necessary after account closure (PIPEDA Principle 4.5.3)
  • Whether Loblaw collected unnecessary personal information by requiring physical card holders to create an online account to delete their PC Optimum account (PIPEDA Principle 4.4)
  • Whether Loblaw established retention schedules for customer support logs (PIPEDA Principle 4.5.2)
  • Whether Loblaw retains universal login credentials (PCids) for longer than necessary for members with no other associated accounts (PIPEDA Principle 4.5.3)
  • Whether Loblaw's anonymization process for retained Historical Transaction Data, Loyalty Data, and Usage Data ensures no serious possibility of re-identification
  • Whether Loblaw's retention of public IP address data after account closure is sufficiently anonymized
  • Whether Loblaw's practice of retaining email domain portions after account closure is sufficiently anonymized
  • Whether manual processing errors in Loblaw's de-identification process were adequately detected and addressed
  • Whether Loblaw ensured identifiers were removed from back-up systems as part of its anonymization process
  • Whether Loblaw considered the impact of other factors affecting re-identification risk, such as separately retained PCid data
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 9, 2026PIPEDA Findings #2026-003Indexed Jun 30, 2026

PIPEDA Findings #2026-003: Investigation into Bell’s compliance with PIPEDA when responding to an access request for personal information

Bell Canada

The complainant alleged that Bell Canada contravened PIPEDA by failing to respond to an access request within 30 days and by denying access to his cellphone logs. The OPC found that Bell contravened subsection 8(3) of PIPEDA for the delayed response and Principle 4.9 for denying access, as the phone logs constituted the complainant's personal information. The OPC determined that the complainant's privacy interest in his phone logs outweighed the ex-spouse's interest, and there was a public interest in disclosure. Bell agreed to provide the requested logs to the complainant, resolving that aspect of the complaint. Bell also committed to implementing recommendations to improve its access request procedures and enhance openness regarding data access on shared accounts, leading to a conditionally resolved outcome for these issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2026-003: Investigation into Bell’s compliance with PIPEDA when responding to an access request for personal information

Jan 9, 2026PIPEDA Findings #2026-003
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Bell Canada contravened PIPEDA by failing to respond to an access request within 30 days and by denying access to his cellphone logs. The OPC found that Bell contravened subsection 8(3) of PIPEDA for the delayed response and Principle 4.9 for denying access, as the phone logs constituted the complainant's personal information. The OPC determined that the complainant's privacy interest in his phone logs outweighed the ex-spouse's interest, and there was a public interest in disclosure. Bell agreed to provide the requested logs to the complainant, resolving that aspect of the complaint. Bell also committed to implementing recommendations to improve its access request procedures and enhance openness regarding data access on shared accounts, leading to a conditionally resolved outcome for these issues.

Key Issues
  • Whether Bell responded to the Complainant’s access request within thirty days as per subsection 8(3) of PIPEDA
  • Whether Bell adequately responded to the Complainant’s request to access his personal information under Principle 4.9 of PIPEDA
  • Whether phone logs relating to a specific phoneline constitute the personal information of the phoneline's user, even if they are not the account holder
  • Whether the Complainant's interest in accessing the phone logs is greater than the ex-spouse's interest in non-disclosure of the phone logs
  • Whether Bell was sufficiently open with individuals about account holders' access to phone usage details on shared accounts, contrary to PIPEDA's Openness principle (Principle 4.8.1)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 1, 2025PIPEDA Findings #2025-004Indexed Jun 30, 2026

PIPEDA Findings #2025-004: Investigation into the privacy practices of Staples Canada ULC related to electronic devices to be resold as part of its Openbox program

