The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

8 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jun 26, 2024Indexed Jun 30, 2026

Investigation into the denial of access to a child’s personal information by Immigration, Refugees and Citizenship Canada

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant, a father involved in a custody dispute, submitted an ATIP request to Immigration, Refugees and Citizenship Canada (IRCC) for his minor child's passport application, which had been submitted by his former spouse. He provided a court order authorizing him to obtain his children's information from third parties. IRCC denied the request, stating that the child's consent was required. The complainant alleged that IRCC improperly denied access despite the court order. The OPC investigated whether the complainant had a right of access under paragraph 10(a) of the Privacy Regulations, which allows access on behalf of a minor under certain conditions. The OPC found that while the child was a minor and the complainant had legal authorization to administer the child's affairs, the request was not made on the child's behalf, but rather for the complainant's own interests. Therefore, the third condition of paragraph 10(a) was not met, and IRCC's denial was deemed reasonable.

Quick view

Privacy ActNot well-founded

Investigation into the denial of access to a child’s personal information by Immigration, Refugees and Citizenship Canada

Jun 26, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant, a father involved in a custody dispute, submitted an ATIP request to Immigration, Refugees and Citizenship Canada (IRCC) for his minor child's passport application, which had been submitted by his former spouse. He provided a court order authorizing him to obtain his children's information from third parties. IRCC denied the request, stating that the child's consent was required. The complainant alleged that IRCC improperly denied access despite the court order. The OPC investigated whether the complainant had a right of access under paragraph 10(a) of the Privacy Regulations, which allows access on behalf of a minor under certain conditions. The OPC found that while the child was a minor and the complainant had legal authorization to administer the child's affairs, the request was not made on the child's behalf, but rather for the complainant's own interests. Therefore, the third condition of paragraph 10(a) was not met, and IRCC's denial was deemed reasonable.

Key Issues
  • Whether the complainant had a right of access to his child’s personal information under section 10 of the Privacy Regulations
  • Whether the child was a minor at the time of the ATIP request
  • Whether the complainant had legal authorization to administer the child's affairs
  • Whether the complainant exercised the right of access on the minor’s behalf
  • Whether the child had the decision-making capacity to provide consent for the release of their personal information
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 29, 2024Indexed Jun 30, 2026

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Department of National Defence

The complainant, as the executor of a deceased Canadian Armed Forces member's estate, requested personal information from the Department of National Defence (DND) for estate administration purposes. DND initially refused disclosure, citing that the request did not meet the criteria under paragraph 10(b) of the Privacy Regulations and withheld information under section 26 of the Privacy Act, also claiming some records were not under its control or had surpassed retention periods. The OPC found that the complainant was authorized under paragraph 10(b) to access certain information (items 4, 5, 9, and later 2, 6, 7, 8) as it was relevant to potential civil claims regarding the deceased's financial situation and alleged undue influence. The investigation concluded that DND failed to conduct an adequate search for records and improperly applied section 26 without reviewing the records. DND was also found to have improperly deferred the complainant to an informal avenue without formally processing the request. The OPC recommended DND conduct a reasonable search for the specified records and provide a new response, which DND agreed to do. The complaint was therefore found well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Apr 29, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant, as the executor of a deceased Canadian Armed Forces member's estate, requested personal information from the Department of National Defence (DND) for estate administration purposes. DND initially refused disclosure, citing that the request did not meet the criteria under paragraph 10(b) of the Privacy Regulations and withheld information under section 26 of the Privacy Act, also claiming some records were not under its control or had surpassed retention periods. The OPC found that the complainant was authorized under paragraph 10(b) to access certain information (items 4, 5, 9, and later 2, 6, 7, 8) as it was relevant to potential civil claims regarding the deceased's financial situation and alleged undue influence. The investigation concluded that DND failed to conduct an adequate search for records and improperly applied section 26 without reviewing the records. DND was also found to have improperly deferred the complainant to an informal avenue without formally processing the request. The OPC recommended DND conduct a reasonable search for the specified records and provide a new response, which DND agreed to do. The complaint was therefore found well-founded and conditionally resolved.

Key Issues
  • Whether the complainant, as executor, was entitled to make a request on behalf of the deceased member under paragraph 10(b) of the Privacy Regulations for the purpose of administering the estate.
  • Whether the complainant sufficiently articulated or substantiated the precise purposes of the information to administer the estate and how the records in question could further those purposes.
  • Whether DND properly applied section 26 of the Privacy Act in refusing to disclose the requested information.
  • Whether DND conducted an adequate search for the requested records.
  • Whether DND improperly deferred the complainant to another avenue without formally processing a portion of the access request.
  • Whether personal information of a deceased individual (less than 20 years deceased) retains the same privacy protection as a living individual.
  • Whether the 'only for the purpose of such administration' clause in paragraph 10(b) of the Regulations imposes stricter requirements than 'relates to the administration of the individual’s estate' in MFIPPA.
  • Whether records sought to assist in prosecuting a civil claim brought on behalf of the estate for damages recoverable by the estate relate to the administration of the estate.
  • Whether records relevant to the deceased’s financial situation and allegations of fraud or theft of the deceased’s property relate to the administration of the estate.
  • Whether DND's obligation to process a formal access request is relieved if other informal avenues exist.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 28, 2024Indexed Jun 30, 2026

