The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

15 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 14, 2026Indexed Jul 15, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

WestJet

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

Jul 14, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Key Issues
  • Adequacy of security safeguards under PIPEDA
  • Adequacy of notifications to affected individuals under PIPEDA
  • Whether WestJet's post-breach remediation actions and future commitments provide a fair and reasonable response to the incident
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 11, 2026PIPEDA Findings #2026-004Indexed Jun 30, 2026

PIPEDA Findings #2026-004: Commissioner-initiated complaints concerning X Corp.’s and X.AI LLC’s compliance with PIPEDA

X Corp. and X.AI LLC

The Office of the Privacy Commissioner of Canada (OPC) initiated complaints against X Corp. and X.AI LLC following reports that their AI chatbot, Grok, generated millions of sexualized deepfakes of identifiable individuals. The investigation focused on whether valid consent was obtained for the collection, use, and disclosure of personal information for this purpose, and if such practices were appropriate under PIPEDA. The OPC found that neither company obtained valid consent, noting the sensitive nature of the information, the unreasonableness of individuals' expectations, and the significant risk of harm. Furthermore, the OPC concluded that the generation of sexualized deepfakes was inappropriate, as the loss of privacy and harm far outweighed any benefits, and less privacy-invasive means were available. While the companies implemented some safeguards, the OPC deemed their initial response insufficient and their current measures unproven. Consequently, the matter was found well-founded, with the OPC making several recommendations for improved safeguards, proactive monitoring, and annual third-party audits, while committing to ongoing monitoring.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2026-004: Commissioner-initiated complaints concerning X Corp.’s and X.AI LLC’s compliance with PIPEDA

Jun 11, 2026PIPEDA Findings #2026-004
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated complaints against X Corp. and X.AI LLC following reports that their AI chatbot, Grok, generated millions of sexualized deepfakes of identifiable individuals. The investigation focused on whether valid consent was obtained for the collection, use, and disclosure of personal information for this purpose, and if such practices were appropriate under PIPEDA. The OPC found that neither company obtained valid consent, noting the sensitive nature of the information, the unreasonableness of individuals' expectations, and the significant risk of harm. Furthermore, the OPC concluded that the generation of sexualized deepfakes was inappropriate, as the loss of privacy and harm far outweighed any benefits, and less privacy-invasive means were available. While the companies implemented some safeguards, the OPC deemed their initial response insufficient and their current measures unproven. Consequently, the matter was found well-founded, with the OPC making several recommendations for improved safeguards, proactive monitoring, and annual third-party audits, while committing to ongoing monitoring.

Key Issues
  • Whether PIPEDA applies to X Corp. and X.AI LLC, specifically regarding the existence of a "real and substantial connection" to Canada.
  • Whether deepfakes of identifiable individuals, including sexualized deepfakes, constitute "personal information" under PIPEDA.
  • Whether X Corp. and X.AI LLC obtained valid consent for the collection, use, and disclosure of personal information to generate sexualized deepfakes, as required by Principle 4.3 of PIPEDA.
  • Whether express consent was required for the generation of sexualized deepfakes, considering the sensitivity of the information, individuals' reasonable expectations, and the risk of significant harm (Principle 4.3.4, 4.3.5, and s.6.1 of PIPEDA).
  • Whether X Corp. and X.AI LLC are accountable for ensuring valid consent for content generated by their tools in the course of commercial activity.
  • Whether a reasonable person would consider the collection, use, and disclosure of personal information for the purpose of an image generation service capable of producing sexualized deepfakes to be appropriate in the circumstances, as per subsection 5(3) of PIPEDA.
  • Whether the organizations had a legitimate need or bona fide business interest that extended to providing an image generation tool capable of producing non-consensual sexualized deepfakes.
  • Whether less privacy-invasive means were available to achieve the organizations' purposes at comparable cost and benefits.
  • Whether the loss of privacy and risk of harm associated with sexualized deepfakes were proportionate to the benefits of the practice.
  • Whether X Corp. and X.AI LLC's initial response and implemented safeguards were sufficient and effective in preventing the generation of sexualized deepfakes.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & unresolved
Federal (Canada) flag
May 6, 2026PIPEDA Findings #2026-002Indexed Jun 30, 2026

