The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

7 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 20, 2018PIPEDA Report of Findings #2018-004Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-004: Microsoft to obtain opt-in consent, enhance transparency for Windows 10 privacy settings

Microsoft

An anonymous complainant raised concerns that Microsoft Windows 10 defaulted several privacy settings to "on" during installation, and these settings were difficult to understand and change. The OPC investigated whether Microsoft obtained valid consent for collecting, using, and disclosing personal information via these default settings. Initial concerns about clarity and consistency were shared with Microsoft regarding the original Windows 10 version. Following the Creators Update, the OPC identified further issues, particularly regarding the meaningfulness of consent for Location, Diagnostics, Tailored Experiences, Relevant Ads, and Speech Recognition settings, noting confusion caused by conflating related practices. Microsoft cooperated and committed to implementing changes, including obtaining opt-in consent for all installation privacy settings, enhancing transparency, and correcting the functioning of Speech Recognition. The OPC found the complaint well-founded and conditionally resolved, pending Microsoft's implementation of these commitments by the end of 2018.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-004: Microsoft to obtain opt-in consent, enhance transparency for Windows 10 privacy settings

Jun 20, 2018PIPEDA Report of Findings #2018-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant raised concerns that Microsoft Windows 10 defaulted several privacy settings to "on" during installation, and these settings were difficult to understand and change. The OPC investigated whether Microsoft obtained valid consent for collecting, using, and disclosing personal information via these default settings. Initial concerns about clarity and consistency were shared with Microsoft regarding the original Windows 10 version. Following the Creators Update, the OPC identified further issues, particularly regarding the meaningfulness of consent for Location, Diagnostics, Tailored Experiences, Relevant Ads, and Speech Recognition settings, noting confusion caused by conflating related practices. Microsoft cooperated and committed to implementing changes, including obtaining opt-in consent for all installation privacy settings, enhancing transparency, and correcting the functioning of Speech Recognition. The OPC found the complaint well-founded and conditionally resolved, pending Microsoft's implementation of these commitments by the end of 2018.

Key Issues
  • Whether Microsoft obtained valid and meaningful consent for the collection, use, and disclosure of personal information through Windows 10 default privacy settings.
  • Whether the initial Windows 10 (Version 1507) installation process provided sufficient prominence for customizing settings and adequate information via "Learn more" links.
  • Whether the explanations for Advertising ID and Diagnostics settings in Version 1507 were clear, consistent, and comprehensive.
  • Whether opt-out consent was appropriate for the Location setting in the Creators Update, and if Microsoft's explanations were sufficiently transparent regarding exceptions and the use of "de-identified location information."
  • Whether "Full" Diagnostics should be the default setting, and if Microsoft's transparency regarding data collected at this level was adequate for meaningful consent.
  • Whether Microsoft obtained valid consent for Tailored Experiences, particularly concerning the use of broad diagnostic data and the protection of sensitive information.
  • Whether Microsoft's practices for Tailored Experiences complied with accountability requirements under Principle 4.1.4.
  • Whether opt-out consent was appropriate for the Relevant Ads (Advertising ID) setting, and if Microsoft's communications clearly distinguished it from its own advertising program.
  • Whether opt-out consent was appropriate for the Speech Recognition setting, given the sensitivity of voice data and its cloud-based nature.
  • Whether Microsoft's explanations for Speech Recognition clearly distinguished between cloud-based and device-based functionality.
  • Whether Microsoft consistently respected user choices regarding the Speech Recognition setting, especially when conflicting with Cortana settings.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 12, 2018PIPEDA Report of Findings #2018-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-002: Company’s re-use of millions of Canadian Facebook user profiles violated privacy law

Profile Technology Ltd.

Multiple complainants alleged that Profile Technology Ltd. copied their personal information from Facebook profiles and groups without consent and posted it on its social networking website, making removal difficult, and indefinitely retaining helpdesk information. The OPC asserted jurisdiction over the New Zealand-based company due to a real and substantial connection to Canada. The OPC found that the information was not "publicly available" under PIPEDA's Regulations, and Profile Technology failed to obtain valid consent for its new purpose of operating a social networking site. Furthermore, the OPC determined that using this information for such a purpose was not appropriate in the circumstances and that the indefinite retention of helpdesk ticket information violated retention principles. Profile Technology refused to implement recommendations for deletion and a retention policy. Although the company later removed profiles from its website, it uploaded much of the data to the Internet Archive, which the OPC found did not resolve the contraventions and created new privacy risks. The matter was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2018-002: Company’s re-use of millions of Canadian Facebook user profiles violated privacy law

Jun 12, 2018PIPEDA Report of Findings #2018-002
Adjudicator: Daniel Therrien
Plain-Language Summary

