The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

4 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 15, 2007Settled Case summary #30Indexed Jun 30, 2026

Settled Case summary #30: Solicitor’s lien insufficient grounds to deny access to personal information (November 15, 2007)

A law firm

A client sought access to her personal information from her former lawyer. The lawyer refused access, citing outstanding fees and asserting a solicitor's lien on the client's file, believing that providing access could jeopardize payment. The OPC noted that PIPEDA's subsection 9(3) provides an exhaustive list of reasons for refusing access, which does not include a solicitor's lien. Therefore, lawyers must grant access to personal information even if a valid lien exists. The OPC suggested that allowing the individual to view, but not copy, the information could balance the right to access with the lien. The lawyer subsequently provided a complete copy of the file, and the complaint was settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #30: Solicitor’s lien insufficient grounds to deny access to personal information (November 15, 2007)

Nov 15, 2007Settled Case summary #30
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A client sought access to her personal information from her former lawyer. The lawyer refused access, citing outstanding fees and asserting a solicitor's lien on the client's file, believing that providing access could jeopardize payment. The OPC noted that PIPEDA's subsection 9(3) provides an exhaustive list of reasons for refusing access, which does not include a solicitor's lien. Therefore, lawyers must grant access to personal information even if a valid lien exists. The OPC suggested that allowing the individual to view, but not copy, the information could balance the right to access with the lien. The lawyer subsequently provided a complete copy of the file, and the complaint was settled.

Key Issues
  • Whether a solicitor's lien is a valid ground to refuse access to personal information under PIPEDA
  • Whether subsection 9(3) of PIPEDA provides an exhaustive list of circumstances for refusing access
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 2, 2007Executive SummaryIndexed Jun 30, 2026

Executive Summary: Privacy Commissioner of Canada v. SWIFT

SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication)

The Privacy Commissioner of Canada launched an investigation into SWIFT SCRL following allegations that it disclosed personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) via administrative subpoenas. SWIFT provides messaging services to financial institutions globally, and some messages contain personal information. The Commissioner determined that SWIFT was subject to PIPEDA due to its operations and significant presence in Canada. While acknowledging SWIFT's compliance with US laws, the Commissioner found that SWIFT had not contravened PIPEDA, as the Act allows for disclosure without consent in response to a subpoena from a body with jurisdiction to compel information. The Commissioner emphasized that organizations operating in Canada must still abide by PIPEDA, even when subject to foreign laws. She also recommended that US authorities use existing information-sharing mechanisms with built-in privacy protections rather than subpoenas for Canadian-related financial information.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Executive Summary: Privacy Commissioner of Canada v. SWIFT

Apr 2, 2007Executive Summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Privacy Commissioner of Canada launched an investigation into SWIFT SCRL following allegations that it disclosed personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) via administrative subpoenas. SWIFT provides messaging services to financial institutions globally, and some messages contain personal information. The Commissioner determined that SWIFT was subject to PIPEDA due to its operations and significant presence in Canada. While acknowledging SWIFT's compliance with US laws, the Commissioner found that SWIFT had not contravened PIPEDA, as the Act allows for disclosure without consent in response to a subpoena from a body with jurisdiction to compel information. The Commissioner emphasized that organizations operating in Canada must still abide by PIPEDA, even when subject to foreign laws. She also recommended that US authorities use existing information-sharing mechanisms with built-in privacy protections rather than subpoenas for Canadian-related financial information.

Key Issues
  • Whether SWIFT is subject to PIPEDA
  • Whether SWIFT contravened PIPEDA by disclosing personal information to the US Department of the Treasury
  • Whether the exception to consent for disclosures in response to a subpoena applies
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 2, 2007Report of FindingsIndexed Jun 30, 2026

