The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

16 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 7, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Canada Revenue Agency

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

May 7, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Key Issues
  • Whether the CRA adequately protected personal information against unauthorized disclosure and modification
  • Whether the CRA contravened subsection 6(2) of the Privacy Act regarding accuracy of personal information
  • Whether the CRA contravened subsection 8(2) of the Privacy Act regarding disclosure of personal information
  • Whether the CRA's prevention measures were adequate
  • Whether the CRA implemented mandatory multi-factor authentication (MFA) in a timely manner and with sufficient strength
  • Whether the CRA's authentication processes by phone were strong enough
  • Whether the CRA considered and integrated a zero-trust approach into its security measures
  • Whether the CRA had sufficient visibility over its attack surface and managed it effectively
  • Whether the CRA's vetting, training, and awareness tools were effective for employees and third parties
  • Whether the CRA's monitoring and detection approach was tailored to the threats and risks leading to Unauthorized Use of Taxpayer Information by a Third Party (UUTP)
  • Whether the CRA's remediation efforts for individual UUTPs were adequate, including root cause analysis
  • Whether the CRA's governance processes for addressing UUTPs were coordinated, comprehensive, and efficient
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 12, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Quick view

Privacy ActNot well-founded

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Mar 12, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Key Issues
  • Whether the CBSA authorized contractors to access personal information collected through ArriveCAN without the required security clearance, in contravention of sections 7 and 8 of the Privacy Act
  • Whether ArriveCAN contracts and Task Authorizations (TAs) contained appropriate clauses to ensure the protection of travellers’ personal information that contractors had access to
  • Whether security requirements identified in contracts and TAs were accurate and specific
  • Whether the CBSA complied with organizational security screening requirements for vendors
  • Whether the CBSA complied with personnel security screening requirements for contractors
  • Whether the CBSA implemented adequate administrative safeguards to protect personal information accessed by contractors
  • Whether the CBSA implemented adequate technical safeguards to protect personal information accessed by contractors
  • Whether the CBSA restricted contractor permissions and access to personal information to what was strictly necessary
Federal (Canada)Privacy ActWell-founded & unresolved
Federal (Canada) flag
Mar 11, 2025Indexed Jun 30, 2026

Investigation of the loss of an unencrypted Universal Serial Bus (USB) storage device by the Royal Canadian Mounted Police

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP) following the loss of an unencrypted USB storage device containing sensitive personal information of 1,741 individuals. The investigation focused on whether the RCMP contravened section 8 of the Privacy Act regarding disclosure, the appropriateness of its breach response, and the sufficiency of its safeguards for USB devices. The OPC found that the RCMP contravened section 8 due to unauthorized disclosure, as the device was lost, unencrypted, and its contents were copied and offered for sale. While the RCMP's notification to affected individuals and mitigation steps were generally appropriate after discovery, the initial reporting of the loss was significantly delayed. Furthermore, the RCMP failed to implement adequate safeguards, as its own policies for procurement, inventory, and encryption of USB devices were not followed, and security awareness training was insufficient. Despite the RCMP accepting the OPC's recommendations to strengthen safeguards, audit procedures, and awareness programs, it refused to commit to specific timelines for implementation. Consequently, the complaint was found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded & unresolved

Investigation of the loss of an unencrypted Universal Serial Bus (USB) storage device by the Royal Canadian Mounted Police

