The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

7 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 7, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Canada Revenue Agency

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

May 7, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Key Issues
  • Whether the CRA adequately protected personal information against unauthorized disclosure and modification
  • Whether the CRA contravened subsection 6(2) of the Privacy Act regarding accuracy of personal information
  • Whether the CRA contravened subsection 8(2) of the Privacy Act regarding disclosure of personal information
  • Whether the CRA's prevention measures were adequate
  • Whether the CRA implemented mandatory multi-factor authentication (MFA) in a timely manner and with sufficient strength
  • Whether the CRA's authentication processes by phone were strong enough
  • Whether the CRA considered and integrated a zero-trust approach into its security measures
  • Whether the CRA had sufficient visibility over its attack surface and managed it effectively
  • Whether the CRA's vetting, training, and awareness tools were effective for employees and third parties
  • Whether the CRA's monitoring and detection approach was tailored to the threats and risks leading to Unauthorized Use of Taxpayer Information by a Third Party (UUTP)
  • Whether the CRA's remediation efforts for individual UUTPs were adequate, including root cause analysis
  • Whether the CRA's governance processes for addressing UUTPs were coordinated, comprehensive, and efficient
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 25, 2026Indexed Jun 30, 2026

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Immigration, Refugees and Citizenship Canada (IRCC)

The OPC investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding its systematic practice of withholding access to certain personal information in its Global Case Management System (GCMS). IRCC's policy was to retrieve and process only a "Short Form" GCMS Report in response to access requests, even when individuals requested their entire file or specific content found in the "Long Form." The OPC found that the "History Section" of the GCMS file, which is part of the Long Form, contained the complainant's personal information and that IRCC's practice contravened Section 12 of the Privacy Act. While IRCC eventually provided the complainant with the requested Long Form, it did not agree to update its procedures to systematically retrieve and process the Long Form for all future requests. Consequently, the OPC found the complaint well-founded but not resolved, as IRCC had not committed to addressing the systemic issue.

Quick view

Privacy ActWell-founded

Immigration, Refugees and Citizenship Canada systematically withholds access to certain personal information in its Global Case Management System

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding its systematic practice of withholding access to certain personal information in its Global Case Management System (GCMS). IRCC's policy was to retrieve and process only a "Short Form" GCMS Report in response to access requests, even when individuals requested their entire file or specific content found in the "Long Form." The OPC found that the "History Section" of the GCMS file, which is part of the Long Form, contained the complainant's personal information and that IRCC's practice contravened Section 12 of the Privacy Act. While IRCC eventually provided the complainant with the requested Long Form, it did not agree to update its procedures to systematically retrieve and process the Long Form for all future requests. Consequently, the OPC found the complaint well-founded but not resolved, as IRCC had not committed to addressing the systemic issue.

Key Issues
  • Whether IRCC's practice of providing only a "Short Form" GCMS Report in response to access requests contravenes Section 12 of the Privacy Act
  • Whether the "History Section" of the GCMS file contains personal information
  • Whether information in the "Long Form" GCMS Report is always exempt from disclosure
  • Whether IRCC has an obligation to retrieve and process all records responsive to a Privacy Act request
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2026Indexed Jun 30, 2026

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Canada Border Services Agency (CBSA)

An employee of the Canada Border Services Agency (CBSA) filed a complaint after their personal information, including sensitive details about an accommodation request, was inadvertently made accessible to other CBSA employees through the Apollo information management system. The issue stemmed from improperly set permissions on an old ATIP file folder, which allowed document titles and sometimes the first line of emails containing personal information to be visible via Apollo's search function. The OPC found that the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority. While the CBSA corrected the specific permissions and committed to broader reviews and improved naming conventions, it did not agree to implement mandatory and trackable training for employees on Apollo permissions management. Consequently, the OPC found the complaint well-founded but unresolved, as it was not satisfied that sufficient safeguards were in place to prevent recurrence.

Quick view

Privacy ActWell-founded

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Mar 24, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee of the Canada Border Services Agency (CBSA) filed a complaint after their personal information, including sensitive details about an accommodation request, was inadvertently made accessible to other CBSA employees through the Apollo information management system. The issue stemmed from improperly set permissions on an old ATIP file folder, which allowed document titles and sometimes the first line of emails containing personal information to be visible via Apollo's search function. The OPC found that the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority. While the CBSA corrected the specific permissions and committed to broader reviews and improved naming conventions, it did not agree to implement mandatory and trackable training for employees on Apollo permissions management. Consequently, the OPC found the complaint well-founded but unresolved, as it was not satisfied that sufficient safeguards were in place to prevent recurrence.

