The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

138 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Sep 16, 2014Indexed Jun 30, 2026

Name tags for border officers not a violation - September 16, 2014

Canada Border Services Agency (CBSA)

A group of Canada Border Services Agency (CBSA) employees complained that a new policy requiring them to wear name tags displaying their surnames, instead of badge numbers, violated sections 7 and 8 of the Privacy Act. They argued this constituted an unreasonable invasion of privacy and made them vulnerable to violence and intimidation, as their names could be used to find personal information. The CBSA contended that the name tags were part of a service excellence initiative, promoted professionalism and accountability, and that an employee's name on a name tag falls under an exception to the definition of personal information in the Act. The OPC found that while a surname on a name tag is information about an identifiable individual, it falls under paragraph (j) of the definition of personal information, which excludes information relating to the position or functions of a government employee for the purposes of sections 7 and 8. Therefore, the OPC concluded that the policy did not violate the Act.

Quick view

Privacy ActNot well-founded

Name tags for border officers not a violation - September 16, 2014

Sep 16, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A group of Canada Border Services Agency (CBSA) employees complained that a new policy requiring them to wear name tags displaying their surnames, instead of badge numbers, violated sections 7 and 8 of the Privacy Act. They argued this constituted an unreasonable invasion of privacy and made them vulnerable to violence and intimidation, as their names could be used to find personal information. The CBSA contended that the name tags were part of a service excellence initiative, promoted professionalism and accountability, and that an employee's name on a name tag falls under an exception to the definition of personal information in the Act. The OPC found that while a surname on a name tag is information about an identifiable individual, it falls under paragraph (j) of the definition of personal information, which excludes information relating to the position or functions of a government employee for the purposes of sections 7 and 8. Therefore, the OPC concluded that the policy did not violate the Act.

Key Issues
  • Whether the surname of a Border Services Officer (BSO) displayed on a name tag constitutes "personal information" under section 3 of the Privacy Act
  • Whether the surname on a name tag falls within the exception to the definition of personal information under paragraph (j) of section 3 of the Privacy Act
  • Whether the CBSA's requirement for BSOs to wear name tags displaying their surnames violates sections 7 and 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 5, 2014Indexed Jun 30, 2026

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Aboriginal Affairs and Northern Development Canada (AANDC)

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Quick view

Privacy ActWell-founded

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Sep 5, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Key Issues
  • Whether the document contained personal information under s.3 of the Privacy Act
  • Whether all AANDC officials who accessed the document had a need-to-know the identity of the requesters under s.7(a) of the Privacy Act and TBS Policy on Access to Information s.6.2.3
  • Whether the disclosure of the information to La Presse constituted a contravention of s.8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 9, 2014Indexed Jun 30, 2026

Sharing of health information unjustified - July 9, 2014

Public Service Commission of Canada (PSC)

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Quick view

Privacy ActWell-founded

Sharing of health information unjustified - July 9, 2014

Jul 9, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Key Issues
  • Whether the disclosure of the complainant's medical information to witnesses was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the PSC's interpretation of "affected person" and the requirements of procedural fairness justified the disclosure of sensitive medical information to all witnesses
  • Whether the PSC contravened subsection 8(1) of the Privacy Act by disclosing personal information without consent or a valid exception
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2014Indexed Jun 30, 2026

IP54-56/2014 — Employment and Social Development Canada

Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Quick view

Privacy ActWell-founded

IP54-56/2014 — Employment and Social Development Canada

Mar 24, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Key Issues
  • Whether ESDC failed to implement adequate physical security controls for personal information stored on portable media.
  • Whether ESDC failed to implement adequate technical security controls, such as encryption and risk assessments, for personal information on portable media.
  • Whether ESDC failed to implement adequate administrative controls, including asset inventory, information classification, and lifecycle management, for personal information.
  • Whether ESDC failed to implement adequate personnel security controls, such as employee training, awareness, and accountability, regarding personal information.
  • Whether ESDC contravened subsection 6(3) of the Privacy Act by failing to properly dispose of personal information.
  • Whether ESDC contravened section 7 of the Privacy Act regarding the use of personal information.
  • Whether ESDC contravened section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether the delay in notifying affected individuals of the breach was reasonable.
  • Whether the scope of personal information reported to affected individuals in the notification letters was complete.
Federal (Canada)Privacy ActNo jurisdiction
Federal (Canada) flag
Mar 4, 2014Indexed Jun 30, 2026

Retroactive removal of Privacy Act provisions leaves gun registry complainant with no recourse - 2015