Mar 11, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP) following the loss of an unencrypted USB storage device containing sensitive personal information of 1,741 individuals. The investigation focused on whether the RCMP contravened section 8 of the Privacy Act regarding disclosure, the appropriateness of its breach response, and the sufficiency of its safeguards for USB devices. The OPC found that the RCMP contravened section 8 due to unauthorized disclosure, as the device was lost, unencrypted, and its contents were copied and offered for sale. While the RCMP's notification to affected individuals and mitigation steps were generally appropriate after discovery, the initial reporting of the loss was significantly delayed. Furthermore, the RCMP failed to implement adequate safeguards, as its own policies for procurement, inventory, and encryption of USB devices were not followed, and security awareness training was insufficient. Despite the RCMP accepting the OPC's recommendations to strengthen safeguards, audit procedures, and awareness programs, it refused to commit to specific timelines for implementation. Consequently, the complaint was found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP disclosed personal information in contravention of section 8 of the Privacy Act
  • Whether the RCMP's response to the privacy breach was appropriate in the circumstances
  • Whether the RCMP's measures to protect personal information contained on USB storage devices were sufficient
  • Whether RCMP personnel failed to report the loss of the USB storage device to authorities in a timely manner
  • Whether the RCMP's policies and procedures for procurement, inventory, and encryption of USB devices were followed and enforced
  • Whether the RCMP's security and privacy awareness training for members was effective and sufficient
  • Whether the RCMP's policy compliance monitoring for USB device use was adequate
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Canada Revenue Agency and Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Key Issues
  • Whether Canada Revenue Agency (CRA) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether Employment and Social Development Canada (ESDC) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether CRA contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether ESDC contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether CRA and ESDC adequately assessed the level of identity authentication warranted for their online services.
  • Whether CRA and ESDC's identity assurance practices adequately protected against identity theft.
  • Whether CRA and ESDC's credential assurance practices adequately protected against credential stuffing.
  • Whether CRA and ESDC had adequately informed and accountable security decision-making processes.
  • Whether interdepartmental information sharing and accountability systems were adequate to protect personal information.
  • Whether CRA and ESDC conducted comprehensive vulnerability assessments and penetration testing.
  • Whether CRA and ESDC had effective monitoring to detect and promptly contain the ongoing breach.
  • Whether other federal departments using the GC Key service experienced fraudulent access or modification of personal information.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP's collection of personal information via Social Studio complied with Section 4 of the Privacy Act.
  • Whether the RCMP's collection of personal information via Babel X complied with Section 4 of the Privacy Act.
  • Whether the RCMP conducted adequate due diligence on the lawfulness of collection practices of Babel X and its data providers.
  • Whether Section 4 of the Privacy Act permits the collection of personal information from a third-party agent that collected, used, or disclosed the information in contravention of a law that third party is subject to.
  • Whether the RCMP's publicly available descriptions of its open-source information gathering are granular enough to meet transparency obligations under Section 11 of the Privacy Act.
  • Whether the RCMP's published descriptions clarify limits on purposes for collection under Section 11 of the Privacy Act.
  • Whether the RCMP's descriptions of open-source information collection and related purposes are adequate under Section 11 of the Privacy Act.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

Multiple federal separate employers

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints from federal public service employees against several separate employers regarding COVID-19 vaccination attestation requirements. Employees alleged that the collection, use, and disclosure of their vaccination status and accommodation requests contravened the Privacy Act. The OPC examined whether the information collected related directly to an operating program or activity (s.4) and if its uses and disclosures were authorized (s.7 and s.8). The OPC found that the collection was directly related to the employers' occupational health and safety programs and that uses and disclosures were consistent with the purpose of collection. Additionally, the OPC assessed the necessity and proportionality of these measures, concluding they were necessary and proportional given the emergency context of the pandemic. Consequently, the OPC found the complaints to be not well-founded. However, the OPC recommended that Canada Post Corporation refine its access controls for sensitive information and that all institutions conduct structured necessity and proportionality analyses for future privacy-invasive programs.

Quick view

Privacy ActNot well-founded

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints from federal public service employees against several separate employers regarding COVID-19 vaccination attestation requirements. Employees alleged that the collection, use, and disclosure of their vaccination status and accommodation requests contravened the Privacy Act. The OPC examined whether the information collected related directly to an operating program or activity (s.4) and if its uses and disclosures were authorized (s.7 and s.8). The OPC found that the collection was directly related to the employers' occupational health and safety programs and that uses and disclosures were consistent with the purpose of collection. Additionally, the OPC assessed the necessity and proportionality of these measures, concluding they were necessary and proportional given the emergency context of the pandemic. Consequently, the OPC found the complaints to be not well-founded. However, the OPC recommended that Canada Post Corporation refine its access controls for sensitive information and that all institutions conduct structured necessity and proportionality analyses for future privacy-invasive programs.