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

OpenAI OpCo, LLC

This joint investigation by the OPC, CAI, OIPC-BC, and OIPC-AB examined OpenAI OpCo, LLC's compliance with federal and provincial privacy laws regarding its ChatGPT service. The Offices investigated OpenAI's collection, use, and disclosure of personal information for model training, consent practices, openness, accuracy, individual rights (access, correction, deletion), data retention, and accountability. While OpenAI challenged jurisdiction and argued for implied consent, the Offices largely found contraventions in its initial practices, particularly concerning the overbroad collection of personal information from public sources and user interactions without valid consent or sufficient transparency. However, in response to the preliminary report, OpenAI committed to implementing significant privacy-enhancing measures, including a new filtering tool for training data, improved transparency, and enhanced individual rights processes. Consequently, the OPC found the matter well-founded and conditionally resolved under PIPEDA, expecting continued implementation and improvement of these measures. The OIPC-AB and OIPC-BC, due to stricter provincial consent requirements, found the consent issues well-founded and unresolved, while the CAI had mixed outcomes, also finding some issues unresolved. The Offices will monitor OpenAI's implementation of the agreed-upon recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & unresolved

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

May 6, 2026PIPEDA Findings #2026-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

This joint investigation by the OPC, CAI, OIPC-BC, and OIPC-AB examined OpenAI OpCo, LLC's compliance with federal and provincial privacy laws regarding its ChatGPT service. The Offices investigated OpenAI's collection, use, and disclosure of personal information for model training, consent practices, openness, accuracy, individual rights (access, correction, deletion), data retention, and accountability. While OpenAI challenged jurisdiction and argued for implied consent, the Offices largely found contraventions in its initial practices, particularly concerning the overbroad collection of personal information from public sources and user interactions without valid consent or sufficient transparency. However, in response to the preliminary report, OpenAI committed to implementing significant privacy-enhancing measures, including a new filtering tool for training data, improved transparency, and enhanced individual rights processes. Consequently, the OPC found the matter well-founded and conditionally resolved under PIPEDA, expecting continued implementation and improvement of these measures. The OIPC-AB and OIPC-BC, due to stricter provincial consent requirements, found the consent issues well-founded and unresolved, while the CAI had mixed outcomes, also finding some issues unresolved. The Offices will monitor OpenAI's implementation of the agreed-upon recommendations.

Key Issues
  • Whether the Offices had jurisdiction over OpenAI's activities under federal and provincial privacy laws.
  • Whether OpenAI collected, used, and disclosed personal information for purposes that a reasonable person would consider appropriate in the circumstances.
  • Whether OpenAI obtained valid consent for the collection and use of personal information from publicly accessible websites and licensed third-party sources for model training.
  • Whether OpenAI obtained valid consent and met its obligation to inform individuals with respect to the collection and use of personal information included in their interactions with ChatGPT.
  • Whether OpenAI obtained valid consent and met its obligation to inform individuals with respect to the disclosure of personal information collected from various sources via ChatGPT.
  • Whether OpenAI was sufficiently open and transparent about its models and information handling practices.
  • Whether OpenAI took reasonable steps to ensure that the information it generates about individuals is as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used.
  • Whether OpenAI provided individuals with the ability to obtain access to their personal information.
  • Whether OpenAI provided individuals with the ability to correct their personal information.
  • Whether OpenAI provided individuals with the ability to remove/delete their personal information from its models.
  • Whether OpenAI established appropriate retention and disposal procedures for the personal information that it collects, uses, and discloses.
  • Whether OpenAI met its accountability requirements in respect of the personal information under its control.
  • Whether the personal or domestic purposes exemption applied to OpenAI's commercial activities.
  • Whether the publicly available information exception applied to OpenAI's collection of personal information from the Internet.
  • Whether the journalistic, historical, or genealogical material exception under Quebec's Private Sector Act applied to OpenAI's model training data.
  • Whether section 9.1 of Quebec's Private Sector Act (privacy by default) applied to ChatGPT's privacy settings.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Sep 23, 2025PIPEDA Findings #2025-003Indexed Jun 30, 2026

PIPEDA Findings #2025-003: Joint investigation of TikTok Pte. Ltd. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, and the Office of the Information and Privacy Commissioner of Alberta

TikTok Pte. Ltd.