Key Issues
  • Whether the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority
  • Whether the CBSA appropriately responded to the unauthorized disclosure
  • Whether the CBSA's proposed measures, without mandatory and trackable training, are sufficient to prevent future unauthorized disclosures
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 18, 2026Indexed Jun 30, 2026

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Treasury Board of Canada Secretariat

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Treasury Board of Canada Secretariat (TBS) regarding its personal information practices for monitoring employee on-site presence under the federal government's hybrid work model. The complainant alleged invasive collection, use, and disclosure of personal information, questioning TBS's compliance with sections 4, 6, 7, and 8 of the Privacy Act, as well as transparency, necessity, proportionality, and Privacy Impact Assessment (PIA) requirements. The OPC found that TBS's collection of aggregated data for organizational compliance was for non-administrative purposes, authorized by existing statutes, and appropriately de-identified to fall outside the scope of the Act for disclosure. For individual compliance, managers primarily relied on observation and self-reporting, supported by internal guidance. While TBS's practices were largely compliant, the OPC encouraged TBS to update its Personal Information Bank (PIB) description for Physical Access Controls (PSU 907) to explicitly reflect the potential use of access logs in formal investigations and to clearly communicate this to employees. Overall, the OPC concluded that TBS's personal information handling practices were compliant with the Privacy Act.

Quick view

Privacy ActNot well-founded

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Mar 18, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Treasury Board of Canada Secretariat (TBS) regarding its personal information practices for monitoring employee on-site presence under the federal government's hybrid work model. The complainant alleged invasive collection, use, and disclosure of personal information, questioning TBS's compliance with sections 4, 6, 7, and 8 of the Privacy Act, as well as transparency, necessity, proportionality, and Privacy Impact Assessment (PIA) requirements. The OPC found that TBS's collection of aggregated data for organizational compliance was for non-administrative purposes, authorized by existing statutes, and appropriately de-identified to fall outside the scope of the Act for disclosure. For individual compliance, managers primarily relied on observation and self-reporting, supported by internal guidance. While TBS's practices were largely compliant, the OPC encouraged TBS to update its Personal Information Bank (PIB) description for Physical Access Controls (PSU 907) to explicitly reflect the potential use of access logs in formal investigations and to clearly communicate this to employees. Overall, the OPC concluded that TBS's personal information handling practices were compliant with the Privacy Act.

Key Issues
  • Whether the collection of employees' personal information for on-site presence monitoring was related directly to TBS's operating programs or activities under section 4 of the Privacy Act.
  • Whether TBS's retention and disposal practices for personal information collected for on-site presence monitoring complied with section 6 of the Privacy Act, specifically subsections 6(1) and 6(3).
  • Whether TBS's use of personal information for on-site presence monitoring was a 'consistent use' authorized under section 7(a) of the Privacy Act.
  • Whether TBS's disclosure of aggregated on-site presence data to senior management constituted personal information under section 3 of the Privacy Act and complied with section 8.
  • Whether TBS's transparency and openness related to its hybrid compliance monitoring approach, including standard Personal Information Banks (PIBs), was adequate under sections 10 and 11 of the Privacy Act.
  • Whether TBS's personal information practices for on-site presence monitoring complied with the necessity and proportionality data principles.
  • Whether TBS was required to complete a Privacy Impact Assessment (PIA) for its verification regime.
  • Whether managers' practices for monitoring individual compliance with the hybrid work model contravened the Privacy Act.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 12, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Quick view

Privacy ActNot well-founded

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Mar 12, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Key Issues
  • Whether the CBSA authorized contractors to access personal information collected through ArriveCAN without the required security clearance, in contravention of sections 7 and 8 of the Privacy Act
  • Whether ArriveCAN contracts and Task Authorizations (TAs) contained appropriate clauses to ensure the protection of travellers’ personal information that contractors had access to
  • Whether security requirements identified in contracts and TAs were accurate and specific
  • Whether the CBSA complied with organizational security screening requirements for vendors
  • Whether the CBSA complied with personnel security screening requirements for contractors
  • Whether the CBSA implemented adequate administrative safeguards to protect personal information accessed by contractors
  • Whether the CBSA implemented adequate technical safeguards to protect personal information accessed by contractors
  • Whether the CBSA restricted contractor permissions and access to personal information to what was strictly necessary
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 3, 2026Indexed Jun 30, 2026

Correctional Service of Canada Deleted Video

Correctional Service of Canada (CSC)

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Correctional Service of Canada Deleted Video

Mar 3, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether CSC failed to retain personal information used for an administrative purpose as required by Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations
  • Whether the complainant was denied a reasonable opportunity to obtain access to their personal information due to non-retention
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Feb 26, 2026Indexed Jun 30, 2026

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Canada Border Services Agency (CBSA)

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Quick view

Privacy ActWell-founded & resolved

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Feb 26, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Key Issues
  • Whether the CBSA's disclosure of employee personal information via spreadsheets contravened section 8 of the Privacy Act
  • Whether the inclusion of excess information in spreadsheets constituted unauthorized disclosure
  • Whether the use of personal email addresses for work-related data sharing contravened the Privacy Act
  • Whether the CBSA took adequate steps to address the incidents, including notification to affected individuals
  • Whether the CBSA's measures to reduce the risk of recurrence were reasonable