The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

138 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

PA-048557, PA-048561 — Canadian Air Transport Security Authority (CATSA)

Canadian Air Transport Security Authority (CATSA)

An individual complained that the Canadian Air Transport Security Authority (CATSA) contravened the Privacy Act by collecting and disclosing his personal information to police after finding legal medical cannabis during a security screening. The complainant argued that CATSA's mandate is aviation security, not general law enforcement, and that cannabis is not a prohibited item. CATSA maintained that its actions were incidental to its mandate and in the public interest, consistent with its regulator's direction. The OPC found that CATSA lacked the legal authority under section 4 of the Privacy Act to collect personal information for general law enforcement purposes related to cannabis, as cannabis is not on the Prohibited Items List and does not pose an aviation security threat. Similarly, the OPC concluded that the disclosure of this personal information to police was not consistent with section 8 of the Privacy Act. However, the OPC found CATSA's practice of destroying records related to such searches to be consistent with section 6 of the Act. The OPC recommended that CATSA cease unauthorized collection and disclosure of personal information related to cannabis and destroy any existing records, which CATSA agreed to implement.

Quick view

Privacy ActWell-founded & conditionally resolved

PA-048557, PA-048561 — Canadian Air Transport Security Authority (CATSA)

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that the Canadian Air Transport Security Authority (CATSA) contravened the Privacy Act by collecting and disclosing his personal information to police after finding legal medical cannabis during a security screening. The complainant argued that CATSA's mandate is aviation security, not general law enforcement, and that cannabis is not a prohibited item. CATSA maintained that its actions were incidental to its mandate and in the public interest, consistent with its regulator's direction. The OPC found that CATSA lacked the legal authority under section 4 of the Privacy Act to collect personal information for general law enforcement purposes related to cannabis, as cannabis is not on the Prohibited Items List and does not pose an aviation security threat. Similarly, the OPC concluded that the disclosure of this personal information to police was not consistent with section 8 of the Privacy Act. However, the OPC found CATSA's practice of destroying records related to such searches to be consistent with section 6 of the Act. The OPC recommended that CATSA cease unauthorized collection and disclosure of personal information related to cannabis and destroy any existing records, which CATSA agreed to implement.

Key Issues
  • Whether the collection of personal information from travellers found to be in possession of cannabis is consistent with section 4 of the Privacy Act
  • Whether the disclosure of the personal information of travellers found to be in possession of cannabis is consistent with section 8 of the Privacy Act
  • Whether CATSA’s record retention practices in terms of the personal information collected from travellers found to be in possession of cannabis are consistent with section 6 of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Aug 6, 2020Indexed Jun 30, 2026

PA-055322 (PCO) et PA-055323 (DOJ) — Privy Council Office (PCO) and Department of Justice (DOJ)

Privy Council Office (PCO) and Department of Justice (DOJ)

The OPC investigated a complaint regarding the unauthorized disclosure of personal information about Supreme Court candidate Chief Justice Glenn Joyal. Media reports claimed an anonymous source revealed a disagreement between the Prime Minister's Office (PMO) and the former Attorney General over Joyal's nomination. The complainant alleged breaches of the Privacy Act by the Privy Council Office (PCO), Department of Justice (DOJ), Office of the Commissioner of Federal Judicial Affairs (CFJA), and the PMO. The OPC determined it lacked jurisdiction over the CFJA and PMO, focusing its investigation on the PCO and DOJ. The investigation found no evidence that either the PCO or the DOJ had access to the specific information that was leaked, nor that the disclosure originated from these institutions. While no contravention was found, the OPC highlighted that Chief Justice Joyal's privacy was compromised and called for legislative reform to extend the Privacy Act's coverage to all government institutions, including Ministers' Offices and the PMO.

