BreachOfPrivacy
Decisions/Federal (Canada)

Federal (Canada) Privacy Decisions

Browse privacy decisions from Federal (Canada) — with AI-generated plain-language summaries for every ruling.

119 decisions matching
Federal (Canada)Privacy ActWell-founded
Mar 25, 2026· Indexed Jun 5, 2026

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Immigration, Refugees and Citizenship Canada

The OPC investigated a complaint alleging that Immigration, Refugees and Citizenship Canada (IRCC) improperly withheld access to personal information. The complainant requested the "History Section" of their case file, but IRCC only provided a subset of information from other sections, referred to as the "Short Form" report. The OPC found that IRCC's practice of systematically retrieving and processing only the Short Form report contravenes section 12 of the Privacy Act, as it fails to provide individuals with access to all personal information under the government's control. Although the specific file was eventually provided, IRCC refused to update its procedures to address the systemic issue.

Quick View

Privacy ActWell-founded

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint alleging that Immigration, Refugees and Citizenship Canada (IRCC) improperly withheld access to personal information. The complainant requested the "History Section" of their case file, but IRCC only provided a subset of information from other sections, referred to as the "Short Form" report. The OPC found that IRCC's practice of systematically retrieving and processing only the Short Form report contravenes section 12 of the Privacy Act, as it fails to provide individuals with access to all personal information under the government's control. Although the specific file was eventually provided, IRCC refused to update its procedures to address the systemic issue.

Key Issues
  • Whether IRCC's practice of only retrieving and processing a "Short Form" subset of records in response to access requests complies with the Privacy Act's access obligations.
  • Whether the "History Section" of the Global Case Management System (GCMS) file contains personal information.
  • Whether IRCC's assertion that information outside the "Short Form" would always be withheld under exemptions is valid.
  • Whether IRCC's failure to commit to updating its procedures constitutes a continuing contravention of the Privacy Act.
Federal (Canada)Privacy ActWell-founded
Mar 24, 2026· Indexed Jun 5, 2026

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Canada Border Services Agency (CBSA)

An employee of the Canada Border Services Agency (CBSA) complained that their personal information was inadvertently disclosed to colleagues due to improperly set folder permissions in the CBSA's information management system, Apollo. The CBSA confirmed the contravention of section 8 of the Privacy Act. While the CBSA took steps to correct the issue and improve practices, it did not commit to mandatory, trackable training for managing permissions, leading the OPC to find the complaint well-founded but unresolved.

Quick View

Privacy ActWell-founded

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Mar 24, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee of the Canada Border Services Agency (CBSA) complained that their personal information was inadvertently disclosed to colleagues due to improperly set folder permissions in the CBSA's information management system, Apollo. The CBSA confirmed the contravention of section 8 of the Privacy Act. While the CBSA took steps to correct the issue and improve practices, it did not commit to mandatory, trackable training for managing permissions, leading the OPC to find the complaint well-founded but unresolved.

Key Issues
  • Whether CBSA contravened section 8 of the Privacy Act by improperly disclosing employee personal information.
  • Adequacy of CBSA's response and corrective measures.
  • Whether CBSA's training and awareness initiatives for managing information system permissions are sufficient.
  • Whether the matter is resolved given CBSA's non-commitment to mandatory, trackable training.
Federal (Canada)Privacy ActNot well-founded
Mar 18, 2026· Indexed Jun 5, 2026

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Treasury Board of Canada Secretariat

This investigation examined the Treasury Board of Canada Secretariat's (TBS) handling of employee personal information related to the administration of the Direction on Prescribed Presence in the Workplace, which mandates minimum on-site workdays. The Office of the Privacy Commissioner of Canada (OPC) found that TBS's practices for both organizational compliance reporting (using aggregated data like turnstile and HR data) and individual compliance monitoring (relying on manager observation and self-reporting) were compliant with the Privacy Act. The OPC concluded that the complaint was not well-founded, noting TBS's effective balance between operational needs and employee privacy.

Quick View

Privacy ActNot well-founded

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Mar 18, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

This investigation examined the Treasury Board of Canada Secretariat's (TBS) handling of employee personal information related to the administration of the Direction on Prescribed Presence in the Workplace, which mandates minimum on-site workdays. The Office of the Privacy Commissioner of Canada (OPC) found that TBS's practices for both organizational compliance reporting (using aggregated data like turnstile and HR data) and individual compliance monitoring (relying on manager observation and self-reporting) were compliant with the Privacy Act. The OPC concluded that the complaint was not well-founded, noting TBS's effective balance between operational needs and employee privacy.

