The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

1,631 decisions in the archive
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2014Indexed Jun 30, 2026

Collection of RCMP member's health information unnecessary (VAC) - November 17, 2014

Veterans Affairs Canada (VAC)

A former RCMP member complained that Veterans Affairs Canada (VAC) inappropriately disclosed her medical diagnosis, disability percentage, and financial information to the RCMP's National Compensation Policy Centre. VAC argued the disclosure was a 'consistent use' under the Privacy Act, citing the RCMP's responsibility for members' health services and an MOU between the two institutions. The OPC found that the information provided to the complainant at the time of application was inadequate to establish informed consent for such disclosure. Furthermore, the MOU did not explicitly authorize the sharing of detailed medical and financial information with the RCMP's National Compensation Policy Centre. The OPC concluded that the disclosure was not a consistent use and therefore contravened the Privacy Act, noting the systemic nature of this issue affecting many RCMP employees.

Quick view

Privacy ActWell-founded

Collection of RCMP member's health information unnecessary (VAC) - November 17, 2014

Nov 17, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A former RCMP member complained that Veterans Affairs Canada (VAC) inappropriately disclosed her medical diagnosis, disability percentage, and financial information to the RCMP's National Compensation Policy Centre. VAC argued the disclosure was a 'consistent use' under the Privacy Act, citing the RCMP's responsibility for members' health services and an MOU between the two institutions. The OPC found that the information provided to the complainant at the time of application was inadequate to establish informed consent for such disclosure. Furthermore, the MOU did not explicitly authorize the sharing of detailed medical and financial information with the RCMP's National Compensation Policy Centre. The OPC concluded that the disclosure was not a consistent use and therefore contravened the Privacy Act, noting the systemic nature of this issue affecting many RCMP employees.

Key Issues
  • Whether the disclosure of the complainant's medical and financial information by VAC to the RCMP was authorized by consent under subsection 8(1) of the Privacy Act
  • Whether the disclosure of the complainant's medical and financial information by VAC to the RCMP was for a consistent use under paragraph 8(2)(a) of the Privacy Act
  • Whether the information provided to disability pension applicants by VAC was sufficient to establish informed consent for disclosure to the RCMP
  • Whether the Memorandum of Understanding (MOU) between VAC and the RCMP authorized the detailed sharing of personal medical and financial information
  • Whether the RCMP's National Compensation Policy Centre had a 'need to know' the complainant's detailed medical and financial information
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Nov 13, 2014Indexed Jun 30, 2026

Video surveillance of employees vs. right to privacy - a delicate balance - November 13, 2014

Canada Border Services Agency (CBSA)

An employee of the Canada Border Services Agency (CBSA) complained on behalf of colleagues that the CBSA was using video monitoring to collect personal information for the purpose of monitoring employee conduct and performance, beyond the original safety and security purposes. The complainant also alleged insufficient signage. The OPC found the signage issue was resolved early in the investigation as the CBSA added more signs. Regarding the use of video for monitoring conduct and performance, the CBSA updated its policy to clarify that video technology would not be used for performance monitoring. The OPC accepted the CBSA's rationale for using video recordings to investigate serious misconduct, finding it met the standard for collection under section 4 of the Privacy Act. However, the resolution was conditional on the CBSA providing updated guidelines for implementing its policy.

Quick view

Privacy ActResolved

Video surveillance of employees vs. right to privacy - a delicate balance - November 13, 2014

Nov 13, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee of the Canada Border Services Agency (CBSA) complained on behalf of colleagues that the CBSA was using video monitoring to collect personal information for the purpose of monitoring employee conduct and performance, beyond the original safety and security purposes. The complainant also alleged insufficient signage. The OPC found the signage issue was resolved early in the investigation as the CBSA added more signs. Regarding the use of video for monitoring conduct and performance, the CBSA updated its policy to clarify that video technology would not be used for performance monitoring. The OPC accepted the CBSA's rationale for using video recordings to investigate serious misconduct, finding it met the standard for collection under section 4 of the Privacy Act. However, the resolution was conditional on the CBSA providing updated guidelines for implementing its policy.

