The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

14 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 21, 2004Incident Summary #1Indexed Jun 30, 2026

Incident Summary #1: Misdirected faxes containing health information end up in apartment managers' hands

Dynacare and Viewpoint

This incident summary details two separate investigations into misdirected faxes containing personal health information. In both cases, faxes from Dynacare and Viewpoint were erroneously sent to apartment managers. The OPC found that both companies disclosed personal information without consent, contravening PIPEDA. Dynacare implemented an electronic auto-fax function and revised policies, while Viewpoint committed to retrieving misdirected faxes and verifying numbers. The Assistant Commissioner recommended both organizations implement OPC faxing guidelines, notify affected individuals, and annually update employee confidentiality agreements.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #1: Misdirected faxes containing health information end up in apartment managers' hands

Dec 21, 2004Incident Summary #1
Adjudicator: Jennifer Stoddart
Plain-Language Summary

This incident summary details two separate investigations into misdirected faxes containing personal health information. In both cases, faxes from Dynacare and Viewpoint were erroneously sent to apartment managers. The OPC found that both companies disclosed personal information without consent, contravening PIPEDA. Dynacare implemented an electronic auto-fax function and revised policies, while Viewpoint committed to retrieving misdirected faxes and verifying numbers. The Assistant Commissioner recommended both organizations implement OPC faxing guidelines, notify affected individuals, and annually update employee confidentiality agreements.

Key Issues
  • Whether Dynacare disclosed personal information without consent, contrary to PIPEDA
  • Whether Viewpoint disclosed personal information without consent, contrary to PIPEDA
  • Whether Dynacare's security safeguards were adequate to prevent misdirected faxes
  • Whether Viewpoint's security safeguards were adequate to prevent misdirected faxes
  • Whether Dynacare should notify the affected individual
  • Whether Viewpoint should notify the affected individual
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 16, 2004Settled Case summaryIndexed Jun 30, 2026

#12 — A department store

A department store

An individual complained that a department store disclosed his personal information to a third party, a credit monitoring service, after he had requested that his information not be shared. The complainant received a mail solicitation that appeared to be supported by the department store but sent by the third party. The investigation found that the department store had not disclosed the complainant's personal information; rather, the store conducted the mail-out on behalf of the third party. The store acknowledged that the mail-out should have been clearer about its role and apologized. The store also agreed to review its account application policies to allow new customers to opt out at enrolment and to improve its suppression mechanisms. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

#12 — A department store

Nov 16, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a department store disclosed his personal information to a third party, a credit monitoring service, after he had requested that his information not be shared. The complainant received a mail solicitation that appeared to be supported by the department store but sent by the third party. The investigation found that the department store had not disclosed the complainant's personal information; rather, the store conducted the mail-out on behalf of the third party. The store acknowledged that the mail-out should have been clearer about its role and apologized. The store also agreed to review its account application policies to allow new customers to opt out at enrolment and to improve its suppression mechanisms. The complaint was settled during the investigation.

Key Issues
  • Whether the department store disclosed personal information to a third party without consent
  • Whether the mail-out clearly indicated the department store's role
  • Whether the department store's opt-out mechanisms were adequate
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 15, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #10 — A collection agency

A collection agency

An individual complained to the OPC after a collection agency failed to correct inaccurate information in his credit file, despite his lawyer's repeated attempts. The complainant had paid off a debt years prior, but the collection agency had not reported this to credit bureaux, causing him difficulty in securing credit. The collection agency initially had no record of the lawyer's correspondence. However, after the OPC intervened and the lawyer sent another letter, the agency investigated and confirmed the debt was paid. Consequently, the agency updated the credit bureaux, and the complainant's credit files were amended. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #10 — A collection agency

Nov 15, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained to the OPC after a collection agency failed to correct inaccurate information in his credit file, despite his lawyer's repeated attempts. The complainant had paid off a debt years prior, but the collection agency had not reported this to credit bureaux, causing him difficulty in securing credit. The collection agency initially had no record of the lawyer's correspondence. However, after the OPC intervened and the lawyer sent another letter, the agency investigated and confirmed the debt was paid. Consequently, the agency updated the credit bureaux, and the complainant's credit files were amended. The complaint was settled during the investigation.

