The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

138 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 7, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Canada Revenue Agency

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

May 7, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Key Issues
  • Whether the CRA adequately protected personal information against unauthorized disclosure and modification
  • Whether the CRA contravened subsection 6(2) of the Privacy Act regarding accuracy of personal information
  • Whether the CRA contravened subsection 8(2) of the Privacy Act regarding disclosure of personal information
  • Whether the CRA's prevention measures were adequate
  • Whether the CRA implemented mandatory multi-factor authentication (MFA) in a timely manner and with sufficient strength
  • Whether the CRA's authentication processes by phone were strong enough
  • Whether the CRA considered and integrated a zero-trust approach into its security measures
  • Whether the CRA had sufficient visibility over its attack surface and managed it effectively
  • Whether the CRA's vetting, training, and awareness tools were effective for employees and third parties
  • Whether the CRA's monitoring and detection approach was tailored to the threats and risks leading to Unauthorized Use of Taxpayer Information by a Third Party (UUTP)
  • Whether the CRA's remediation efforts for individual UUTPs were adequate, including root cause analysis
  • Whether the CRA's governance processes for addressing UUTPs were coordinated, comprehensive, and efficient
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 25, 2026Indexed Jun 30, 2026

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Immigration, Refugees and Citizenship Canada (IRCC)

The OPC investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding its systematic practice of withholding access to certain personal information in its Global Case Management System (GCMS). IRCC's policy was to retrieve and process only a "Short Form" GCMS Report in response to access requests, even when individuals requested their entire file or specific content found in the "Long Form." The OPC found that the "History Section" of the GCMS file, which is part of the Long Form, contained the complainant's personal information and that IRCC's practice contravened Section 12 of the Privacy Act. While IRCC eventually provided the complainant with the requested Long Form, it did not agree to update its procedures to systematically retrieve and process the Long Form for all future requests. Consequently, the OPC found the complaint well-founded but not resolved, as IRCC had not committed to addressing the systemic issue.

Quick view

Privacy ActWell-founded

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding its systematic practice of withholding access to certain personal information in its Global Case Management System (GCMS). IRCC's policy was to retrieve and process only a "Short Form" GCMS Report in response to access requests, even when individuals requested their entire file or specific content found in the "Long Form." The OPC found that the "History Section" of the GCMS file, which is part of the Long Form, contained the complainant's personal information and that IRCC's practice contravened Section 12 of the Privacy Act. While IRCC eventually provided the complainant with the requested Long Form, it did not agree to update its procedures to systematically retrieve and process the Long Form for all future requests. Consequently, the OPC found the complaint well-founded but not resolved, as IRCC had not committed to addressing the systemic issue.

Key Issues
  • Whether IRCC's practice of providing only a "Short Form" GCMS Report in response to access requests contravenes Section 12 of the Privacy Act
  • Whether the "History Section" of the GCMS file contains personal information
  • Whether information in the "Long Form" GCMS Report is always exempt from disclosure
  • Whether IRCC has an obligation to retrieve and process all records responsive to a Privacy Act request
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2026Indexed Jun 30, 2026

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Canada Border Services Agency (CBSA)

An employee of the Canada Border Services Agency (CBSA) filed a complaint after their personal information, including sensitive details about an accommodation request, was inadvertently made accessible to other CBSA employees through the Apollo information management system. The issue stemmed from improperly set permissions on an old ATIP file folder, which allowed document titles and sometimes the first line of emails containing personal information to be visible via Apollo's search function. The OPC found that the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority. While the CBSA corrected the specific permissions and committed to broader reviews and improved naming conventions, it did not agree to implement mandatory and trackable training for employees on Apollo permissions management. Consequently, the OPC found the complaint well-founded but unresolved, as it was not satisfied that sufficient safeguards were in place to prevent recurrence.

Quick view

Privacy ActWell-founded

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Mar 24, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee of the Canada Border Services Agency (CBSA) filed a complaint after their personal information, including sensitive details about an accommodation request, was inadvertently made accessible to other CBSA employees through the Apollo information management system. The issue stemmed from improperly set permissions on an old ATIP file folder, which allowed document titles and sometimes the first line of emails containing personal information to be visible via Apollo's search function. The OPC found that the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority. While the CBSA corrected the specific permissions and committed to broader reviews and improved naming conventions, it did not agree to implement mandatory and trackable training for employees on Apollo permissions management. Consequently, the OPC found the complaint well-founded but unresolved, as it was not satisfied that sufficient safeguards were in place to prevent recurrence.