Key Issues
  • Whether the information collected by the respondents related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act
  • Whether uses and disclosures of information relating to employee vaccination status and requests for accommodation were authorized under sections 7 and 8 of the Privacy Act
  • Whether the information collected was necessary and proportional
  • Whether the measure was demonstrably necessary to meet a specific need
  • Whether the measure was likely to be effective in meeting that need
  • Whether there was a less privacy-intrusive way of achieving the same end
  • Whether the loss of privacy was proportional to the need
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by Department of National Defence for members of the Canadian Armed Forces

Department of National Defence / Canadian Armed Forces

The Office of the Privacy Commissioner of Canada (OPC) investigated 16 complaints against the Department of National Defence (DND) and the Canadian Armed Forces (CAF) regarding their COVID-19 vaccination attestation requirements. Complainants alleged unreasonable collection, improper use, insufficient access controls in the Monitor MASS system leading to unauthorized disclosure, and inaccurate data. The OPC found that the collection of vaccination status information, including for accommodation requests, directly related to DND's operating programs for health and safety and operational readiness, satisfying section 4 of the Privacy Act. The use of this information was also deemed consistent with the purposes for which it was collected, in line with section 7. While concerns were raised about Monitor MASS access controls, the OPC found no evidence of actual unauthorized disclosures, thus deeming this allegation not well-founded, though it did recommend improved oversight which DND declined. Furthermore, DND was found to have taken reasonable steps to ensure the accuracy of vaccination status data under section 6(2). The OPC also concluded that the measures were necessary and proportional given the pandemic context and the CAF's unique operational role.

Quick view

Privacy ActNot well-founded

Investigation into COVID-19 vaccination attestation requirements established by Department of National Defence for members of the Canadian Armed Forces

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 16 complaints against the Department of National Defence (DND) and the Canadian Armed Forces (CAF) regarding their COVID-19 vaccination attestation requirements. Complainants alleged unreasonable collection, improper use, insufficient access controls in the Monitor MASS system leading to unauthorized disclosure, and inaccurate data. The OPC found that the collection of vaccination status information, including for accommodation requests, directly related to DND's operating programs for health and safety and operational readiness, satisfying section 4 of the Privacy Act. The use of this information was also deemed consistent with the purposes for which it was collected, in line with section 7. While concerns were raised about Monitor MASS access controls, the OPC found no evidence of actual unauthorized disclosures, thus deeming this allegation not well-founded, though it did recommend improved oversight which DND declined. Furthermore, DND was found to have taken reasonable steps to ensure the accuracy of vaccination status data under section 6(2). The OPC also concluded that the measures were necessary and proportional given the pandemic context and the CAF's unique operational role.

Key Issues
  • Whether the collection of personal information, including vaccination status and accommodation request details, by DND/CAF related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act.
  • Whether the use of the personal information collected under the Directive was authorized under section 7 of the Privacy Act, specifically for applying administrative consequences.
  • Whether the use of Monitor MASS for collection and storage of CAF members' vaccination status resulted in unauthorized disclosure of information due to insufficient access controls, contrary to section 8(1) of the Privacy Act.
  • Whether DND took reasonable steps to ensure that personal information used for determining the COVID-19 vaccination status of CAF members was accurate, up-to-date, and complete as required by section 6(2) of the Privacy Act.
  • Whether the COVID-19 vaccination attestation requirements and associated information collection were necessary and proportional, applying the OPC's four-part test.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into the collection and use of de-identified mobility data in the course of the COVID-19 pandemic