Key Issues
  • Whether the collection agency failed to ensure the accuracy of personal information it held
  • Whether the collection agency failed to correct inaccurate personal information upon request
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 5, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #4 — A federally regulated transportation company

A federally regulated transportation company

Several employees of a federally regulated transportation company complained that a list of employees receiving severance packages, including names, identification and seniority numbers, and Social Insurance Numbers (SINs), was disclosed to their union without their knowledge or consent. The company admitted that the SINs were included on an electronic spreadsheet provided to the union, though in a hidden column. The employer did not obtain employee consent for this disclosure. During the investigation, the company changed its severance application process to no longer require SINs. The company also agreed to amend its application form to include a consent statement for the release of personal information to the union. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #4 — A federally regulated transportation company

Nov 5, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

Several employees of a federally regulated transportation company complained that a list of employees receiving severance packages, including names, identification and seniority numbers, and Social Insurance Numbers (SINs), was disclosed to their union without their knowledge or consent. The company admitted that the SINs were included on an electronic spreadsheet provided to the union, though in a hidden column. The employer did not obtain employee consent for this disclosure. During the investigation, the company changed its severance application process to no longer require SINs. The company also agreed to amend its application form to include a consent statement for the release of personal information to the union. The complaint was settled during the investigation.

Key Issues
  • Whether the disclosure of employee names, identification numbers, seniority numbers, and Social Insurance Numbers to a union without consent contravened PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 1, 2004Settled Case summaryIndexed Jun 30, 2026

Settled Case summary: Credit check to open a personal deposit account - November 2004

A bank

An individual complained that a bank inappropriately required a credit check and other personal information, including length of employment and Social Insurance Number (SIN), to open a no-fee personal deposit account online. The complainant also found the language regarding information exchange with credit bureaus unclear. The bank agreed to modify its online application forms to clarify that credit checks are optional for deposit accounts if applied for in person. It also agreed to only request length of employment for credit applications and make SIN provision optional. The bank committed to reviewing the language concerning credit bureau information exchange. The OPC confirmed the complainant's credit rating was unaffected. Both the complainant and the OPC were satisfied with the bank's actions.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary: Credit check to open a personal deposit account - November 2004

Nov 1, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a bank inappropriately required a credit check and other personal information, including length of employment and Social Insurance Number (SIN), to open a no-fee personal deposit account online. The complainant also found the language regarding information exchange with credit bureaus unclear. The bank agreed to modify its online application forms to clarify that credit checks are optional for deposit accounts if applied for in person. It also agreed to only request length of employment for credit applications and make SIN provision optional. The bank committed to reviewing the language concerning credit bureau information exchange. The OPC confirmed the complainant's credit rating was unaffected. Both the complainant and the OPC were satisfied with the bank's actions.

Key Issues
  • Whether a credit check was appropriately required for a no-fee personal deposit account
  • Whether length of employment was appropriately required for a no-fee personal deposit account
  • Whether the Social Insurance Number (SIN) was appropriately required for a no-fee personal deposit account
  • Whether the language describing information exchange with credit bureaus was clear
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Oct 26, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #2 — A chain of pharmacies

A chain of pharmacies

An individual complained that a pharmacy chain required him to sign an overly broad consent form for medication, fearing his personal information would be used for marketing. The complainant was concerned he would be denied medication if he refused consent. The OPC clarified with the pharmacy that it did not disclose personal information for secondary marketing purposes. The pharmacy, having received similar complaints, revised its consent form to be simpler and clearer. It also introduced a new policy allowing customers to verbally consent to privacy practices if they were uncomfortable signing the form. The complainant was satisfied with these changes.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #2 — A chain of pharmacies

Oct 26, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a pharmacy chain required him to sign an overly broad consent form for medication, fearing his personal information would be used for marketing. The complainant was concerned he would be denied medication if he refused consent. The OPC clarified with the pharmacy that it did not disclose personal information for secondary marketing purposes. The pharmacy, having received similar complaints, revised its consent form to be simpler and clearer. It also introduced a new policy allowing customers to verbally consent to privacy practices if they were uncomfortable signing the form. The complainant was satisfied with these changes.

Key Issues
  • Whether the pharmacy's consent form authorized overly broad disclosure practices
  • Whether personal information was being disclosed for marketing purposes
  • Whether the pharmacy's consent process was appropriate under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jul 6, 2004Settled Case summaryIndexed Jun 30, 2026

Settled Case summary: Windows reveal too much information - July and October 2004

Two financial institutions

The OPC received two separate complaints against two different banks concerning the improper disclosure of personal information through envelope windows. In the first case, a complainant received RRSP transfer documents where Social Insurance Numbers (SINs) were visible through the envelope window. The bank acknowledged the issue and implemented a new process to ensure SINs and account numbers are not visible. In the second case, a complainant received a dormant account notice where the word "Bankrupt" and a date were visible through the envelope window below his name. The bank modified its process for client profile notations to prevent such information from appearing in the address field. Both complaints were settled during the course of the investigations, with the banks taking satisfactory corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary: Windows reveal too much information - July and October 2004