Key Issues
  • Whether the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority
  • Whether the CBSA appropriately responded to the unauthorized disclosure
  • Whether the CBSA's proposed measures, without mandatory and trackable training, are sufficient to prevent future unauthorized disclosures
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 18, 2026Indexed Jun 30, 2026

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Treasury Board of Canada Secretariat

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Treasury Board of Canada Secretariat (TBS) regarding its personal information practices for monitoring employee on-site presence under the federal government's hybrid work model. The complainant alleged invasive collection, use, and disclosure of personal information, questioning TBS's compliance with sections 4, 6, 7, and 8 of the Privacy Act, as well as transparency, necessity, proportionality, and Privacy Impact Assessment (PIA) requirements. The OPC found that TBS's collection of aggregated data for organizational compliance was for non-administrative purposes, authorized by existing statutes, and appropriately de-identified to fall outside the scope of the Act for disclosure. For individual compliance, managers primarily relied on observation and self-reporting, supported by internal guidance. While TBS's practices were largely compliant, the OPC encouraged TBS to update its Personal Information Bank (PIB) description for Physical Access Controls (PSU 907) to explicitly reflect the potential use of access logs in formal investigations and to clearly communicate this to employees. Overall, the OPC concluded that TBS's personal information handling practices were compliant with the Privacy Act.

Quick view

Privacy ActNot well-founded

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Mar 18, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Treasury Board of Canada Secretariat (TBS) regarding its personal information practices for monitoring employee on-site presence under the federal government's hybrid work model. The complainant alleged invasive collection, use, and disclosure of personal information, questioning TBS's compliance with sections 4, 6, 7, and 8 of the Privacy Act, as well as transparency, necessity, proportionality, and Privacy Impact Assessment (PIA) requirements. The OPC found that TBS's collection of aggregated data for organizational compliance was for non-administrative purposes, authorized by existing statutes, and appropriately de-identified to fall outside the scope of the Act for disclosure. For individual compliance, managers primarily relied on observation and self-reporting, supported by internal guidance. While TBS's practices were largely compliant, the OPC encouraged TBS to update its Personal Information Bank (PIB) description for Physical Access Controls (PSU 907) to explicitly reflect the potential use of access logs in formal investigations and to clearly communicate this to employees. Overall, the OPC concluded that TBS's personal information handling practices were compliant with the Privacy Act.

Key Issues
  • Whether the collection of employees' personal information for on-site presence monitoring was related directly to TBS's operating programs or activities under section 4 of the Privacy Act.
  • Whether TBS's retention and disposal practices for personal information collected for on-site presence monitoring complied with section 6 of the Privacy Act, specifically subsections 6(1) and 6(3).
  • Whether TBS's use of personal information for on-site presence monitoring was a 'consistent use' authorized under section 7(a) of the Privacy Act.
  • Whether TBS's disclosure of aggregated on-site presence data to senior management constituted personal information under section 3 of the Privacy Act and complied with section 8.
  • Whether TBS's transparency and openness related to its hybrid compliance monitoring approach, including standard Personal Information Banks (PIBs), was adequate under sections 10 and 11 of the Privacy Act.
  • Whether TBS's personal information practices for on-site presence monitoring complied with the necessity and proportionality data principles.
  • Whether TBS was required to complete a Privacy Impact Assessment (PIA) for its verification regime.
  • Whether managers' practices for monitoring individual compliance with the hybrid work model contravened the Privacy Act.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 12, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Quick view

