The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

1,631 decisions in the archive
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jun 28, 2015Early resolved case summary #2015-05Indexed Jun 30, 2026

Early resolved case summary #2015-05: Anti-virus service provider steps up safeguards after customer personal information fraudulently used by someone posing as an employee

Anti-virus service provider

A couple received fraudulent calls from someone posing as an anti-virus service provider technician, who gained remote access to their computer and processed a fraudulent credit card payment. The fraudster used the couple's private account number, which they believed was obtained from the legitimate service provider. The couple struggled to get the service provider to investigate the matter, leading them to file a complaint with the OPC. The OPC requested the service provider conduct an investigation, which revealed an employee had improperly accessed the complainant's account. The employee was dismissed, and the service provider reimbursed the couple and implemented new safeguards, including an auditing system for employee access and a streamlined procedure for escalating privacy concerns. The complainants were satisfied with these outcomes.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-05: Anti-virus service provider steps up safeguards after customer personal information fraudulently used by someone posing as an employee

Jun 28, 2015Early resolved case summary #2015-05
Adjudicator: Daniel Therrien
Plain-Language Summary

A couple received fraudulent calls from someone posing as an anti-virus service provider technician, who gained remote access to their computer and processed a fraudulent credit card payment. The fraudster used the couple's private account number, which they believed was obtained from the legitimate service provider. The couple struggled to get the service provider to investigate the matter, leading them to file a complaint with the OPC. The OPC requested the service provider conduct an investigation, which revealed an employee had improperly accessed the complainant's account. The employee was dismissed, and the service provider reimbursed the couple and implemented new safeguards, including an auditing system for employee access and a streamlined procedure for escalating privacy concerns. The complainants were satisfied with these outcomes.

Key Issues
  • Whether the anti-virus service provider adequately protected personal information against unauthorized access by employees (Principle 4.7 PIPEDA)
  • Whether the anti-virus service provider had adequate procedures to receive and respond to complaints about personal information handling (Principle 4.10 PIPEDA)
  • Whether the anti-virus service provider adequately investigated the complaint (Principle 4.10.4 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
May 22, 2015Early resolved case summary #2015-06Indexed Jun 30, 2026

Early resolved case summary #2015-06: Manager snoops on employee’s personal bank account after employee calls in sick

A credit union

An employee of a credit union complained that her manager accessed her personal financial information without consent. The manager suspected the employee had falsely called in sick and checked her bank account transactions to see if she had used her debit card out of province. The employee discovered this when her employment was terminated and the manager referenced the incident. After receiving an inconclusive response from the credit union, she filed a complaint with the OPC. The OPC initiated its early resolution process, and the credit union acknowledged the manager's actions were without a valid business purpose and constituted an unauthorized use of personal information. The credit union committed to addressing the issue with the manager and sent a letter of apology to the employee. The employee was satisfied with this resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-06: Manager snoops on employee’s personal bank account after employee calls in sick

May 22, 2015Early resolved case summary #2015-06
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee of a credit union complained that her manager accessed her personal financial information without consent. The manager suspected the employee had falsely called in sick and checked her bank account transactions to see if she had used her debit card out of province. The employee discovered this when her employment was terminated and the manager referenced the incident. After receiving an inconclusive response from the credit union, she filed a complaint with the OPC. The OPC initiated its early resolution process, and the credit union acknowledged the manager's actions were without a valid business purpose and constituted an unauthorized use of personal information. The credit union committed to addressing the issue with the manager and sent a letter of apology to the employee. The employee was satisfied with this resolution.

Key Issues
  • Whether a manager accessing an employee's personal bank account without a valid business purpose constitutes unauthorized use of personal information under PIPEDA
  • Whether the credit union's actions to address the manager's conduct and apologize to the employee were satisfactory for early resolution
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

An organization

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Key Issues
  • Whether the disclosed leave information constituted personal information under PIPEDA
  • Whether the organization's purposes for disclosing employee leave information to other employees were appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the disclosure of leave type was necessary for the organization to meet its employee schedule management needs
  • Whether the benefits of the leave exchange system were proportional to the loss of privacy experienced by employees
Federal (Canada)Access to Information ActResolved
Federal (Canada) flag
May 14, 2015Indexed Jun 30, 2026

Investigation into an access to information request for the Long-gun Registry

Royal Canadian Mounted Police

The complainant requested access to the Firearms Registry database from the Royal Canadian Mounted Police (RCMP) on March 27, 2012, prior to the enactment of the Ending the Long-gun Registry Act. The complainant alleged that the RCMP provided an incomplete response, failed to justify the incompleteness, and obstructed the right of access by destroying responsive records. The investigation focused on whether the RCMP's actions, particularly the destruction of records, constituted an obstruction of the right of access under section 67.1 of the Access to Information Act. The Commissioner examined the circumstances surrounding the destruction of the Long-gun Registry data. The Commissioner found that the destruction of the records was carried out in accordance with a valid legislative process and did not constitute an obstruction of the right of access.

