The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

138 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Feb 28, 2024Indexed Jun 30, 2026

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Department of National Defence

A representative, on behalf of a deceased member's estate executor, requested personal information from the Department of National Defence (DND) related to an investigation into allegations against the deceased. DND processed the request informally and disclosed some information under subparagraph 8(2)(m)(i) of the Privacy Act, but did not explicitly state its refusal to process the request formally under paragraph 10(b) of the Privacy Regulations. The OPC investigated whether the representative was entitled to make the request for the purpose of administering the estate. The OPC found that while the representative was authorized to administer the estate, they did not sufficiently demonstrate a connection between the requested information and the administration of the estate. Therefore, the complaint was not well-founded, as the representative failed to meet the requirements of paragraph 10(b) of the Regulations.

Quick view

Privacy ActNot well-founded

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Feb 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

A representative, on behalf of a deceased member's estate executor, requested personal information from the Department of National Defence (DND) related to an investigation into allegations against the deceased. DND processed the request informally and disclosed some information under subparagraph 8(2)(m)(i) of the Privacy Act, but did not explicitly state its refusal to process the request formally under paragraph 10(b) of the Privacy Regulations. The OPC investigated whether the representative was entitled to make the request for the purpose of administering the estate. The OPC found that while the representative was authorized to administer the estate, they did not sufficiently demonstrate a connection between the requested information and the administration of the estate. Therefore, the complaint was not well-founded, as the representative failed to meet the requirements of paragraph 10(b) of the Regulations.

Key Issues
  • Whether the representative was authorized to make a request on behalf of the deceased under paragraph 10(b) of the Regulations
  • Whether the request related only to the administration of the deceased's estate under paragraph 10(b) of the Regulations
  • Whether DND complied with section 16 of the Privacy Act regarding refusal notifications
  • Whether DND properly processed the request informally without explicit written consent and notification of rights
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Canada Revenue Agency and Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Key Issues
  • Whether Canada Revenue Agency (CRA) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether Employment and Social Development Canada (ESDC) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether CRA contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether ESDC contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether CRA and ESDC adequately assessed the level of identity authentication warranted for their online services.
  • Whether CRA and ESDC's identity assurance practices adequately protected against identity theft.
  • Whether CRA and ESDC's credential assurance practices adequately protected against credential stuffing.
  • Whether CRA and ESDC had adequately informed and accountable security decision-making processes.
  • Whether interdepartmental information sharing and accountability systems were adequate to protect personal information.
  • Whether CRA and ESDC conducted comprehensive vulnerability assessments and penetration testing.
  • Whether CRA and ESDC had effective monitoring to detect and promptly contain the ongoing breach.
  • Whether other federal departments using the GC Key service experienced fraudulent access or modification of personal information.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP's collection of personal information via Social Studio complied with Section 4 of the Privacy Act.
  • Whether the RCMP's collection of personal information via Babel X complied with Section 4 of the Privacy Act.
  • Whether the RCMP conducted adequate due diligence on the lawfulness of collection practices of Babel X and its data providers.
  • Whether Section 4 of the Privacy Act permits the collection of personal information from a third-party agent that collected, used, or disclosed the information in contravention of a law that third party is subject to.
  • Whether the RCMP's publicly available descriptions of its open-source information gathering are granular enough to meet transparency obligations under Section 11 of the Privacy Act.
  • Whether the RCMP's published descriptions clarify limits on purposes for collection under Section 11 of the Privacy Act.
  • Whether the RCMP's descriptions of open-source information collection and related purposes are adequate under Section 11 of the Privacy Act.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 24, 2024Indexed Jun 30, 2026

Investigation into a privacy breach at Immigration, Refugees and Citizenship Canada

Immigration, Refugees and Citizenship Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach. IRCC inadvertently disclosed the personal information of 497 individuals when sending mass email notifications for a work permit extension program. An employee failed to apply a filter to the email address column in an Excel spreadsheet, causing email addresses to misalign with other personal data, leading to notifications being sent to incorrect recipients. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose and that its prevention measures were insufficient. While IRCC's mitigation efforts, including notifying affected individuals, were deemed adequate, the OPC recommended implementing robust procedural and administrative controls. IRCC accepted these recommendations, committing to measures such as a 'two pairs of eyes' rule, updated operating procedures, and data quality assurance checks. Consequently, the OPC considered the matter resolved.