Privacy ActNot well-founded

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Mar 12, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Key Issues
  • Whether the CBSA authorized contractors to access personal information collected through ArriveCAN without the required security clearance, in contravention of sections 7 and 8 of the Privacy Act
  • Whether ArriveCAN contracts and Task Authorizations (TAs) contained appropriate clauses to ensure the protection of travellers’ personal information that contractors had access to
  • Whether security requirements identified in contracts and TAs were accurate and specific
  • Whether the CBSA complied with organizational security screening requirements for vendors
  • Whether the CBSA complied with personnel security screening requirements for contractors
  • Whether the CBSA implemented adequate administrative safeguards to protect personal information accessed by contractors
  • Whether the CBSA implemented adequate technical safeguards to protect personal information accessed by contractors
  • Whether the CBSA restricted contractor permissions and access to personal information to what was strictly necessary
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 3, 2026Indexed Jun 30, 2026

Correctional Service of Canada Deleted Video

Correctional Service of Canada (CSC)

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Correctional Service of Canada Deleted Video

Mar 3, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether CSC failed to retain personal information used for an administrative purpose as required by Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations
  • Whether the complainant was denied a reasonable opportunity to obtain access to their personal information due to non-retention
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Feb 26, 2026Indexed Jun 30, 2026

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Canada Border Services Agency (CBSA)

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Quick view

Privacy ActWell-founded & resolved

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Feb 26, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Key Issues
  • Whether the CBSA's disclosure of employee personal information via spreadsheets contravened section 8 of the Privacy Act
  • Whether the inclusion of excess information in spreadsheets constituted unauthorized disclosure
  • Whether the use of personal email addresses for work-related data sharing contravened the Privacy Act
  • Whether the CBSA took adequate steps to address the incidents, including notification to affected individuals
  • Whether the CBSA's measures to reduce the risk of recurrence were reasonable
Federal (Canada)Privacy ActWell-founded & unresolved
Federal (Canada) flag
Mar 11, 2025Indexed Jun 30, 2026

Investigation of the loss of an unencrypted Universal Serial Bus (USB) storage device by the Royal Canadian Mounted Police

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP) following the loss of an unencrypted USB storage device containing sensitive personal information of 1,741 individuals. The investigation focused on whether the RCMP contravened section 8 of the Privacy Act regarding disclosure, the appropriateness of its breach response, and the sufficiency of its safeguards for USB devices. The OPC found that the RCMP contravened section 8 due to unauthorized disclosure, as the device was lost, unencrypted, and its contents were copied and offered for sale. While the RCMP's notification to affected individuals and mitigation steps were generally appropriate after discovery, the initial reporting of the loss was significantly delayed. Furthermore, the RCMP failed to implement adequate safeguards, as its own policies for procurement, inventory, and encryption of USB devices were not followed, and security awareness training was insufficient. Despite the RCMP accepting the OPC's recommendations to strengthen safeguards, audit procedures, and awareness programs, it refused to commit to specific timelines for implementation. Consequently, the complaint was found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded & unresolved

Investigation of the loss of an unencrypted Universal Serial Bus (USB) storage device by the Royal Canadian Mounted Police

Mar 11, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP) following the loss of an unencrypted USB storage device containing sensitive personal information of 1,741 individuals. The investigation focused on whether the RCMP contravened section 8 of the Privacy Act regarding disclosure, the appropriateness of its breach response, and the sufficiency of its safeguards for USB devices. The OPC found that the RCMP contravened section 8 due to unauthorized disclosure, as the device was lost, unencrypted, and its contents were copied and offered for sale. While the RCMP's notification to affected individuals and mitigation steps were generally appropriate after discovery, the initial reporting of the loss was significantly delayed. Furthermore, the RCMP failed to implement adequate safeguards, as its own policies for procurement, inventory, and encryption of USB devices were not followed, and security awareness training was insufficient. Despite the RCMP accepting the OPC's recommendations to strengthen safeguards, audit procedures, and awareness programs, it refused to commit to specific timelines for implementation. Consequently, the complaint was found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP disclosed personal information in contravention of section 8 of the Privacy Act
  • Whether the RCMP's response to the privacy breach was appropriate in the circumstances
  • Whether the RCMP's measures to protect personal information contained on USB storage devices were sufficient
  • Whether RCMP personnel failed to report the loss of the USB storage device to authorities in a timely manner
  • Whether the RCMP's policies and procedures for procurement, inventory, and encryption of USB devices were followed and enforced
  • Whether the RCMP's security and privacy awareness training for members was effective and sufficient
  • Whether the RCMP's policy compliance monitoring for USB device use was adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 27, 2025Indexed Jun 30, 2026