Staples Canada ULC

A former employee complained that Staples Canada ULC (Staples) failed to adequately protect and remove personal information from returned laptops before reselling them through its Openbox program. The complainant alleged that Staples lacked adequate internal policies, processes, and training for staff to wipe data from these devices. The OPC's investigation found deficiencies in Staples' policies, procedures, and training, and that employees did not consistently follow manufacturer guidelines for data wiping, leading to residual personal information on 23% of sampled devices. Staples agreed to implement recommendations to improve its data wiping procedures, training, and to arrange for independent third-party spot checks. The OPC concluded that Staples contravened PIPEDA Principles 4.7.1 and 4.7.3.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2025-004: Investigation into the privacy practices of Staples Canada ULC related to electronic devices to be resold as part of its Openbox program

Dec 1, 2025PIPEDA Findings #2025-004
Adjudicator: Philippe Dufresne
Plain-Language Summary

A former employee complained that Staples Canada ULC (Staples) failed to adequately protect and remove personal information from returned laptops before reselling them through its Openbox program. The complainant alleged that Staples lacked adequate internal policies, processes, and training for staff to wipe data from these devices. The OPC's investigation found deficiencies in Staples' policies, procedures, and training, and that employees did not consistently follow manufacturer guidelines for data wiping, leading to residual personal information on 23% of sampled devices. Staples agreed to implement recommendations to improve its data wiping procedures, training, and to arrange for independent third-party spot checks. The OPC concluded that Staples contravened PIPEDA Principles 4.7.1 and 4.7.3.

Key Issues
  • Whether Staples had adequate security safeguards to protect personal information on returned laptops under Principle 4.7.1 PIPEDA
  • Whether Staples' methods of protection included adequate physical, organizational, and technological measures under Principle 4.7.3 PIPEDA
  • Whether Staples' internal policies and procedures for data wiping were clear and consistent
  • Whether Staples provided adequate training to employees responsible for wiping data from returned devices
  • Whether Staples consistently performed full data wipes according to manufacturer instructions on returned laptops
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 25, 2025PIPEDA Findings #2025-005Indexed Jun 30, 2026

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

A privately owned swimming pool

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

Nov 25, 2025PIPEDA Findings #2025-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Key Issues
  • Whether requiring consent for promotional photos and videos of children as a condition of service for swimming lessons contravenes Principle 4.3.3 of PIPEDA
  • Whether images of children in swim attire constitute sensitive personal information
  • Whether the collection, use, or disclosure of images for promotional or staff training purposes is strictly necessary for the provision of swimming lessons
  • Whether the organization offered individuals a choice regarding the collection, use, or disclosure of images for promotional or staff training purposes
  • Whether the organization should have sought express consent for the collection, use, or disclosure of images of children
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 27, 2025PIPEDA Findings #2025-002Indexed Jun 30, 2026

PIPEDA Findings #2025-002: Investigation and recommendations concerning Google search engine service’s compliance with its obligations under PIPEDA

Google LLC

The OPC investigated a complaint against Google regarding its search engine displaying outdated media articles about the Complainant's HIV status and a stayed criminal charge when their name was searched. The Complainant alleged these articles caused significant harm, including physical assault and lost employment, and sought their de-listing from name-based search results. The OPC's jurisdiction over Google's search engine under PIPEDA was affirmed by the Federal Court and Federal Court of Appeal, rejecting Google's claims of non-commercial activity and journalistic exemption. The OPC found Google did not contravene Principle 4.6 (accuracy), as its responsibility was for the search results accurately reflecting linked content, not the content itself. However, the OPC concluded that Google contravened subsection 5(3) (appropriate purposes), determining that the significant harms to the Complainant's safety and dignity outweighed the limited public interest in the articles remaining linked to their name. The OPC recommended Google de-list the articles from searches for the Complainant's name, balancing privacy rights with freedom of expression. Google declined to implement this recommendation, stating it required further court guidance on the "right to de-listing" and Charter implications. Consequently, the complaint was found well-founded and unresolved regarding subsection 5(3), and not well-founded for the accuracy issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2025-002: Investigation and recommendations concerning Google search engine service’s compliance with its obligations under PIPEDA