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and provincial privacy regulators (CAI, OIPC BC, OIPC AB) examined TikTok Pte. Ltd.'s compliance with federal and provincial private sector privacy laws. The investigation focused on TikTok's collection, use, and disclosure of personal information for ad targeting and content personalization, with a particular emphasis on practices affecting children. The Offices found that TikTok's age assurance measures were inadequate, leading to the collection and use of sensitive personal information from a large number of underage users for purposes deemed inappropriate. Furthermore, TikTok failed to obtain valid and meaningful consent from both adult and youth users due to unclear, inaccessible, and incomplete privacy communications, including regarding biometric information and cross-border data transfers. The CAI specifically identified contraventions related to Quebec's transparency and privacy-by-default obligations. While TikTok disagreed with the findings, it committed to implementing enhanced age assurance mechanisms, improving privacy communications, and limiting ad targeting for under-18 users. The Offices concluded the matter as well-founded and conditionally resolved, contingent on TikTok's satisfactory implementation of these significant commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2025-003: Joint investigation of TikTok Pte. Ltd. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, and the Office of the Information and Privacy Commissioner of Alberta

Sep 23, 2025PIPEDA Findings #2025-003
Adjudicator: Philippe Dufresne
Plain-Language Summary

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and provincial privacy regulators (CAI, OIPC BC, OIPC AB) examined TikTok Pte. Ltd.'s compliance with federal and provincial private sector privacy laws. The investigation focused on TikTok's collection, use, and disclosure of personal information for ad targeting and content personalization, with a particular emphasis on practices affecting children. The Offices found that TikTok's age assurance measures were inadequate, leading to the collection and use of sensitive personal information from a large number of underage users for purposes deemed inappropriate. Furthermore, TikTok failed to obtain valid and meaningful consent from both adult and youth users due to unclear, inaccessible, and incomplete privacy communications, including regarding biometric information and cross-border data transfers. The CAI specifically identified contraventions related to Quebec's transparency and privacy-by-default obligations. While TikTok disagreed with the findings, it committed to implementing enhanced age assurance mechanisms, improving privacy communications, and limiting ad targeting for under-18 users. The Offices concluded the matter as well-founded and conditionally resolved, contingent on TikTok's satisfactory implementation of these significant commitments.

Key Issues
  • Whether TikTok was collecting, using, and disclosing personal information, particularly with respect to children, for an appropriate, reasonable, and legitimate purpose.
  • Whether TikTok's age assurance mechanisms were effective in preventing underage users from accessing the platform.
  • Whether TikTok obtained valid and meaningful consent from its users for tracking, profiling, targeting, and content personalization.
  • Whether TikTok's privacy communications provided sufficient upfront, clear, and comprehensive information to adult users to ensure meaningful consent.
  • Whether TikTok adequately explained its collection and use of users' biometric information to ensure meaningful consent.
  • Whether TikTok's privacy communications were adequate to obtain meaningful consent from youth (13-17), considering their cognitive development and potential harms from targeted ads.
  • Whether TikTok met its obligations under Quebec's Private Sector Act to inform persons concerned about the collection and use of personal information for user profiles, ad targeting, and content personalization.
  • Whether TikTok ensured that privacy settings provided the highest level of privacy by default under Quebec's Private Sector Act.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 20, 2025PIPEDA Findings #2025-001Indexed Jun 30, 2026