Report of Findings: Privacy Commissioner of Canada v. SWIFT

SWIFT SCRL

The Privacy Commissioner of Canada initiated a complaint against SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication) for allegedly disclosing personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) in response to administrative subpoenas. SWIFT, a global financial messaging service, argued it was legally compelled to comply with valid US subpoenas and had negotiated privacy protections with the UST. The OPC first determined that the Personal Information Protection and Electronic Documents Act (PIPEDA) applied to SWIFT due to its significant presence and commercial activities in Canada. The key issue was whether SWIFT's disclosure without consent complied with PIPEDA, specifically the exception for subpoenas under paragraph 7(3)(c) and the appropriateness of the disclosure under subsection 5(3). The Commissioner concluded that paragraph 7(3)(c) allows for compliance with valid foreign subpoenas when an organization operates in multiple jurisdictions and legitimately stores data abroad, and that the disclosure was appropriate given the legal compulsion and privacy safeguards SWIFT negotiated. Consequently, the complaint was found not well-founded, as SWIFT's actions did not contravene PIPEDA. The Commissioner, however, recommended that the Canadian government engage with US counterparts to encourage the use of existing information-sharing mechanisms with built-in privacy protections, and noted SWIFT's efforts to explore enhanced privacy solutions.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Report of Findings: Privacy Commissioner of Canada v. SWIFT

Apr 2, 2007Report of Findings
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Privacy Commissioner of Canada initiated a complaint against SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication) for allegedly disclosing personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) in response to administrative subpoenas. SWIFT, a global financial messaging service, argued it was legally compelled to comply with valid US subpoenas and had negotiated privacy protections with the UST. The OPC first determined that the Personal Information Protection and Electronic Documents Act (PIPEDA) applied to SWIFT due to its significant presence and commercial activities in Canada. The key issue was whether SWIFT's disclosure without consent complied with PIPEDA, specifically the exception for subpoenas under paragraph 7(3)(c) and the appropriateness of the disclosure under subsection 5(3). The Commissioner concluded that paragraph 7(3)(c) allows for compliance with valid foreign subpoenas when an organization operates in multiple jurisdictions and legitimately stores data abroad, and that the disclosure was appropriate given the legal compulsion and privacy safeguards SWIFT negotiated. Consequently, the complaint was found not well-founded, as SWIFT's actions did not contravene PIPEDA. The Commissioner, however, recommended that the Canadian government engage with US counterparts to encourage the use of existing information-sharing mechanisms with built-in privacy protections, and noted SWIFT's efforts to explore enhanced privacy solutions.

Key Issues
  • Whether the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to SWIFT’s collection, use, and disclosure of personal information in the course of its operations in Canada.
  • Whether SWIFT is engaged in a commercial activity within Canada under paragraph 4(1)(a) of PIPEDA.
  • Whether personal information collected by SWIFT from Canadian financial institutions was disclosed to US authorities in accordance with PIPEDA.
  • Whether the disclosure of personal information without knowledge or consent was permitted under paragraph 7(3)(c) of PIPEDA (subpoena exception).
  • Whether a "subpoena or warrant" under paragraph 7(3)(c) must be issued only by a body within Canada.
  • Whether SWIFT’s disclosure to the UST was appropriate in the circumstances, as per subsection 5(3) of PIPEDA.
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Feb 5, 2007Settled Case summary #29Indexed Jun 30, 2026

Settled case summary #29 — A department store

A department store

An individual complained that a department store's method of collecting tax exemption information allowed other customers to view her personal data and the data of previous customers. The store used a petition-style form where customers wrote their names, shopping dates, and tax exemption numbers, making this information visible to subsequent customers. The complainant was concerned about the lack of privacy for her personal information. In response to the complaint, the department store first implemented a temporary measure of using a new form where only one customer's information appeared per page. Subsequently, the store reconfigured its cash registers to electronically print a receipt-style form for tax exemptions, which was then completed by the customer and securely stored in the register. This new electronic system prevented customers from viewing each other's personal information. The complainant was satisfied with these changes, and the matter was considered settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #29 — A department store

Feb 5, 2007Settled Case summary #29
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a department store's method of collecting tax exemption information allowed other customers to view her personal data and the data of previous customers. The store used a petition-style form where customers wrote their names, shopping dates, and tax exemption numbers, making this information visible to subsequent customers. The complainant was concerned about the lack of privacy for her personal information. In response to the complaint, the department store first implemented a temporary measure of using a new form where only one customer's information appeared per page. Subsequently, the store reconfigured its cash registers to electronically print a receipt-style form for tax exemptions, which was then completed by the customer and securely stored in the register. This new electronic system prevented customers from viewing each other's personal information. The complainant was satisfied with these changes, and the matter was considered settled.

Key Issues
  • Whether the department store's method of collecting tax exemption information allowed unauthorized disclosure of personal information to other customers
  • Whether the department store adequately safeguarded customers' personal information