Aug 27, 2025PIPEDA Findings #2025-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint against Google regarding its search engine displaying outdated media articles about the Complainant's HIV status and a stayed criminal charge when their name was searched. The Complainant alleged these articles caused significant harm, including physical assault and lost employment, and sought their de-listing from name-based search results. The OPC's jurisdiction over Google's search engine under PIPEDA was affirmed by the Federal Court and Federal Court of Appeal, rejecting Google's claims of non-commercial activity and journalistic exemption. The OPC found Google did not contravene Principle 4.6 (accuracy), as its responsibility was for the search results accurately reflecting linked content, not the content itself. However, the OPC concluded that Google contravened subsection 5(3) (appropriate purposes), determining that the significant harms to the Complainant's safety and dignity outweighed the limited public interest in the articles remaining linked to their name. The OPC recommended Google de-list the articles from searches for the Complainant's name, balancing privacy rights with freedom of expression. Google declined to implement this recommendation, stating it required further court guidance on the "right to de-listing" and Charter implications. Consequently, the complaint was found well-founded and unresolved regarding subsection 5(3), and not well-founded for the accuracy issue.

Key Issues
  • Whether PIPEDA applies to Google's search engine service as a commercial activity within the meaning of paragraph 4(1)(a) of PIPEDA
  • Whether the operation of Google’s search engine service is excluded from the application of Part 1 of PIPEDA by virtue of paragraph 4(2)(c) of PIPEDA because it involves the collection, use or disclosure of personal information for journalistic, artistic or literary purposes and for no other purpose
  • Whether Google is contravening Accuracy requirements under Principle 4.6 of Schedule 1 of PIPEDA by continuing to display the search results in response to searches for the Complainant’s name
  • Whether Google is contravening subsection 5(3) of PIPEDA by continuing to display the search results in response to searches for the Complainant’s name, considering whether the purposes are appropriate in the circumstances
  • Whether the accessibility of information in response to a search for the Complainant's name causes significant harm to the Complainant
  • Whether the significant harm to the Complainant outweighs the public interest in the search results remaining available through Google's search engine by searching the Complainant's name
  • Whether Google collected, used, or disclosed personal information without consent under Principles 4.3.4 and 4.3.8 of Schedule 1 of PIPEDA (OPC declined to address)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 28, 2024PIPEDA Findings #2024-002Indexed Jun 30, 2026

PIPEDA Findings #2024-002: Investigation into Brinks Home

Brinks Home

A Brinks Home customer complained that he could view other customers' personal information through his online portal. The OPC investigated whether Brinks Home had adequate security safeguards and complied with breach notification requirements. Brinks Home acknowledged an employee error caused 3,340 customer records to be accessible to 102 other customers, with up to 20 potentially accessing the data. The OPC found that Brinks Home failed to adequately protect personal information, but this issue was resolved by the company's corrective actions and subsequent sale of its Canadian customer accounts. Regarding breach notification, the OPC determined that while the information was sensitive, the probability of misuse was low because the unauthorized access was by known customers, not malicious actors. Therefore, the incident did not pose a real risk of significant harm, and Brinks Home was not required to report it or notify affected individuals.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2024-002: Investigation into Brinks Home

Mar 28, 2024PIPEDA Findings #2024-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

A Brinks Home customer complained that he could view other customers' personal information through his online portal. The OPC investigated whether Brinks Home had adequate security safeguards and complied with breach notification requirements. Brinks Home acknowledged an employee error caused 3,340 customer records to be accessible to 102 other customers, with up to 20 potentially accessing the data. The OPC found that Brinks Home failed to adequately protect personal information, but this issue was resolved by the company's corrective actions and subsequent sale of its Canadian customer accounts. Regarding breach notification, the OPC determined that while the information was sensitive, the probability of misuse was low because the unauthorized access was by known customers, not malicious actors. Therefore, the incident did not pose a real risk of significant harm, and Brinks Home was not required to report it or notify affected individuals.