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

23andMe Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

Jun 20, 2025PIPEDA Findings #2025-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Key Issues
  • Whether 23andMe had appropriate safeguards to protect highly sensitive personal information under its control, specifically against credential stuffing attacks.
  • Whether 23andMe's prevention measures, including mandatory Multi-factor Authentication (MFA), compromised-password checks, and minimum password requirements, were adequate.
  • Whether 23andMe's detection measures, including detection systems, digital fingerprinting, and device history, were adequate to identify ongoing attacks.
  • Whether 23andMe adequately investigated anomalies and claims of breach prior to public disclosure.
  • Whether 23andMe's breach response, including the timeliness of disabling active user sessions, disabling raw DNA download features, and implementing mandatory MFA, was adequate.
  • Whether 23andMe adequately notified the OPC about the breach, including the completeness of information provided and timeliness.
  • Whether 23andMe adequately notified affected individuals about the breach, including the completeness of information provided and timeliness.
  • Whether the data breach created a real risk of significant harm to affected individuals, triggering notification obligations.
  • Whether 23andMe's methodology for identifying and notifying individuals whose raw DNA was downloaded by the Threat Actor was adequate.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 1, 2022PIPEDA Findings #2022-001Indexed Jun 30, 2026

PIPEDA Findings #2022-001: Joint investigation into location tracking by the Tim Hortons App

The TDL Group Corp. (Tim Hortons)

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-001: Joint investigation into location tracking by the Tim Hortons App

Jun 1, 2022PIPEDA Findings #2022-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

Key Issues
  • Whether Tim Hortons collected or used personal information for an appropriate purpose under the Acts.
  • Whether Tim Hortons obtained valid consent for the collection and use of granular location data.
  • Adequacy of contractual protections for personal information transferred to third-party service providers.
  • Tim Hortons' accountability and implementation of a privacy management program.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Feb 2, 2021PIPEDA Findings #2021-001Indexed Jun 30, 2026

PIPEDA Findings #2021-001: Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta

Clearview AI, Inc.

A joint investigation by Canadian privacy commissioners examined Clearview AI's facial recognition tool, which scraped billions of images from public websites to create a database for law enforcement and other users. Clearview argued that Canadian privacy laws did not apply due to a lack of jurisdiction and that the information was "publicly available," thus exempt from consent requirements. The Offices asserted jurisdiction, finding a real and substantial connection to Canada through Clearview's marketing and use by Canadian entities. They determined Clearview failed to obtain requisite consent, as the "publicly available" exception did not apply to sensitive biometric data scraped from social media for unrelated purposes. Furthermore, Clearview's mass collection and use of sensitive facial biometric information for commercial purposes were deemed inappropriate. In Quebec, Clearview also failed to report its biometric database and obtain express consent as required by law. The matter was found to be well-founded, with recommendations for Clearview to cease operations in Canada and delete Canadian data, which Clearview did not commit to implementing.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2021-001: Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta

Feb 2, 2021PIPEDA Findings #2021-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A joint investigation by Canadian privacy commissioners examined Clearview AI's facial recognition tool, which scraped billions of images from public websites to create a database for law enforcement and other users. Clearview argued that Canadian privacy laws did not apply due to a lack of jurisdiction and that the information was "publicly available," thus exempt from consent requirements. The Offices asserted jurisdiction, finding a real and substantial connection to Canada through Clearview's marketing and use by Canadian entities. They determined Clearview failed to obtain requisite consent, as the "publicly available" exception did not apply to sensitive biometric data scraped from social media for unrelated purposes. Furthermore, Clearview's mass collection and use of sensitive facial biometric information for commercial purposes were deemed inappropriate. In Quebec, Clearview also failed to report its biometric database and obtain express consent as required by law. The matter was found to be well-founded, with recommendations for Clearview to cease operations in Canada and delete Canadian data, which Clearview did not commit to implementing.

Key Issues
  • Whether the Canadian privacy commissioners had jurisdiction over Clearview AI's activities.
  • Whether Clearview AI obtained requisite consent for its collection, use, and disclosure of personal information under PIPEDA, PIPA AB, PIPA BC, and Quebec's Private Sector Act.
  • Whether the "publicly available" information exception applied to Clearview AI's collection of images from public websites.
  • Whether Clearview AI's collection, use, and disclosure of personal information was for an appropriate purpose under PIPEDA, PIPA AB, PIPA BC, and Quebec's Private Sector Act.
  • Whether Clearview AI satisfied its biometric obligations in Quebec, specifically regarding reporting the creation of a biometric database and obtaining express consent under the LCCJTI.
  • Whether Clearview AI's activities were protected by freedom of expression under the Canadian Charter of Rights and Freedoms.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 14, 2020PIPEDA Findings #2020-005Indexed Jun 30, 2026

PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019

Desjardins

The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019

Dec 14, 2020PIPEDA Findings #2020-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.