Quick view

Privacy ActWell-founded

Investigation into a privacy breach at Immigration, Refugees and Citizenship Canada

Jan 24, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach. IRCC inadvertently disclosed the personal information of 497 individuals when sending mass email notifications for a work permit extension program. An employee failed to apply a filter to the email address column in an Excel spreadsheet, causing email addresses to misalign with other personal data, leading to notifications being sent to incorrect recipients. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose and that its prevention measures were insufficient. While IRCC's mitigation efforts, including notifying affected individuals, were deemed adequate, the OPC recommended implementing robust procedural and administrative controls. IRCC accepted these recommendations, committing to measures such as a 'two pairs of eyes' rule, updated operating procedures, and data quality assurance checks. Consequently, the OPC considered the matter resolved.

Key Issues
  • Whether IRCC's disclosure of personal information to unintended recipients contravened section 8 of the Privacy Act.
  • Whether IRCC had sufficient measures in place to prevent unauthorized disclosures of personal information of this nature.
  • Whether IRCC's response to mitigate the impact of the breach on affected individuals was adequate.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 21, 2023Indexed Jun 30, 2026

Investigation into IRCC’s search for records using modified wording

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) failed to disclose all information sought under the Privacy Act, specifically regarding the cancellation and reissuing of visas for the complainant and her children. The investigation found that IRCC initially narrowed the scope of the request without the complainant's approval and did not conduct a sufficiently broad search for records. The OPC determined that IRCC did not initially conduct a reasonable search for records. However, during the investigation, IRCC expanded its search to include additional offices and a specific former employee's correspondence. Although no additional records were found, IRCC's subsequent efforts satisfied the OPC that it had met its obligations under the Act.

Quick view

Privacy ActWell-founded

Investigation into IRCC’s search for records using modified wording

Sep 21, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) failed to disclose all information sought under the Privacy Act, specifically regarding the cancellation and reissuing of visas for the complainant and her children. The investigation found that IRCC initially narrowed the scope of the request without the complainant's approval and did not conduct a sufficiently broad search for records. The OPC determined that IRCC did not initially conduct a reasonable search for records. However, during the investigation, IRCC expanded its search to include additional offices and a specific former employee's correspondence. Although no additional records were found, IRCC's subsequent efforts satisfied the OPC that it had met its obligations under the Act.

Key Issues
  • Whether IRCC conducted a reasonable search for records responsive to the access request
  • Whether IRCC improperly reduced the scope of the request without the complainant's approval
  • Whether IRCC tasked all appropriate Offices of Primary Interest (OPIs) in its initial search
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 19, 2023Indexed Jun 30, 2026

Canada Post’s collection and use of personal information for marketing purposes not compliant with the Act

Canada Post

An individual complained that Canada Post (CPC) was using personal information gathered from the outside of delivered envelopes and parcels to create mail marketing lists, which it then rented to the private sector. The Office of the Privacy Commissioner (OPC) investigated whether CPC's Smartmail Marketing Program (SMM Program) complied with the Privacy Act. The OPC found that CPC's collection of personal information for the SMM Program was directly related to an operating program (s.4) and that its use and disclosure were for an original purpose of collection (s.7 and s.8), thus compliant with these sections. However, the OPC determined that the SMM Program constituted an "administrative purpose" under the Act, and CPC had failed to obtain individuals' authorization for the indirect collection of their personal information, contravening section 5. CPC disagreed with this finding and refused to implement the OPC's recommendation to cease the practice without authorization, proposing only enhanced transparency measures which the OPC deemed insufficient. Consequently, the complaint was found to be well-founded and not resolved.

Quick view

Privacy ActWell-founded

Canada Post’s collection and use of personal information for marketing purposes not compliant with the Act

Sep 19, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that Canada Post (CPC) was using personal information gathered from the outside of delivered envelopes and parcels to create mail marketing lists, which it then rented to the private sector. The Office of the Privacy Commissioner (OPC) investigated whether CPC's Smartmail Marketing Program (SMM Program) complied with the Privacy Act. The OPC found that CPC's collection of personal information for the SMM Program was directly related to an operating program (s.4) and that its use and disclosure were for an original purpose of collection (s.7 and s.8), thus compliant with these sections. However, the OPC determined that the SMM Program constituted an "administrative purpose" under the Act, and CPC had failed to obtain individuals' authorization for the indirect collection of their personal information, contravening section 5. CPC disagreed with this finding and refused to implement the OPC's recommendation to cease the practice without authorization, proposing only enhanced transparency measures which the OPC deemed insufficient. Consequently, the complaint was found to be well-founded and not resolved.