Royal Canadian Mounted Police (RCMP)

The complainant alleged that the RCMP continued to retain and use personal information from the national long-gun registry, which should have been destroyed under the Ending the Long-Gun Registry Act. Specific allegations included a High River RCMP member's statement about locating firearms and an email from a Langley RCMP member referring to non-restricted firearm registration. The RCMP stated that electronic records were destroyed in October 2012 and hard copies by December 2013 (except for Quebec records). They also argued that information extracted from the registry before its destruction and retained in case files could be used consistent with its original purpose. The OPC found no evidence of contravention, noting that recent legislative amendments retroactively excluded the application of the Privacy Act to certain long-gun registry records, preventing further investigation into specific examples.

Quick view

Privacy ActNo jurisdiction

Retroactive removal of Privacy Act provisions leaves gun registry complainant with no recourse - 2015

Mar 4, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The complainant alleged that the RCMP continued to retain and use personal information from the national long-gun registry, which should have been destroyed under the Ending the Long-Gun Registry Act. Specific allegations included a High River RCMP member's statement about locating firearms and an email from a Langley RCMP member referring to non-restricted firearm registration. The RCMP stated that electronic records were destroyed in October 2012 and hard copies by December 2013 (except for Quebec records). They also argued that information extracted from the registry before its destruction and retained in case files could be used consistent with its original purpose. The OPC found no evidence of contravention, noting that recent legislative amendments retroactively excluded the application of the Privacy Act to certain long-gun registry records, preventing further investigation into specific examples.

Key Issues
  • Whether the RCMP continued to retain and use personal information from the national long-gun registry after it was required to be destroyed
  • Whether the High River RCMP used personal information from the long-gun registry in June 2013
  • Whether other RCMP detachments continued to use personal information from the long-gun registry after electronic records were destroyed in October 2012
  • Whether copies of the long-gun registry containing personal information still exist in the possession of the RCMP or other police services
  • Whether the use of personal information from the long-gun registry, retained in case files prior to the Ending the Long-gun Registry Act, is consistent with section 7 of the Privacy Act
  • Whether the retroactive exclusion of the Privacy Act by Bill C-59 affects the investigation
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Concern raised over online disclosure - The Qalipu Mi’kmaq First Nation Band

Aboriginal Affairs and Northern Development Canada (AANDC)

A woman complained to the OPC that Aboriginal Affairs and Northern Development Canada (AANDC) was putting her at risk of identity theft by publishing her full name and date of birth in the Canada Gazette, which is available online. This information was published as part of the enrollment process for the Qalipu Mi’kmaq First Nation Band. The OPC investigated whether this disclosure was consistent with the Privacy Act. The OPC determined that the disclosure was for the purpose for which the information was originally collected, which was for the identification and recognition of Band members. Therefore, the disclosure was permissible under the Privacy Act without the individual's consent. The complaint was found to be not well-founded, but the OPC recommended AANDC explore future options to mitigate identity theft risks.

Quick view

Privacy ActNot well-founded

Concern raised over online disclosure - The Qalipu Mi’kmaq First Nation Band

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained to the OPC that Aboriginal Affairs and Northern Development Canada (AANDC) was putting her at risk of identity theft by publishing her full name and date of birth in the Canada Gazette, which is available online. This information was published as part of the enrollment process for the Qalipu Mi’kmaq First Nation Band. The OPC investigated whether this disclosure was consistent with the Privacy Act. The OPC determined that the disclosure was for the purpose for which the information was originally collected, which was for the identification and recognition of Band members. Therefore, the disclosure was permissible under the Privacy Act without the individual's consent. The complaint was found to be not well-founded, but the OPC recommended AANDC explore future options to mitigate identity theft risks.

Key Issues
  • Whether the disclosure of full name and date of birth in the Canada Gazette was consistent with the Privacy Act
  • Whether personal information can be disclosed without consent when it is for the purpose for which it was originally collected
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Royal Canadian Mounted Police revealed absolute discharge

Royal Canadian Mounted Police (RCMP)

A man applied for a Transportation Security Clearance in July 2010, which was denied by Transport Canada (TC) in September 2011 based on information from the RCMP. The man complained that the RCMP improperly disclosed his personal information to TC. The RCMP had obtained information about an incident involving the complainant in 2009, which resulted in an absolute discharge a few months later. The RCMP provided this information to TC in 2011. The OPC found that the disclosure contravened the Criminal Records Act because more than a year had passed since the absolute discharge and no ministerial approval was obtained. The disclosure was also not authorized under the Privacy Act. The complaint was found to be well-founded.