Key Issues
  • Whether Brinks Home implemented adequate security safeguards to protect customers' personal information under Principle 4.7 of Schedule 1 of PIPEDA
  • Whether Brinks Home complied with breach notification requirements under section 10.1 of PIPEDA
  • Whether the breach presented a real risk of significant harm (RROSH)
  • Whether the personal information involved was sensitive
  • Whether the probability of misuse of the personal information was low
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Feb 29, 2024PIPEDA Findings #2024-001Indexed Jun 30, 2026

PIPEDA Findings #2024-001: Investigation into Aylo (formerly MindGeek)’s Compliance with PIPEDA

Aylo (formerly MindGeek)

The OPC investigated Aylo (formerly MindGeek), a global technology company operating major pornographic websites like Pornhub, following a complaint from an individual whose intimate video was uploaded without her consent. The investigation focused on MindGeek's compliance with PIPEDA regarding consent for personal information collection, its content takedown process, and overall accountability. The OPC found that MindGeek failed to obtain valid and meaningful express consent directly from individuals depicted in highly sensitive content, relying instead on uploaders, which was deemed insufficient. MindGeek's content takedown process was also found to be not easily accessible, simple-to-use, or effective for individuals seeking removal of non-consensual content. These deficiencies demonstrated a broader lack of accountability for the vast amount of sensitive personal information under MindGeek's control. MindGeek disagreed with the findings and did not commit to implementing the OPC's recommendations, which included ceasing uploads without direct consent, deleting non-consensual content, and establishing a privacy management program. Consequently, the complaint was found to be well-founded and unresolved, with the OPC issuing several recommendations for compliance and independent oversight.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2024-001: Investigation into Aylo (formerly MindGeek)’s Compliance with PIPEDA

Feb 29, 2024PIPEDA Findings #2024-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated Aylo (formerly MindGeek), a global technology company operating major pornographic websites like Pornhub, following a complaint from an individual whose intimate video was uploaded without her consent. The investigation focused on MindGeek's compliance with PIPEDA regarding consent for personal information collection, its content takedown process, and overall accountability. The OPC found that MindGeek failed to obtain valid and meaningful express consent directly from individuals depicted in highly sensitive content, relying instead on uploaders, which was deemed insufficient. MindGeek's content takedown process was also found to be not easily accessible, simple-to-use, or effective for individuals seeking removal of non-consensual content. These deficiencies demonstrated a broader lack of accountability for the vast amount of sensitive personal information under MindGeek's control. MindGeek disagreed with the findings and did not commit to implementing the OPC's recommendations, which included ceasing uploads without direct consent, deleting non-consensual content, and establishing a privacy management program. Consequently, the complaint was found to be well-founded and unresolved, with the OPC issuing several recommendations for compliance and independent oversight.

Key Issues
  • Whether PIPEDA applied to MindGeek given its international operations but significant Canadian connection.
  • Whether MindGeek obtained valid and meaningful consent for the collection, use, and disclosure of highly sensitive personal information (intimate images and associated identifiers) of individuals depicted in content uploaded to its websites, as required by Principle 4.3 and s. 6.1 of PIPEDA.
  • Whether MindGeek's reliance on uploaders to attest consent constituted reasonable efforts to ensure meaningful consent.
  • Whether MindGeek's "enhanced" consent practices implemented in 2020 remedied the contravention of consent requirements.
  • Whether MindGeek provided individuals with an easily accessible, simple-to-use, and effective process for having their personal information removed from its websites, as required by Principles 4.10 and 4.10.2 of PIPEDA.
  • Whether MindGeek's takedown process was effective at preventing further uploads of the same or other content depicting the requester.
  • Whether MindGeek was accountable for the personal information under its control, as required by Principle 4.1 of Schedule 1 of PIPEDA.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 31, 2023PIPEDA Findings #2023-002Indexed Jun 30, 2026

PIPEDA Findings #2023-002: Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information

Agronomy Company of Canada Ltd.