Key Issues
  • Whether Canada Post's collection of personal information for marketing mail list services complies with section 4 of the Privacy Act (related directly to an operating program or activity).
  • Whether Canada Post's use and disclosure of personal information for marketing mail list services complies with sections 7 and 8 of the Privacy Act (for the purpose obtained or consistent use, or with consent).
  • Whether Canada Post's collection of personal information for marketing mail list services complies with section 5 of the Privacy Act (direct collection for administrative purpose, or with authorization).
  • Whether the use of an individual's information to provide mail marketing services constitutes an "administrative purpose" under section 3 of the Privacy Act.
  • Whether individuals implicitly authorized Canada Post to indirectly collect their personal information for the SMM Program by accepting mail delivery or through the availability of an opt-out mechanism.
  • Whether the exceptions under subsection 5(3) of the Privacy Act apply.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Sep 11, 2023Indexed Jun 30, 2026

Investigation of Immigration, Refugees and Citizenship Canada’s disclosure of personal information to the Canada Border Services Agency

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) inappropriately disclosed his Permanent Resident Card (PRC) renewal paperwork to the Canada Border Services Agency (CBSA), which was then used in a cessation application, contrary to the purpose for which it was collected. The OPC investigated whether IRCC was authorized to disclose this personal information to the CBSA under paragraph 8(2)(a) of the Privacy Act, which permits disclosure for a consistent use. IRCC and CBSA argued that their information sharing for the administration and enforcement of the Immigration and Refugee Protection Act (IRPA) constitutes a consistent use. The OPC found that the privacy notice on the PRC renewal application and the relevant Personal Information Bank (PIB) explicitly stated that information might be shared with CBSA for investigations related to immigration legislation. Therefore, the OPC concluded that the disclosure was for a consistent use, and the complaints against both departments were not well-founded.

Quick view

Privacy ActNot well-founded

Investigation of Immigration, Refugees and Citizenship Canada’s disclosure of personal information to the Canada Border Services Agency

Sep 11, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) inappropriately disclosed his Permanent Resident Card (PRC) renewal paperwork to the Canada Border Services Agency (CBSA), which was then used in a cessation application, contrary to the purpose for which it was collected. The OPC investigated whether IRCC was authorized to disclose this personal information to the CBSA under paragraph 8(2)(a) of the Privacy Act, which permits disclosure for a consistent use. IRCC and CBSA argued that their information sharing for the administration and enforcement of the Immigration and Refugee Protection Act (IRPA) constitutes a consistent use. The OPC found that the privacy notice on the PRC renewal application and the relevant Personal Information Bank (PIB) explicitly stated that information might be shared with CBSA for investigations related to immigration legislation. Therefore, the OPC concluded that the disclosure was for a consistent use, and the complaints against both departments were not well-founded.

Key Issues
  • Whether IRCC's disclosure of the complainant's personal information to CBSA was authorized under paragraph 8(2)(a) of the Privacy Act
  • Whether the use of the personal information by CBSA in a cessation application was consistent with the purpose for which it was collected by IRCC
  • Whether the complainant could reasonably expect the disclosure of his PRC renewal application to CBSA for immigration investigations
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by Department of National Defence for members of the Canadian Armed Forces

Department of National Defence / Canadian Armed Forces

The Office of the Privacy Commissioner of Canada (OPC) investigated 16 complaints against the Department of National Defence (DND) and the Canadian Armed Forces (CAF) regarding their COVID-19 vaccination attestation requirements. Complainants alleged unreasonable collection, improper use, insufficient access controls in the Monitor MASS system leading to unauthorized disclosure, and inaccurate data. The OPC found that the collection of vaccination status information, including for accommodation requests, directly related to DND's operating programs for health and safety and operational readiness, satisfying section 4 of the Privacy Act. The use of this information was also deemed consistent with the purposes for which it was collected, in line with section 7. While concerns were raised about Monitor MASS access controls, the OPC found no evidence of actual unauthorized disclosures, thus deeming this allegation not well-founded, though it did recommend improved oversight which DND declined. Furthermore, DND was found to have taken reasonable steps to ensure the accuracy of vaccination status data under section 6(2). The OPC also concluded that the measures were necessary and proportional given the pandemic context and the CAF's unique operational role.