Key Issues
  • Collection of employee personal information for hybrid work model compliance
  • Retention and disposal of personal information
  • Use and disclosure of personal information
  • Transparency and adequacy of Personal Information Banks (PIBs)
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Mar 3, 2026· Indexed Jun 5, 2026

Correctional Service of Canada Deleted Video

Correctional Service of Canada

An inmate alleged that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, violating the Privacy Act's retention obligations. The OPC found that CSC did dispose of footage that it was obligated to retain for at least two years under the Act. CSC agreed to implement enhanced oversight, including monthly attestations and quarterly audits of use of force footage retention in its Pacific Region.

Quick View

Privacy ActWell-founded & conditionally resolved

Correctional Service of Canada Deleted Video

Mar 3, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An inmate alleged that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, violating the Privacy Act's retention obligations. The OPC found that CSC did dispose of footage that it was obligated to retain for at least two years under the Act. CSC agreed to implement enhanced oversight, including monthly attestations and quarterly audits of use of force footage retention in its Pacific Region.

Key Issues
  • Obligation to retain personal information used for administrative purposes under the Privacy Act
  • Adequacy of institutional policies for video retention
  • Ensuring reasonable access to personal information
  • Effectiveness of oversight measures for compliance
Federal (Canada)Privacy ActWell-founded & resolved
Feb 26, 2026· Indexed Jun 5, 2026

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Canada Border Services Agency

This report details an investigation into the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees due to improperly shared spreadsheets. While the CBSA contravened section 8 of the Privacy Act by disclosing information beyond what was necessary for the stated purposes, the agency took appropriate steps to notify affected individuals, contain the breaches, and implement measures to prevent recurrence. These measures included new data request procedures and the development of a new information management system.

Quick View

Privacy ActWell-founded & resolved

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Feb 26, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

This report details an investigation into the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees due to improperly shared spreadsheets. While the CBSA contravened section 8 of the Privacy Act by disclosing information beyond what was necessary for the stated purposes, the agency took appropriate steps to notify affected individuals, contain the breaches, and implement measures to prevent recurrence. These measures included new data request procedures and the development of a new information management system.

Key Issues
  • Whether the CBSA contravened section 8 of the Privacy Act by disclosing personal information.
  • Whether the CBSA took adequate steps to notify affected individuals.
  • Whether the CBSA took adequate steps to contain the impact of the breaches.
  • Whether the CBSA took adequate steps to reduce the risk of future breaches.
Federal (Canada)Privacy ActWell-founded
Feb 27, 2025· Indexed Apr 12, 2026

Investigation into the disclosure of an adopted child’s name to their biological mother by the Canada Revenue Agency

Canada Revenue Agency

This investigation examined allegations that the Canada Revenue Agency (CRA) inappropriately disclosed an adopted child's adoptive name, and the adoptive mother's personal information, to the child's biological mother. The OPC found that, on the balance of probabilities, the CRA likely disclosed the child's adoptive name, contravening section 8 of the Privacy Act. Deficiencies were also identified in the CRA's internal procedures for safeguarding adopted children's personal information. The complaint was found to be well-founded but not resolved, as the CRA agreed to implement some, but not all, of the OPC's recommendations.

Quick View

Privacy ActWell-founded

Investigation into the disclosure of an adopted child’s name to their biological mother by the Canada Revenue Agency

Feb 27, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

This investigation examined allegations that the Canada Revenue Agency (CRA) inappropriately disclosed an adopted child's adoptive name, and the adoptive mother's personal information, to the child's biological mother. The OPC found that, on the balance of probabilities, the CRA likely disclosed the child's adoptive name, contravening section 8 of the Privacy Act. Deficiencies were also identified in the CRA's internal procedures for safeguarding adopted children's personal information. The complaint was found to be well-founded but not resolved, as the CRA agreed to implement some, but not all, of the OPC's recommendations.

