The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

18 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Dec 18, 2015PIPEDA findings #2015-021Indexed Jun 30, 2026

PIPEDA findings #2015-021: Telecom company responsible for erroneous debt collection calls

A telecommunications company

An individual complained that a telecommunications company continued to report a debt to a credit-reporting agency and that a collection agency was still contacting her, despite the debt being discharged in bankruptcy years prior. This inaccurate reporting was hindering her ability to rebuild her credit score. The telecommunications company investigated and found that an internal manual process error had caused the information to be overlooked. The company subsequently corrected its records, notified the credit-reporting agency of the updated information, and ensured that all collection activities against the complainant would cease. The complainant expressed satisfaction with the resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

PIPEDA findings #2015-021: Telecom company responsible for erroneous debt collection calls

Dec 18, 2015PIPEDA findings #2015-021
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a telecommunications company continued to report a debt to a credit-reporting agency and that a collection agency was still contacting her, despite the debt being discharged in bankruptcy years prior. This inaccurate reporting was hindering her ability to rebuild her credit score. The telecommunications company investigated and found that an internal manual process error had caused the information to be overlooked. The company subsequently corrected its records, notified the credit-reporting agency of the updated information, and ensured that all collection activities against the complainant would cease. The complainant expressed satisfaction with the resolution.

Key Issues
  • Whether the telecommunications company maintained sufficiently accurate personal information (Principle 4.6 PIPEDA)
  • Whether the telecommunications company appropriately disclosed accurate personal information to a third party (Principle 4.6 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 15, 2015PIPEDA Case Summary #2015-014Indexed Jun 30, 2026

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

A pension and benefit provider

An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

Dec 15, 2015PIPEDA Case Summary #2015-014
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.

Key Issues
  • Whether the provider disclosed the complainant's unique identifier to a third party without consent (Principle 4.3 PIPEDA)
  • Whether the provider failed to keep the complainant's address information accurate (Principle 4.6 PIPEDA)
  • Whether the provider failed to implement appropriate safeguards to protect personal information from unauthorized disclosure and modification (Principle 4.7 PIPEDA)
  • Whether proper authentication of the caller took place before the complainant's ID number was given out (Principle 4.7.1 PIPEDA)
  • Whether the provider's failure to detect and correct the erroneous address sooner constituted a contravention of Principle 4.6.1 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Dec 2, 2015Discontinued Case Summary #2015-001Indexed Jun 30, 2026

Discontinued Case Summary #2015-001: Real estate management company responds fairly and reasonably to surveillance camera concerns

A real estate management company

An individual complained that a real estate management company collected his personal information without consent through surveillance cameras. He alleged inadequate signage and over-collection when a camera was focused on him after a dispute about his service dog. The company responded by posting new, clearer signage about video surveillance at all entrances, including the one previously lacking. They also addressed the over-collection concern by explaining that a new security guard had mistakenly focused the camera, and provided additional training to staff regarding service animals. The OPC found the company's response to be fair and reasonable, addressing the complainant's concerns proactively. Consequently, the investigation was discontinued.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Discontinued Case Summary #2015-001: Real estate management company responds fairly and reasonably to surveillance camera concerns

Dec 2, 2015Discontinued Case Summary #2015-001
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a real estate management company collected his personal information without consent through surveillance cameras. He alleged inadequate signage and over-collection when a camera was focused on him after a dispute about his service dog. The company responded by posting new, clearer signage about video surveillance at all entrances, including the one previously lacking. They also addressed the over-collection concern by explaining that a new security guard had mistakenly focused the camera, and provided additional training to staff regarding service animals. The OPC found the company's response to be fair and reasonable, addressing the complainant's concerns proactively. Consequently, the investigation was discontinued.

Key Issues
  • Whether the organization collected personal information without adequate signage for video surveillance
  • Whether the organization over-collected personal information by focusing a camera on the complainant
  • Whether the organization's response to the concerns was fair and reasonable under paragraph 12.2(1)(c) of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 10, 2015PIPEDA Case Summary #2015-015Indexed Jun 30, 2026

PIPEDA Case Summary #2015-015: Roofing company takes measures to ensure sub-contractors follow its privacy policy

A roofing company (the "second roofer")