Key Issues
  • Whether personal information held by Desjardins was protected throughout its life cycle by security safeguards appropriate to the sensitivity of the information as required by PIPEDA Safeguards Principle 4.7.
  • Whether Desjardins fulfilled its responsibilities to implement procedures to protect personal information and train its staff, as set out in Accountability Principle 4.1.
  • Whether the personal information of individuals was handled in accordance with the retention and destruction requirements as set out in PIPEDA Principle 4.5, limiting use, disclosure and retention.
  • Whether the mitigation measures offered by Desjardins to affected individuals were adequate to protect their personal information from unauthorized use, such as future identity theft, in accordance with PIPEDA Safeguards Principle 4.7.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Nov 26, 2019PIPEDA Findings #2019-004Indexed Jun 30, 2026

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

AggregateIQ Data Services Ltd.

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Nov 26, 2019PIPEDA Findings #2019-004
Adjudicator: Daniel Therrien
Plain-Language Summary

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Key Issues
  • Whether AIQ was compliant with consent requirements for the collection, use, or disclosure of personal information under PIPEDA and PIPA.
  • Whether AIQ could rely on consent obtained by its clients for its own collection, use, and disclosure of personal information.
  • Whether consent was adequate for specific uses, such as disclosing personal information to Facebook for "custom audiences" and "lookalike audiences."
  • Whether consent was adequate for sensitive personal information, such as political opinions or psychographic profiles.
  • Whether AIQ took reasonable security measures to protect the personal information in its custody or control under PIPEDA and PIPA.
  • Whether the security breach involving the GitLab repository constituted a failure of reasonable security measures.
  • Whether personal information collected from public telephone directories required consent.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 9, 2019PIPEDA Findings #2019-001Indexed Jun 30, 2026

PIPEDA Findings #2019-001: Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information

Equifax Canada Co.

The Office of the Privacy Commissioner of Canada (OPC) investigated a 2017 data breach that compromised the personal information of approximately 19,000 Canadians held by Equifax Inc., the US parent company of Equifax Canada Co. The investigation examined the adequacy of security safeguards by both entities, Equifax Canada's accountability for data processed by Equifax Inc., the validity of consent obtained for data transfers, retention practices, and the sufficiency of post-breach mitigation measures. The OPC concluded that both Equifax Inc. and Equifax Canada contravened PIPEDA in all these areas, citing inadequate vulnerability management, network segregation, basic information security practices, and oversight. Equifax Canada signed a compliance agreement, committing to corrective measures for most findings, which were deemed well-founded and conditionally resolved. However, the finding regarding post-breach safeguards was only partially resolved, as Equifax Canada committed to extended credit monitoring but not a free credit freeze product.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-001: Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information

Apr 9, 2019PIPEDA Findings #2019-001
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a 2017 data breach that compromised the personal information of approximately 19,000 Canadians held by Equifax Inc., the US parent company of Equifax Canada Co. The investigation examined the adequacy of security safeguards by both entities, Equifax Canada's accountability for data processed by Equifax Inc., the validity of consent obtained for data transfers, retention practices, and the sufficiency of post-breach mitigation measures. The OPC concluded that both Equifax Inc. and Equifax Canada contravened PIPEDA in all these areas, citing inadequate vulnerability management, network segregation, basic information security practices, and oversight. Equifax Canada signed a compliance agreement, committing to corrective measures for most findings, which were deemed well-founded and conditionally resolved. However, the finding regarding post-breach safeguards was only partially resolved, as Equifax Canada committed to extended credit monitoring but not a free credit freeze product.

