The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

4 decisions matching
Federal (Canada)Privacy ActWell-founded & unresolved
Federal (Canada) flag
Mar 11, 2025Indexed Jun 30, 2026

Investigation of the loss of an unencrypted Universal Serial Bus (USB) storage device by the Royal Canadian Mounted Police

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP) following the loss of an unencrypted USB storage device containing sensitive personal information of 1,741 individuals. The investigation focused on whether the RCMP contravened section 8 of the Privacy Act regarding disclosure, the appropriateness of its breach response, and the sufficiency of its safeguards for USB devices. The OPC found that the RCMP contravened section 8 due to unauthorized disclosure, as the device was lost, unencrypted, and its contents were copied and offered for sale. While the RCMP's notification to affected individuals and mitigation steps were generally appropriate after discovery, the initial reporting of the loss was significantly delayed. Furthermore, the RCMP failed to implement adequate safeguards, as its own policies for procurement, inventory, and encryption of USB devices were not followed, and security awareness training was insufficient. Despite the RCMP accepting the OPC's recommendations to strengthen safeguards, audit procedures, and awareness programs, it refused to commit to specific timelines for implementation. Consequently, the complaint was found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded & unresolved

Investigation of the loss of an unencrypted Universal Serial Bus (USB) storage device by the Royal Canadian Mounted Police

Mar 11, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP) following the loss of an unencrypted USB storage device containing sensitive personal information of 1,741 individuals. The investigation focused on whether the RCMP contravened section 8 of the Privacy Act regarding disclosure, the appropriateness of its breach response, and the sufficiency of its safeguards for USB devices. The OPC found that the RCMP contravened section 8 due to unauthorized disclosure, as the device was lost, unencrypted, and its contents were copied and offered for sale. While the RCMP's notification to affected individuals and mitigation steps were generally appropriate after discovery, the initial reporting of the loss was significantly delayed. Furthermore, the RCMP failed to implement adequate safeguards, as its own policies for procurement, inventory, and encryption of USB devices were not followed, and security awareness training was insufficient. Despite the RCMP accepting the OPC's recommendations to strengthen safeguards, audit procedures, and awareness programs, it refused to commit to specific timelines for implementation. Consequently, the complaint was found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP disclosed personal information in contravention of section 8 of the Privacy Act
  • Whether the RCMP's response to the privacy breach was appropriate in the circumstances
  • Whether the RCMP's measures to protect personal information contained on USB storage devices were sufficient
  • Whether RCMP personnel failed to report the loss of the USB storage device to authorities in a timely manner
  • Whether the RCMP's policies and procedures for procurement, inventory, and encryption of USB devices were followed and enforced
  • Whether the RCMP's security and privacy awareness training for members was effective and sufficient
  • Whether the RCMP's policy compliance monitoring for USB device use was adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 27, 2025Indexed Jun 30, 2026

Investigation into the disclosure of an adopted child’s name to their biological mother by the Canada Revenue Agency

Canada Revenue Agency (CRA)

A complainant alleged that the Canada Revenue Agency (CRA) inappropriately disclosed her adoptive child's name and her personal information to the child's biological mother, contravening section 8 of the Privacy Act. The child's name had been changed for safety reasons after a closed adoption. The OPC found that, on the balance of probabilities, the CRA likely disclosed the child's adoptive name to the biological mother, leading to significant negative impacts on the family. The investigation also revealed deficiencies in the CRA's internal procedures for safeguarding adopted children's personal information. The OPC issued recommendations to revise procedures, provide comprehensive training, and implement oversight measures. The CRA agreed to implement two of the three recommendations, but declined the oversight measure, leading to a "well-founded and not resolved" finding.

Quick view

Privacy ActWell-founded

Investigation into the disclosure of an adopted child’s name to their biological mother by the Canada Revenue Agency

Feb 27, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

A complainant alleged that the Canada Revenue Agency (CRA) inappropriately disclosed her adoptive child's name and her personal information to the child's biological mother, contravening section 8 of the Privacy Act. The child's name had been changed for safety reasons after a closed adoption. The OPC found that, on the balance of probabilities, the CRA likely disclosed the child's adoptive name to the biological mother, leading to significant negative impacts on the family. The investigation also revealed deficiencies in the CRA's internal procedures for safeguarding adopted children's personal information. The OPC issued recommendations to revise procedures, provide comprehensive training, and implement oversight measures. The CRA agreed to implement two of the three recommendations, but declined the oversight measure, leading to a "well-founded and not resolved" finding.