An individual complained that an estimator working for a roofing company (the "second roofer") disclosed his personal financial situation and contractual history to a competitor (the "first roofer") without his consent. The individual had engaged the second roofer for an estimate to fix issues with work done by the first roofer, and later cancelled a contract with the second roofer. The OPC found that the estimator was acting as an agent for the second roofer, making the second roofer responsible for the estimator's actions. The OPC concluded that the disclosure of personal information without the individual's knowledge or consent contravened Principle 4.3 of PIPEDA. The second roofer subsequently implemented recommendations to establish agreements with sub-contractors to adhere to its privacy policy and provide training. As a result, the complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2015-015: Roofing company takes measures to ensure sub-contractors follow its privacy policy

Nov 10, 2015PIPEDA Case Summary #2015-015
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an estimator working for a roofing company (the "second roofer") disclosed his personal financial situation and contractual history to a competitor (the "first roofer") without his consent. The individual had engaged the second roofer for an estimate to fix issues with work done by the first roofer, and later cancelled a contract with the second roofer. The OPC found that the estimator was acting as an agent for the second roofer, making the second roofer responsible for the estimator's actions. The OPC concluded that the disclosure of personal information without the individual's knowledge or consent contravened Principle 4.3 of PIPEDA. The second roofer subsequently implemented recommendations to establish agreements with sub-contractors to adhere to its privacy policy and provide training. As a result, the complaint was deemed well-founded and resolved.

Key Issues
  • Whether the estimator was acting as an agent of the second roofer
  • Whether the second roofer was responsible for the personal information handling practices of its estimator
  • Whether personal information was disclosed without the individual's knowledge or consent
  • Whether the disclosure contravened Principle 4.3 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Oct 26, 2015Early resolved case summary #2015-02Indexed Jun 30, 2026

Early resolved case summary #2015-02: Retailer takes remedial actions after employee inappropriately texted customer

A retailer

An individual complained to the OPC after a retailer's delivery person inappropriately texted her using her phone number, which he had transferred from his faulty work phone to his personal device. The complainant also felt the retailer's management initially showed a lack of concern. The OPC's inquiries revealed the delivery person obtained the customer's number from his work phone. The retailer, disapproving of employees transferring customer information to personal devices, subsequently implemented a new policy requiring delivery employees with faulty work phones to return to the warehouse immediately. The retailer also took disciplinary action against the delivery person, provided mandatory privacy retraining to employees, and the company president met personally with the affected customer. The customer was satisfied with the actions taken by the retailer.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-02: Retailer takes remedial actions after employee inappropriately texted customer

Oct 26, 2015Early resolved case summary #2015-02
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after a retailer's delivery person inappropriately texted her using her phone number, which he had transferred from his faulty work phone to his personal device. The complainant also felt the retailer's management initially showed a lack of concern. The OPC's inquiries revealed the delivery person obtained the customer's number from his work phone. The retailer, disapproving of employees transferring customer information to personal devices, subsequently implemented a new policy requiring delivery employees with faulty work phones to return to the warehouse immediately. The retailer also took disciplinary action against the delivery person, provided mandatory privacy retraining to employees, and the company president met personally with the affected customer. The customer was satisfied with the actions taken by the retailer.

Key Issues
  • Whether the delivery person's use of customer information for personal communication was appropriate
  • Whether the retailer adequately protected customer personal information when work devices were faulty
  • Whether the retailer responded appropriately to the customer's complaint
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Aug 14, 2015Early resolved case summary #2015-07Indexed Jun 30, 2026

Early resolved case summary #2015-07: Employee training a key factor in effectively satisfying customers’ requests about an organization’s personal information handling practices

A car dealership

An individual complained that a car dealership could not provide details about its personal information handling practices. The complainant was asked for her driver's license and credit card for a loaner car, and when she inquired about the collection and safeguards, the employee could not provide satisfactory answers. Her subsequent email to the dealership's privacy officer also went unanswered. The OPC conducted a site visit and reviewed the dealership's policies and practices, finding them satisfactory. However, the OPC emphasized the need for employees to be knowledgeable about these practices. The dealership agreed to conduct a review session for its employees. The complainant was satisfied with the outcome, and the matter was early resolved.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-07: Employee training a key factor in effectively satisfying customers’ requests about an organization’s personal information handling practices

Aug 14, 2015Early resolved case summary #2015-07
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a car dealership could not provide details about its personal information handling practices. The complainant was asked for her driver's license and credit card for a loaner car, and when she inquired about the collection and safeguards, the employee could not provide satisfactory answers. Her subsequent email to the dealership's privacy officer also went unanswered. The OPC conducted a site visit and reviewed the dealership's policies and practices, finding them satisfactory. However, the OPC emphasized the need for employees to be knowledgeable about these practices. The dealership agreed to conduct a review session for its employees. The complainant was satisfied with the outcome, and the matter was early resolved.