Investigation into the treatment by a government institution of the personal information of two employees with the same name

A federal government institution

An employee complained that her personal information was repeatedly disclosed to another employee with the same name, and that numerous administrative errors occurred in their respective files. The OPC found that the government institution contravened section 8 of the Privacy Act by mistakenly disclosing the complainant's personal information, including her PRI, email, mailing address, and financial and health information. It also contravened subsection 6(2) of the Act by failing to ensure the accuracy of personal information used for administrative purposes, leading to errors in employee files. The OPC concluded that these issues were systemic due to human error and a lack of awareness among employees regarding privacy breach reporting procedures. The institution accepted the OPC's recommendations to prevent unauthorized disclosures and ensure data accuracy, leading to a conditionally resolved finding.

Quick view

Privacy ActWell-founded

Investigation into the treatment by a government institution of the personal information of two employees with the same name

Mar 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee complained that her personal information was repeatedly disclosed to another employee with the same name, and that numerous administrative errors occurred in their respective files. The OPC found that the government institution contravened section 8 of the Privacy Act by mistakenly disclosing the complainant's personal information, including her PRI, email, mailing address, and financial and health information. It also contravened subsection 6(2) of the Act by failing to ensure the accuracy of personal information used for administrative purposes, leading to errors in employee files. The OPC concluded that these issues were systemic due to human error and a lack of awareness among employees regarding privacy breach reporting procedures. The institution accepted the OPC's recommendations to prevent unauthorized disclosures and ensure data accuracy, leading to a conditionally resolved finding.

Key Issues
  • Whether the government institution contravened section 8 of the Privacy Act by mistakenly disclosing the complainant’s personal information to another employee with the same name
  • Whether the government institution contravened subsection 6(2) of the Privacy Act by failing to ensure that personal information used for administrative purposes was accurate, up-to-date, and complete
  • Whether the repeated disclosures and inaccuracies constituted a systemic problem
  • Whether the institution's assessment of the sensitivity of the disclosed information was appropriate
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2024Indexed Jun 30, 2026

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Canada Revenue Agency (CRA)

An individual complained that the Canada Revenue Agency (CRA) failed to ensure the accuracy of their personal information, leading to an imposter fraudulently obtaining Canada Emergency Response Benefit (CERB) payments in their name. The imposter gained unauthorized access to the complainant's CRA My Account, changed direct deposit information, and applied for benefits. This resulted in the complainant receiving a tax reassessment for over $5,500. The OPC found that the CRA relied on inadequate safeguards against unauthorized access and modification, thus failing to take reasonable steps to ensure the accuracy of personal information used for administrative decisions under section 6(2) of the Privacy Act. The CRA has since implemented corrective measures, including enhanced authentication processes and security for high-impact modifications. The OPC found the complaint well-founded and conditionally resolved, noting the CRA's commitments to address the issues.

Quick view

Privacy ActWell-founded & conditionally resolved

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Mar 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that the Canada Revenue Agency (CRA) failed to ensure the accuracy of their personal information, leading to an imposter fraudulently obtaining Canada Emergency Response Benefit (CERB) payments in their name. The imposter gained unauthorized access to the complainant's CRA My Account, changed direct deposit information, and applied for benefits. This resulted in the complainant receiving a tax reassessment for over $5,500. The OPC found that the CRA relied on inadequate safeguards against unauthorized access and modification, thus failing to take reasonable steps to ensure the accuracy of personal information used for administrative decisions under section 6(2) of the Privacy Act. The CRA has since implemented corrective measures, including enhanced authentication processes and security for high-impact modifications. The OPC found the complaint well-founded and conditionally resolved, noting the CRA's commitments to address the issues.

Key Issues
  • Whether the CRA took all reasonable steps to ensure the accuracy of personal information used for administrative purposes under subsection 6(2) of the Privacy Act
  • Whether the safeguards in place at the time of the breach were adequate to prevent unauthorized access and modification of personal information
  • Whether the CRA's authentication processes were sufficient to prevent identity theft and fraudulent activity
  • Whether the CRA should have contacted Employment and Social Development Canada (ESDC) sooner regarding the complainant's identity theft
  • Whether the CRA provided timely notification of the privacy breach to the affected individual
  • Whether the CRA fulfilled its mandatory privacy breach reporting obligations to the OPC
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Feb 28, 2024Indexed Jun 30, 2026

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Department of National Defence

A representative, on behalf of a deceased member's estate executor, requested personal information from the Department of National Defence (DND) related to an investigation into allegations against the deceased. DND processed the request informally and disclosed some information under subparagraph 8(2)(m)(i) of the Privacy Act, but did not explicitly state its refusal to process the request formally under paragraph 10(b) of the Privacy Regulations. The OPC investigated whether the representative was entitled to make the request for the purpose of administering the estate. The OPC found that while the representative was authorized to administer the estate, they did not sufficiently demonstrate a connection between the requested information and the administration of the estate. Therefore, the complaint was not well-founded, as the representative failed to meet the requirements of paragraph 10(b) of the Regulations.