Investigation into the disclosure of an adopted child’s name to their biological mother by the Canada Revenue Agency

Canada Revenue Agency (CRA)

A complainant alleged that the Canada Revenue Agency (CRA) inappropriately disclosed her adoptive child's name and her personal information to the child's biological mother, contravening section 8 of the Privacy Act. The child's name had been changed for safety reasons after a closed adoption. The OPC found that, on the balance of probabilities, the CRA likely disclosed the child's adoptive name to the biological mother, leading to significant negative impacts on the family. The investigation also revealed deficiencies in the CRA's internal procedures for safeguarding adopted children's personal information. The OPC issued recommendations to revise procedures, provide comprehensive training, and implement oversight measures. The CRA agreed to implement two of the three recommendations, but declined the oversight measure, leading to a "well-founded and not resolved" finding.

Quick view

Privacy ActWell-founded

Investigation into the disclosure of an adopted child’s name to their biological mother by the Canada Revenue Agency

Feb 27, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

A complainant alleged that the Canada Revenue Agency (CRA) inappropriately disclosed her adoptive child's name and her personal information to the child's biological mother, contravening section 8 of the Privacy Act. The child's name had been changed for safety reasons after a closed adoption. The OPC found that, on the balance of probabilities, the CRA likely disclosed the child's adoptive name to the biological mother, leading to significant negative impacts on the family. The investigation also revealed deficiencies in the CRA's internal procedures for safeguarding adopted children's personal information. The OPC issued recommendations to revise procedures, provide comprehensive training, and implement oversight measures. The CRA agreed to implement two of the three recommendations, but declined the oversight measure, leading to a "well-founded and not resolved" finding.

Key Issues
  • Whether the CRA disclosed the child’s adoptive name to the biological mother in contravention of section 8 of the Privacy Act
  • Whether the CRA's internal procedures for safeguarding adopted children's personal information were adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 26, 2025Indexed Jun 30, 2026

Investigation into the Canada Revenue Agency’s application of paragraph 22(1)(b) to refuse access to personal information

Canada Revenue Agency (CRA)

The complainant alleged that the Canada Revenue Agency (CRA) improperly denied access to personal information related to five grievances, relying on exceptions in subsection 12(1), paragraph 22(1)(b), and section 26 of the Privacy Act. The OPC found that while the CRA conducted reasonable searches, it failed to substantiate its use of some exemptions, particularly paragraph 22(1)(b). The CRA did not demonstrate a clear and direct connection between disclosure and a risk of harm, instead relying on general assertions. The OPC concluded that the complainant did not receive all entitled personal information and found the complaint well-founded. The OPC recommended the CRA reassess its reliance on paragraph 22(1)(b) and disclose more information. However, the CRA maintained its position, leading the OPC to consider the complaint unresolved.

Quick view

Privacy ActWell-founded

Investigation into the Canada Revenue Agency’s application of paragraph 22(1)(b) to refuse access to personal information

Feb 26, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that the Canada Revenue Agency (CRA) improperly denied access to personal information related to five grievances, relying on exceptions in subsection 12(1), paragraph 22(1)(b), and section 26 of the Privacy Act. The OPC found that while the CRA conducted reasonable searches, it failed to substantiate its use of some exemptions, particularly paragraph 22(1)(b). The CRA did not demonstrate a clear and direct connection between disclosure and a risk of harm, instead relying on general assertions. The OPC concluded that the complainant did not receive all entitled personal information and found the complaint well-founded. The OPC recommended the CRA reassess its reliance on paragraph 22(1)(b) and disclose more information. However, the CRA maintained its position, leading the OPC to consider the complaint unresolved.