Key Issues
  • Whether the car dealership provided sufficient details about its personal information handling practices upon request
  • Whether the car dealership's employees were adequately trained to answer questions about personal information collection, safeguards, and retention
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Aug 1, 2015Early resolved case summary #2015-04Indexed Jun 30, 2026

Early resolved case summary #2015-04: Misidentification and lack of access to personal information leads to mistaken four-year debt pursuit

A collection agency

An individual complained that a collection agency was pursuing him for a debt he did not owe, which was negatively impacting his credit report. The individual alleged that the agency had been calling him for years and disclosed his financial information to his household members. He also claimed he was denied access to documentation validating the debt. The OPC contacted the collection agency, which then investigated the matter after discrepancies were noted in the original credit application. The agency ceased debt collection, acknowledged possible fraud, and committed to correcting the individual's credit report. The individual was satisfied with this resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-04: Misidentification and lack of access to personal information leads to mistaken four-year debt pursuit

Aug 1, 2015Early resolved case summary #2015-04
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a collection agency was pursuing him for a debt he did not owe, which was negatively impacting his credit report. The individual alleged that the agency had been calling him for years and disclosed his financial information to his household members. He also claimed he was denied access to documentation validating the debt. The OPC contacted the collection agency, which then investigated the matter after discrepancies were noted in the original credit application. The agency ceased debt collection, acknowledged possible fraud, and committed to correcting the individual's credit report. The individual was satisfied with this resolution.

Key Issues
  • Whether the collection agency ensured the accuracy of personal information used for debt collection (Principle 4.5 PIPEDA)
  • Whether the collection agency provided the individual with access to his personal information (Principle 4.9 PIPEDA)
  • Whether the collection agency disclosed personal financial information to third parties without consent (Principle 4.3 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jul 28, 2015Discontinued Case Summary #2015-002Indexed Jun 30, 2026

Discontinued Case Summary #2015-002: OPC discontinues additional complaints against Globe24h.com following investigation into same privacy issues

Globe24h.com

Multiple complainants alleged that Globe24h.com collected, used, and disclosed their personal information without consent by republishing Canadian court and tribunal decisions and charging for removal. The OPC had previously investigated similar complaints against Globe24h.com and found them to be well-founded. Despite this, additional complaints continued to be received. The OPC decided to discontinue these new complaints under paragraph 12.2(1)(e) of PIPEDA, as the matter had already been the subject of a Commissioner's report. The OPC noted its continued interest in Globe24h.com's compliance and later participated in a Federal Court proceeding initiated by one of the original complainants. The Federal Court ultimately confirmed the OPC's findings and ordered Globe24h.com to remove the information and cease contravening PIPEDA, leading to the website's closure.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Discontinued Case Summary #2015-002: OPC discontinues additional complaints against Globe24h.com following investigation into same privacy issues

Jul 28, 2015Discontinued Case Summary #2015-002
Adjudicator: Daniel Therrien
Plain-Language Summary

Multiple complainants alleged that Globe24h.com collected, used, and disclosed their personal information without consent by republishing Canadian court and tribunal decisions and charging for removal. The OPC had previously investigated similar complaints against Globe24h.com and found them to be well-founded. Despite this, additional complaints continued to be received. The OPC decided to discontinue these new complaints under paragraph 12.2(1)(e) of PIPEDA, as the matter had already been the subject of a Commissioner's report. The OPC noted its continued interest in Globe24h.com's compliance and later participated in a Federal Court proceeding initiated by one of the original complainants. The Federal Court ultimately confirmed the OPC's findings and ordered Globe24h.com to remove the information and cease contravening PIPEDA, leading to the website's closure.

Key Issues
  • Whether Globe24h.com collected, used, and disclosed personal information without consent
  • Whether the Commissioner should discontinue investigation of additional complaints when the matter has already been reported on
  • Whether the practices of Globe24h.com contravened PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Jul 22, 2015PIPEDA findings #2015-019Indexed Jun 30, 2026

PIPEDA findings #2015-019: OPC complaint prompts telecom’s fraud investigation

A telecommunications company

A complainant reported a fraudulent telecommunications account causing a false debt statement on their credit report. The complainant alleged they never lived at the address associated with the debt, and the telecommunications company initially refused to correct the debt or provide proof of account opening. The credit-reporting agency had validated the debt with the telecom company. Upon the OPC's intervention, the telecommunications company's fraud team reviewed the file and determined the account was fraudulent. The company then cancelled the fraudulent account and updated the credit-reporting agency with accurate information. The complainant was satisfied with these actions, leading to an early resolution.