Key Issues
  • Whether the CRA disclosed the child's adoptive name and the adoptive mother's personal information to the biological mother without consent.
  • Whether the CRA's internal procedures adequately protected the personal information of adopted children.
  • Whether the CRA's actions contravened section 8 of the Privacy Act.
  • Whether the complaint was resolved based on the CRA's response to the OPC's recommendations.
Federal (Canada)Privacy ActWell-founded
Feb 26, 2025· Indexed Apr 12, 2026

Investigation into the Canada Revenue Agency’s application of paragraph 22(1)(b) to refuse access to personal information

Canada Revenue Agency

The complainant alleged that the Canada Revenue Agency (CRA) improperly denied access to personal information related to five grievances, relying on exceptions under the Privacy Act. The OPC found that while the CRA conducted reasonable searches, it failed to adequately substantiate its use of paragraph 22(1)(b) of the Act to withhold information. Much of the withheld information was transactional and did not demonstrate a clear risk of harm upon disclosure. The complaint was found to be well-founded, but unresolved, as the CRA maintained its position on the withheld information.

Quick View

Privacy ActWell-founded

Investigation into the Canada Revenue Agency’s application of paragraph 22(1)(b) to refuse access to personal information

Feb 26, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that the Canada Revenue Agency (CRA) improperly denied access to personal information related to five grievances, relying on exceptions under the Privacy Act. The OPC found that while the CRA conducted reasonable searches, it failed to adequately substantiate its use of paragraph 22(1)(b) of the Act to withhold information. Much of the withheld information was transactional and did not demonstrate a clear risk of harm upon disclosure. The complaint was found to be well-founded, but unresolved, as the CRA maintained its position on the withheld information.

Key Issues
  • Proper application of paragraph 22(1)(b) of the Privacy Act regarding risk of harm.
  • Adequacy of government institution's searches for responsive records.
  • Substantiation of claims for withholding information under statutory exemptions.
  • Requirement for case-by-case assessment when applying exemptions.
Federal (Canada)Privacy ActWell-founded
Jan 24, 2025· Indexed Apr 12, 2026

Measures to anonymize sensitive polygraph records mitigated privacy impacts of NSIRA review

NSIRA Secretariat

This investigation examined complaints regarding the National Security and Intelligence Review Agency's (NSIRA) Secretariat's request for access to polygraph records as part of a review of the Communications Security Establishment. The OPC found that the anonymization measures significantly reduced re-identification risks, and the polygraph recordings themselves contained no personal information. However, concerns were raised about the timeliness of the Secretariat's requests to Treasury Board Secretariat for approval of Personal Information Banks (PIBs). The collection issue was found not well-founded, but the timeliness of PIB updates was found well-founded and subsequently resolved.

Quick View

Privacy ActWell-founded

Measures to anonymize sensitive polygraph records mitigated privacy impacts of NSIRA review

Jan 24, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

This investigation examined complaints regarding the National Security and Intelligence Review Agency's (NSIRA) Secretariat's request for access to polygraph records as part of a review of the Communications Security Establishment. The OPC found that the anonymization measures significantly reduced re-identification risks, and the polygraph recordings themselves contained no personal information. However, concerns were raised about the timeliness of the Secretariat's requests to Treasury Board Secretariat for approval of Personal Information Banks (PIBs). The collection issue was found not well-founded, but the timeliness of PIB updates was found well-founded and subsequently resolved.

Key Issues
  • Whether the NSIRA Secretariat collected personal information without a direct relationship to its operating programs or activities.
  • Whether the NSIRA Secretariat complied with its obligations to include all personal information under its control in Personal Information Banks (PIBs).
  • Assessment of privacy mitigation measures implemented by CSE to anonymize polygraph records.
  • Timeliness of the NSIRA Secretariat's requests for PIB approvals and publication of its Info Source page.
Federal (Canada)Privacy ActNot well-founded
Jun 26, 2024· Indexed Apr 12, 2026

Investigation into the denial of access to a child’s personal information by Immigration, Refugees and Citizenship Canada

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant requested his minor child's passport application from Immigration, Refugees and Citizenship Canada (IRCC), citing a court order granting him access to his children's information. IRCC denied the request, stating the child's consent was required. The OPC found that while the complainant had legal authorization to act on his child's behalf, the request was not made for the child's benefit or best interests, a key condition under the Privacy Regulations. Therefore, the OPC concluded that the complainant did not have a right of access to the child's personal information.

Quick View

Privacy ActNot well-founded

Investigation into the denial of access to a child’s personal information by Immigration, Refugees and Citizenship Canada

Jun 26, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant requested his minor child's passport application from Immigration, Refugees and Citizenship Canada (IRCC), citing a court order granting him access to his children's information. IRCC denied the request, stating the child's consent was required. The OPC found that while the complainant had legal authorization to act on his child's behalf, the request was not made for the child's benefit or best interests, a key condition under the Privacy Regulations. Therefore, the OPC concluded that the complainant did not have a right of access to the child's personal information.