Key Issues
  • Whether the Canada Revenue Agency conducted reasonable searches for responsive records
  • Whether the Canada Revenue Agency properly applied subsection 12(1) of the Privacy Act to withhold information
  • Whether the Canada Revenue Agency properly applied paragraph 22(1)(b) of the Privacy Act to withhold information
  • Whether the Canada Revenue Agency properly applied section 26 of the Privacy Act to withhold information
  • Whether the Canada Revenue Agency demonstrated a clear and direct connection between disclosure and a risk of harm under paragraph 22(1)(b)
  • Whether general assertions of harm are sufficient to justify withholding information under paragraph 22(1)(b)
  • Whether the mere fact of an ongoing investigation meets the threshold for harm under paragraph 22(1)(b)
  • Whether the potential for strategic advantage is sufficient to justify withholding information under paragraph 22(1)(b)
  • Whether professional expertise alone is sufficient to substantiate an exemption claim under paragraph 22(1)(b)
  • Whether a case-by-case assessment is required for the application of paragraph 22(1)(b)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 24, 2025Indexed Jun 30, 2026

Measures to anonymize sensitive polygraph records mitigated privacy impacts of NSIRA review

NSIRA Secretariat

The Office of the Privacy Commissioner (OPC) investigated complaints against the NSIRA Secretariat regarding its access to sensitive polygraph records during a review of the Communications Security Establishment's (CSE) Internal Security Program. Complainants questioned whether the collection of personal information complied with section 4 of the Privacy Act and if the Secretariat met its Personal Information Bank (PIB) obligations under section 10. The OPC found that while some un-redacted elements in security screening files posed a re-identification risk, the polygraph recordings themselves were sufficiently anonymized. Given NSIRA's broad mandate and right of access, the OPC concluded the collection issue was not well-founded. However, the Secretariat's delay in requesting approval for PIB changes was found well-founded, though resolved by subsequent submission. The OPC recommended the Secretariat prioritize PIB approvals and publish its Info Source page for transparency. The Secretariat committed to these actions.

Quick view

Privacy ActWell-founded

Measures to anonymize sensitive polygraph records mitigated privacy impacts of NSIRA review

Jan 24, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated complaints against the NSIRA Secretariat regarding its access to sensitive polygraph records during a review of the Communications Security Establishment's (CSE) Internal Security Program. Complainants questioned whether the collection of personal information complied with section 4 of the Privacy Act and if the Secretariat met its Personal Information Bank (PIB) obligations under section 10. The OPC found that while some un-redacted elements in security screening files posed a re-identification risk, the polygraph recordings themselves were sufficiently anonymized. Given NSIRA's broad mandate and right of access, the OPC concluded the collection issue was not well-founded. However, the Secretariat's delay in requesting approval for PIB changes was found well-founded, though resolved by subsequent submission. The OPC recommended the Secretariat prioritize PIB approvals and publish its Info Source page for transparency. The Secretariat committed to these actions.

Key Issues
  • Whether the NSIRA Secretariat's collection of personal information (polygraph records) complied with section 4 of the Privacy Act.
  • Whether the anonymization measures applied to polygraph records were sufficient to prevent re-identification.
  • Whether the NSIRA Secretariat's viewing of personal information, even if not recorded, constituted a 'collection' under section 4.
  • Whether the NSIRA Secretariat met its obligations under section 10 of the Privacy Act regarding Personal Information Banks (PIBs).
  • Whether the NSIRA Secretariat's request for PIB approval was timely.
  • Whether the NSIRA Secretariat published its Info Source page as required by TBS policy.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jun 26, 2024Indexed Jun 30, 2026

Investigation into the denial of access to a child’s personal information by Immigration, Refugees and Citizenship Canada

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant, a father involved in a custody dispute, submitted an ATIP request to Immigration, Refugees and Citizenship Canada (IRCC) for his minor child's passport application, which had been submitted by his former spouse. He provided a court order authorizing him to obtain his children's information from third parties. IRCC denied the request, stating that the child's consent was required. The complainant alleged that IRCC improperly denied access despite the court order. The OPC investigated whether the complainant had a right of access under paragraph 10(a) of the Privacy Regulations, which allows access on behalf of a minor under certain conditions. The OPC found that while the child was a minor and the complainant had legal authorization to administer the child's affairs, the request was not made on the child's behalf, but rather for the complainant's own interests. Therefore, the third condition of paragraph 10(a) was not met, and IRCC's denial was deemed reasonable.