Quick view

Personal Information Protection and Electronic Documents ActResolved

PIPEDA findings #2015-019: OPC complaint prompts telecom’s fraud investigation

Jul 22, 2015PIPEDA findings #2015-019
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant reported a fraudulent telecommunications account causing a false debt statement on their credit report. The complainant alleged they never lived at the address associated with the debt, and the telecommunications company initially refused to correct the debt or provide proof of account opening. The credit-reporting agency had validated the debt with the telecom company. Upon the OPC's intervention, the telecommunications company's fraud team reviewed the file and determined the account was fraudulent. The company then cancelled the fraudulent account and updated the credit-reporting agency with accurate information. The complainant was satisfied with these actions, leading to an early resolution.

Key Issues
  • Whether the telecommunications company failed to ensure the accuracy of personal information
  • Whether the telecommunications company failed to correct inaccurate personal information
  • Whether the credit-reporting agency failed to ensure the accuracy of personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jul 9, 2015Early resolved case summary #2015-01Indexed Jun 30, 2026

Early resolved case summary #2015-01: Store stops practice of posting pictures of suspected shoplifters - July 2015

A department store

A customer complained to the OPC after noticing a department store publicly displaying photographs of individuals, asking for information about them. The store claimed police and legal counsel advised this practice was permissible for alleged shoplifters. The OPC disagreed, explaining that publicly disclosing personal information (photographs) without consent is not allowed under PIPEDA. The store agreed to remove the pictures and discontinue the practice, opting to deal with police directly for such matters. The complainant was satisfied with this resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-01: Store stops practice of posting pictures of suspected shoplifters - July 2015

Jul 9, 2015Early resolved case summary #2015-01
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained to the OPC after noticing a department store publicly displaying photographs of individuals, asking for information about them. The store claimed police and legal counsel advised this practice was permissible for alleged shoplifters. The OPC disagreed, explaining that publicly disclosing personal information (photographs) without consent is not allowed under PIPEDA. The store agreed to remove the pictures and discontinue the practice, opting to deal with police directly for such matters. The complainant was satisfied with this resolution.

Key Issues
  • Whether publicly displaying photographs of suspected shoplifters without consent constitutes an unauthorized disclosure of personal information under PIPEDA
  • Whether photographs of individuals recorded on video surveillance are considered personal information under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 6, 2015PIPEDA Case Summary #2015-010Indexed Jun 30, 2026

PIPEDA Case Summary #2015-010: Customer’s emails sent to her acquaintance following a telecom employee’s attempt to fix a problem with the customer’s email service

A telecommunications provider

An individual complained that her telecommunications provider disclosed her personal information without consent. A technical support representative, while attempting to fix her email service, inadvertently configured her email application to automatically forward her emails, including one containing a temporary password, to an acquaintance. The OPC found that this constituted a disclosure of personal information without consent, contravening Principle 4.3. The telecom provider initially provided inaccurate information to the OPC regarding corrective measures taken, but later clarified its existing measures. The complaint was found to be well-founded and resolved, as the provider had some measures in place to prevent recurrence, despite the initial misrepresentations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2015-010: Customer’s emails sent to her acquaintance following a telecom employee’s attempt to fix a problem with the customer’s email service

Jul 6, 2015PIPEDA Case Summary #2015-010
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that her telecommunications provider disclosed her personal information without consent. A technical support representative, while attempting to fix her email service, inadvertently configured her email application to automatically forward her emails, including one containing a temporary password, to an acquaintance. The OPC found that this constituted a disclosure of personal information without consent, contravening Principle 4.3. The telecom provider initially provided inaccurate information to the OPC regarding corrective measures taken, but later clarified its existing measures. The complaint was found to be well-founded and resolved, as the provider had some measures in place to prevent recurrence, despite the initial misrepresentations.