Key Issues
  • Whether Equifax Inc.'s security safeguards were appropriate to the sensitivity of the information as required by PIPEDA Safeguards Principle 4.7.
  • Whether Equifax Inc.'s retention and destruction practices for Canadian personal information complied with PIPEDA Principle 4.5.
  • Whether Equifax Canada demonstrated adequate accountability for protecting Canadian personal information handled by Equifax Inc. as required under PIPEDA Principle 4.1.
  • Whether there was adequate consent from Canadians for the collection of their personal information by Equifax Inc. and disclosure to Equifax Inc. by Equifax Canada, as required under PIPEDA Principle 4.3 and s.6.1.
  • Whether Equifax Canada's security safeguards for personal information it held directly were appropriate as required by PIPEDA Safeguards Principle 4.7.
  • Whether the post-breach mitigation measures offered by Equifax Canada were adequate to protect against unauthorized use of compromised personal information as required by PIPEDA Safeguards Principle 4.7.1.
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 26, 2017Incident case summary #2017-001Indexed Jun 30, 2026

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Multiple organizations (Airline, Retailer, Digital media company)

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Apr 26, 2017Incident case summary #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Key Issues
  • Whether organizations adequately responded to breaches caused by password reuse
  • Whether organizations implemented appropriate safeguards to prevent recurrence of breaches due to password reuse
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 22, 2016PIPEDA Report of Findings #2016-005Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Avid Life Media Inc. (ALM)

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Aug 22, 2016PIPEDA Report of Findings #2016-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Key Issues
  • Whether ALM's security safeguards were appropriate to the sensitivity of the information under PIPEDA Principle 4.7.
  • Whether ALM implemented policies and practices to give effect to the Principles, including procedures to protect personal information, under PIPEDA Principle 4.1.4.
  • Whether ALM's indefinite retention of personal information for deactivated or inactive accounts contravened PIPEDA Principle 4.5.
  • Whether ALM's failure to establish maximum retention periods for personal information contravened PIPEDA Principle 4.5.2.
  • Whether ALM's practice of charging a fee for the complete deletion of personal information contravened an individual's right to withdraw consent under PIPEDA Principle 4.3.8.
  • Whether ALM took reasonable steps to ensure personal information (email addresses) was accurate, complete, and up-to-date as necessary for its purposes, taking into account the interests of the individual, under PIPEDA Principle 4.6 and 4.6.1.
  • Whether ALM's consent for the collection, use, or disclosure of personal information was valid, given the nature, purpose, and consequences, under PIPEDA s.6.1 and Principle 4.3.
  • Whether ALM made information about its personal information handling policies and practices readily available and understandable, and did not obtain consent through deception, under PIPEDA Principle 4.8, 4.8.1, and 4.3.5.
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 18, 2016Incident Summary #13Indexed Jun 30, 2026

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

A Canadian financial institution

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

Feb 18, 2016Incident Summary #13
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Key Issues
  • Whether the financial institution adequately protected customer personal information from unauthorized disclosure by a fraudster
  • Whether the financial institution took appropriate steps to mitigate the impact of the breach and prevent recurrence
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 4, 2006Incident Summary #3Indexed Jun 30, 2026

Incident Summary #3: Misdirected faxes - December 4, 2006

Two Canadian banks

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #3: Misdirected faxes - December 4, 2006

Dec 4, 2006Incident Summary #3
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Key Issues
  • Whether organizations adequately safeguard personal information to prevent inappropriate disclosure (Principle 4.7 PIPEDA)
  • Whether organizations implement effective policies and procedures to give effect to fair information practices (Principle 4.1 PIPEDA)
  • Whether employees are attuned to privacy issues and can respond to problems when they arise
  • Whether organizations notify affected customers of privacy breaches
  • Whether organizations have processes for confirming correct fax transmission
  • Whether organizations have measures to recover erroneously transmitted customer information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 18, 2005Incident Summary #2Indexed Jun 30, 2026

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

CIBC

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

Apr 18, 2005Incident Summary #2
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Key Issues
  • Whether CIBC's privacy practices adequately protected personal information from misdirected faxes
  • Whether CIBC effectively responded to notifications of misdirected faxes
  • Whether CIBC appropriately recovered misdirected personal information
  • Whether CIBC adequately notified affected customers of privacy breaches
  • Whether CIBC employees recognized misdirected faxes as privacy issues
  • Whether CIBC's internal privacy management structure was sufficient to address breaches