Quick view

Access to Information ActResolved

Investigation into an access to information request for the Long-gun Registry

May 14, 2015
Adjudicator: Suzanne Legault
Plain-Language Summary

The complainant requested access to the Firearms Registry database from the Royal Canadian Mounted Police (RCMP) on March 27, 2012, prior to the enactment of the Ending the Long-gun Registry Act. The complainant alleged that the RCMP provided an incomplete response, failed to justify the incompleteness, and obstructed the right of access by destroying responsive records. The investigation focused on whether the RCMP's actions, particularly the destruction of records, constituted an obstruction of the right of access under section 67.1 of the Access to Information Act. The Commissioner examined the circumstances surrounding the destruction of the Long-gun Registry data. The Commissioner found that the destruction of the records was carried out in accordance with a valid legislative process and did not constitute an obstruction of the right of access.

Key Issues
  • Whether the information provided was incomplete
  • Whether the RCMP justified the incomplete response
  • Whether the destruction of responsive records by the RCMP obstructed the right of access under section 67.1 of the Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 29, 2015Indexed Jun 30, 2026

Disclosure to Interpol raises concerns regarding electronic transmission of personal information

Canada Border Services Agency

The complainant alleged that the Canada Border Services Agency (CBSA) improperly disclosed his personal information, including a judgment from his country of origin, to the High Commission of Canada in Ghana and subsequently to Interpol, without his consent. This disclosure occurred during the verification of documents submitted for his refugee claim, which alleged persecution by the Nigerian government. The CBSA argued the disclosure was a consistent use under the Privacy Act for refugee determination and enforcement of the IRPA, necessary to verify the authenticity of the judgment after other documents were found fraudulent. The OPC found that the disclosure itself was permitted under paragraph 8(2)(a) of the Privacy Act as a consistent use for refugee determination purposes, thus concluding the primary complaint was "not well-founded." However, the OPC raised significant concerns regarding the CBSA's lack of established procedures for such verifications at the time, and the use of insecure commercial email (Yahoo!) for transmitting sensitive personal information of a refugee claimant. The OPC emphasized the inherent sensitivity of such information and the potential risk to claimants, recommending that CBSA review and strengthen its procedures, particularly concerning secure transmission methods and training. The OPC also noted it lacked jurisdiction over the actions of Interpol or Nigerian authorities.

Quick view

Privacy ActWell-founded

Disclosure to Interpol raises concerns regarding electronic transmission of personal information

Apr 29, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) improperly disclosed his personal information, including a judgment from his country of origin, to the High Commission of Canada in Ghana and subsequently to Interpol, without his consent. This disclosure occurred during the verification of documents submitted for his refugee claim, which alleged persecution by the Nigerian government. The CBSA argued the disclosure was a consistent use under the Privacy Act for refugee determination and enforcement of the IRPA, necessary to verify the authenticity of the judgment after other documents were found fraudulent. The OPC found that the disclosure itself was permitted under paragraph 8(2)(a) of the Privacy Act as a consistent use for refugee determination purposes, thus concluding the primary complaint was "not well-founded." However, the OPC raised significant concerns regarding the CBSA's lack of established procedures for such verifications at the time, and the use of insecure commercial email (Yahoo!) for transmitting sensitive personal information of a refugee claimant. The OPC emphasized the inherent sensitivity of such information and the potential risk to claimants, recommending that CBSA review and strengthen its procedures, particularly concerning secure transmission methods and training. The OPC also noted it lacked jurisdiction over the actions of Interpol or Nigerian authorities.