Quick view

Privacy ActWell-founded

Royal Canadian Mounted Police revealed absolute discharge

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A man applied for a Transportation Security Clearance in July 2010, which was denied by Transport Canada (TC) in September 2011 based on information from the RCMP. The man complained that the RCMP improperly disclosed his personal information to TC. The RCMP had obtained information about an incident involving the complainant in 2009, which resulted in an absolute discharge a few months later. The RCMP provided this information to TC in 2011. The OPC found that the disclosure contravened the Criminal Records Act because more than a year had passed since the absolute discharge and no ministerial approval was obtained. The disclosure was also not authorized under the Privacy Act. The complaint was found to be well-founded.

Key Issues
  • Whether the RCMP's disclosure of personal information to Transport Canada contravened the Criminal Records Act
  • Whether the RCMP's disclosure of personal information to Transport Canada was authorized under the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Aboriginal Affairs and Northern Development Canada wrongly collects information from First Nations activist’s personal Facebook page

Aboriginal Affairs and Northern Development Canada and Department of Justice Canada

First Nations activist Cindy Blackstock complained that Aboriginal Affairs and Northern Development Canada (AANDC) and the Department of Justice Canada (DOJ) contravened the Privacy Act by collecting her personal information from her Facebook page. The departments argued that information posted publicly on Facebook was not personal. The OPC rejected this argument, finding that publicly available information can still be personal under the Privacy Act. The OPC found that the collection of personal information from Ms. Blackstock's personal Facebook page was not directly related to a government operating program or activity. Both departments accepted the OPC's recommendations to cease such collection, destroy previously collected personal information, and develop policies for social media monitoring.

Quick view

Privacy ActWell-founded

Aboriginal Affairs and Northern Development Canada wrongly collects information from First Nations activist’s personal Facebook page

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

First Nations activist Cindy Blackstock complained that Aboriginal Affairs and Northern Development Canada (AANDC) and the Department of Justice Canada (DOJ) contravened the Privacy Act by collecting her personal information from her Facebook page. The departments argued that information posted publicly on Facebook was not personal. The OPC rejected this argument, finding that publicly available information can still be personal under the Privacy Act. The OPC found that the collection of personal information from Ms. Blackstock's personal Facebook page was not directly related to a government operating program or activity. Both departments accepted the OPC's recommendations to cease such collection, destroy previously collected personal information, and develop policies for social media monitoring.

Key Issues
  • Whether information posted on a personal Facebook page constitutes "personal information" under the Privacy Act
  • Whether the public availability of personal information on the Internet renders it non-personal
  • Whether the collection of personal information from Ms. Blackstock's personal Facebook page was directly related to a government operating program or activity
  • Whether the monitoring of Ms. Blackstock's public speeches constituted collection of "personal information" under the Privacy Act
  • Whether repeated accessing of Ms. Blackstock's Indian status records was a contravention of the Privacy Act
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Correctional Service of Canada initially denies access to full report in favour of giving the “gist”

Correctional Service of Canada (CSC)

A complainant alleged that the Correctional Service of Canada (CSC) denied him full access to a report concerning his treatment and supervision. The complainant initially received a three-page summary, but later learned the full report was ten pages with more findings. The OPC's investigation confirmed the existence of the longer report. CSC stated they provided a condensed version because the full report was based on informal interviews. The OPC found that providing an abbreviated version misrepresented the information and was contrary to CSC's obligations under the Privacy Act to process all relevant information. After negotiations, CSC provided the full report with third-party personal information redacted and committed to reviewing its access request handling and educating staff on Privacy Act obligations.

Quick view

Privacy ActResolved

Correctional Service of Canada initially denies access to full report in favour of giving the “gist”

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that the Correctional Service of Canada (CSC) denied him full access to a report concerning his treatment and supervision. The complainant initially received a three-page summary, but later learned the full report was ten pages with more findings. The OPC's investigation confirmed the existence of the longer report. CSC stated they provided a condensed version because the full report was based on informal interviews. The OPC found that providing an abbreviated version misrepresented the information and was contrary to CSC's obligations under the Privacy Act to process all relevant information. After negotiations, CSC provided the full report with third-party personal information redacted and committed to reviewing its access request handling and educating staff on Privacy Act obligations.