Public Health Agency of Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated 12 complaints against the Public Health Agency of Canada (PHAC) and Health Canada regarding their collection and use of de-identified mobility data during the COVID-19 pandemic. Complainants alleged PHAC secretly collected data on 33 million mobile devices. PHAC maintained it only used de-identified and aggregated data, arguing the Privacy Act did not apply as no personal information was collected. The OPC's primary issue was whether the mobility data constituted "personal information" under Section 3 of the Privacy Act, specifically if de-identification and safeguards reduced re-identification risk below the "serious possibility" threshold. The investigation examined two data streams, from TELUS and BlueDot, and assessed the de-identification techniques, aggregation levels, access controls, and contractual safeguards in place. The OPC concluded that the combination of these measures reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were found to be not well-founded, as the data did not meet the definition of personal information under the Act. Despite this finding, the OPC made several recommendations to PHAC concerning ongoing assessment of de-identification techniques, due diligence with data providers, and enhanced transparency, which PHAC accepted.

Quick view

Privacy ActNot well-founded

Investigation into the collection and use of de-identified mobility data in the course of the COVID-19 pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 12 complaints against the Public Health Agency of Canada (PHAC) and Health Canada regarding their collection and use of de-identified mobility data during the COVID-19 pandemic. Complainants alleged PHAC secretly collected data on 33 million mobile devices. PHAC maintained it only used de-identified and aggregated data, arguing the Privacy Act did not apply as no personal information was collected. The OPC's primary issue was whether the mobility data constituted "personal information" under Section 3 of the Privacy Act, specifically if de-identification and safeguards reduced re-identification risk below the "serious possibility" threshold. The investigation examined two data streams, from TELUS and BlueDot, and assessed the de-identification techniques, aggregation levels, access controls, and contractual safeguards in place. The OPC concluded that the combination of these measures reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were found to be not well-founded, as the data did not meet the definition of personal information under the Act. Despite this finding, the OPC made several recommendations to PHAC concerning ongoing assessment of de-identification techniques, due diligence with data providers, and enhanced transparency, which PHAC accepted.

Key Issues
  • Whether mobility data collected and used by PHAC constituted "personal information" as defined under Section 3 of the Privacy Act.
  • Whether de-identification techniques and safeguards against re-identification were sufficient to reduce the risk of an individual being identified below the "serious possibility" threshold.
  • Whether access to data within TELUS's system constituted "collection" under the Privacy Act.
  • Whether de-identification alone is sufficient to render mobility data non-personal.
  • Whether robust contractual and physical protections were in place to limit access and use of de-identified data.
  • Whether acceptable data aggregation levels and access controls existed for aggregated mobility data.
  • Whether PHAC was sufficiently transparent with the public about its use of mobility data.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Protecting privacy in a pandemic

Federal Government Institutions and Biron Health Group

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

Quick view

Privacy ActWell-founded & conditionally resolved

Protecting privacy in a pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

Key Issues
  • Whether the collection of COVID-19 vaccination status for domestic travel was lawful under the Privacy Act
  • Whether the collection of COVID-19 vaccination status for domestic travel was necessary and proportional
  • Whether the handling of personal information collected for domestic travel vaccine mandates was reasonable
  • Whether the collection of COVID-19 vaccination status for entry into Canada was lawful under the Privacy Act
  • Whether the collection of COVID-19 vaccination status for entry into Canada was necessary and proportional
  • Whether the collection of federal employees' vaccination status and related medical/religious information was lawful under the Privacy Act
  • Whether the collection of federal employees' vaccination status and related medical/religious information was necessary and proportional
  • Whether the Monitor-MASS system used by DND/CAF had adequate oversight to prevent unauthorized access to personal information
  • Whether there were inappropriate disclosures of personal information related to federal employee vaccination status
  • Whether the Treasury Board of Canada contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description
  • Whether the Canada Border Services Agency (CBSA) took all reasonable steps to ensure the accuracy of information in the ArriveCAN app under section 6 of the Privacy Act
  • Whether the collection and use of de-identified mobility data by PHAC constituted the collection of personal information under the Privacy Act
  • Whether Biron Health Group obtained valid consent under PIPEDA for using personal information collected for COVID-19 testing for marketing purposes
  • Whether information sharing by RCMP, FINTRAC, and CSIS under the Emergencies Act complied with the Privacy Act
  • Whether information sharing under the Emergencies Act was necessary and proportionate
  • Whether there was clear direction and guidance for information sharing under the Emergencies Act
  • Whether appropriate safeguards were in place for personal information shared under the Emergencies Act
  • The need for modernized privacy laws to address necessity, proportionality, and de-identified information
  • The importance of transparency and accountability in government initiatives involving personal information during crises
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