Key Issues
  • Whether the disclosure of the complainant's personal information (including the Judgment) by CBSA to the High Commission and Interpol without consent contravened section 8 of the Privacy Act.
  • Whether the disclosure was for a purpose consistent with the original collection under paragraph 8(2)(a) of the Privacy Act.
  • Whether CBSA's procedures for verifying documents with countries of origin and Interpol were sufficient at the time of disclosure.
  • Whether the electronic transmission of personal information via commercial email (Yahoo!) was secure and appropriate given the sensitivity.
  • Whether the OPC had jurisdiction over alleged secondary disclosures by Interpol or Nigerian authorities.
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 23, 2015PIPEDA Report of Findings #2015-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

An investment brokerage

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 23, 2015PIPEDA Report of Findings #2015-006
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Key Issues
  • Whether the collection of net worth, marital status, and spouse's occupation was necessary for opening a self-directed investment account under Principle 4.4 PIPEDA
  • Whether the purposes for collecting the personal information were explicitly specified under Principle 4.2 PIPEDA
  • Whether the purposes for collecting the personal information were legitimate and appropriate under subsection 5(3) PIPEDA
  • Whether the organization required consent to the collection of information beyond that required for explicitly specified and legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 16, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – Public Services and Procurement Canada

Public Services and Procurement Canada (PSPC)

An individual complained that Public Services and Procurement Canada (PSPC) mishandled her personal information by disclosing that she had filed a harassment complaint against her Director. The complainant alleged that the Director revealed this information during a management meeting. The investigation confirmed that the Director disclosed at a management meeting that the complainant had filed a complaint against her, as evidenced by meeting notes and confirmations from attendees. While the Director claimed the information was also her personal information, the OPC found no evidence that the employees present at the meeting needed to know the complainant's identity. The OPC concluded that PSPC did not reasonably consider the appropriateness of disclosing the complainant's identity without her consent, violating the Privacy Act.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – Public Services and Procurement Canada

Apr 16, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Public Services and Procurement Canada (PSPC) mishandled her personal information by disclosing that she had filed a harassment complaint against her Director. The complainant alleged that the Director revealed this information during a management meeting. The investigation confirmed that the Director disclosed at a management meeting that the complainant had filed a complaint against her, as evidenced by meeting notes and confirmations from attendees. While the Director claimed the information was also her personal information, the OPC found no evidence that the employees present at the meeting needed to know the complainant's identity. The OPC concluded that PSPC did not reasonably consider the appropriateness of disclosing the complainant's identity without her consent, violating the Privacy Act.

Key Issues
  • Whether the disclosure of the complainant's identity as having filed a harassment complaint constituted personal information under s.3 of the Privacy Act
  • Whether the disclosure of the complainant's identity was made without her consent
  • Whether the disclosure was for a purpose consistent with the purpose for which the information was obtained or compiled, as per s.8(2)(a) of the Privacy Act
  • Whether the employees present at the meeting needed to know the complainant's identity
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 13, 2015PIPEDA Report of Findings #2015-007Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-007: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Peoples Trust

The OPC initiated an investigation into Peoples Trust following a data breach that compromised sensitive personal information of approximately 12,000 customers. The investigation found that Peoples Trust failed to implement adequate technological and organizational safeguards, including using an outdated and vulnerable web editor and lacking ongoing monitoring. Additionally, the organization unnecessarily stored duplicate, unencrypted customer information on a web server for longer than required, contravening its retention policies. Following the OPC's intervention, Peoples Trust implemented comprehensive remedial measures, such as redesigning its web portal, enhancing monitoring, and developing a new Information Security Policy. As a result, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2015-007: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 13, 2015PIPEDA Report of Findings #2015-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated an investigation into Peoples Trust following a data breach that compromised sensitive personal information of approximately 12,000 customers. The investigation found that Peoples Trust failed to implement adequate technological and organizational safeguards, including using an outdated and vulnerable web editor and lacking ongoing monitoring. Additionally, the organization unnecessarily stored duplicate, unencrypted customer information on a web server for longer than required, contravening its retention policies. Following the OPC's intervention, Peoples Trust implemented comprehensive remedial measures, such as redesigning its web portal, enhancing monitoring, and developing a new Information Security Policy. As a result, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether Peoples Trust implemented adequate technological and organizational safeguards appropriate to the sensitivity of the information, as per Principle 4.7 and 4.1.4(a) PIPEDA
  • Whether Peoples Trust retained personal information for longer than necessary to fulfill its purposes, as per Principle 4.5 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Mar 12, 2015PIPEDA findings #2015-020Indexed Jun 30, 2026