Quick view

Privacy ActNot well-founded

PA-055322 (PCO) et PA-055323 (DOJ) — Privy Council Office (PCO) and Department of Justice (DOJ)

Aug 6, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated a complaint regarding the unauthorized disclosure of personal information about Supreme Court candidate Chief Justice Glenn Joyal. Media reports claimed an anonymous source revealed a disagreement between the Prime Minister's Office (PMO) and the former Attorney General over Joyal's nomination. The complainant alleged breaches of the Privacy Act by the Privy Council Office (PCO), Department of Justice (DOJ), Office of the Commissioner of Federal Judicial Affairs (CFJA), and the PMO. The OPC determined it lacked jurisdiction over the CFJA and PMO, focusing its investigation on the PCO and DOJ. The investigation found no evidence that either the PCO or the DOJ had access to the specific information that was leaked, nor that the disclosure originated from these institutions. While no contravention was found, the OPC highlighted that Chief Justice Joyal's privacy was compromised and called for legislative reform to extend the Privacy Act's coverage to all government institutions, including Ministers' Offices and the PMO.

Key Issues
  • Whether the Office of the Commissioner of Federal Judicial Affairs (CFJA) is a 'government institution' under the Privacy Act
  • Whether the Prime Minister's Office (PMO) is a 'government institution' under the Privacy Act
  • Whether the Privy Council Office (PCO) was responsible for the unauthorized disclosure of Chief Justice Joyal's personal information under section 8 of the Privacy Act
  • Whether the Department of Justice (DOJ) was responsible for the unauthorized disclosure of Chief Justice Joyal's personal information under section 8 of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jul 14, 2020Indexed Jun 30, 2026

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Canada Border Services Agency (CBSA)

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Quick view

Privacy ActNot well-founded

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Jul 14, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Key Issues
  • Did the CBSA disclose the complainant’s personal information?
  • Was any disclosed information “publicly available”, such that subsection 69(2) of the Act excludes application of sections 7 and 8?
  • If not, was the disclosure permitted under subsection 8(2) of the Act?
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Mar 31, 2020Indexed Jun 30, 2026

CBSA should only retain travellers’ digital device passcodes when necessary

Canada Border Services Agency (CBSA)

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Quick view

Privacy ActResolved

CBSA should only retain travellers’ digital device passcodes when necessary

Mar 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Key Issues
  • Whether the CBSA has the authority to require a traveller to provide a passcode to unlock a digital device for inspection purposes under the Customs Act
  • Whether the CBSA officer followed internal policies regarding the collection and retention of personal information (passcodes)
  • Whether the CBSA's retention of the passcode was necessary beyond the examination process when no further action was taken
  • Whether passcodes constitute sensitive personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 31, 2020Indexed Jun 30, 2026

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Employment and Social Development Canada (ESDC)

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Quick view

Privacy ActWell-founded

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Jan 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Key Issues
  • Whether the collection of video surveillance footage constituted personal information under s.3 of the Privacy Act
  • Whether the initial collection of video surveillance footage by ESDC was in compliance with s.4 of the Privacy Act
  • Whether ESDC informed individuals of the purpose for collecting personal information via video surveillance, as required by s.5 of the Privacy Act
  • Whether ESDC's use of video surveillance footage to monitor an employee's departure times was consistent with the purpose for which it was collected, as required by s.7(a) of the Privacy Act
  • Whether ESDC obtained consent for the use of video surveillance footage for purposes other than security, as required by s.7(a) of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jan 15, 2020Indexed Jun 30, 2026

Public disclosure of medical information during military trial consistent with Privacy Act

Department of National Defence

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

Public disclosure of medical information during military trial consistent with Privacy Act

Jan 15, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Key Issues
  • Whether the Privacy Act applies to military summary trial proceedings conducted by the Canadian Forces
  • Whether the disclosure of the complainant's medical information during the summary trial was made in accordance with section 8 of the Privacy Act
  • Whether the information became publicly available under section 69(2) of the Privacy Act once disclosed in an open court proceeding
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 30, 2019Indexed Jun 30, 2026

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Department of National Defence and Department of Justice

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Quick view

Privacy ActNot well-founded

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Dec 30, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Key Issues
  • Whether the collection of the complainant's personal medical information by the DOJ from the DND contravened the Privacy Act
  • Whether the disclosure of the complainant's personal medical information by the DND to the DOJ contravened the Privacy Act
  • Whether the collection by DOJ related directly to an operating program or activity of the institution under s.4 of the Privacy Act
  • Whether the collection by DOJ was permissible under s.5(1) of the Privacy Act given the disclosure under s.8(2)(d)
  • Whether the disclosure by DND was to the Attorney General of Canada under s.8(2)(d) of the Privacy Act
  • Whether the disclosure by DND was for use in legal proceedings involving the Crown in right of Canada or the Government of Canada under s.8(2)(d) of the Privacy Act
  • Whether the sensitivity of medical information impacts the permissibility of disclosure under the Privacy Act
  • Whether doctor-patient confidentiality prevents disclosure under the Privacy Act for litigation purposes
  • Whether the safeguarding measures for the disclosed information were adequate
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 9, 2019Statistics CanadaIndexed Jun 30, 2026

Statistics Canada: Invasive data initiatives should be redesigned with privacy in mind

Statistics Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated over a hundred complaints against Statistics Canada concerning its Credit Information Project and Financial Transactions Project. These initiatives involved collecting detailed personal information from a credit bureau (TransUnion) and financial institutions without individuals' direct knowledge or consent. The OPC found that Statistics Canada had the legal authority under section 13 of the Statistics Act to collect information for the Credit Information Project, as TransUnion provided existing records, thus deeming this aspect of the complaints not well-founded. However, the OPC had serious concerns that the Financial Transactions Project, as originally designed, would have exceeded this authority by requiring financial institutions to create new records; no formal finding was made as the project was halted. While no contravention of the Privacy Act was found, the OPC identified significant privacy concerns regarding the necessity and proportionality of both projects, Statistics Canada's lack of transparency, and deficiencies in internal monitoring safeguards. Statistics Canada committed to implementing all six OPC recommendations, including redesigning both projects with privacy principles in mind, increasing transparency, and enhancing internal security measures. The OPC also called for legislative reform of the Statistics Act and Privacy Act to address modern data collection practices.

Quick view

Privacy ActNot well-founded

Statistics Canada: Invasive data initiatives should be redesigned with privacy in mind

Dec 9, 2019Statistics Canada
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated over a hundred complaints against Statistics Canada concerning its Credit Information Project and Financial Transactions Project. These initiatives involved collecting detailed personal information from a credit bureau (TransUnion) and financial institutions without individuals' direct knowledge or consent. The OPC found that Statistics Canada had the legal authority under section 13 of the Statistics Act to collect information for the Credit Information Project, as TransUnion provided existing records, thus deeming this aspect of the complaints not well-founded. However, the OPC had serious concerns that the Financial Transactions Project, as originally designed, would have exceeded this authority by requiring financial institutions to create new records; no formal finding was made as the project was halted. While no contravention of the Privacy Act was found, the OPC identified significant privacy concerns regarding the necessity and proportionality of both projects, Statistics Canada's lack of transparency, and deficiencies in internal monitoring safeguards. Statistics Canada committed to implementing all six OPC recommendations, including redesigning both projects with privacy principles in mind, increasing transparency, and enhancing internal security measures. The OPC also called for legislative reform of the Statistics Act and Privacy Act to address modern data collection practices.

Key Issues
  • Whether Statistics Canada's collection of personal information for the Credit Information Project was within its legal authority under section 13 of the Statistics Act.
  • Whether Statistics Canada's proposed collection of personal information for the Financial Transactions Project, as originally designed, would have been within its legal authority under section 13 of the Statistics Act.
  • Whether the collection of personal information for the Credit Information Project related directly to an operating program or activity of Statistics Canada under section 4 of the Privacy Act.
  • Whether the collection of personal information for the Financial Transactions Project related directly to an operating program or activity of Statistics Canada under section 4 of the Privacy Act.
  • Whether the Credit Information Project, as originally designed, met the principles of necessity and proportionality.
  • Whether the Financial Transactions Project, as originally designed, met the principles of necessity and proportionality.
  • Whether Statistics Canada provided adequate transparency to individuals regarding the collection of their personal information for the Projects.
  • Whether Statistics Canada had appropriate safeguards, specifically regarding logging and monitoring for internal unauthorized access, to protect personal information collected via the Projects.
  • Whether Statistics Canada's de-identification and encryption safeguards were adequate.
  • Whether Statistics Canada had proper procedures for individuals to access their personal information.
  • Whether there was a risk of personal information collected via the Projects being disclosed for secondary purposes.
  • Whether Statistics Canada's Directive on Discretionary Disclosures adequately considered individuals' privacy interests when making disclosures under section 17(2)(a) of the Statistics Act.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 21, 2019Indexed Jun 30, 2026

Crossing the line? The CBSA’s examination of digital devices at the border

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Quick view

Privacy ActWell-founded

Crossing the line? The CBSA’s examination of digital devices at the border

Oct 21, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Key Issues
  • Whether CBSA's collection of personal information via digital device searches contravened section 4 of the Privacy Act.
  • Whether the definition of "goods" under the Customs Act extends to electronic documents on digital devices.
  • Whether CBSA's authority to search digital devices is limited to information stored on the device.
  • Whether Border Services Officers (BSOs) complied with CBSA's internal policy (Operational Bulletin PRG-2015-31) regarding digital device examinations (e.g., airplane mode, note-taking, search threshold).
  • Whether the copying of content from a digital device by a BSO was consistent with CBSA's legal authority and policy.
  • Whether the CBSA complied with its obligations under subsection 6(1) of the Privacy Act to retain personal information used for administrative purposes.
  • Whether the CBSA's practices regarding training, awareness, and accountability mechanisms for digital device searches were adequate.
  • Whether the Customs Act requires amendment to include a clear legal framework and a higher threshold for digital device examinations.
  • Whether the threshold for digital device examinations should be "reasonable grounds to suspect".
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jun 9, 2019Indexed Jun 30, 2026

Video recording in the workplace at correctional institutions consistent with the Privacy Act

Correctional Service Canada (CSC)

Three complaints alleged that Correctional Service Canada (CSC) improperly used video footage, collected for security, to monitor employee performance. The complainants provided emails from a correctional manager commenting on their patrols as evidence. CSC acknowledged using video for security and incident investigation but denied using it for performance monitoring. The OPC found that CSC reviewed the footage to identify systemic deficiencies in patrols following an inmate's death, aiming to improve security and prevent future deaths. The review was part of an action plan to address deficiencies identified in the death investigation. The OPC concluded that this use was consistent with the original purpose of collection, which was security, and therefore the complaints were not well-founded.

Quick view

Privacy ActNot well-founded

Video recording in the workplace at correctional institutions consistent with the Privacy Act

Jun 9, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

Three complaints alleged that Correctional Service Canada (CSC) improperly used video footage, collected for security, to monitor employee performance. The complainants provided emails from a correctional manager commenting on their patrols as evidence. CSC acknowledged using video for security and incident investigation but denied using it for performance monitoring. The OPC found that CSC reviewed the footage to identify systemic deficiencies in patrols following an inmate's death, aiming to improve security and prevent future deaths. The review was part of an action plan to address deficiencies identified in the death investigation. The OPC concluded that this use was consistent with the original purpose of collection, which was security, and therefore the complaints were not well-founded.

Key Issues
  • Whether video footage of employees constitutes personal information under s.3 of the Privacy Act
  • Whether CSC's use of video footage to review employee patrols constituted monitoring employee performance
  • Whether CSC's use of video footage was for the purpose for which it was obtained or compiled, or for a use consistent with that purpose, as per s.7(a) of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 29, 2019Indexed Jun 30, 2026

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Global Affairs Canada

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Quick view

Privacy ActWell-founded

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Mar 29, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Key Issues
  • Whether the information in the diplomatic passport constitutes personal information under s.3 of the Privacy Act
  • Whether Global Affairs Canada's request for the diplomatic passport constituted a collection of personal information
  • Whether Global Affairs Canada demonstrated its authority to collect the personal travel information under s.4 of the Privacy Act
  • Whether the collection of personal travel information related directly to an operating program or activity of Global Affairs Canada
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 28, 2019Indexed Jun 30, 2026

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Employment and Social Development Canada (ESDC)

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Quick view

Privacy ActWell-founded

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Mar 28, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Key Issues
  • Whether the complainant's name, telephone number, and email address constitute personal information under the Act
  • Whether ESDC was required to collect personal information directly from the complainant under section 5 of the Act
  • Whether ESDC complied with section 4 of the Act regarding the collection of personal information
  • Whether ESDC adequately ensured Grey House Publishing Canada complied with consent requirements as per their contract
  • Whether ESDC improperly collected the complainant's information after he requested removal from the distribution list
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 11, 2019Indexed Jun 30, 2026

The name of an individual is considered personal information if it is accompanied by information that is about the individual

Canadian Transportation Agency (CTA)

The complainant, an air passenger rights advocate, requested access to all records about himself held by the Canadian Transportation Agency (CTA). The CTA initially withheld 760 pages, arguing that most references to the complainant's name were not personal information because he was acting on behalf of an organization. The OPC found that the information was indeed personal information, as the organization was not a separate legal entity and the records contained views and information directly about the complainant. The OPC also found that the CTA incorrectly applied exemptions under section 26 (third-party personal information) and subsection 70(1) (cabinet confidences) in some instances, and over-redacted under section 27 (solicitor-client privilege). The complaint was found to be well-founded, and the CTA agreed to implement the OPC's recommendations to disclose the withheld information.

Quick view

Privacy ActWell-founded

The name of an individual is considered personal information if it is accompanied by information that is about the individual

Feb 11, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, an air passenger rights advocate, requested access to all records about himself held by the Canadian Transportation Agency (CTA). The CTA initially withheld 760 pages, arguing that most references to the complainant's name were not personal information because he was acting on behalf of an organization. The OPC found that the information was indeed personal information, as the organization was not a separate legal entity and the records contained views and information directly about the complainant. The OPC also found that the CTA incorrectly applied exemptions under section 26 (third-party personal information) and subsection 70(1) (cabinet confidences) in some instances, and over-redacted under section 27 (solicitor-client privilege). The complaint was found to be well-founded, and the CTA agreed to implement the OPC's recommendations to disclose the withheld information.

Key Issues
  • Whether information relating to the complainant's advocacy activities, where his name appears, constitutes personal information under section 3 of the Privacy Act
  • Whether the CTA correctly invoked paragraph 12(1)(b) to deny access to information it deemed not to be personal information
  • Whether the CTA correctly withheld third-party personal information under section 26 of the Privacy Act
  • Whether the CTA correctly withheld information under section 27 of the Privacy Act (solicitor-client privilege)
  • Whether the CTA correctly withheld information under subsection 70(1) of the Privacy Act (cabinet confidences)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 20, 2018Indexed Jun 30, 2026

Innovation, Science and Economic Development Canada fails to ensure that the information it used to staff a position was accurate

Innovation, Science and Economic Development Canada (ISED)

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) used inaccurate personal information about him when staffing a position. ISED acknowledged that its Human Resources officials mistakenly selected the complainant's profile in the MyGCHR system instead of another individual with the same name, leading to the complainant being 'hired' by ISED and 'terminated' from his position at Public Services and Procurement Canada (PSPC). This error caused the complainant to miss pay periods. The OPC found that ISED did not take all reasonable steps to ensure the accuracy of the personal information, as officials only used first and last names for the search and did not verify with additional identifiers like a Personal Record Identifier (PRI) or date of birth. The complaint was found to be well-founded, but ISED has since implemented a new policy requiring staff to validate identities using multiple data fields.

Quick view

Privacy ActWell-founded

Innovation, Science and Economic Development Canada fails to ensure that the information it used to staff a position was accurate

Aug 20, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) used inaccurate personal information about him when staffing a position. ISED acknowledged that its Human Resources officials mistakenly selected the complainant's profile in the MyGCHR system instead of another individual with the same name, leading to the complainant being 'hired' by ISED and 'terminated' from his position at Public Services and Procurement Canada (PSPC). This error caused the complainant to miss pay periods. The OPC found that ISED did not take all reasonable steps to ensure the accuracy of the personal information, as officials only used first and last names for the search and did not verify with additional identifiers like a Personal Record Identifier (PRI) or date of birth. The complaint was found to be well-founded, but ISED has since implemented a new policy requiring staff to validate identities using multiple data fields.

Key Issues
  • Whether the information at issue constituted personal information under section 3 of the Privacy Act
  • Whether ISED took all reasonable steps to ensure that the personal information it used for an administrative purpose was as accurate, up-to-date and complete as possible, as required by subsection 6(2) of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 12, 2018Repeat offenderIndexed Jun 30, 2026

Repeat offender: CSC unlawfully denies complainant access to his personal information a second time

Correctional Service Canada (CSC)

A federal inmate complained that Correctional Service Canada (CSC) repeatedly denied him access to his personal information, specifically video and audio recordings, in contravention of the Privacy Act. This complaint followed a similar investigation in 2012 where the OPC found serious deficiencies in CSC's handling of the complainant's requests, including failure to retain video recordings before destruction. In the current investigation, the OPC found that CSC again failed to retrieve and retain requested video recordings within their short retention period in two cases, and failed to respond to four other requests for grievance-related records. The OPC concluded that CSC contravened subsection 12(1) of the Privacy Act by denying the complainant access to his personal information. CSC accepted the OPC's recommendations to improve its processes for handling access requests for records with short retention periods and to respond to outstanding requests.

Quick view

Privacy ActWell-founded

Repeat offender: CSC unlawfully denies complainant access to his personal information a second time

Jun 12, 2018Repeat offender
Adjudicator: Daniel Therrien
Plain-Language Summary

A federal inmate complained that Correctional Service Canada (CSC) repeatedly denied him access to his personal information, specifically video and audio recordings, in contravention of the Privacy Act. This complaint followed a similar investigation in 2012 where the OPC found serious deficiencies in CSC's handling of the complainant's requests, including failure to retain video recordings before destruction. In the current investigation, the OPC found that CSC again failed to retrieve and retain requested video recordings within their short retention period in two cases, and failed to respond to four other requests for grievance-related records. The OPC concluded that CSC contravened subsection 12(1) of the Privacy Act by denying the complainant access to his personal information. CSC accepted the OPC's recommendations to improve its processes for handling access requests for records with short retention periods and to respond to outstanding requests.

Key Issues
  • Whether CSC contravened subsection 6(1) of the Privacy Act by failing to retain personal information for a prescribed period
  • Whether CSC contravened subsection 12(1) of the Privacy Act by failing to provide access to personal information
  • Whether CSC contravened subsection 16(3) of the Privacy Act by failing to respond to access requests within statutory time limits
  • Whether CSC appropriately applied paragraph 22(1)(c) of the Privacy Act to withhold video recordings
  • Whether CSC appropriately applied section 26 of the Privacy Act to withhold video recordings
  • Whether CSC made reasonable efforts to secure video recordings before destruction as per previous OPC recommendations
  • Whether CSC's processes for handling access requests for records with short retention periods are adequate