The Office of the Privacy Commissioner of Canada (OPC) investigated Agronomy Company of Canada Ltd. following a complaint alleging inadequate safeguards, lack of accountability, and invalid consent for personal information collection and use, stemming from a data breach. A malicious actor gained access to Agronomy's systems, exfiltrating sensitive personal information of 845 individuals, including SINs, financial details, and identification documents, before deploying ransomware. The OPC found Agronomy failed to implement appropriate safeguards, citing a lack of multifactor authentication, network segregation, data encryption, and detection tools, which contributed to the breach. Furthermore, Agronomy lacked a comprehensive privacy policy, a designated privacy officer, and adequate staff training, indicating a failure in accountability. While these two aspects were found well-founded, Agronomy committed to significant improvements, leading to a conditionally resolved outcome. However, the OPC found the complaint regarding invalid consent for credit services not well-founded, as the complainant had signed a clearly labelled credit application and utilized the extended credit.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2023-002: Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information

Jul 31, 2023PIPEDA Findings #2023-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated Agronomy Company of Canada Ltd. following a complaint alleging inadequate safeguards, lack of accountability, and invalid consent for personal information collection and use, stemming from a data breach. A malicious actor gained access to Agronomy's systems, exfiltrating sensitive personal information of 845 individuals, including SINs, financial details, and identification documents, before deploying ransomware. The OPC found Agronomy failed to implement appropriate safeguards, citing a lack of multifactor authentication, network segregation, data encryption, and detection tools, which contributed to the breach. Furthermore, Agronomy lacked a comprehensive privacy policy, a designated privacy officer, and adequate staff training, indicating a failure in accountability. While these two aspects were found well-founded, Agronomy committed to significant improvements, leading to a conditionally resolved outcome. However, the OPC found the complaint regarding invalid consent for credit services not well-founded, as the complainant had signed a clearly labelled credit application and utilized the extended credit.

Key Issues
  • Whether Agronomy implemented appropriate safeguards to adequately protect personal information under its control, as per PIPEDA Principle 4.7.
  • Whether Agronomy's technical safeguards (multifactor authentication, network segregation, data encryption, detection and response tools) were appropriate for the sensitivity of the information.
  • Whether Agronomy's organizational safeguards (incident response protocols, information management, security documentation, staff training) were adequate.
  • Whether Agronomy was accountable for personal information under its control, including designating an individual for PIPEDA compliance and implementing policies and practices, as per PIPEDA Principle 4.1.
  • Whether Agronomy obtained valid and meaningful consent for the collection and use of personal information for credit services, particularly sensitive information, as per PIPEDA Principle 4.3.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 26, 2023PIPEDA Findings #2023-001Indexed Jun 30, 2026

PIPEDA Findings #2023-001: Investigation into Home Depot of Canada Inc.’s compliance with PIPEDA

Home Depot of Canada Inc.

The complainant alleged that Home Depot disclosed his personal information to Meta (formerly Facebook) without his knowledge and consent. Home Depot was sending in-store customers' hashed email addresses and purchase details to Meta via an "Offline Conversions" tool when customers requested an e-receipt. This data allowed Meta to measure ad effectiveness and use the information for its own business purposes, including targeted advertising. The OPC found that Home Depot failed to obtain valid consent, as its privacy statement was not readily available or sufficiently clear, and customers would not reasonably expect such disclosure. Home Depot discontinued the use of the tool in October 2022 in response to OPC recommendations. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2023-001: Investigation into Home Depot of Canada Inc.’s compliance with PIPEDA