Quick view

Privacy ActNot well-founded

Investigation into the denial of access to a child’s personal information by Immigration, Refugees and Citizenship Canada

Jun 26, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant, a father involved in a custody dispute, submitted an ATIP request to Immigration, Refugees and Citizenship Canada (IRCC) for his minor child's passport application, which had been submitted by his former spouse. He provided a court order authorizing him to obtain his children's information from third parties. IRCC denied the request, stating that the child's consent was required. The complainant alleged that IRCC improperly denied access despite the court order. The OPC investigated whether the complainant had a right of access under paragraph 10(a) of the Privacy Regulations, which allows access on behalf of a minor under certain conditions. The OPC found that while the child was a minor and the complainant had legal authorization to administer the child's affairs, the request was not made on the child's behalf, but rather for the complainant's own interests. Therefore, the third condition of paragraph 10(a) was not met, and IRCC's denial was deemed reasonable.

Key Issues
  • Whether the complainant had a right of access to his child’s personal information under section 10 of the Privacy Regulations
  • Whether the child was a minor at the time of the ATIP request
  • Whether the complainant had legal authorization to administer the child's affairs
  • Whether the complainant exercised the right of access on the minor’s behalf
  • Whether the child had the decision-making capacity to provide consent for the release of their personal information
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 29, 2024Indexed Jun 30, 2026

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Department of National Defence

The complainant, as the executor of a deceased Canadian Armed Forces member's estate, requested personal information from the Department of National Defence (DND) for estate administration purposes. DND initially refused disclosure, citing that the request did not meet the criteria under paragraph 10(b) of the Privacy Regulations and withheld information under section 26 of the Privacy Act, also claiming some records were not under its control or had surpassed retention periods. The OPC found that the complainant was authorized under paragraph 10(b) to access certain information (items 4, 5, 9, and later 2, 6, 7, 8) as it was relevant to potential civil claims regarding the deceased's financial situation and alleged undue influence. The investigation concluded that DND failed to conduct an adequate search for records and improperly applied section 26 without reviewing the records. DND was also found to have improperly deferred the complainant to an informal avenue without formally processing the request. The OPC recommended DND conduct a reasonable search for the specified records and provide a new response, which DND agreed to do. The complaint was therefore found well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Apr 29, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant, as the executor of a deceased Canadian Armed Forces member's estate, requested personal information from the Department of National Defence (DND) for estate administration purposes. DND initially refused disclosure, citing that the request did not meet the criteria under paragraph 10(b) of the Privacy Regulations and withheld information under section 26 of the Privacy Act, also claiming some records were not under its control or had surpassed retention periods. The OPC found that the complainant was authorized under paragraph 10(b) to access certain information (items 4, 5, 9, and later 2, 6, 7, 8) as it was relevant to potential civil claims regarding the deceased's financial situation and alleged undue influence. The investigation concluded that DND failed to conduct an adequate search for records and improperly applied section 26 without reviewing the records. DND was also found to have improperly deferred the complainant to an informal avenue without formally processing the request. The OPC recommended DND conduct a reasonable search for the specified records and provide a new response, which DND agreed to do. The complaint was therefore found well-founded and conditionally resolved.

Key Issues
  • Whether the complainant, as executor, was entitled to make a request on behalf of the deceased member under paragraph 10(b) of the Privacy Regulations for the purpose of administering the estate.
  • Whether the complainant sufficiently articulated or substantiated the precise purposes of the information to administer the estate and how the records in question could further those purposes.
  • Whether DND properly applied section 26 of the Privacy Act in refusing to disclose the requested information.
  • Whether DND conducted an adequate search for the requested records.
  • Whether DND improperly deferred the complainant to another avenue without formally processing a portion of the access request.
  • Whether personal information of a deceased individual (less than 20 years deceased) retains the same privacy protection as a living individual.
  • Whether the 'only for the purpose of such administration' clause in paragraph 10(b) of the Regulations imposes stricter requirements than 'relates to the administration of the individual’s estate' in MFIPPA.
  • Whether records sought to assist in prosecuting a civil claim brought on behalf of the estate for damages recoverable by the estate relate to the administration of the estate.
  • Whether records relevant to the deceased’s financial situation and allegations of fraud or theft of the deceased’s property relate to the administration of the estate.
  • Whether DND's obligation to process a formal access request is relieved if other informal avenues exist.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2024Indexed Jun 30, 2026

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Canada Revenue Agency (CRA)