Jul 6, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC received two separate complaints against two different banks concerning the improper disclosure of personal information through envelope windows. In the first case, a complainant received RRSP transfer documents where Social Insurance Numbers (SINs) were visible through the envelope window. The bank acknowledged the issue and implemented a new process to ensure SINs and account numbers are not visible. In the second case, a complainant received a dormant account notice where the word "Bankrupt" and a date were visible through the envelope window below his name. The bank modified its process for client profile notations to prevent such information from appearing in the address field. Both complaints were settled during the course of the investigations, with the banks taking satisfactory corrective actions.

Key Issues
  • Whether Social Insurance Numbers visible through an envelope window constituted inadequate protection of personal information under PIPEDA
  • Whether a bankruptcy notation visible through an envelope window constituted improper disclosure of personal information under PIPEDA
  • Whether the banks' practices for handling and displaying personal information on mailings met PIPEDA's protection requirements
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jun 24, 2004Settled Case summaryIndexed Jun 30, 2026

Settled Case summary: Concerns result in improved language of consent - June 2004

An insurance company

An individual complained that an insurance company required overly broad consent for the collection, use, and disclosure of personal information when applying for life insurance. The OPC found the company's actual practices were compliant with PIPEDA. However, the company acknowledged the complainant's concerns about the clarity and precision of its consent language. The company agreed to revise its consent forms and share the updated language with the complainant for feedback. The complainant was satisfied with the company's explanation and its commitment to review the consent language. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary: Concerns result in improved language of consent - June 2004

Jun 24, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that an insurance company required overly broad consent for the collection, use, and disclosure of personal information when applying for life insurance. The OPC found the company's actual practices were compliant with PIPEDA. However, the company acknowledged the complainant's concerns about the clarity and precision of its consent language. The company agreed to revise its consent forms and share the updated language with the complainant for feedback. The complainant was satisfied with the company's explanation and its commitment to review the consent language. The complaint was settled during the investigation.

Key Issues
  • Whether the insurance company's consent language was overly broad
  • Whether the insurance company's collection, use, and disclosure practices were consistent with PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jun 24, 2004Settled Case summaryIndexed Jun 30, 2026

#11 — A trucking company

A trucking company

An individual complained that his former employer, an interprovincial trucking company, disclosed his personal information to a creditor without his consent. The investigation found no evidence to support this allegation; in fact, the complainant had provided some of the information to the creditor himself. During the investigation, the trucking company, a small family-owned business, developed and implemented a written privacy policy, appointed an Information Officer, and reviewed its practices regarding employee information. The company also took steps to ensure its employees were aware of fair information handling practices. Both the complainant and the OPC were satisfied with these actions, and the matter was settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

#11 — A trucking company

Jun 24, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that his former employer, an interprovincial trucking company, disclosed his personal information to a creditor without his consent. The investigation found no evidence to support this allegation; in fact, the complainant had provided some of the information to the creditor himself. During the investigation, the trucking company, a small family-owned business, developed and implemented a written privacy policy, appointed an Information Officer, and reviewed its practices regarding employee information. The company also took steps to ensure its employees were aware of fair information handling practices. Both the complainant and the OPC were satisfied with these actions, and the matter was settled.

Key Issues
  • Whether the trucking company disclosed the complainant's personal information to a creditor without consent
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jun 23, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #1 — A retail store

A retail store

A complainant's laptop, returned for repair, was sold by a retail store with her personal information still on it. The individual who purchased the laptop contacted the complainant, raising concerns about the store's safeguards. The investigation revealed an employee sold the returned laptop without wiping its data. The company retrieved the laptop and returned it to the complainant. In response, the store implemented new procedures to ensure all customer data is wiped from returned electronic devices, with documentation required for these actions. The complainant was satisfied with these changes, and the complaint was settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #1 — A retail store

Jun 23, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant's laptop, returned for repair, was sold by a retail store with her personal information still on it. The individual who purchased the laptop contacted the complainant, raising concerns about the store's safeguards. The investigation revealed an employee sold the returned laptop without wiping its data. The company retrieved the laptop and returned it to the complainant. In response, the store implemented new procedures to ensure all customer data is wiped from returned electronic devices, with documentation required for these actions. The complainant was satisfied with these changes, and the complaint was settled.