PIPEDA findings #2015-020: Hotel chain alerts its clients about “special offer” telephone scam

A major hotel chain

An individual complained after receiving a promotional phone call from a hotel chain shortly after visiting its website, suspecting the hotel linked her IP address to her phone number. The hotel chain denied making such calls or collecting her personal information, stating the call was part of a telemarketing scam by an unrelated party. The OPC's investigation confirmed the calls were indeed a scam. The complainant suggested the hotel warn its customers, which the hotel did. The matter was resolved through the OPC's early resolution process.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

PIPEDA findings #2015-020: Hotel chain alerts its clients about “special offer” telephone scam

Mar 12, 2015PIPEDA findings #2015-020
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained after receiving a promotional phone call from a hotel chain shortly after visiting its website, suspecting the hotel linked her IP address to her phone number. The hotel chain denied making such calls or collecting her personal information, stating the call was part of a telemarketing scam by an unrelated party. The OPC's investigation confirmed the calls were indeed a scam. The complainant suggested the hotel warn its customers, which the hotel did. The matter was resolved through the OPC's early resolution process.

Key Issues
  • Whether the hotel chain collected the complainant's personal information (phone number) from her website visit
  • Whether the promotional phone call originated from the hotel chain or an unrelated third party
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 3, 2015Indexed Jun 30, 2026

Accidental disclosure by Health Canada - March 3, 2015

Health Canada

The Office of the Privacy Commissioner (OPC) initiated a complaint against Health Canada (HC) after HC sent 41,514 letters to "Marihuana Medical Access Program" (MMAP) clients in windowed envelopes that allowed the program name to be openly visible. The OPC also received 339 individual complaints regarding this incident. Complainants were concerned that the visible program name revealed their association with MMAP to Canada Post employees and the public, potentially impacting their careers, reputation, and safety due to the stigma associated with marihuana. HC argued that the disclosure was implicitly consented to, was a consistent use of information, or was not an unlawful disclosure by HC. The OPC found that the combination of the MMAP name and the individual's name and address constituted sensitive personal information. HC failed to demonstrate appropriate consent or that any permissible disclosures under section 8(2) of the Privacy Act applied. The OPC concluded that HC contravened the Privacy Act.

Quick view

Privacy ActWell-founded

Accidental disclosure by Health Canada - March 3, 2015

Mar 3, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) initiated a complaint against Health Canada (HC) after HC sent 41,514 letters to "Marihuana Medical Access Program" (MMAP) clients in windowed envelopes that allowed the program name to be openly visible. The OPC also received 339 individual complaints regarding this incident. Complainants were concerned that the visible program name revealed their association with MMAP to Canada Post employees and the public, potentially impacting their careers, reputation, and safety due to the stigma associated with marihuana. HC argued that the disclosure was implicitly consented to, was a consistent use of information, or was not an unlawful disclosure by HC. The OPC found that the combination of the MMAP name and the individual's name and address constituted sensitive personal information. HC failed to demonstrate appropriate consent or that any permissible disclosures under section 8(2) of the Privacy Act applied. The OPC concluded that HC contravened the Privacy Act.

Key Issues
  • Whether the phrase "Marihuana Medical Access Program" combined with an individual's name and address constitutes personal information under section 3 of the Privacy Act
  • Whether subsequent actions by individuals (e.g., media communication) alter Health Canada's obligations under the Privacy Act
  • Whether mail recipients implicitly consented to the disclosure of their personal information under section 8(1) of the Privacy Act
  • Whether the disclosure was a "consistent use" under section 8(2)(a) of the Privacy Act
  • Whether limiting information on return address blocks would have broad implications for government communication
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 10, 2015Indexed Jun 30, 2026

Records deemed 'transitory' prematurely destroyed - February 10, 2015

Department of National Defence (DND)

A former Canadian Forces member complained that the Department of National Defence (DND) prematurely destroyed an audio recording of his Progress Review Board (PRB) hearing, thereby contravening the retention and disposal provisions of the Privacy Act. The complainant argued that the recording was personal information used for an administrative purpose and should have been retained for a reasonable period to allow him access. DND contended the recording was a "transitory" record, destroyed after minutes were drafted, and that the complainant had implicitly consented to its disposal by signing the minutes. The OPC found that the audio recording contained personal information used for an administrative purpose and that the complainant had not consented to its disposal. Therefore, DND was obligated to retain the recording for at least two years.