Key Issues
  • Whether the CBSA's use of video monitoring for employee conduct and performance monitoring contravened the Privacy Act
  • Whether the collection of personal information via video technology was necessary and related directly to an operating program or activity of the institution under section 4 of the Privacy Act
  • Whether the CBSA had sufficient signage to inform employees of video monitoring
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Oct 31, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-013Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-013: Organization could reasonably assume customer's implied consent for disclosure in dispute resolution situation

An Internet service provider (ISP)

A complainant alleged that his Internet service provider (ISP) disclosed his personal information without consent to a newspaper columnist. The complainant had contacted the columnist for assistance in resolving a service dispute with the ISP. The ISP argued it had implied consent to disclose information relevant to the dispute. The OPC found that the personal information disclosed was not sensitive and that, given the complainant's actions and familiarity with the columnist's work, it was reasonable for the ISP to infer implied consent. The ISP also limited its disclosure to information relevant to the complaint. Therefore, the OPC concluded that the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Commissioner’s Findings - PIPEDA Report of Findings #2014-013: Organization could reasonably assume customer's implied consent for disclosure in dispute resolution situation

Oct 31, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-013
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that his Internet service provider (ISP) disclosed his personal information without consent to a newspaper columnist. The complainant had contacted the columnist for assistance in resolving a service dispute with the ISP. The ISP argued it had implied consent to disclose information relevant to the dispute. The OPC found that the personal information disclosed was not sensitive and that, given the complainant's actions and familiarity with the columnist's work, it was reasonable for the ISP to infer implied consent. The ISP also limited its disclosure to information relevant to the complaint. Therefore, the OPC concluded that the complaint was not well-founded.

Key Issues
  • Whether the ISP had the complainant's consent to disclose information to the newspaper columnist
  • Whether the personal information disclosed was sensitive
  • Whether implied consent was appropriate in the circumstances
  • Whether the ISP limited its disclosure to relevant information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Wanted by the CBSA Program

Canada Border Services Agency (CBSA)

The Canadian Council for Refugees complained that the Canada Border Services Agency (CBSA) improperly disclosed an individual's personal information on its "Wanted by the CBSA" website. The program aimed to solicit public help in locating individuals with Canada-wide warrants for removal, including those accused of war crimes. The OPC found that while the disclosure of personal information was permissible under the Privacy Act as a consistent use for immigration law enforcement, the CBSA failed to ensure the information was accurate, up-to-date, and complete. Specifically, the website implied a conviction for war crimes when the individual was only deemed inadmissible under immigration law. This led to a well-founded finding regarding the accuracy of the information. The CBSA accepted five recommendations, including revisiting the amount of personal information disclosed, clarifying the distinction between criminal conviction and immigration determination, and improving the timely removal of profiles.

Quick view

Privacy ActWell-founded

Wanted by the CBSA Program

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canadian Council for Refugees complained that the Canada Border Services Agency (CBSA) improperly disclosed an individual's personal information on its "Wanted by the CBSA" website. The program aimed to solicit public help in locating individuals with Canada-wide warrants for removal, including those accused of war crimes. The OPC found that while the disclosure of personal information was permissible under the Privacy Act as a consistent use for immigration law enforcement, the CBSA failed to ensure the information was accurate, up-to-date, and complete. Specifically, the website implied a conviction for war crimes when the individual was only deemed inadmissible under immigration law. This led to a well-founded finding regarding the accuracy of the information. The CBSA accepted five recommendations, including revisiting the amount of personal information disclosed, clarifying the distinction between criminal conviction and immigration determination, and improving the timely removal of profiles.

Key Issues
  • Whether the disclosure of personal information on the "Wanted by the CBSA" website was permissible under the Privacy Act as a consistent use
  • Whether the CBSA took all reasonable steps to ensure the personal information was accurate, up-to-date, and complete as required by the Privacy Act
  • Whether the CBSA should have conducted a Privacy Impact Assessment before launching the program
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Oct 30, 2014Early resolved case summary #9Indexed Jun 30, 2026

Early resolved case summary #9: Equipment store ends practice of photocopying driver’s licences as a condition of renting equipment - October 30, 2014