Quick view

Privacy ActNot well-founded

Investigation into COVID-19 vaccination attestation requirements established by Department of National Defence for members of the Canadian Armed Forces

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 16 complaints against the Department of National Defence (DND) and the Canadian Armed Forces (CAF) regarding their COVID-19 vaccination attestation requirements. Complainants alleged unreasonable collection, improper use, insufficient access controls in the Monitor MASS system leading to unauthorized disclosure, and inaccurate data. The OPC found that the collection of vaccination status information, including for accommodation requests, directly related to DND's operating programs for health and safety and operational readiness, satisfying section 4 of the Privacy Act. The use of this information was also deemed consistent with the purposes for which it was collected, in line with section 7. While concerns were raised about Monitor MASS access controls, the OPC found no evidence of actual unauthorized disclosures, thus deeming this allegation not well-founded, though it did recommend improved oversight which DND declined. Furthermore, DND was found to have taken reasonable steps to ensure the accuracy of vaccination status data under section 6(2). The OPC also concluded that the measures were necessary and proportional given the pandemic context and the CAF's unique operational role.

Key Issues
  • Whether the collection of personal information, including vaccination status and accommodation request details, by DND/CAF related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act.
  • Whether the use of the personal information collected under the Directive was authorized under section 7 of the Privacy Act, specifically for applying administrative consequences.
  • Whether the use of Monitor MASS for collection and storage of CAF members' vaccination status resulted in unauthorized disclosure of information due to insufficient access controls, contrary to section 8(1) of the Privacy Act.
  • Whether DND took reasonable steps to ensure that personal information used for determining the COVID-19 vaccination status of CAF members was accurate, up-to-date, and complete as required by section 6(2) of the Privacy Act.
  • Whether the COVID-19 vaccination attestation requirements and associated information collection were necessary and proportional, applying the OPC's four-part test.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Vaccine mandates for domestic travel

Transport Canada

The Office of the Privacy Commissioner (OPC) investigated 18 complaints regarding the collection, use, and disclosure of vaccination information by Transport Canada, VIA Rail, and CATSA for domestic air and rail travel mandates between November 2021 and June 2022. Complainants alleged unlawful privacy violations and unreasonable limitations on mobility. The OPC found that the collection of vaccination information by CATSA and VIA Rail was directly related to their operating programs and activities, specifically administering Ministerial Orders for transportation safety. Furthermore, the uses and disclosures of personal information by CATSA and VIA Rail, and the centralized collection and use by Transport Canada, complied with sections 4, 7, and 8 of the Privacy Act. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed these principles and found the collections were overall necessary and proportional. However, the OPC identified concerns with the broad scope of the Orders' objectives and Transport Canada's limited documentation of less privacy-invasive alternatives. Consequently, the complaints were deemed not well-founded, but Transport Canada accepted recommendations for future similar measures to better define objectives and document alternative assessments. This report highlights the need to better reflect necessity and proportionality in public sector privacy law.

Quick view

Privacy ActNot well-founded

Vaccine mandates for domestic travel

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated 18 complaints regarding the collection, use, and disclosure of vaccination information by Transport Canada, VIA Rail, and CATSA for domestic air and rail travel mandates between November 2021 and June 2022. Complainants alleged unlawful privacy violations and unreasonable limitations on mobility. The OPC found that the collection of vaccination information by CATSA and VIA Rail was directly related to their operating programs and activities, specifically administering Ministerial Orders for transportation safety. Furthermore, the uses and disclosures of personal information by CATSA and VIA Rail, and the centralized collection and use by Transport Canada, complied with sections 4, 7, and 8 of the Privacy Act. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed these principles and found the collections were overall necessary and proportional. However, the OPC identified concerns with the broad scope of the Orders' objectives and Transport Canada's limited documentation of less privacy-invasive alternatives. Consequently, the complaints were deemed not well-founded, but Transport Canada accepted recommendations for future similar measures to better define objectives and document alternative assessments. This report highlights the need to better reflect necessity and proportionality in public sector privacy law.