Key Issues
  • Whether the retail store adequately safeguarded the complainant's personal information on a returned laptop
  • Whether the retail store's practices led to an unauthorized disclosure of personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jun 15, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #8 — A lending institution

A lending institution

An individual complained that a lending institution disclosed information about her delinquent account to her uncle without consent. The OPC's investigation found merit in the complaint. The lending institution agreed to apologize to the complainant and adjust her outstanding loan. Furthermore, the OPC noted the institution lacked privacy policies and practices. The institution committed to implementing privacy policies, establishing a privacy committee, providing employee training, and reminding staff about limiting information disclosure during debt recovery. Both the complainant and the OPC were satisfied with these actions.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #8 — A lending institution

Jun 15, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a lending institution disclosed information about her delinquent account to her uncle without consent. The OPC's investigation found merit in the complaint. The lending institution agreed to apologize to the complainant and adjust her outstanding loan. Furthermore, the OPC noted the institution lacked privacy policies and practices. The institution committed to implementing privacy policies, establishing a privacy committee, providing employee training, and reminding staff about limiting information disclosure during debt recovery. Both the complainant and the OPC were satisfied with these actions.

Key Issues
  • Whether the lending institution disclosed personal information without consent
  • Whether the lending institution had adequate privacy policies and practices in place
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jun 15, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #6 — A trucking company

A trucking company

A former employee complained that his previous employer, a trucking company, disclosed his personal information to other trucking firms after his employment ended. While the original complaint focused on the disclosure, the Office of the Privacy Commissioner (OPC) also identified the absence of a company privacy policy and a designated privacy representative as issues. Through discussions, both parties reached a settlement. The trucking company agreed to develop privacy policies and procedures, which it subsequently provided to the OPC, and also appointed a privacy officer. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #6 — A trucking company

Jun 15, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A former employee complained that his previous employer, a trucking company, disclosed his personal information to other trucking firms after his employment ended. While the original complaint focused on the disclosure, the Office of the Privacy Commissioner (OPC) also identified the absence of a company privacy policy and a designated privacy representative as issues. Through discussions, both parties reached a settlement. The trucking company agreed to develop privacy policies and procedures, which it subsequently provided to the OPC, and also appointed a privacy officer. The complaint was settled during the investigation.

Key Issues
  • Whether a trucking company disclosed personal information about a former employee to other firms without authorization
  • Whether the trucking company had adequate privacy policies and procedures in place
  • Whether the trucking company had a designated privacy officer
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jun 5, 2004Early resolved case summary #1Indexed Jun 30, 2026

Early resolved case summary #1: Access request ignored, but no personal information existed

A professional organization

A doctor complained that a professional organization ignored his request for access to his personal information. The complainant believed he was the subject of a planned conference talk by a member of the organization and sought access to information related to this presentation. The OPC confirmed that the organization had not acted on the access request. However, the OPC also found that the presentation was never given, and therefore the organization held no personal information about the doctor. The complainant was satisfied with this explanation and withdrew his complaint.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #1: Access request ignored, but no personal information existed

Jun 5, 2004Early resolved case summary #1
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A doctor complained that a professional organization ignored his request for access to his personal information. The complainant believed he was the subject of a planned conference talk by a member of the organization and sought access to information related to this presentation. The OPC confirmed that the organization had not acted on the access request. However, the OPC also found that the presentation was never given, and therefore the organization held no personal information about the doctor. The complainant was satisfied with this explanation and withdrew his complaint.

Key Issues
  • Whether the professional organization failed to respond to an access request
  • Whether the professional organization held personal information about the complainant
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Feb 27, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #7 — A national transportation company

A national transportation company

An employee of a national transportation company complained about the security of personal information in an automated crew management system. The complainant was concerned that unauthorized personnel, particularly union representatives, could access sensitive data like date of birth, social insurance number, wage rates, and vacation eligibility. While some information was not accessible to union representatives, the company agreed to modify the system. The adjustments ensured that screens would no longer display Social Insurance Numbers, birth dates, and health information. As the complainant's concerns were addressed, the case was considered settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #7 — A national transportation company

Feb 27, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An employee of a national transportation company complained about the security of personal information in an automated crew management system. The complainant was concerned that unauthorized personnel, particularly union representatives, could access sensitive data like date of birth, social insurance number, wage rates, and vacation eligibility. While some information was not accessible to union representatives, the company agreed to modify the system. The adjustments ensured that screens would no longer display Social Insurance Numbers, birth dates, and health information. As the complainant's concerns were addressed, the case was considered settled.

Key Issues
  • Whether employee personal information in an automated crew management system was adequately protected from unauthorized access
  • Whether union representatives had unauthorized access to sensitive employee personal information