Multiple complainants alleged that Profile Technology Ltd. copied their personal information from Facebook profiles and groups without consent and posted it on its social networking website, making removal difficult, and indefinitely retaining helpdesk information. The OPC asserted jurisdiction over the New Zealand-based company due to a real and substantial connection to Canada. The OPC found that the information was not "publicly available" under PIPEDA's Regulations, and Profile Technology failed to obtain valid consent for its new purpose of operating a social networking site. Furthermore, the OPC determined that using this information for such a purpose was not appropriate in the circumstances and that the indefinite retention of helpdesk ticket information violated retention principles. Profile Technology refused to implement recommendations for deletion and a retention policy. Although the company later removed profiles from its website, it uploaded much of the data to the Internet Archive, which the OPC found did not resolve the contraventions and created new privacy risks. The matter was found to be well-founded.

Key Issues
  • Whether the OPC had jurisdiction to investigate a New Zealand-based company's activities affecting Canadians.
  • Whether the investigation was time-barred under subsection 13(1) of PIPEDA.
  • Whether PIPEDA's application to commercial activity is constitutionally valid under the federal Trade and Commerce power.
  • Whether personal information copied from Facebook profiles was "publicly available" under PIPEDA's Regulations Specifying Publicly Available Information.
  • Whether Facebook profiles constitute a "publication" for the purposes of the Regulations.
  • Whether Profile Technology obtained valid knowledge and consent (Principle 4.3 PIPEDA) for the collection, use, and disclosure of personal information for its social networking website.
  • Whether consent obtained by Facebook was sufficient for Profile Technology's subsequent use of the data.
  • Whether opt-out consent would be an appropriate form of consent in this context (Principle 4.3.4 PIPEDA).
  • Whether Profile Technology's use of Facebook profile information for its social networking site was for purposes a reasonable person would consider "appropriate in the circumstances" (subsection 5(3) PIPEDA).
  • Whether Profile Technology retained personal information (helpdesk tickets) longer than necessary (Principle 4.5 PIPEDA).
  • Whether Profile Technology was responsible for personal information held by its third-party helpdesk service provider.
  • Whether Profile Technology's actions of removing profiles from its website and uploading data to the Internet Archive resolved the identified contraventions.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 24, 2018PIPEDA Report of Findings #2018-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-003: Facebook agrees to stop using non-users’ personal information in users’ address books

Facebook Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Facebook Inc. following a 2013 privacy breach where contact information, including that of non-users, was inadvertently disclosed via the 'Download Your Information' (DYI) tool. The investigation focused on Facebook's safeguards, consent practices for its 'matching across address books' process for both users and non-users, and the ability for individuals to access and correct their personal information. The OPC found Facebook's safeguards inadequate prior to the breach, but deemed the issue resolved after Facebook implemented a new Privacy Framework. While Facebook's use of user contact information for matching was found not to contravene consent principles, the OPC determined Facebook was not sufficiently open about these practices, an issue conditionally resolved by Facebook's commitment to revise its notices. The OPC also found Facebook used non-users' personal information for matching without meaningful consent, an issue resolved by Facebook's agreement to stop maintaining such data. Finally, Facebook was found not to be providing adequate access to and correction of matched data, which was resolved through an interim solution.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-003: Facebook agrees to stop using non-users’ personal information in users’ address books

May 24, 2018PIPEDA Report of Findings #2018-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Facebook Inc. following a 2013 privacy breach where contact information, including that of non-users, was inadvertently disclosed via the 'Download Your Information' (DYI) tool. The investigation focused on Facebook's safeguards, consent practices for its 'matching across address books' process for both users and non-users, and the ability for individuals to access and correct their personal information. The OPC found Facebook's safeguards inadequate prior to the breach, but deemed the issue resolved after Facebook implemented a new Privacy Framework. While Facebook's use of user contact information for matching was found not to contravene consent principles, the OPC determined Facebook was not sufficiently open about these practices, an issue conditionally resolved by Facebook's commitment to revise its notices. The OPC also found Facebook used non-users' personal information for matching without meaningful consent, an issue resolved by Facebook's agreement to stop maintaining such data. Finally, Facebook was found not to be providing adequate access to and correction of matched data, which was resolved through an interim solution.