Key Issues
  • Whether the vaccination information collected by CATSA and VIA Rail was directly related to their operating programs or activities, as required by section 4 of the Privacy Act
  • Whether the uses or disclosures of personal information by CATSA and VIA Rail were compliant with sections 4, 7, and 8 of the Privacy Act
  • Whether the centralized collection and use of personal information by Transport Canada was compliant with sections 4, 7, and 8 of the Privacy Act
  • Whether the collection of information was demonstrably necessary to meet a specific need
  • Whether the collection of information was likely to be effective in meeting that need
  • Whether there were less privacy-intrusive ways of achieving the same end
  • Whether the loss of privacy was proportional to the need
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Erroneous quarantine notifications from ArriveCAN

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint regarding erroneous quarantine notifications sent by the ArriveCAN application to approximately 10,200 Apple device users. These notifications, issued between June 28 and July 20, 2022, incorrectly instructed fully vaccinated travellers to quarantine due to a defect in ArriveCAN version 3.0. The OPC found that the Canada Border Services Agency (CBSA) failed to take all reasonable steps to ensure the accuracy of personal information used for an administrative purpose, as required by subsection 6(2) of the Privacy Act. Specifically, the OPC identified shortcomings in rigorous pre-release testing, effective human intervention, and timely correction and recourse for affected individuals. The CBSA disagreed with the finding and refused to implement the OPC's recommendation to correct the inaccurate "quarantine_exempted" value in its database. Consequently, the complaint was found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded

Erroneous quarantine notifications from ArriveCAN

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint regarding erroneous quarantine notifications sent by the ArriveCAN application to approximately 10,200 Apple device users. These notifications, issued between June 28 and July 20, 2022, incorrectly instructed fully vaccinated travellers to quarantine due to a defect in ArriveCAN version 3.0. The OPC found that the Canada Border Services Agency (CBSA) failed to take all reasonable steps to ensure the accuracy of personal information used for an administrative purpose, as required by subsection 6(2) of the Privacy Act. Specifically, the OPC identified shortcomings in rigorous pre-release testing, effective human intervention, and timely correction and recourse for affected individuals. The CBSA disagreed with the finding and refused to implement the OPC's recommendation to correct the inaccurate "quarantine_exempted" value in its database. Consequently, the complaint was found to be well-founded and unresolved.

Key Issues
  • Whether the Canada Border Services Agency (CBSA) took all reasonable steps to ensure that personal information used for an administrative decision was as accurate as possible under subsection 6(2) of the Privacy Act.
  • Whether the "quarantine_exempted" data field constituted personal information used for an administrative purpose by the CBSA.
  • Whether the CBSA conducted rigorous pre-release testing for issues that could lead to the highest negative impacts on individual users.
  • Whether the CBSA ensured effective human intervention with respect to high-impact decisions on individuals.
  • Whether the CBSA provided effective and timely correction and recourse for individuals affected by inaccurate information.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into the collection and use of de-identified mobility data in the course of the COVID-19 pandemic

Public Health Agency of Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated 12 complaints against the Public Health Agency of Canada (PHAC) and Health Canada regarding their collection and use of de-identified mobility data during the COVID-19 pandemic. Complainants alleged PHAC secretly collected data on 33 million mobile devices. PHAC maintained it only used de-identified and aggregated data, arguing the Privacy Act did not apply as no personal information was collected. The OPC's primary issue was whether the mobility data constituted "personal information" under Section 3 of the Privacy Act, specifically if de-identification and safeguards reduced re-identification risk below the "serious possibility" threshold. The investigation examined two data streams, from TELUS and BlueDot, and assessed the de-identification techniques, aggregation levels, access controls, and contractual safeguards in place. The OPC concluded that the combination of these measures reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were found to be not well-founded, as the data did not meet the definition of personal information under the Act. Despite this finding, the OPC made several recommendations to PHAC concerning ongoing assessment of de-identification techniques, due diligence with data providers, and enhanced transparency, which PHAC accepted.

Quick view

Privacy ActNot well-founded

Investigation into the collection and use of de-identified mobility data in the course of the COVID-19 pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 12 complaints against the Public Health Agency of Canada (PHAC) and Health Canada regarding their collection and use of de-identified mobility data during the COVID-19 pandemic. Complainants alleged PHAC secretly collected data on 33 million mobile devices. PHAC maintained it only used de-identified and aggregated data, arguing the Privacy Act did not apply as no personal information was collected. The OPC's primary issue was whether the mobility data constituted "personal information" under Section 3 of the Privacy Act, specifically if de-identification and safeguards reduced re-identification risk below the "serious possibility" threshold. The investigation examined two data streams, from TELUS and BlueDot, and assessed the de-identification techniques, aggregation levels, access controls, and contractual safeguards in place. The OPC concluded that the combination of these measures reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were found to be not well-founded, as the data did not meet the definition of personal information under the Act. Despite this finding, the OPC made several recommendations to PHAC concerning ongoing assessment of de-identification techniques, due diligence with data providers, and enhanced transparency, which PHAC accepted.