Key Issues
  • Whether Correctional Service of Canada denied full access to a report
  • Whether providing a condensed version of a report constitutes a misrepresentation of information
  • Whether Correctional Service of Canada fulfilled its responsibility to identify and process all relevant information under the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Estranged wife accessed husband’s medical records

National Defence (DND)

A sergeant complained that his estranged wife, a civilian employee at a Canadian Forces Base, had unauthorized access to his military health records. The sergeant provided an audit log showing his wife accessed his Canadian Forces Health Information Services (CFHIS) account and deleted a physiotherapy appointment. National Defence (DND) confirmed the unauthorized access and noted she also accessed a paper physiotherapy file. DND determined she willfully breached departmental rules and implemented system restrictions to bar her access. The OPC found the access and use of medical information inconsistent with its original purpose and not a permissible use under the Privacy Act, upholding the complaint as well-founded. DND has since implemented new CFHIS controls and is evaluating its systems and practices for health information.

Quick view

Privacy ActWell-founded

Estranged wife accessed husband’s medical records

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A sergeant complained that his estranged wife, a civilian employee at a Canadian Forces Base, had unauthorized access to his military health records. The sergeant provided an audit log showing his wife accessed his Canadian Forces Health Information Services (CFHIS) account and deleted a physiotherapy appointment. National Defence (DND) confirmed the unauthorized access and noted she also accessed a paper physiotherapy file. DND determined she willfully breached departmental rules and implemented system restrictions to bar her access. The OPC found the access and use of medical information inconsistent with its original purpose and not a permissible use under the Privacy Act, upholding the complaint as well-founded. DND has since implemented new CFHIS controls and is evaluating its systems and practices for health information.

Key Issues
  • Whether the estranged wife's access to the sergeant's medical records was authorized
  • Whether the access and use of medical information was consistent with the purpose for which it was originally intended
  • Whether the access and use met permissible uses defined in the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Criminal background check on tenant

Royal Canadian Mounted Police (RCMP)

A woman complained that two RCMP employee landlords performed a criminal background check on her using the Canadian Police Information Centre (CPIC) database when she applied to rent a basement apartment. The landlords requested personal identification to "look into" prospective tenants. An internal RCMP investigation confirmed that one officer accessed CPIC for personal reasons, citing the applicant being from "out of town" and concerns for officer safety and organizational security. The OPC found that the CPIC database contains personal information and its use is restricted to legitimate law enforcement purposes. The investigation concluded that the officer's access was for personal reasons, not authorized operational purposes. The complaint was found to be well-founded, and the RCMP took remedial actions including an apology to the complainant and a communiqué to employees regarding CPIC use policies.

Quick view

Privacy ActWell-founded

Criminal background check on tenant

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained that two RCMP employee landlords performed a criminal background check on her using the Canadian Police Information Centre (CPIC) database when she applied to rent a basement apartment. The landlords requested personal identification to "look into" prospective tenants. An internal RCMP investigation confirmed that one officer accessed CPIC for personal reasons, citing the applicant being from "out of town" and concerns for officer safety and organizational security. The OPC found that the CPIC database contains personal information and its use is restricted to legitimate law enforcement purposes. The investigation concluded that the officer's access was for personal reasons, not authorized operational purposes. The complaint was found to be well-founded, and the RCMP took remedial actions including an apology to the complainant and a communiqué to employees regarding CPIC use policies.

Key Issues
  • Whether the CPIC database contains personal information under the Privacy Act
  • Whether the RCMP officer accessed the CPIC database for personal reasons
  • Whether the access to the CPIC database was for an authorized operational purpose
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Canada Revenue Agency employee accesses tax file without authorization

Canada Revenue Agency (CRA)

A complainant alleged that the Canada Revenue Agency (CRA) contravened the Privacy Act when an employee accessed his tax file without authorization in 2005 and 2006. The complainant became suspicious after community members showed knowledge of his financial information. An audit trail report revealed that a CRA employee had accessed his T1 tax account twice, viewing sensitive personal information including his Social Insurance Number, income, and family details. The OPC's investigation confirmed that the employee accessed the account without authorization and beyond the scope of their duties. The complaint was found to be well-founded, and CRA confirmed the employee no longer has access to taxpayer information.

Quick view

Privacy ActWell-founded

Canada Revenue Agency employee accesses tax file without authorization

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that the Canada Revenue Agency (CRA) contravened the Privacy Act when an employee accessed his tax file without authorization in 2005 and 2006. The complainant became suspicious after community members showed knowledge of his financial information. An audit trail report revealed that a CRA employee had accessed his T1 tax account twice, viewing sensitive personal information including his Social Insurance Number, income, and family details. The OPC's investigation confirmed that the employee accessed the account without authorization and beyond the scope of their duties. The complaint was found to be well-founded, and CRA confirmed the employee no longer has access to taxpayer information.