Treasury Board of Canada Secretariat

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

Quick view

Privacy ActWell-founded & resolved

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

Key Issues
  • Whether the information collected by institutions related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act.
  • Whether institutions properly met the transparency requirements of subsection 5(2) of the Privacy Act regarding informing individuals of the purpose of collection.
  • Whether the Treasury Board of Canada Secretariat (TBS) complied with subsection 11(1) of the Privacy Act by publishing an index of personal information banks.
  • Whether disclosures of personal information collected under the Policy were authorized under section 8 of the Privacy Act.
  • Whether the collection of personal information was necessary and proportional, applying the OPC's four-part test.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 20, 2022Indexed Jun 30, 2026

Investigation into a privacy breach at a Canada Border Services Agency contractor

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at a Canada Border Services Agency contractor

May 20, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Key Issues
  • Whether licence plate image files, including associated metadata (jurisdiction, characters, date, time, border crossing site, lane number), constitute personal information under Section 3 of the Privacy Act.
  • Whether the unauthorized access and disclosure of these licence plate image files constituted an improper disclosure under Section 8 of the Privacy Act.
  • Whether the Canada Border Services Agency (CBSA) had adequate security safeguards in place, particularly in its contractual arrangements with a third-party contractor, to protect personal information.
  • Whether the data retention practices for licence plate image files by the CBSA and its contractor were appropriate and compliant with the Privacy Act.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Review of passport protection practices of four federal institutions

Immigration, Refugees and Citizenship Canada (IRCC)

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Quick view

Privacy ActWell-founded & conditionally resolved

Review of passport protection practices of four federal institutions

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Key Issues
  • Whether the institutions had adequate controls to prevent unauthorized disclosures of passports under s.8 of the Privacy Act
  • Whether the institutions had adequate measures to detect potential unauthorized disclosures of passports
  • Whether the institutions had adequate measures to remediate risks to individuals from unauthorized disclosures of passports
  • Whether the institutions consistently and appropriately assessed the "materiality" of passport-related breaches
  • Whether notifications to affected individuals regarding lost or stolen passports were timely
  • Whether concrete assistance, such as credit monitoring, was offered to individuals affected by lost or stolen passports
  • Whether incident assessment and investigation processes were robust enough to identify suspicious patterns and share lessons learned among relevant stakeholders
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 9, 2019Statistics CanadaIndexed Jun 30, 2026

Statistics Canada: Invasive data initiatives should be redesigned with privacy in mind

Statistics Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated over a hundred complaints against Statistics Canada concerning its Credit Information Project and Financial Transactions Project. These initiatives involved collecting detailed personal information from a credit bureau (TransUnion) and financial institutions without individuals' direct knowledge or consent. The OPC found that Statistics Canada had the legal authority under section 13 of the Statistics Act to collect information for the Credit Information Project, as TransUnion provided existing records, thus deeming this aspect of the complaints not well-founded. However, the OPC had serious concerns that the Financial Transactions Project, as originally designed, would have exceeded this authority by requiring financial institutions to create new records; no formal finding was made as the project was halted. While no contravention of the Privacy Act was found, the OPC identified significant privacy concerns regarding the necessity and proportionality of both projects, Statistics Canada's lack of transparency, and deficiencies in internal monitoring safeguards. Statistics Canada committed to implementing all six OPC recommendations, including redesigning both projects with privacy principles in mind, increasing transparency, and enhancing internal security measures. The OPC also called for legislative reform of the Statistics Act and Privacy Act to address modern data collection practices.