Key Issues
  • Whether mobility data collected and used by PHAC constituted "personal information" as defined under Section 3 of the Privacy Act.
  • Whether de-identification techniques and safeguards against re-identification were sufficient to reduce the risk of an individual being identified below the "serious possibility" threshold.
  • Whether access to data within TELUS's system constituted "collection" under the Privacy Act.
  • Whether de-identification alone is sufficient to render mobility data non-personal.
  • Whether robust contractual and physical protections were in place to limit access and use of de-identified data.
  • Whether acceptable data aggregation levels and access controls existed for aggregated mobility data.
  • Whether PHAC was sufficiently transparent with the public about its use of mobility data.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Protecting privacy in a pandemic

Federal Government Institutions and Biron Health Group

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

Quick view

Privacy ActWell-founded & conditionally resolved

Protecting privacy in a pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

Key Issues
  • Whether the collection of COVID-19 vaccination status for domestic travel was lawful under the Privacy Act
  • Whether the collection of COVID-19 vaccination status for domestic travel was necessary and proportional
  • Whether the handling of personal information collected for domestic travel vaccine mandates was reasonable
  • Whether the collection of COVID-19 vaccination status for entry into Canada was lawful under the Privacy Act
  • Whether the collection of COVID-19 vaccination status for entry into Canada was necessary and proportional
  • Whether the collection of federal employees' vaccination status and related medical/religious information was lawful under the Privacy Act
  • Whether the collection of federal employees' vaccination status and related medical/religious information was necessary and proportional
  • Whether the Monitor-MASS system used by DND/CAF had adequate oversight to prevent unauthorized access to personal information
  • Whether there were inappropriate disclosures of personal information related to federal employee vaccination status
  • Whether the Treasury Board of Canada contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description
  • Whether the Canada Border Services Agency (CBSA) took all reasonable steps to ensure the accuracy of information in the ArriveCAN app under section 6 of the Privacy Act
  • Whether the collection and use of de-identified mobility data by PHAC constituted the collection of personal information under the Privacy Act
  • Whether Biron Health Group obtained valid consent under PIPEDA for using personal information collected for COVID-19 testing for marketing purposes
  • Whether information sharing by RCMP, FINTRAC, and CSIS under the Emergencies Act complied with the Privacy Act
  • Whether information sharing under the Emergencies Act was necessary and proportionate
  • Whether there was clear direction and guidance for information sharing under the Emergencies Act
  • Whether appropriate safeguards were in place for personal information shared under the Emergencies Act
  • The need for modernized privacy laws to address necessity, proportionality, and de-identified information
  • The importance of transparency and accountability in government initiatives involving personal information during crises
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

Multiple federal separate employers

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints from federal public service employees against several separate employers regarding COVID-19 vaccination attestation requirements. Employees alleged that the collection, use, and disclosure of their vaccination status and accommodation requests contravened the Privacy Act. The OPC examined whether the information collected related directly to an operating program or activity (s.4) and if its uses and disclosures were authorized (s.7 and s.8). The OPC found that the collection was directly related to the employers' occupational health and safety programs and that uses and disclosures were consistent with the purpose of collection. Additionally, the OPC assessed the necessity and proportionality of these measures, concluding they were necessary and proportional given the emergency context of the pandemic. Consequently, the OPC found the complaints to be not well-founded. However, the OPC recommended that Canada Post Corporation refine its access controls for sensitive information and that all institutions conduct structured necessity and proportionality analyses for future privacy-invasive programs.