Key Issues
  • Whether FB had appropriate safeguards in place prior to the breach to protect contact information of users and non-users.
  • Whether FB implemented appropriate safeguards after the breach.
  • Whether FB was using the personal information of users and non-users during the process of matching across address books.
  • Whether FB was obtaining meaningful consent from users for the use of personal information during the matching process.
  • Whether FB was meeting its obligation to be open about its policies and practices regarding the matching process for users.
  • Whether FB was obtaining meaningful consent from non-users for the use of personal information during the matching process.
  • Whether FB was providing users and non-users the ability to obtain access to their personal information/data.
  • Whether FB was providing users and non-users the ability to correct their personal information/data.
  • Whether the breach resulted in unauthorized disclosure of personal information.
  • Whether the testing conducted by FB for the DYI tool was adequate.
  • Whether the notice provided to non-users in email invitations was consistent with PIPEDA s.6.1 and Principles 4.3 and 4.8.
  • Whether providing access to matched data would likely reveal personal information about a third party under PIPEDA s.9(1).
  • Whether providing access to matched data would raise safety and security concerns.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 29, 2018PIPEDA Case Summary #2018-005Indexed Jun 30, 2026

PIPEDA Case Summary #2018-005: Courier company discontinues practice of delivery to a neighbour

A courier company

A complainant alleged that a courier company disclosed her personal information without consent by delivering a package containing financial documents to her neighbour. The courier company's policy allowed drivers to deliver packages to neighbours if the addressee was not home, a practice the complainant was unaware of as she was not expecting the package. The OPC found that the courier company contravened Principle 4.3 of PIPEDA by failing to obtain consent for this practice, either directly from the complainant or by ensuring the shipper had obtained it. The OPC noted that the sensitivity of the package's contents and the complainant's unlisted phone number on the label heightened the need for express consent. The courier company committed to ending the 'delivery to a neighbour' practice in response to the OPC's recommendations. The OPC later confirmed the practice had ceased.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2018-005: Courier company discontinues practice of delivery to a neighbour

Mar 29, 2018PIPEDA Case Summary #2018-005
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a courier company disclosed her personal information without consent by delivering a package containing financial documents to her neighbour. The courier company's policy allowed drivers to deliver packages to neighbours if the addressee was not home, a practice the complainant was unaware of as she was not expecting the package. The OPC found that the courier company contravened Principle 4.3 of PIPEDA by failing to obtain consent for this practice, either directly from the complainant or by ensuring the shipper had obtained it. The OPC noted that the sensitivity of the package's contents and the complainant's unlisted phone number on the label heightened the need for express consent. The courier company committed to ending the 'delivery to a neighbour' practice in response to the OPC's recommendations. The OPC later confirmed the practice had ceased.

Key Issues
  • Whether the courier company obtained valid consent for delivering a package to a neighbour
  • Whether the courier company exercised due diligence to ensure the shipper obtained consent for 'delivery to a neighbour'
  • Whether the information disclosed (name, address, unlisted telephone number, and package contents) was sensitive in context
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 7, 2018PIPEDA Report of Findings #2018-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-006: Breach of the World Anti-Doping database

World Anti-Doping Agency (WADA)

The Office of the Privacy Commissioner of Canada (OPC) initiated an investigation into the World Anti-Doping Agency (WADA) following a 2016 data breach of its Anti-Doping Administration and Management System (ADAMS) by the "Fancy Bear" hacking group. The breach led to the public disclosure of highly sensitive personal and health information of 127 athletes, with 11,837 athletes' data potentially accessible. The OPC examined whether WADA had sufficient security safeguards under PIPEDA Principles 4.1.4, 4.7, 4.7.1, 4.7.2, and 4.7.3. The investigation found WADA's safeguards to be insufficient, particularly concerning access controls, monitoring, policies, and encryption, given the sensitivity of the data and the sophisticated nature of the attack. WADA agreed to implement most of the OPC's recommendations, including developing a comprehensive information security framework, strengthening access controls, and employing encryption at rest. The OPC accepted WADA's proposal for optional two-factor authentication for athletes, provided WADA actively promotes its use. Consequently, the matter was concluded as well-founded and conditionally resolved, with the OPC entering into a compliance agreement to monitor WADA's implementation.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-006: Breach of the World Anti-Doping database

Feb 7, 2018PIPEDA Report of Findings #2018-006
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated an investigation into the World Anti-Doping Agency (WADA) following a 2016 data breach of its Anti-Doping Administration and Management System (ADAMS) by the "Fancy Bear" hacking group. The breach led to the public disclosure of highly sensitive personal and health information of 127 athletes, with 11,837 athletes' data potentially accessible. The OPC examined whether WADA had sufficient security safeguards under PIPEDA Principles 4.1.4, 4.7, 4.7.1, 4.7.2, and 4.7.3. The investigation found WADA's safeguards to be insufficient, particularly concerning access controls, monitoring, policies, and encryption, given the sensitivity of the data and the sophisticated nature of the attack. WADA agreed to implement most of the OPC's recommendations, including developing a comprehensive information security framework, strengthening access controls, and employing encryption at rest. The OPC accepted WADA's proposal for optional two-factor authentication for athletes, provided WADA actively promotes its use. Consequently, the matter was concluded as well-founded and conditionally resolved, with the OPC entering into a compliance agreement to monitor WADA's implementation.