Key Issues
  • Whether a parent has an automatic right of access to a minor child's personal information under the Privacy Act.
  • Interpretation of the Privacy Regulations regarding requests made on behalf of a minor.
  • Whether the complainant's request served the child's best interests.
  • The decision-making capacity of a minor regarding their personal information.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Apr 29, 2024· Indexed Apr 12, 2026

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Department of National Defence

The complainant, as executor of a deceased individual's estate, requested personal information from the Department of National Defence (DND). DND refused to disclose most information, citing Privacy Act exemptions and arguing the request didn't meet the criteria for accessing information on behalf of a deceased person. The OPC found that the complainant was entitled to make the request for estate administration purposes and that DND failed to conduct an adequate search. DND agreed to conduct searches and provide a new response, leading to the complaint being conditionally resolved.

Quick View

Privacy ActWell-founded & conditionally resolved

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Apr 29, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant, as executor of a deceased individual's estate, requested personal information from the Department of National Defence (DND). DND refused to disclose most information, citing Privacy Act exemptions and arguing the request didn't meet the criteria for accessing information on behalf of a deceased person. The OPC found that the complainant was entitled to make the request for estate administration purposes and that DND failed to conduct an adequate search. DND agreed to conduct searches and provide a new response, leading to the complaint being conditionally resolved.

Key Issues
  • Eligibility of an estate executor to request personal information of a deceased individual.
  • Proper application of section 26 of the Privacy Act (disclosure of personal information about others).
  • Adequacy of DND's search for requested records.
  • DND's obligation to process formal access requests even if informal avenues exist.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Mar 28, 2024· Indexed Apr 12, 2026

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Canada Revenue Agency

The OPC investigated a complaint that the Canada Revenue Agency (CRA) failed to ensure the accuracy of a taxpayer's personal information used for administrative decisions. An imposter used the complainant's compromised CRA My Account to fraudulently receive COVID-19 benefits and Employment Insurance. The investigation found that the CRA's inadequate safeguards allowed unauthorized access and modification, contravening section 6(2) of the Privacy Act. The CRA has since implemented corrective measures.

Quick View

Privacy ActWell-founded & conditionally resolved

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Mar 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint that the Canada Revenue Agency (CRA) failed to ensure the accuracy of a taxpayer's personal information used for administrative decisions. An imposter used the complainant's compromised CRA My Account to fraudulently receive COVID-19 benefits and Employment Insurance. The investigation found that the CRA's inadequate safeguards allowed unauthorized access and modification, contravening section 6(2) of the Privacy Act. The CRA has since implemented corrective measures.

Key Issues
  • Adequacy of safeguards to protect against unauthorized access and modification of personal information.
  • Reasonable steps taken by the CRA to ensure the accuracy of personal information used for administrative decisions.
  • Timeliness of notification and privacy breach reporting.
  • Impact of identity theft on tax reassessments.
Federal (Canada)Privacy ActWell-founded
Mar 28, 2024· Indexed Apr 12, 2026

Investigation into the treatment by a government institution of the personal information of two employees with the same name

A federal government institution

The Office of the Privacy Commissioner of Canada investigated a complaint from a federal government employee who alleged that her personal information was repeatedly disclosed to another employee with the same name, and that administrative errors occurred in their files. The OPC found that the institution contravened the Privacy Act by improperly disclosing the complainant's personal information and by failing to ensure the accuracy of information used for administrative purposes. The complaint was found to be well-founded but conditionally resolved after the institution committed to implementing corrective measures.

Quick View

Privacy ActWell-founded

Investigation into the treatment by a government institution of the personal information of two employees with the same name

Mar 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada investigated a complaint from a federal government employee who alleged that her personal information was repeatedly disclosed to another employee with the same name, and that administrative errors occurred in their files. The OPC found that the institution contravened the Privacy Act by improperly disclosing the complainant's personal information and by failing to ensure the accuracy of information used for administrative purposes. The complaint was found to be well-founded but conditionally resolved after the institution committed to implementing corrective measures.