Jan 26, 2023PIPEDA Findings #2023-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Home Depot disclosed his personal information to Meta (formerly Facebook) without his knowledge and consent. Home Depot was sending in-store customers' hashed email addresses and purchase details to Meta via an "Offline Conversions" tool when customers requested an e-receipt. This data allowed Meta to measure ad effectiveness and use the information for its own business purposes, including targeted advertising. The OPC found that Home Depot failed to obtain valid consent, as its privacy statement was not readily available or sufficiently clear, and customers would not reasonably expect such disclosure. Home Depot discontinued the use of the tool in October 2022 in response to OPC recommendations. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether Home Depot obtained valid consent for disclosing customer personal information to Meta
  • Whether the disclosure of personal information to Meta constituted a processing activity not requiring additional consent
  • Whether Home Depot's Privacy Statement and Meta's Privacy Policy were sufficient to obtain meaningful implied consent
  • Whether express opt-in consent was required for the disclosure of customer information to Meta
  • Whether the information disclosed was sensitive
  • Whether the disclosure was within the reasonable expectations of the individual
  • Whether the ability to withdraw consent after the fact was sufficient
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 27, 2022PIPEDA Findings #2022-006Indexed Jun 30, 2026

PIPEDA Findings #2022-006: Investigation into Trimac’s use of an audio and video surveillance device in its truck cabins

Trimac Transportation Services Inc.

A truck driver complained that Trimac Transportation Services Inc. (Trimac) installed a dash camera in his vehicle that continuously recorded audio and video without his consent, particularly concerned with audio recording. The OPC investigated two main issues: the appropriateness of the audio recording functionality and whether employee consent was required. The OPC found that Trimac's continuous audio recording, even when drivers were off-duty, was disproportionately privacy-intrusive, despite legitimate business needs. Trimac also initially failed to be transparent about the disciplinary purposes of the system, meaning it could not rely on the employment relationship exception to consent. Trimac agreed to implement recommendations to limit audio recording to on-duty hours and restrict access to recorded clips, and has since clarified the system's disciplinary uses to employees. The OPC found the audio recording issue well-founded and conditionally resolved, and the consent issue well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-006: Investigation into Trimac’s use of an audio and video surveillance device in its truck cabins

Jul 27, 2022PIPEDA Findings #2022-006
Adjudicator: Philippe Dufresne
Plain-Language Summary

A truck driver complained that Trimac Transportation Services Inc. (Trimac) installed a dash camera in his vehicle that continuously recorded audio and video without his consent, particularly concerned with audio recording. The OPC investigated two main issues: the appropriateness of the audio recording functionality and whether employee consent was required. The OPC found that Trimac's continuous audio recording, even when drivers were off-duty, was disproportionately privacy-intrusive, despite legitimate business needs. Trimac also initially failed to be transparent about the disciplinary purposes of the system, meaning it could not rely on the employment relationship exception to consent. Trimac agreed to implement recommendations to limit audio recording to on-duty hours and restrict access to recorded clips, and has since clarified the system's disciplinary uses to employees. The OPC found the audio recording issue well-founded and conditionally resolved, and the consent issue well-founded and resolved.

Key Issues
  • Whether road safety, asset protection, and employee performance management are appropriate purposes for the continuous collection of in-cabin audio via the System, including when drivers are off-duty and not driving, under subsection 5(3) of PIPEDA.
  • Whether the collection of sensitive personal information (in-cabin audio) was justified given the legitimate need, effectiveness, less privacy-invasive means, and proportionality.
  • Whether employee consent was required for the collection of personal information via the System, specifically whether Trimac could rely on the exception to consent under subsection 7.3 of PIPEDA.
  • Whether Trimac was sufficiently transparent about the disciplinary purposes of its dash camera system to rely on the subsection 7.3 exception to consent.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 15, 2022PIPEDA Findings #2022-005Indexed Jun 30, 2026

PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor

Marriott International, Inc.