Quick view

Privacy ActNot well-founded

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Feb 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

A representative, on behalf of a deceased member's estate executor, requested personal information from the Department of National Defence (DND) related to an investigation into allegations against the deceased. DND processed the request informally and disclosed some information under subparagraph 8(2)(m)(i) of the Privacy Act, but did not explicitly state its refusal to process the request formally under paragraph 10(b) of the Privacy Regulations. The OPC investigated whether the representative was entitled to make the request for the purpose of administering the estate. The OPC found that while the representative was authorized to administer the estate, they did not sufficiently demonstrate a connection between the requested information and the administration of the estate. Therefore, the complaint was not well-founded, as the representative failed to meet the requirements of paragraph 10(b) of the Regulations.

Key Issues
  • Whether the representative was authorized to make a request on behalf of the deceased under paragraph 10(b) of the Regulations
  • Whether the request related only to the administration of the deceased's estate under paragraph 10(b) of the Regulations
  • Whether DND complied with section 16 of the Privacy Act regarding refusal notifications
  • Whether DND properly processed the request informally without explicit written consent and notification of rights
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Canada Revenue Agency and Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Key Issues
  • Whether Canada Revenue Agency (CRA) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether Employment and Social Development Canada (ESDC) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether CRA contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether ESDC contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether CRA and ESDC adequately assessed the level of identity authentication warranted for their online services.
  • Whether CRA and ESDC's identity assurance practices adequately protected against identity theft.
  • Whether CRA and ESDC's credential assurance practices adequately protected against credential stuffing.
  • Whether CRA and ESDC had adequately informed and accountable security decision-making processes.
  • Whether interdepartmental information sharing and accountability systems were adequate to protect personal information.
  • Whether CRA and ESDC conducted comprehensive vulnerability assessments and penetration testing.
  • Whether CRA and ESDC had effective monitoring to detect and promptly contain the ongoing breach.
  • Whether other federal departments using the GC Key service experienced fraudulent access or modification of personal information.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP's collection of personal information via Social Studio complied with Section 4 of the Privacy Act.
  • Whether the RCMP's collection of personal information via Babel X complied with Section 4 of the Privacy Act.
  • Whether the RCMP conducted adequate due diligence on the lawfulness of collection practices of Babel X and its data providers.
  • Whether Section 4 of the Privacy Act permits the collection of personal information from a third-party agent that collected, used, or disclosed the information in contravention of a law that third party is subject to.
  • Whether the RCMP's publicly available descriptions of its open-source information gathering are granular enough to meet transparency obligations under Section 11 of the Privacy Act.
  • Whether the RCMP's published descriptions clarify limits on purposes for collection under Section 11 of the Privacy Act.
  • Whether the RCMP's descriptions of open-source information collection and related purposes are adequate under Section 11 of the Privacy Act.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 24, 2024Indexed Jun 30, 2026

Investigation into a privacy breach at Immigration, Refugees and Citizenship Canada

Immigration, Refugees and Citizenship Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach. IRCC inadvertently disclosed the personal information of 497 individuals when sending mass email notifications for a work permit extension program. An employee failed to apply a filter to the email address column in an Excel spreadsheet, causing email addresses to misalign with other personal data, leading to notifications being sent to incorrect recipients. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose and that its prevention measures were insufficient. While IRCC's mitigation efforts, including notifying affected individuals, were deemed adequate, the OPC recommended implementing robust procedural and administrative controls. IRCC accepted these recommendations, committing to measures such as a 'two pairs of eyes' rule, updated operating procedures, and data quality assurance checks. Consequently, the OPC considered the matter resolved.

Quick view

Privacy ActWell-founded

Investigation into a privacy breach at Immigration, Refugees and Citizenship Canada

Jan 24, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach. IRCC inadvertently disclosed the personal information of 497 individuals when sending mass email notifications for a work permit extension program. An employee failed to apply a filter to the email address column in an Excel spreadsheet, causing email addresses to misalign with other personal data, leading to notifications being sent to incorrect recipients. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose and that its prevention measures were insufficient. While IRCC's mitigation efforts, including notifying affected individuals, were deemed adequate, the OPC recommended implementing robust procedural and administrative controls. IRCC accepted these recommendations, committing to measures such as a 'two pairs of eyes' rule, updated operating procedures, and data quality assurance checks. Consequently, the OPC considered the matter resolved.

Key Issues
  • Whether IRCC's disclosure of personal information to unintended recipients contravened section 8 of the Privacy Act.
  • Whether IRCC had sufficient measures in place to prevent unauthorized disclosures of personal information of this nature.
  • Whether IRCC's response to mitigate the impact of the breach on affected individuals was adequate.