Quick view

Privacy ActNot well-founded

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints from federal public service employees against several separate employers regarding COVID-19 vaccination attestation requirements. Employees alleged that the collection, use, and disclosure of their vaccination status and accommodation requests contravened the Privacy Act. The OPC examined whether the information collected related directly to an operating program or activity (s.4) and if its uses and disclosures were authorized (s.7 and s.8). The OPC found that the collection was directly related to the employers' occupational health and safety programs and that uses and disclosures were consistent with the purpose of collection. Additionally, the OPC assessed the necessity and proportionality of these measures, concluding they were necessary and proportional given the emergency context of the pandemic. Consequently, the OPC found the complaints to be not well-founded. However, the OPC recommended that Canada Post Corporation refine its access controls for sensitive information and that all institutions conduct structured necessity and proportionality analyses for future privacy-invasive programs.

Key Issues
  • Whether the information collected by the respondents related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act
  • Whether uses and disclosures of information relating to employee vaccination status and requests for accommodation were authorized under sections 7 and 8 of the Privacy Act
  • Whether the information collected was necessary and proportional
  • Whether the measure was demonstrably necessary to meet a specific need
  • Whether the measure was likely to be effective in meeting that need
  • Whether there was a less privacy-intrusive way of achieving the same end
  • Whether the loss of privacy was proportional to the need
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

Treasury Board of Canada Secretariat

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

Quick view

Privacy ActWell-founded & resolved

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

Key Issues
  • Whether the information collected by institutions related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act.
  • Whether institutions properly met the transparency requirements of subsection 5(2) of the Privacy Act regarding informing individuals of the purpose of collection.
  • Whether the Treasury Board of Canada Secretariat (TBS) complied with subsection 11(1) of the Privacy Act by publishing an index of personal information banks.
  • Whether disclosures of personal information collected under the Policy were authorized under section 8 of the Privacy Act.
  • Whether the collection of personal information was necessary and proportional, applying the OPC's four-part test.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Vaccine mandates for entry into Canada

Public Health Agency of Canada (PHAC) and Canada Border Services Agency (CBSA)

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints regarding the collection, use, retention, and disclosure of personal information, including vaccination status, by the Public Health Agency of Canada (PHAC) and Canada Border Services Agency (CBSA) under Emergency Orders for entry into Canada during the COVID-19 pandemic. Complainants argued the measures were unlawful, unnecessary, and disproportionate. The OPC found that the collection of personal information was directly related to an operating program or activity of PHAC and CBSA, and its use and disclosure were for the purpose collected or consistent with it, or authorized by an Act of Parliament. The OPC also determined that the retention and disposal of information complied with the Privacy Act and related regulations. While necessity and proportionality are not explicit requirements of the Privacy Act, the OPC assessed these principles and found the collection overall to be necessary and proportional. However, the OPC identified gaps in PHAC's assessment and documentation of less privacy-intrusive alternatives and clarity of objectives in the final six months of the Orders. All complaints alleging contraventions of the Privacy Act were found to be not well-founded.

Quick view

Privacy ActNot well-founded

Vaccine mandates for entry into Canada

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints regarding the collection, use, retention, and disclosure of personal information, including vaccination status, by the Public Health Agency of Canada (PHAC) and Canada Border Services Agency (CBSA) under Emergency Orders for entry into Canada during the COVID-19 pandemic. Complainants argued the measures were unlawful, unnecessary, and disproportionate. The OPC found that the collection of personal information was directly related to an operating program or activity of PHAC and CBSA, and its use and disclosure were for the purpose collected or consistent with it, or authorized by an Act of Parliament. The OPC also determined that the retention and disposal of information complied with the Privacy Act and related regulations. While necessity and proportionality are not explicit requirements of the Privacy Act, the OPC assessed these principles and found the collection overall to be necessary and proportional. However, the OPC identified gaps in PHAC's assessment and documentation of less privacy-intrusive alternatives and clarity of objectives in the final six months of the Orders. All complaints alleging contraventions of the Privacy Act were found to be not well-founded.

Key Issues
  • Whether the personal information collected was directly related to an operating program or activity of PHAC and CBSA (s.4 Privacy Act)
  • Whether the personal information was used or disclosed for the purpose for which it was compiled/obtained, or in accordance with an Act of Parliament (s.7, s.8 Privacy Act)
  • Whether the personal information was disposed of in accordance with the Privacy Regulations and the Directive on Privacy Practices (s.6(3) Privacy Act)
  • Whether the collection of personal information under the Emergency Orders was necessary
  • Whether the collection of personal information under the Emergency Orders was effective
  • Whether there were less privacy-intrusive ways of achieving the same end
  • Whether the loss of privacy was proportional to the need