On November 30, 2018, Marriott International, Inc. announced a data security breach involving unauthorized access to a Starwood Hotels database, which it had acquired in 2016. The breach, spanning over four years, affected up to 12.8 million Canadian records, including passport and payment card details. The OPC launched an investigation into Luxury Hotels Canada, Marriott's Canadian operating company, following eleven complaints. The investigation found Marriott's security safeguards, accountability measures, and information retention practices to be inadequate, contravening PIPEDA Principles 4.7, 4.1.4, and 4.5. Specifically, Marriott failed to detect the breach sooner due to insufficient logging, monitoring, and multi-factor authentication, and retained personal information longer than necessary. While Marriott's notification to affected individuals was deemed adequate, the OPC had outstanding concerns regarding remote access, unencrypted data storage, and retention periods. The findings are well-founded and conditionally resolved, as Marriott committed to implementing the OPC's recommendations, including engaging an external assessor and reviewing its privacy framework.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor

Jul 15, 2022PIPEDA Findings #2022-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

On November 30, 2018, Marriott International, Inc. announced a data security breach involving unauthorized access to a Starwood Hotels database, which it had acquired in 2016. The breach, spanning over four years, affected up to 12.8 million Canadian records, including passport and payment card details. The OPC launched an investigation into Luxury Hotels Canada, Marriott's Canadian operating company, following eleven complaints. The investigation found Marriott's security safeguards, accountability measures, and information retention practices to be inadequate, contravening PIPEDA Principles 4.7, 4.1.4, and 4.5. Specifically, Marriott failed to detect the breach sooner due to insufficient logging, monitoring, and multi-factor authentication, and retained personal information longer than necessary. While Marriott's notification to affected individuals was deemed adequate, the OPC had outstanding concerns regarding remote access, unencrypted data storage, and retention periods. The findings are well-founded and conditionally resolved, as Marriott committed to implementing the OPC's recommendations, including engaging an external assessor and reviewing its privacy framework.

Key Issues
  • Whether personal information held by Marriott was protected by security safeguards appropriate to the sensitivity of the information as required by Principle 4.7 (Safeguards).
  • Whether Marriott demonstrated due diligence and took steps to fulfil its responsibilities to implement policies and practices to protect personal information under Principle 4.1.4 (Accountability) when acquiring control of the Starwood network.
  • Whether Marriott retained personal information for longer than necessary, relevant to Principle 4.5 (Limiting use, disclosure and retention).
  • Whether the mitigation measures offered by Marriott to affected individuals were adequate to protect their personal information from unauthorized use, such as future identity theft, in accordance with Principle 4.7 (Safeguards).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2022PIPEDA Findings #2022-004Indexed Jun 30, 2026

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

MGM Resorts International

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

May 19, 2022PIPEDA Findings #2022-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Key Issues
  • Whether MGM had the obligation to report the breach to the OPC and notify affected Canadians
  • Whether the MGM breach met the RROSH reporting and notification threshold
  • Whether the personal information involved was sensitive
  • Whether there was a high probability of misuse of the personal information
  • Whether MGM notified the OPC and affected Canadians as soon as feasible
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
May 10, 2022PIPEDA Findings #2022-002Indexed Jun 30, 2026

PIPEDA Findings #2022-002: Biron Health Group has ceased sending promotional emails to travellers arriving in Canada who undergo COVID-19 testing

Biron Health Group

The complainant alleged that Biron Health Group (Biron) sent him promotional emails without his consent after he underwent mandatory COVID-19 testing upon arrival at Montreal Trudeau Airport. He provided his email solely for test results. Biron initially believed it had implicit consent due to an established business relationship. The OPC found that Biron could not reasonably assume implicit consent, as travellers had no choice but to use Biron for mandatory testing and would not expect their health information to be used for marketing. Biron ceased the practice and deleted affected email addresses from its marketing database. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

PIPEDA Findings #2022-002: Biron Health Group has ceased sending promotional emails to travellers arriving in Canada who undergo COVID-19 testing

May 10, 2022PIPEDA Findings #2022-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Biron Health Group (Biron) sent him promotional emails without his consent after he underwent mandatory COVID-19 testing upon arrival at Montreal Trudeau Airport. He provided his email solely for test results. Biron initially believed it had implicit consent due to an established business relationship. The OPC found that Biron could not reasonably assume implicit consent, as travellers had no choice but to use Biron for mandatory testing and would not expect their health information to be used for marketing. Biron ceased the practice and deleted affected email addresses from its marketing database. The complaint was settled during the investigation.