Key Issues
  • Whether the CRA disclosed the child’s adoptive name to the biological mother in contravention of section 8 of the Privacy Act
  • Whether the CRA's internal procedures for safeguarding adopted children's personal information were adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 26, 2025Indexed Jun 30, 2026

Investigation into the Canada Revenue Agency’s application of paragraph 22(1)(b) to refuse access to personal information

Canada Revenue Agency (CRA)

The complainant alleged that the Canada Revenue Agency (CRA) improperly denied access to personal information related to five grievances, relying on exceptions in subsection 12(1), paragraph 22(1)(b), and section 26 of the Privacy Act. The OPC found that while the CRA conducted reasonable searches, it failed to substantiate its use of some exemptions, particularly paragraph 22(1)(b). The CRA did not demonstrate a clear and direct connection between disclosure and a risk of harm, instead relying on general assertions. The OPC concluded that the complainant did not receive all entitled personal information and found the complaint well-founded. The OPC recommended the CRA reassess its reliance on paragraph 22(1)(b) and disclose more information. However, the CRA maintained its position, leading the OPC to consider the complaint unresolved.

Quick view

Privacy ActWell-founded

Investigation into the Canada Revenue Agency’s application of paragraph 22(1)(b) to refuse access to personal information

Feb 26, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that the Canada Revenue Agency (CRA) improperly denied access to personal information related to five grievances, relying on exceptions in subsection 12(1), paragraph 22(1)(b), and section 26 of the Privacy Act. The OPC found that while the CRA conducted reasonable searches, it failed to substantiate its use of some exemptions, particularly paragraph 22(1)(b). The CRA did not demonstrate a clear and direct connection between disclosure and a risk of harm, instead relying on general assertions. The OPC concluded that the complainant did not receive all entitled personal information and found the complaint well-founded. The OPC recommended the CRA reassess its reliance on paragraph 22(1)(b) and disclose more information. However, the CRA maintained its position, leading the OPC to consider the complaint unresolved.

Key Issues
  • Whether the Canada Revenue Agency conducted reasonable searches for responsive records
  • Whether the Canada Revenue Agency properly applied subsection 12(1) of the Privacy Act to withhold information
  • Whether the Canada Revenue Agency properly applied paragraph 22(1)(b) of the Privacy Act to withhold information
  • Whether the Canada Revenue Agency properly applied section 26 of the Privacy Act to withhold information
  • Whether the Canada Revenue Agency demonstrated a clear and direct connection between disclosure and a risk of harm under paragraph 22(1)(b)
  • Whether general assertions of harm are sufficient to justify withholding information under paragraph 22(1)(b)
  • Whether the mere fact of an ongoing investigation meets the threshold for harm under paragraph 22(1)(b)
  • Whether the potential for strategic advantage is sufficient to justify withholding information under paragraph 22(1)(b)
  • Whether professional expertise alone is sufficient to substantiate an exemption claim under paragraph 22(1)(b)
  • Whether a case-by-case assessment is required for the application of paragraph 22(1)(b)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 24, 2025Indexed Jun 30, 2026

Measures to anonymize sensitive polygraph records mitigated privacy impacts of NSIRA review

NSIRA Secretariat

The Office of the Privacy Commissioner (OPC) investigated complaints against the NSIRA Secretariat regarding its access to sensitive polygraph records during a review of the Communications Security Establishment's (CSE) Internal Security Program. Complainants questioned whether the collection of personal information complied with section 4 of the Privacy Act and if the Secretariat met its Personal Information Bank (PIB) obligations under section 10. The OPC found that while some un-redacted elements in security screening files posed a re-identification risk, the polygraph recordings themselves were sufficiently anonymized. Given NSIRA's broad mandate and right of access, the OPC concluded the collection issue was not well-founded. However, the Secretariat's delay in requesting approval for PIB changes was found well-founded, though resolved by subsequent submission. The OPC recommended the Secretariat prioritize PIB approvals and publish its Info Source page for transparency. The Secretariat committed to these actions.

Quick view

Privacy ActWell-founded

Measures to anonymize sensitive polygraph records mitigated privacy impacts of NSIRA review

Jan 24, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated complaints against the NSIRA Secretariat regarding its access to sensitive polygraph records during a review of the Communications Security Establishment's (CSE) Internal Security Program. Complainants questioned whether the collection of personal information complied with section 4 of the Privacy Act and if the Secretariat met its Personal Information Bank (PIB) obligations under section 10. The OPC found that while some un-redacted elements in security screening files posed a re-identification risk, the polygraph recordings themselves were sufficiently anonymized. Given NSIRA's broad mandate and right of access, the OPC concluded the collection issue was not well-founded. However, the Secretariat's delay in requesting approval for PIB changes was found well-founded, though resolved by subsequent submission. The OPC recommended the Secretariat prioritize PIB approvals and publish its Info Source page for transparency. The Secretariat committed to these actions.

Key Issues
  • Whether the NSIRA Secretariat's collection of personal information (polygraph records) complied with section 4 of the Privacy Act.
  • Whether the anonymization measures applied to polygraph records were sufficient to prevent re-identification.
  • Whether the NSIRA Secretariat's viewing of personal information, even if not recorded, constituted a 'collection' under section 4.
  • Whether the NSIRA Secretariat met its obligations under section 10 of the Privacy Act regarding Personal Information Banks (PIBs).
  • Whether the NSIRA Secretariat's request for PIB approval was timely.
  • Whether the NSIRA Secretariat published its Info Source page as required by TBS policy.