Quick view

Privacy ActNot well-founded

Statistics Canada: Invasive data initiatives should be redesigned with privacy in mind

Dec 9, 2019Statistics Canada
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated over a hundred complaints against Statistics Canada concerning its Credit Information Project and Financial Transactions Project. These initiatives involved collecting detailed personal information from a credit bureau (TransUnion) and financial institutions without individuals' direct knowledge or consent. The OPC found that Statistics Canada had the legal authority under section 13 of the Statistics Act to collect information for the Credit Information Project, as TransUnion provided existing records, thus deeming this aspect of the complaints not well-founded. However, the OPC had serious concerns that the Financial Transactions Project, as originally designed, would have exceeded this authority by requiring financial institutions to create new records; no formal finding was made as the project was halted. While no contravention of the Privacy Act was found, the OPC identified significant privacy concerns regarding the necessity and proportionality of both projects, Statistics Canada's lack of transparency, and deficiencies in internal monitoring safeguards. Statistics Canada committed to implementing all six OPC recommendations, including redesigning both projects with privacy principles in mind, increasing transparency, and enhancing internal security measures. The OPC also called for legislative reform of the Statistics Act and Privacy Act to address modern data collection practices.

Key Issues
  • Whether Statistics Canada's collection of personal information for the Credit Information Project was within its legal authority under section 13 of the Statistics Act.
  • Whether Statistics Canada's proposed collection of personal information for the Financial Transactions Project, as originally designed, would have been within its legal authority under section 13 of the Statistics Act.
  • Whether the collection of personal information for the Credit Information Project related directly to an operating program or activity of Statistics Canada under section 4 of the Privacy Act.
  • Whether the collection of personal information for the Financial Transactions Project related directly to an operating program or activity of Statistics Canada under section 4 of the Privacy Act.
  • Whether the Credit Information Project, as originally designed, met the principles of necessity and proportionality.
  • Whether the Financial Transactions Project, as originally designed, met the principles of necessity and proportionality.
  • Whether Statistics Canada provided adequate transparency to individuals regarding the collection of their personal information for the Projects.
  • Whether Statistics Canada had appropriate safeguards, specifically regarding logging and monitoring for internal unauthorized access, to protect personal information collected via the Projects.
  • Whether Statistics Canada's de-identification and encryption safeguards were adequate.
  • Whether Statistics Canada had proper procedures for individuals to access their personal information.
  • Whether there was a risk of personal information collected via the Projects being disclosed for secondary purposes.
  • Whether Statistics Canada's Directive on Discretionary Disclosures adequately considered individuals' privacy interests when making disclosures under section 17(2)(a) of the Statistics Act.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Employment and Social Development Canada (ESDC)

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Quick view

Privacy ActWell-founded & resolved

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Key Issues
  • Whether Employment and Social Development Canada (ESDC) adequately protected personal information on a lost USB key
  • Whether Justice Canada adequately protected personal information on a lost USB key while in its custody
  • Whether physical controls for personal information were adequate
  • Whether technological controls (encryption, password protection) for personal information were adequate
  • Whether administrative controls for personal information were adequate
  • Whether personnel controls for personal information were adequate
  • Whether ESDC translated its privacy and security policies into meaningful business practices
  • Whether Justice Canada translated its privacy and security policies into meaningful business practices
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Woman fails in attempt to return personal information to Canada Revenue Agency

Canada Revenue Agency (CRA)

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Quick view

Privacy ActWell-founded

Woman fails in attempt to return personal information to Canada Revenue Agency

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Key Issues
  • Whether the Canada Revenue Agency breached the privacy rights of taxpayers by mistakenly sending confidential personal information to an unauthorized individual
  • Whether the Canada Revenue Agency's procedures for handling misdirected mail and breach reporting were adequate
  • Whether the Canada Revenue Agency's client service channels were accessible for reporting privacy breaches