Quick view

Privacy ActWell-founded

Records deemed 'transitory' prematurely destroyed - February 10, 2015

Feb 10, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

A former Canadian Forces member complained that the Department of National Defence (DND) prematurely destroyed an audio recording of his Progress Review Board (PRB) hearing, thereby contravening the retention and disposal provisions of the Privacy Act. The complainant argued that the recording was personal information used for an administrative purpose and should have been retained for a reasonable period to allow him access. DND contended the recording was a "transitory" record, destroyed after minutes were drafted, and that the complainant had implicitly consented to its disposal by signing the minutes. The OPC found that the audio recording contained personal information used for an administrative purpose and that the complainant had not consented to its disposal. Therefore, DND was obligated to retain the recording for at least two years.

Key Issues
  • Whether the audio recording contained the complainant's "personal information" as defined by the Act
  • Whether the personal information in the audio recording was used for an "administrative purpose"
  • Whether the complainant consented to the disposal of the information
  • Whether DND's classification of the recording as "transitory" exempted it from Privacy Act retention requirements
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jan 21, 2015Early resolved case summary #2015-03Indexed Jun 30, 2026

Early resolved case summary #2015-03: Office building tenant reconsiders placement of video surveillance cameras

An office building tenant (call centre company)

An office building tenant complained about five video surveillance cameras installed in a shared common area by another tenant, a call centre company. The complainant found it disturbing that the cameras recorded his and his clients' movements, particularly two cameras positioned between his office, the washrooms, and the elevators. The installing tenant claimed the cameras were for safety following a security incident and that building management had authorized their installation. After the OPC became involved, the building management facilitated the relocation of the two most concerning cameras from the shared hallway into the installing tenant's offices. The complainant expressed satisfaction that his and his clients' privacy rights were now respected. The case was resolved early.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-03: Office building tenant reconsiders placement of video surveillance cameras

Jan 21, 2015Early resolved case summary #2015-03
Adjudicator: Daniel Therrien
Plain-Language Summary

An office building tenant complained about five video surveillance cameras installed in a shared common area by another tenant, a call centre company. The complainant found it disturbing that the cameras recorded his and his clients' movements, particularly two cameras positioned between his office, the washrooms, and the elevators. The installing tenant claimed the cameras were for safety following a security incident and that building management had authorized their installation. After the OPC became involved, the building management facilitated the relocation of the two most concerning cameras from the shared hallway into the installing tenant's offices. The complainant expressed satisfaction that his and his clients' privacy rights were now respected. The case was resolved early.

Key Issues
  • Whether the installation of video surveillance cameras in a shared common area by one tenant infringed on the privacy of another tenant and their clients
  • Whether the collection of personal information via video surveillance was appropriate and proportionate to the stated safety purpose
  • Whether consent was obtained for the video surveillance
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 16, 2014Indexed Jun 30, 2026

Canada Revenue Agency and the Canadian Broadcasting Corporation (CBC) - 2015

Canadian Broadcasting Corporation (CBC)

This report addresses complaints against the Canadian Broadcasting Corporation (CBC) regarding its publication of personal information inadvertently disclosed by the Canada Revenue Agency (CRA). The CRA mistakenly mailed a spreadsheet containing taxpayers' personal information to a CBC journalist. The CBC subsequently published an article detailing the breach, identifying several affected individuals, and including their photographs. Complainants alleged the CBC contravened the Privacy Act by disclosing this information. The CBC argued that the information was obtained legally and that the Privacy Act does not apply to information collected, used, or disclosed for journalistic purposes under section 69.1 of the Act. The OPC found that the CBC's actions were purely journalistic and therefore fell under this exclusion, meaning the Privacy Act did not apply to the CBC's handling of the information.

Quick view

Privacy ActNot well-founded

Canada Revenue Agency and the Canadian Broadcasting Corporation (CBC) - 2015

Dec 16, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

This report addresses complaints against the Canadian Broadcasting Corporation (CBC) regarding its publication of personal information inadvertently disclosed by the Canada Revenue Agency (CRA). The CRA mistakenly mailed a spreadsheet containing taxpayers' personal information to a CBC journalist. The CBC subsequently published an article detailing the breach, identifying several affected individuals, and including their photographs. Complainants alleged the CBC contravened the Privacy Act by disclosing this information. The CBC argued that the information was obtained legally and that the Privacy Act does not apply to information collected, used, or disclosed for journalistic purposes under section 69.1 of the Act. The OPC found that the CBC's actions were purely journalistic and therefore fell under this exclusion, meaning the Privacy Act did not apply to the CBC's handling of the information.