An individual complained that the Canada Revenue Agency (CRA) failed to ensure the accuracy of their personal information, leading to an imposter fraudulently obtaining Canada Emergency Response Benefit (CERB) payments in their name. The imposter gained unauthorized access to the complainant's CRA My Account, changed direct deposit information, and applied for benefits. This resulted in the complainant receiving a tax reassessment for over $5,500. The OPC found that the CRA relied on inadequate safeguards against unauthorized access and modification, thus failing to take reasonable steps to ensure the accuracy of personal information used for administrative decisions under section 6(2) of the Privacy Act. The CRA has since implemented corrective measures, including enhanced authentication processes and security for high-impact modifications. The OPC found the complaint well-founded and conditionally resolved, noting the CRA's commitments to address the issues.

Quick view

Privacy ActWell-founded & conditionally resolved

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Mar 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that the Canada Revenue Agency (CRA) failed to ensure the accuracy of their personal information, leading to an imposter fraudulently obtaining Canada Emergency Response Benefit (CERB) payments in their name. The imposter gained unauthorized access to the complainant's CRA My Account, changed direct deposit information, and applied for benefits. This resulted in the complainant receiving a tax reassessment for over $5,500. The OPC found that the CRA relied on inadequate safeguards against unauthorized access and modification, thus failing to take reasonable steps to ensure the accuracy of personal information used for administrative decisions under section 6(2) of the Privacy Act. The CRA has since implemented corrective measures, including enhanced authentication processes and security for high-impact modifications. The OPC found the complaint well-founded and conditionally resolved, noting the CRA's commitments to address the issues.

Key Issues
  • Whether the CRA took all reasonable steps to ensure the accuracy of personal information used for administrative purposes under subsection 6(2) of the Privacy Act
  • Whether the safeguards in place at the time of the breach were adequate to prevent unauthorized access and modification of personal information
  • Whether the CRA's authentication processes were sufficient to prevent identity theft and fraudulent activity
  • Whether the CRA should have contacted Employment and Social Development Canada (ESDC) sooner regarding the complainant's identity theft
  • Whether the CRA provided timely notification of the privacy breach to the affected individual
  • Whether the CRA fulfilled its mandatory privacy breach reporting obligations to the OPC
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 28, 2024Indexed Jun 30, 2026

Investigation into the treatment by a government institution of the personal information of two employees with the same name

A federal government institution

An employee complained that her personal information was repeatedly disclosed to another employee with the same name, and that numerous administrative errors occurred in their respective files. The OPC found that the government institution contravened section 8 of the Privacy Act by mistakenly disclosing the complainant's personal information, including her PRI, email, mailing address, and financial and health information. It also contravened subsection 6(2) of the Act by failing to ensure the accuracy of personal information used for administrative purposes, leading to errors in employee files. The OPC concluded that these issues were systemic due to human error and a lack of awareness among employees regarding privacy breach reporting procedures. The institution accepted the OPC's recommendations to prevent unauthorized disclosures and ensure data accuracy, leading to a conditionally resolved finding.

Quick view

Privacy ActWell-founded

Investigation into the treatment by a government institution of the personal information of two employees with the same name

Mar 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee complained that her personal information was repeatedly disclosed to another employee with the same name, and that numerous administrative errors occurred in their respective files. The OPC found that the government institution contravened section 8 of the Privacy Act by mistakenly disclosing the complainant's personal information, including her PRI, email, mailing address, and financial and health information. It also contravened subsection 6(2) of the Act by failing to ensure the accuracy of personal information used for administrative purposes, leading to errors in employee files. The OPC concluded that these issues were systemic due to human error and a lack of awareness among employees regarding privacy breach reporting procedures. The institution accepted the OPC's recommendations to prevent unauthorized disclosures and ensure data accuracy, leading to a conditionally resolved finding.

Key Issues
  • Whether the government institution contravened section 8 of the Privacy Act by mistakenly disclosing the complainant’s personal information to another employee with the same name
  • Whether the government institution contravened subsection 6(2) of the Privacy Act by failing to ensure that personal information used for administrative purposes was accurate, up-to-date, and complete
  • Whether the repeated disclosures and inaccuracies constituted a systemic problem
  • Whether the institution's assessment of the sensitivity of the disclosed information was appropriate