Key Issues
  • Whether the telecommunications provider disclosed the individual's personal information without consent
  • Whether the disclosure contravened Principle 4.3 of PIPEDA
  • Whether the telecommunications provider provided accurate information to the OPC during the investigation
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jun 28, 2015Early resolved case summary #2015-05Indexed Jun 30, 2026

Early resolved case summary #2015-05: Anti-virus service provider steps up safeguards after customer personal information fraudulently used by someone posing as an employee

Anti-virus service provider

A couple received fraudulent calls from someone posing as an anti-virus service provider technician, who gained remote access to their computer and processed a fraudulent credit card payment. The fraudster used the couple's private account number, which they believed was obtained from the legitimate service provider. The couple struggled to get the service provider to investigate the matter, leading them to file a complaint with the OPC. The OPC requested the service provider conduct an investigation, which revealed an employee had improperly accessed the complainant's account. The employee was dismissed, and the service provider reimbursed the couple and implemented new safeguards, including an auditing system for employee access and a streamlined procedure for escalating privacy concerns. The complainants were satisfied with these outcomes.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-05: Anti-virus service provider steps up safeguards after customer personal information fraudulently used by someone posing as an employee

Jun 28, 2015Early resolved case summary #2015-05
Adjudicator: Daniel Therrien
Plain-Language Summary

A couple received fraudulent calls from someone posing as an anti-virus service provider technician, who gained remote access to their computer and processed a fraudulent credit card payment. The fraudster used the couple's private account number, which they believed was obtained from the legitimate service provider. The couple struggled to get the service provider to investigate the matter, leading them to file a complaint with the OPC. The OPC requested the service provider conduct an investigation, which revealed an employee had improperly accessed the complainant's account. The employee was dismissed, and the service provider reimbursed the couple and implemented new safeguards, including an auditing system for employee access and a streamlined procedure for escalating privacy concerns. The complainants were satisfied with these outcomes.

Key Issues
  • Whether the anti-virus service provider adequately protected personal information against unauthorized access by employees (Principle 4.7 PIPEDA)
  • Whether the anti-virus service provider had adequate procedures to receive and respond to complaints about personal information handling (Principle 4.10 PIPEDA)
  • Whether the anti-virus service provider adequately investigated the complaint (Principle 4.10.4 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
May 22, 2015Early resolved case summary #2015-06Indexed Jun 30, 2026

Early resolved case summary #2015-06: Manager snoops on employee’s personal bank account after employee calls in sick

A credit union

An employee of a credit union complained that her manager accessed her personal financial information without consent. The manager suspected the employee had falsely called in sick and checked her bank account transactions to see if she had used her debit card out of province. The employee discovered this when her employment was terminated and the manager referenced the incident. After receiving an inconclusive response from the credit union, she filed a complaint with the OPC. The OPC initiated its early resolution process, and the credit union acknowledged the manager's actions were without a valid business purpose and constituted an unauthorized use of personal information. The credit union committed to addressing the issue with the manager and sent a letter of apology to the employee. The employee was satisfied with this resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-06: Manager snoops on employee’s personal bank account after employee calls in sick

May 22, 2015Early resolved case summary #2015-06
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee of a credit union complained that her manager accessed her personal financial information without consent. The manager suspected the employee had falsely called in sick and checked her bank account transactions to see if she had used her debit card out of province. The employee discovered this when her employment was terminated and the manager referenced the incident. After receiving an inconclusive response from the credit union, she filed a complaint with the OPC. The OPC initiated its early resolution process, and the credit union acknowledged the manager's actions were without a valid business purpose and constituted an unauthorized use of personal information. The credit union committed to addressing the issue with the manager and sent a letter of apology to the employee. The employee was satisfied with this resolution.

Key Issues
  • Whether a manager accessing an employee's personal bank account without a valid business purpose constitutes unauthorized use of personal information under PIPEDA
  • Whether the credit union's actions to address the manager's conduct and apologize to the employee were satisfactory for early resolution
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

An organization

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Key Issues
  • Whether the disclosed leave information constituted personal information under PIPEDA
  • Whether the organization's purposes for disclosing employee leave information to other employees were appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the disclosure of leave type was necessary for the organization to meet its employee schedule management needs
  • Whether the benefits of the leave exchange system were proportional to the loss of privacy experienced by employees
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 23, 2015PIPEDA Report of Findings #2015-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

An investment brokerage

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 23, 2015PIPEDA Report of Findings #2015-006
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Key Issues
  • Whether the collection of net worth, marital status, and spouse's occupation was necessary for opening a self-directed investment account under Principle 4.4 PIPEDA
  • Whether the purposes for collecting the personal information were explicitly specified under Principle 4.2 PIPEDA
  • Whether the purposes for collecting the personal information were legitimate and appropriate under subsection 5(3) PIPEDA
  • Whether the organization required consent to the collection of information beyond that required for explicitly specified and legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA