The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

138 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jun 4, 2018Indexed Jun 30, 2026

Disclosure of Canadian Forces members’ medical records by DND authorized under Privacy Act although record retention practices were insufficient

Department of National Defence

The complaint alleged that the Department of National Defence (DND) improperly disclosed deceased Canadian Forces (CF) members’ medical records to Military Police (MP) investigators for "sudden death suicide investigations" under paragraph 8(2)(e) of the Privacy Act, without due consideration for necessity. Complainants argued that CF-NIS investigations should be limited to determining if wounds were self-inflicted, not broader medical history. DND contended that its Directorate of Access to Information and Privacy (DAIP) was not required to "look behind" facially valid requests, and that the lawfulness of an investigation was the responsibility of the investigative body. The Office of the Privacy Commissioner (OPC) found the allegation that DND failed to properly assess the necessity of the information sought under s. 8(2)(e) to be not well-founded, concluding that DAIP generally exercised sufficient scrutiny. However, the OPC also found that DND failed to meet its obligations under subsection 8(4) of the Privacy Act and section 7 of the Privacy Regulations by not retaining copies of 8(2)(e) request forms in several cases and lacking comprehensive records of disclosures. This constituted a well-founded finding regarding DND's recordkeeping practices. The OPC recommended DND update its policies to ensure retention of all request forms, confirmation of statutory authority for investigations, and maintenance of comprehensive disclosure records. DND committed to implementing these recommendations within six months.

Quick view

Privacy ActNot well-founded

Disclosure of Canadian Forces members’ medical records by DND authorized under Privacy Act although record retention practices were insufficient

Jun 4, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint alleged that the Department of National Defence (DND) improperly disclosed deceased Canadian Forces (CF) members’ medical records to Military Police (MP) investigators for "sudden death suicide investigations" under paragraph 8(2)(e) of the Privacy Act, without due consideration for necessity. Complainants argued that CF-NIS investigations should be limited to determining if wounds were self-inflicted, not broader medical history. DND contended that its Directorate of Access to Information and Privacy (DAIP) was not required to "look behind" facially valid requests, and that the lawfulness of an investigation was the responsibility of the investigative body. The Office of the Privacy Commissioner (OPC) found the allegation that DND failed to properly assess the necessity of the information sought under s. 8(2)(e) to be not well-founded, concluding that DAIP generally exercised sufficient scrutiny. However, the OPC also found that DND failed to meet its obligations under subsection 8(4) of the Privacy Act and section 7 of the Privacy Regulations by not retaining copies of 8(2)(e) request forms in several cases and lacking comprehensive records of disclosures. This constituted a well-founded finding regarding DND's recordkeeping practices. The OPC recommended DND update its policies to ensure retention of all request forms, confirmation of statutory authority for investigations, and maintenance of comprehensive disclosure records. DND committed to implementing these recommendations within six months.

Key Issues
  • Whether DND's Directorate of Access to Information and Privacy (DAIP) improperly granted full access to deceased Canadian Forces (CF) members’ medical records under paragraph 8(2)(e) of the Privacy Act.
  • Whether the DAIP gave due consideration to the necessity of the requested records for the investigation.
  • Whether CF-NIS requests for medical records were permissible under paragraph 8(2)(e) given their internal policies limiting the scope of suicide investigations.
  • Whether DND's recordkeeping practices for 8(2)(e) requests and disclosures were consistent with subsection 8(4) of the Privacy Act and section 7 of the Privacy Regulations.
  • Whether the DAIP should verify the statutory authority under which an investigative body's lawful investigation is being conducted, in line with the TBS Directive.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 4, 2018Indexed Jun 30, 2026

Employee text messages intercepted without authorization at the Warkworth Institution

Correctional Service Canada (CSC)

The OPC received complaints alleging that Correctional Service Canada (CSC) contravened the Privacy Act by intercepting cell phone conversations and text messages near Warkworth Institution. CSC confirmed intercepting six text messages but denied recording conversations, stating it did not intend to collect text messages. The investigation found that CSC used a cell-site simulator, operated by a contractor, to detect unauthorized cell phone use by inmates. While the collection of metadata was deemed consistent with the Act due to security concerns, the interception of text message content was not authorized. The OPC concluded that CSC was responsible for the contractor's actions and that the collection of text messages contravened the Privacy Act. The complaints were found to be well-founded.

Quick view

Privacy ActWell-founded

Employee text messages intercepted without authorization at the Warkworth Institution

Jun 4, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC received complaints alleging that Correctional Service Canada (CSC) contravened the Privacy Act by intercepting cell phone conversations and text messages near Warkworth Institution. CSC confirmed intercepting six text messages but denied recording conversations, stating it did not intend to collect text messages. The investigation found that CSC used a cell-site simulator, operated by a contractor, to detect unauthorized cell phone use by inmates. While the collection of metadata was deemed consistent with the Act due to security concerns, the interception of text message content was not authorized. The OPC concluded that CSC was responsible for the contractor's actions and that the collection of text messages contravened the Privacy Act. The complaints were found to be well-founded.

Key Issues
  • Whether cell phone metadata constitutes personal information under the Privacy Act
  • Whether text messages constitute personal information under the Privacy Act
  • Whether the collection of cell phone metadata by CSC was consistent with section 4 of the Privacy Act
  • Whether the interception and collection of text message content by CSC was consistent with section 4 of the Privacy Act
  • Whether CSC is responsible for the actions of its contractor in collecting personal information
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 15, 2018Indexed Jun 30, 2026

Complaints in regard to Transport Canada’s requirement for owners of unmanned aircraft to display their personal information on the device

Transport Canada

Four complaints were filed against Transport Canada (TC) regarding its Interim Order requiring owners of unmanned aircraft (drones) to display their name, address, and telephone number on the device. Complainants argued this contravened the disclosure provisions of the Privacy Act by forcing public exposure of personal information without consent, and raised concerns about harassment or identity theft. TC stated the Interim Order was an interim measure to address significant safety risks posed by recreational drone users, citing a 200% increase in incidents since 2014. The OPC determined that while the information is personal, the requirement does not constitute a 'collection' of personal information by TC under sections 4 and 5 of the Privacy Act, and thus the disclosure provisions of section 8 do not apply. The OPC found no violation of the Act but noted TC's commitment to rework identification requirements in future regulations to address privacy concerns.

Quick view

Privacy ActNot well-founded

Complaints in regard to Transport Canada’s requirement for owners of unmanned aircraft to display their personal information on the device

May 15, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

Four complaints were filed against Transport Canada (TC) regarding its Interim Order requiring owners of unmanned aircraft (drones) to display their name, address, and telephone number on the device. Complainants argued this contravened the disclosure provisions of the Privacy Act by forcing public exposure of personal information without consent, and raised concerns about harassment or identity theft. TC stated the Interim Order was an interim measure to address significant safety risks posed by recreational drone users, citing a 200% increase in incidents since 2014. The OPC determined that while the information is personal, the requirement does not constitute a 'collection' of personal information by TC under sections 4 and 5 of the Privacy Act, and thus the disclosure provisions of section 8 do not apply. The OPC found no violation of the Act but noted TC's commitment to rework identification requirements in future regulations to address privacy concerns.

Key Issues
  • Whether the requirement to display personal information on unmanned aircraft constitutes a collection of personal information by Transport Canada under sections 4 and 5 of the Privacy Act
  • Whether the disclosure provisions of section 8 of the Privacy Act apply to the personal information displayed on unmanned aircraft as per the Interim Order
  • Whether the Interim Order contravenes the Privacy Act by obligating individuals to expose personal information to the public without consent
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 7, 2018Indexed Jun 30, 2026

Statistics Canada takes reasonable measures to safeguard census data transferred to Shared Services Canada

Statistics Canada

An anonymous complainant alleged that Statistics Canada (StatCan) improperly disclosed confidential census information to Shared Services Canada (SSC) when it transferred its informatics infrastructure, contravening the Statistics Act and risking unauthorized disclosure. The complainant raised concerns about StatCan's supervision over SSC employees, the storage of data in shared data centers, and the potential for disclosure during decryption. StatCan argued that SSC took over infrastructure, not data, and that SSC employees with access were 'deemed employees' under the Statistics Act, sworn to confidentiality, and subject to high security clearances. The Office of the Privacy Commissioner (OPC) found that StatCan was legally required to use SSC's services and, under section 16 of the Shared Services Canada Act, StatCan retained control and accountability for the data. The OPC concluded that StatCan took reasonable measures, including comprehensive agreements and security assessments, to define its relationship with SSC and protect the census data. Therefore, the complaint was deemed not well-founded.

Quick view

Privacy ActNot well-founded

Statistics Canada takes reasonable measures to safeguard census data transferred to Shared Services Canada

May 7, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant alleged that Statistics Canada (StatCan) improperly disclosed confidential census information to Shared Services Canada (SSC) when it transferred its informatics infrastructure, contravening the Statistics Act and risking unauthorized disclosure. The complainant raised concerns about StatCan's supervision over SSC employees, the storage of data in shared data centers, and the potential for disclosure during decryption. StatCan argued that SSC took over infrastructure, not data, and that SSC employees with access were 'deemed employees' under the Statistics Act, sworn to confidentiality, and subject to high security clearances. The Office of the Privacy Commissioner (OPC) found that StatCan was legally required to use SSC's services and, under section 16 of the Shared Services Canada Act, StatCan retained control and accountability for the data. The OPC concluded that StatCan took reasonable measures, including comprehensive agreements and security assessments, to define its relationship with SSC and protect the census data. Therefore, the complaint was deemed not well-founded.

Key Issues
  • Whether Statistics Canada improperly disclosed confidential census information to Shared Services Canada by transferring its informatics infrastructure.
  • Whether the sharing of census information with SSC contravenes the Statistics Act.
  • Whether Statistics Canada maintains sufficient supervision over SSC employees accessing census data.
  • Whether the storage of census data in SSC data centers shared with other federal institutions creates a risk of unauthorized disclosure.
  • Whether there is a risk of disclosure of confidential census data when it is decrypted for processing.
  • Whether Statistics Canada has taken sufficient steps to oversee SSC’s handling of census data on its behalf, consistent with its obligations under the Privacy Act.
  • Whether the transfer of personal information by StatCan to SSC for IT infrastructure services is authorized by the SSCA and consistent with the Privacy Act.
  • Whether StatCan has implemented appropriate privacy protection clauses and safeguards in its agreements with SSC.
  • Whether SSC employees with access to confidential census data have been properly sworn in as "deemed employees" under the Statistics Act.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 12, 2018Indexed Jun 30, 2026

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Health Canada

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Quick view

Privacy ActWell-founded

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Mar 12, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Key Issues
  • Whether the information collected by Health Canada on Limited Use forms for drug benefits constitutes personal information under the Privacy Act
  • Whether Health Canada's collection of personal information on Limited Use forms relates directly to an operating program or activity of the institution as required by section 4 of the Privacy Act
  • Whether the specific data fields requesting detailed diagnostic information (e.g., exact number of swollen joints) are necessary for the adjudication of drug benefit claims under the NIHB Program
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 16, 2017Indexed Jun 30, 2026

Cell site simulators used by RCMP not capable of intercepting private communication

Royal Canadian Mounted Police (RCMP)

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Quick view

Privacy ActWell-founded

Cell site simulators used by RCMP not capable of intercepting private communication

Aug 16, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Key Issues
  • Whether RCMP uses cell site simulators (MDIs)
  • Whether RCMP's MDIs are capable of intercepting private communications (voice, text, email, encryption keys)
  • Whether RCMP's collection of personal information using MDIs relates directly to an operating program or activity (s.4 Privacy Act)
  • Whether RCMP's collection of personal information using MDIs was lawful and Charter-compliant, specifically regarding prior judicial authorization
  • Whether exigent circumstances justified warrantless MDI deployments in certain cases
  • Whether RCMP's collection of personal information using MDIs complied with direct collection and notification requirements (s.5 Privacy Act)
  • Whether the RCMP adequately handles, retains, and disposes of third-party personal information (IMSI/IMEI numbers) collected by MDIs
  • Whether the wording in warrants and policies provides adequate protection for collected personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 19, 2017Indexed Jun 30, 2026

MyDemocracy website not designed in a privacy sensitive way

Privy Council Office

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Quick view

Privacy ActWell-founded

MyDemocracy website not designed in a privacy sensitive way

Jul 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Key Issues
  • Whether the MyDemocracy.ca website's design led to the disclosure of personal information to third parties (Facebook, Google Analytics) without consent.
  • Whether IP addresses, browser characteristics, and unique URLs constitute "personal information" under section 3 of the Privacy Act.
  • Whether the Privy Council Office (PCO) met its obligations under section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether PCO's amendments to the website and privacy policy were sufficient to obtain meaningful consent for data disclosure.
  • Whether PCO should have conducted a Privacy Impact Assessment (PIA) for the MyDemocracy.ca initiative.
  • Whether the collection of demographic information was justified and compliant with relevant standards.
  • Whether the use of Google Analytics complied with the Treasury Board of Canada Secretariat's (TBS) Standard on Privacy and Web Analytics.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Phoenix pay system compromised Public Servants’ privacy

Public Services and Procurement Canada

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Quick view

Privacy ActWell-founded

Phoenix pay system compromised Public Servants’ privacy

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Key Issues
  • Whether personal information was at issue in the reported incidents
  • Whether the personal information at issue was improperly disclosed
  • What was the scope of the improper disclosure
  • Whether the personal information that was improperly disclosed was misused
  • Whether PSPC was aware of potential privacy issues with Phoenix before the launch
  • What kind of harm could result from the unauthorized disclosure of the personal information at issue
  • Whether PSPC resolved all of the vulnerabilities within Phoenix
  • Whether PSPC provided individuals with timely information regarding the breaches and vulnerabilities
  • Whether PSPC developed and implemented controls to monitor and document access to personal information held in Phoenix (Recommendation 1)
  • Whether PSPC developed more robust testing and response procedures (Recommendation 2)
  • Whether PSPC conducted necessary assessments to identify potential risks and vulnerabilities in Phoenix (Recommendation 3)
  • Whether PSPC took measures to mitigate the increased vulnerability of information used by employees in call centres (Recommendation 4)
  • Whether PSPC reviewed its breach notification practices and provided notification of the extent of the Phoenix breaches (Recommendation 5)
  • Whether PSPC completed the review of pages with row-level security (Recommendation 6)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Health Canada

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Quick view

Privacy ActWell-founded

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Key Issues
  • Whether diagnostic information about individual patients constitutes 'personal information' under s.3 of the Privacy Act
  • Whether Health Canada contravened s.4 of the Privacy Act by collecting diagnostic information about patients seeking medical transportation and specialist services that was not directly related to an operating program or activity
  • Whether the collection of diagnostic information was demonstrably necessary to achieve a specific and legitimate purpose
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 19, 2017Indexed Jun 30, 2026

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Royal Canadian Mounted Police (RCMP)

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Quick view

Privacy ActWell-founded

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Apr 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Key Issues
  • Whether the RCMP inappropriately disclosed the complainant's personal information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(f) of the Privacy Act.
  • Whether CBP's use of the complainant's personal information for an admissibility assessment constituted "criminal justice purposes" or "law enforcement" as defined in the Memorandum of Cooperation (MOC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(a) of the Privacy Act as a "consistent use."
  • Whether the CPIC policies in effect at the time provided sufficient clarity to guard against unauthorized disclosure of sensitive personal information.
  • Whether the revised CPIC policies, including the "SHARE US A" feature and "SIP-OB" entries, adequately protect against unauthorized disclosure of attempted suicide information.
  • Whether the default setting of the "SHARE US A" feature in CPIC should suppress the sharing of SIP-OB entries relating to threatened or attempted suicides with US border officials.
  • Whether CPIC policies should be revised to provide clear guidance for sharing attempted suicide information with US border officials only where an individual presents an ongoing risk to others.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 20, 2016Indexed Jun 30, 2026

The PBC refuses to process requests for record suspension information

Parole Board of Canada

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Quick view

Privacy ActWell-founded

The PBC refuses to process requests for record suspension information

Dec 20, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Key Issues
  • Whether an individual can make a request under the Privacy Act to confirm that no personal information relating to record suspensions exists.
  • Whether the PBC properly applied the exemption under paragraph 22(1)(b) of the Privacy Act to refuse access requests for record suspension information.
  • Whether the disclosure of record suspension information under the Privacy Act would injure the enforcement of the Criminal Records Act.
  • Whether the PBC's requirement for additional identification (FPS number, PBC reference number, criminal record copy) is necessary to adequately identify a requester under the Privacy Act.
  • Whether the company's record suspension verification service circumvents the vulnerable sector verification process under the CRA.
  • Whether the consent obtained by the company for its service is valid.
  • Whether the proposed use of personal information by the company violates human rights legislation.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 6, 2016Indexed Jun 30, 2026

TV show raises numerous questions of consent

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Quick view

Privacy ActWell-founded

TV show raises numerous questions of consent

Jun 6, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Key Issues
  • Whether the CBSA, as a federal institution, could contract out of its obligations under the Privacy Act
  • Whether the CBSA's collection of personal information in connection with the TV Program related directly to an operating program or activity of the institution (s.4 Privacy Act)
  • Whether the CBSA was involved in the collection of personal information for the purposes of the TV Program
  • Whether there was a real-time disclosure of personal information by the CBSA to Force Four for the purpose of filming the TV Program
  • Whether the CBSA obtained valid, meaningful, and freely given consent from individuals, including the complainant, for the disclosure of their personal information to Force Four (s.8 Privacy Act)
  • Whether the "Voluntary Appearance Release Form" (Waiver) effectively waived individuals' rights under the Privacy Act
  • Whether the practice of "silent filming" by the production crew was consistent with obtaining valid consent
  • Whether the CBSA disclosed personal information of an intended subject to Force Four in advance of filming without authorization (s.8 Privacy Act)
  • Whether the personal information of the intended subject was publicly available at the time of disclosure
  • Whether the facial blurring and other identity concealment techniques used in the TV Program were sufficient to prevent the identification of individuals who had not provided written consent
  • Whether the CBSA demonstrated how the disclosure of personal information of individuals without written consent was consistent with section 8 of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 17, 2016Indexed Jun 30, 2026

Canada Revenue Agency takes adequate measures to ensure personal information not moved to U.S.

Canada Revenue Agency (CRA)

A complainant raised concerns that the Canada Revenue Agency (CRA) outsourced the storage of Canadian taxpayer information to Mobilshred Inc., which the complainant believed was a division of a US-based company, Recall. The complainant was concerned that this could make the personal information vulnerable to disclosure under the USA PATRIOT Act. The OPC investigated whether the CRA had properly safeguarded personal information from unauthorized disclosure. The CRA clarified that Mobilshred Inc. is a Canadian company, and the contract explicitly requires all physical records to remain in Canada. The OPC found that the CRA took appropriate steps to mitigate risks by ensuring all information remained in Canada and that Mobilshred Inc. is a Canadian entity. The complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

Canada Revenue Agency takes adequate measures to ensure personal information not moved to U.S.

May 17, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant raised concerns that the Canada Revenue Agency (CRA) outsourced the storage of Canadian taxpayer information to Mobilshred Inc., which the complainant believed was a division of a US-based company, Recall. The complainant was concerned that this could make the personal information vulnerable to disclosure under the USA PATRIOT Act. The OPC investigated whether the CRA had properly safeguarded personal information from unauthorized disclosure. The CRA clarified that Mobilshred Inc. is a Canadian company, and the contract explicitly requires all physical records to remain in Canada. The OPC found that the CRA took appropriate steps to mitigate risks by ensuring all information remained in Canada and that Mobilshred Inc. is a Canadian entity. The complaint was found to be not well-founded.

Key Issues
  • Whether the CRA properly safeguarded personal information entrusted to Mobilshred Inc. from unauthorized disclosure under the Privacy Act
  • Whether Canadian taxpayer information was vulnerable to disclosure to US authorities under the USA PATRIOT Act due to the contract with Mobilshred Inc.
  • Whether Mobilshred Inc. is a Canadian entity or affiliated with a US-based company
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Feb 8, 2016Indexed Jun 30, 2026

Canada Post collection of online signatures for mail tracking draws complaint

Canada Post Corporation

A complaint was filed against Canada Post Corporation (CPC) regarding its collection, use, and disclosure of electronic signatures for parcel tracking. The complainant raised concerns about the clarity of information provided to addressees regarding their option to opt-out of having their signature displayed online, and the absence of labels on signature devices at a specific postal outlet. The investigation also examined the privacy and security controls of CPC's online tracking website. CPC argued that disclosure of signatures to senders was authorized under the Privacy Act and that it provided an opt-out option. The OPC found that the collection and disclosure of signatures for parcel tracking were consistent with the Act, but raised concerns about the adequacy of security controls for online signatures. CPC committed to implementing enhanced security measures.

Quick view

Privacy ActNot well-founded

Canada Post collection of online signatures for mail tracking draws complaint

Feb 8, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Canada Post Corporation (CPC) regarding its collection, use, and disclosure of electronic signatures for parcel tracking. The complainant raised concerns about the clarity of information provided to addressees regarding their option to opt-out of having their signature displayed online, and the absence of labels on signature devices at a specific postal outlet. The investigation also examined the privacy and security controls of CPC's online tracking website. CPC argued that disclosure of signatures to senders was authorized under the Privacy Act and that it provided an opt-out option. The OPC found that the collection and disclosure of signatures for parcel tracking were consistent with the Act, but raised concerns about the adequacy of security controls for online signatures. CPC committed to implementing enhanced security measures.

Key Issues
  • Whether the collection of electronic signatures by CPC contravenes the Privacy Act
  • Whether the disclosure of electronic signatures to the sender of a parcel contravenes the Privacy Act
  • Whether the disclosure of electronic signatures online contravenes the Privacy Act
  • Whether CPC adequately safeguards digitized signatures displayed online
  • Whether the information provided to addressees about opting out of online signature display is sufficiently clear
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 30, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – RCMP

Royal Canadian Mounted Police (RCMP)

The complainant, an RCMP employee, alleged that the RCMP inappropriately used employees' personal information during a training course for Respectful Workplace Advisors on the National Administrative Records Management System (NARMS). During a data entry exercise, participants were given sheets containing real personal information of 91 employees, including names, ranks, and incident descriptions. The complainant raised concerns as participants were not advised real data would be used nor required to sign confidentiality agreements. The RCMP acknowledged that the use of this personal information for training purposes was not authorized under section 7 of the Privacy Act, as training was not a consistent use described in the applicable Personal Information Bank. The RCMP subsequently notified all 91 affected employees of the breach and took steps to prevent future occurrences. The OPC found the complaint to be well-founded.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – RCMP

Jul 30, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, an RCMP employee, alleged that the RCMP inappropriately used employees' personal information during a training course for Respectful Workplace Advisors on the National Administrative Records Management System (NARMS). During a data entry exercise, participants were given sheets containing real personal information of 91 employees, including names, ranks, and incident descriptions. The complainant raised concerns as participants were not advised real data would be used nor required to sign confidentiality agreements. The RCMP acknowledged that the use of this personal information for training purposes was not authorized under section 7 of the Privacy Act, as training was not a consistent use described in the applicable Personal Information Bank. The RCMP subsequently notified all 91 affected employees of the breach and took steps to prevent future occurrences. The OPC found the complaint to be well-founded.

Key Issues
  • Whether the use of employees' personal information for training purposes constituted an unauthorized use under section 7(a) of the Privacy Act
  • Whether training was a consistent use of personal information as described in the applicable Personal Information Bank (PIB PSU 915)