Key Issues
  • Whether Biron Health Group had implicit consent to send promotional emails to individuals undergoing mandatory COVID-19 testing
  • Whether the collection of personal information for mandatory health testing could be used for secondary marketing purposes
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2022PIPEDA Findings #2022-003Indexed Jun 30, 2026

PIPEDA Findings #2022-003: Telecommunications firm failed to obtain appropriate consent for voiceprint authentication program

Rogers Communications Inc.

The complainant alleged that Rogers Communications Inc. improperly enrolled her in its Voice ID voiceprint authentication program without her consent and failed to allow her to opt out or delete her voiceprint. Rogers utilized a passive voiceprinting technology, "tuning," to create algorithmic voiceprints for customer authentication and fraud prevention. The Office of the Privacy Commissioner (OPC) found Rogers' purpose for collecting voiceprints to be appropriate, concluding this aspect of the complaint was not well-founded. However, the OPC determined that Rogers failed to obtain valid and meaningful express consent for the collection of sensitive biometric voiceprints, both during the "tuning" process and enrolment, as customers would not reasonably expect this. Furthermore, Rogers did not provide a clearly explained and easily accessible option for individuals to opt out and improperly retained voiceprints of opted-out individuals without any actual purpose. The OPC also identified deficiencies in Rogers' training materials and monitoring protocols for ensuring staff obtained valid consent. In response to OPC recommendations, Rogers committed to significant changes, including obtaining express consent before tuning, clearly informing customers of opt-out/deletion, deleting retained voiceprints, and improving training and monitoring. Consequently, the consent and retention aspects of the complaint were found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-003: Telecommunications firm failed to obtain appropriate consent for voiceprint authentication program

Mar 30, 2022PIPEDA Findings #2022-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Rogers Communications Inc. improperly enrolled her in its Voice ID voiceprint authentication program without her consent and failed to allow her to opt out or delete her voiceprint. Rogers utilized a passive voiceprinting technology, "tuning," to create algorithmic voiceprints for customer authentication and fraud prevention. The Office of the Privacy Commissioner (OPC) found Rogers' purpose for collecting voiceprints to be appropriate, concluding this aspect of the complaint was not well-founded. However, the OPC determined that Rogers failed to obtain valid and meaningful express consent for the collection of sensitive biometric voiceprints, both during the "tuning" process and enrolment, as customers would not reasonably expect this. Furthermore, Rogers did not provide a clearly explained and easily accessible option for individuals to opt out and improperly retained voiceprints of opted-out individuals without any actual purpose. The OPC also identified deficiencies in Rogers' training materials and monitoring protocols for ensuring staff obtained valid consent. In response to OPC recommendations, Rogers committed to significant changes, including obtaining express consent before tuning, clearly informing customers of opt-out/deletion, deleting retained voiceprints, and improving training and monitoring. Consequently, the consent and retention aspects of the complaint were found to be well-founded and conditionally resolved.

Key Issues
  • Whether the collection and use of voiceprints for authentication and fraud prevention constituted an appropriate purpose under PIPEDA s. 5(3)
  • Whether Rogers obtained valid and meaningful consent for the collection of voiceprints (tuning and enrolment) under PIPEDA Principle 4.3 and s. 6.1
  • Whether Rogers provided an adequate mechanism for the withdrawal of consent under PIPEDA Principle 4.3.8
  • Whether Rogers' retention of voiceprints after opt-out was compliant with PIPEDA Principle 4.5.3
  • Whether Rogers' training materials and protocols for obtaining consent were adequate