Key Issues
  • Whether the information published by the CBC constituted personal information under section 3 of the Privacy Act
  • Whether the CBC's collection, use, and disclosure of the personal information was for journalistic purposes
  • Whether the exclusion provision under section 69.1 of the Privacy Act applied to the CBC's actions
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 3, 2014Indexed Jun 30, 2026

Canada Revenue Agency and the Canadian Broadcasting Corporation (CRA) - 2015

Canada Revenue Agency

The Canada Revenue Agency (CRA) inadvertently mailed the personal information of approximately 1,000 individuals to a Canadian Broadcasting Corporation (CBC) journalist. This occurred due to an ATIP clerk mistakenly switching cover letters for two different response packages. The disclosed information included names, addresses, and details of donations. The CBC refused the CRA's requests to return the information, leading the CRA to initiate legal action. The OPC found that the CRA disclosed personal information without consent, contravening the Privacy Act. While the OPC noted the CRA's immediate remedial actions and action plan, it concluded that the disclosure did not meet the requirements of the Act.

Quick view

Privacy ActWell-founded

Canada Revenue Agency and the Canadian Broadcasting Corporation (CRA) - 2015

Dec 3, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canada Revenue Agency (CRA) inadvertently mailed the personal information of approximately 1,000 individuals to a Canadian Broadcasting Corporation (CBC) journalist. This occurred due to an ATIP clerk mistakenly switching cover letters for two different response packages. The disclosed information included names, addresses, and details of donations. The CBC refused the CRA's requests to return the information, leading the CRA to initiate legal action. The OPC found that the CRA disclosed personal information without consent, contravening the Privacy Act. While the OPC noted the CRA's immediate remedial actions and action plan, it concluded that the disclosure did not meet the requirements of the Act.

Key Issues
  • Whether the inadvertent mailing of personal information to a journalist constituted a disclosure without consent under the Privacy Act
  • Whether the information disclosed was 'personal information' as defined by section 3 of the Privacy Act
  • Whether the disclosure met the requirements of section 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2014Indexed Jun 30, 2026

Collection of RCMP member's health information unnecessary (RCMP) - November 17, 2014

Royal Canadian Mounted Police (RCMP)

A former RCMP member complained that the RCMP inappropriately collected her personal medical and financial information from Veterans Affairs Canada (VAC) after she was awarded a disability pension. The complainant alleged that the RCMP's National Compensation Policy Centre had no need for this sensitive information. The OPC found that the 2002 Memorandum of Understanding (MOU) between the RCMP and VAC transferred responsibility for pension administration to VAC, meaning the RCMP's National Compensation Policy Centre did not require the detailed medical diagnosis or financial information. The OPC concluded that the collection of this information by the RCMP was not for a purpose consistent with section 4 of the Privacy Act. The complaint was found to be well-founded, and the OPC recommended updating the MOU and reviewing RCMP's internal policies on access to medical records.

Quick view

Privacy ActWell-founded

Collection of RCMP member's health information unnecessary (RCMP) - November 17, 2014

Nov 17, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A former RCMP member complained that the RCMP inappropriately collected her personal medical and financial information from Veterans Affairs Canada (VAC) after she was awarded a disability pension. The complainant alleged that the RCMP's National Compensation Policy Centre had no need for this sensitive information. The OPC found that the 2002 Memorandum of Understanding (MOU) between the RCMP and VAC transferred responsibility for pension administration to VAC, meaning the RCMP's National Compensation Policy Centre did not require the detailed medical diagnosis or financial information. The OPC concluded that the collection of this information by the RCMP was not for a purpose consistent with section 4 of the Privacy Act. The complaint was found to be well-founded, and the OPC recommended updating the MOU and reviewing RCMP's internal policies on access to medical records.

Key Issues
  • Whether the collection of the complainant's financial information by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of the complainant's medical diagnosis/pensioned disability by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of the complainant's disability percentage by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of personal information by the RCMP's National Compensation Policy Centre was consistent with the RCMP's own internal policies restricting access to sensitive medical information
  • Whether the MOU between VAC and the RCMP adequately addressed information sharing practices for sensitive personal information
Federal (Canada) Privacy Decisions | Condita Research