Key Issues
  • Whether WADA's security safeguards were appropriate to the sensitivity of the personal information in ADAMS, as required by PIPEDA Principles 4.7, 4.7.1, 4.7.2, and 4.7.3.
  • Whether WADA had implemented adequate policies and practices to give effect to PIPEDA principles, including procedures for protecting personal information, staff training, and policy documentation, under Principle 4.1.4.
  • Whether WADA's access controls, including password management, multi-factor authentication, and oversight of administrative accounts granted to Anti-Doping Organizations (ADOs), were sufficiently robust.
  • Whether WADA's monitoring and logging capabilities were adequate to detect and respond to security anomalies and intrusions.
  • Whether WADA had a proper incident response plan and a documented risk-management framework.
  • Whether WADA employed encryption for data at rest in the ADAMS database.
  • Whether WADA provided sufficient security awareness training to its staff and ADAMS stakeholders.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 9, 2018PIPEDA findings #2018-007Indexed Jun 30, 2026

PIPEDA findings #2018-007: Online marketplace needs consent from members before contacting them to join advocacy network

online marketplace

An anonymous complainant challenged an online marketplace's privacy practices after receiving an advocacy email without explicit consent. The complaint alleged unauthorized use of personal information for lobbying, inadequate handling of her privacy complaint, and unnecessary retention of data. The OPC found that the retention allegation was not well-founded. However, the OPC determined that the online marketplace failed to obtain adequate consent for sending advocacy emails and mishandled the complainant's privacy concerns, contravening PIPEDA Principles 4.3 and 4.10 respectively. The organization initially committed to corrective measures, including updating its privacy policy, providing an opt-out for advocacy messages, and improving its complaint handling process. Following the successful implementation of these recommendations, the OPC deemed the consent and challenging compliance matters well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA findings #2018-007: Online marketplace needs consent from members before contacting them to join advocacy network

Jan 9, 2018PIPEDA findings #2018-007
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant challenged an online marketplace's privacy practices after receiving an advocacy email without explicit consent. The complaint alleged unauthorized use of personal information for lobbying, inadequate handling of her privacy complaint, and unnecessary retention of data. The OPC found that the retention allegation was not well-founded. However, the OPC determined that the online marketplace failed to obtain adequate consent for sending advocacy emails and mishandled the complainant's privacy concerns, contravening PIPEDA Principles 4.3 and 4.10 respectively. The organization initially committed to corrective measures, including updating its privacy policy, providing an opt-out for advocacy messages, and improving its complaint handling process. Following the successful implementation of these recommendations, the OPC deemed the consent and challenging compliance matters well-founded and resolved.

Key Issues
  • Whether the online marketplace obtained valid consent under PIPEDA Principle 4.3 for using email addresses to send advocacy emails.
  • Whether the online marketplace adequately explained the purposes for using personal information such that the individual could reasonably understand how it would be used (PIPEDA Principle 4.3.2).
  • Whether the form of consent obtained was appropriate given the reasonable expectations of the individual and the sensitivity of the information (PIPEDA Principles 4.3.4, 4.3.5, 4.3.6).
  • Whether the online marketplace enabled the complainant to address concerns to the designated individual accountable for PIPEDA compliance (PIPEDA Principle 4.10).
  • Whether the online marketplace implemented policies and practices to receive and respond to complaints and trained staff (PIPEDA Principles 4.1.4(b), 4.1.4(c)).
  • Whether the online marketplace retained personal information longer than necessary for the identified purpose (PIPEDA Principle 4.5).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 8, 2018PIPEDA Report of Findings #2018-001Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

VTech Holdings Limited

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

Jan 8, 2018PIPEDA Report of Findings #2018-001
Adjudicator: Daniel Therrien
Plain-Language Summary

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Key Issues
  • Whether VTech Holdings Limited failed to adequately safeguard personal information under Principle 4.7 PIPEDA
  • Whether VTech's security safeguards were appropriate to the sensitivity of the information (Principle 4.7 PIPEDA)
  • Whether VTech's safeguards protected against unauthorized access, disclosure, copying, use, or modification (Principle 4.7.1 PIPEDA)
  • Whether the nature of VTech's safeguards varied depending on the sensitivity, amount, distribution, format, and storage method of the information (Principle 4.7.2 PIPEDA)
  • Whether VTech's methods of protection included physical, organizational, and technological measures (Principle 4.7.3 PIPEDA)
  • Whether VTech had adequate testing and maintenance protocols to identify and mitigate vulnerabilities
  • Whether VTech had adequate administrative access controls
  • Whether VTech had adequate cryptographic protection for personal information
  • Whether VTech had sufficient security monitoring and logging to detect threats
  • Whether VTech had a comprehensive security management program