Key Issues
  • Whether a CRA employee accessed the complainant's tax file without authorization
  • Whether the unauthorized access contravened the use and disclosure provisions of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

National Defence employee accesses someone’s personal health records for her own personal reasons

National Defence

A complainant alleged that a Canadian Forces (CF) employee, with whom he had a prior personal relationship, inappropriately accessed his personal health information. The investigation found that the employee accessed the complainant’s health information in the Canadian Forces Health Information System (CFHIS) multiple times after receiving an anonymous message about the complainant's health. The employee admitted to accessing and using the information for personal reasons, which was inconsistent with the purpose for its collection. The complaint was found to be well-founded. As a result, National Defence acknowledged the importance of privacy awareness and training, implemented new controls in CFHIS, updated its health service policy, and provided training to CF healthcare staff.

Quick view

Privacy ActWell-founded

National Defence employee accesses someone’s personal health records for her own personal reasons

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a Canadian Forces (CF) employee, with whom he had a prior personal relationship, inappropriately accessed his personal health information. The investigation found that the employee accessed the complainant’s health information in the Canadian Forces Health Information System (CFHIS) multiple times after receiving an anonymous message about the complainant's health. The employee admitted to accessing and using the information for personal reasons, which was inconsistent with the purpose for its collection. The complaint was found to be well-founded. As a result, National Defence acknowledged the importance of privacy awareness and training, implemented new controls in CFHIS, updated its health service policy, and provided training to CF healthcare staff.

Key Issues
  • Whether a National Defence employee inappropriately accessed personal health information for personal reasons
  • Whether the access was inconsistent with the purpose for which the information was collected
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed May 13, 2026

Denial was the starting point for Correctional Service of Canada

Correctional Service of Canada

An inmate at a maximum-security penitentiary requested video recordings of incidents involving officers. The Correctional Service of Canada (CSC) denied access, citing third-party information and security concerns. The OPC found complaints regarding 16 destroyed videos to be well-founded, as CSC had not even reviewed them before denial. For two other videos, which CSC claimed contained third-party information and posed security risks, the OPC found CSC correctly applied exemptions, thus resolving those complaints.

Quick view

Privacy ActWell-founded

Denial was the starting point for Correctional Service of Canada

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An inmate at a maximum-security penitentiary requested video recordings of incidents involving officers. The Correctional Service of Canada (CSC) denied access, citing third-party information and security concerns. The OPC found complaints regarding 16 destroyed videos to be well-founded, as CSC had not even reviewed them before denial. For two other videos, which CSC claimed contained third-party information and posed security risks, the OPC found CSC correctly applied exemptions, thus resolving those complaints.

Key Issues
  • Timeliness of responding to access to information requests
  • Destruction of records prior to fulfilling requests
  • Application of exemptions for security of penal institutions
  • Proper review of records before withholding information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

Copying Google Result is Collecting Personal Information

Veterans Affairs Canada

An individual complained that Veterans Affairs Canada improperly collected his personal information. The individual had contacted Veterans Affairs and the National Capital Commission regarding a monument. Subsequently, a Veterans Affairs official searched the individual's email address on Google, finding a discussion page with personal information. The official then emailed the URL of this page to the entire email thread, stating the individual's email was "public domain." The OPC found that Veterans Affairs did not have a demonstrable need to collect the URL linking to the personal information. The collection of this URL was deemed a violation of the Privacy Act, as collected personal information must relate directly to an operating program or activity. The complaint was well-founded, and Veterans Affairs apologized and deleted the email from its systems.

Quick view

Privacy ActWell-founded

Copying Google Result is Collecting Personal Information

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Veterans Affairs Canada improperly collected his personal information. The individual had contacted Veterans Affairs and the National Capital Commission regarding a monument. Subsequently, a Veterans Affairs official searched the individual's email address on Google, finding a discussion page with personal information. The official then emailed the URL of this page to the entire email thread, stating the individual's email was "public domain." The OPC found that Veterans Affairs did not have a demonstrable need to collect the URL linking to the personal information. The collection of this URL was deemed a violation of the Privacy Act, as collected personal information must relate directly to an operating program or activity. The complaint was well-founded, and Veterans Affairs apologized and deleted the email from its systems.

Key Issues
  • Whether the collection of a URL linking to publicly available personal information constitutes collection under the Privacy Act
  • Whether the collected personal information related directly to an operating program or activity of Veterans Affairs Canada under section 4 of the Privacy Act