Key Issues
  • Unauthorized disclosure of personal information under section 8 of the Privacy Act.
  • Failure to ensure the accuracy and completeness of personal information used for administrative purposes under subsection 6(2) of the Privacy Act.
  • Lack of employee awareness regarding privacy breach reporting procedures.
  • Systemic nature of errors due to employees having the same name.
Federal (Canada)Privacy ActNot well-founded
Feb 28, 2024· Indexed Apr 12, 2026

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Department of National Defence

A representative acting for the executor of an estate requested personal information about a deceased individual from the Department of National Defence (DND). DND determined the representative was not entitled to the information under paragraph 10(b) of the Privacy Regulations because they did not sufficiently demonstrate a connection between the information sought and the administration of the estate. While DND processed the request informally and disclosed some information under another provision of the Act, they did not clearly state the grounds for refusal. The OPC found the complaint not well-founded as the representative failed to adequately articulate and substantiate the estate's purposes and how the records would serve them.

Quick View

Privacy ActNot well-founded

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Feb 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

A representative acting for the executor of an estate requested personal information about a deceased individual from the Department of National Defence (DND). DND determined the representative was not entitled to the information under paragraph 10(b) of the Privacy Regulations because they did not sufficiently demonstrate a connection between the information sought and the administration of the estate. While DND processed the request informally and disclosed some information under another provision of the Act, they did not clearly state the grounds for refusal. The OPC found the complaint not well-founded as the representative failed to adequately articulate and substantiate the estate's purposes and how the records would serve them.

Key Issues
  • Whether the representative was authorized to make a request on behalf of the deceased under paragraph 10(b) of the Privacy Regulations for the purpose of administering the estate.
  • Whether the representative sufficiently demonstrated a connection between the information sought and the administration of the deceased's estate.
  • Whether DND properly notified the representative of the refusal and the basis for it.
  • Whether DND properly handled the request informally.
Federal (Canada)Privacy ActWell-founded
Jan 24, 2024· Indexed Apr 12, 2026

Investigation into a privacy breach at Immigration, Refugees and Citizenship Canada

Immigration, Refugees and Citizenship Canada

Immigration, Refugees and Citizenship Canada (IRCC) contravened the Privacy Act when an employee inadvertently sent 497 emails containing personal information to the wrong email addresses. The investigation found that IRCC had insufficient administrative and procedural controls to prevent such errors. While IRCC took steps to notify affected individuals and mitigate harm, the Office of the Privacy Commissioner recommended improvements to prevent future breaches. IRCC accepted these recommendations and implemented enhanced measures, leading the OPC to consider the matter resolved.

Quick View

Privacy ActWell-founded

Investigation into a privacy breach at Immigration, Refugees and Citizenship Canada

Jan 24, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

Immigration, Refugees and Citizenship Canada (IRCC) contravened the Privacy Act when an employee inadvertently sent 497 emails containing personal information to the wrong email addresses. The investigation found that IRCC had insufficient administrative and procedural controls to prevent such errors. While IRCC took steps to notify affected individuals and mitigate harm, the Office of the Privacy Commissioner recommended improvements to prevent future breaches. IRCC accepted these recommendations and implemented enhanced measures, leading the OPC to consider the matter resolved.

Key Issues
  • Whether IRCC contravened section 8 of the Privacy Act by disclosing personal information to unintended recipients.
  • Adequacy of IRCC's administrative and procedural controls to prevent accidental disclosures.
  • Effectiveness of IRCC's measures to mitigate the impact of the breach on affected individuals.
  • Sufficiency of IRCC's actions to reduce the risk of recurrence.
Federal (Canada)Privacy ActWell-founded
Sep 21, 2023· Indexed Apr 12, 2026

Investigation into IRCC’s search for records using modified wording

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) failed to disclose all records sought under the Privacy Act. The investigation found that IRCC did not initially conduct a reasonable search for records, particularly concerning visa cancellations and reissuing. However, IRCC subsequently expanded its search to include all relevant offices, and although no additional information was found, the OPC was satisfied that its obligations under the Act were met, resolving the complaint.

Quick View

Privacy ActWell-founded

Investigation into IRCC’s search for records using modified wording

Sep 21, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) failed to disclose all records sought under the Privacy Act. The investigation found that IRCC did not initially conduct a reasonable search for records, particularly concerning visa cancellations and reissuing. However, IRCC subsequently expanded its search to include all relevant offices, and although no additional information was found, the OPC was satisfied that its obligations under the Act were met, resolving the complaint.

Key Issues
  • Reasonableness of IRCC's search for records.
  • Whether IRCC failed to disclose all responsive information.
  • Adequacy of IRCC's search scope and tasked offices.