An equipment store

An individual complained that an equipment store required a scanned copy of his driver's license and a photograph as a condition for renting equipment. The store justified this practice by citing past losses of expensive rental equipment. The OPC informed the store that collecting driver's license information in this manner was generally inappropriate due to the excessive personal information contained on the license and its limited value in theft investigations. The OPC provided guidance on appropriate collection practices. As a result of the OPC's intervention, the store implemented a less privacy-invasive solution and trained its staff. The complainant was satisfied with the outcome.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #9: Equipment store ends practice of photocopying driver’s licences as a condition of renting equipment - October 30, 2014

Oct 30, 2014Early resolved case summary #9
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an equipment store required a scanned copy of his driver's license and a photograph as a condition for renting equipment. The store justified this practice by citing past losses of expensive rental equipment. The OPC informed the store that collecting driver's license information in this manner was generally inappropriate due to the excessive personal information contained on the license and its limited value in theft investigations. The OPC provided guidance on appropriate collection practices. As a result of the OPC's intervention, the store implemented a less privacy-invasive solution and trained its staff. The complainant was satisfied with the outcome.

Key Issues
  • Whether requiring a scanned copy of a driver's license and a photograph for equipment rental constitutes appropriate collection of personal information under PIPEDA
  • Whether the collection of driver's license information is justified for addressing customer theft
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Public Service school called upon to better protect confidentiality

Canada School of Public Service

The Canada School of Public Service (the School) received a letter from the Public Sector Integrity Commissioner (PSIC) detailing allegations of wrongdoing against seven employees. The School then hand-delivered copies of this letter, which identified the seven individuals and the alleged wrongdoings, to each of the named employees. One of these employees complained to the OPC, alleging that the disclosure of his name via this letter violated the Privacy Act. The OPC found the complaint to be well-founded, concluding that the School had improperly disclosed personal information. Following the OPC's recommendations, the School developed new procedures to protect the confidentiality of information related to the Public Servants Disclosure Protection Act and a plan for addressing privacy breaches.

Quick view

Privacy ActWell-founded

Public Service school called upon to better protect confidentiality

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canada School of Public Service (the School) received a letter from the Public Sector Integrity Commissioner (PSIC) detailing allegations of wrongdoing against seven employees. The School then hand-delivered copies of this letter, which identified the seven individuals and the alleged wrongdoings, to each of the named employees. One of these employees complained to the OPC, alleging that the disclosure of his name via this letter violated the Privacy Act. The OPC found the complaint to be well-founded, concluding that the School had improperly disclosed personal information. Following the OPC's recommendations, the School developed new procedures to protect the confidentiality of information related to the Public Servants Disclosure Protection Act and a plan for addressing privacy breaches.

Key Issues
  • Whether the Canada School of Public Service disclosed personal information contrary to the Privacy Act by hand-delivering a letter from the Public Sector Integrity Commissioner to employees named in it
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

RCMP retention period for disciplinary records questioned

Royal Canadian Mounted Police (RCMP)

A complaint was filed on behalf of RCMP members regarding the disclosure of informal disciplinary records to the Crown, arguing it was inconsistent with the Supreme Court's R. v. McNeil decision. The complainant contended that only records from formal disciplinary hearings should be disclosed. The RCMP maintained that both formal and informal misconduct records could be relevant under McNeil, and the OPC agreed with this interpretation, finding the complaint not well-founded. However, the OPC expressed serious concerns about the RCMP's policy of retaining disciplinary records until members reach 100 years of age, which is significantly longer than other police services. The OPC recommended the RCMP reconsider its retention policies, but the RCMP indicated it would continue its current practice.

Quick view

Privacy ActNot well-founded

RCMP retention period for disciplinary records questioned

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed on behalf of RCMP members regarding the disclosure of informal disciplinary records to the Crown, arguing it was inconsistent with the Supreme Court's R. v. McNeil decision. The complainant contended that only records from formal disciplinary hearings should be disclosed. The RCMP maintained that both formal and informal misconduct records could be relevant under McNeil, and the OPC agreed with this interpretation, finding the complaint not well-founded. However, the OPC expressed serious concerns about the RCMP's policy of retaining disciplinary records until members reach 100 years of age, which is significantly longer than other police services. The OPC recommended the RCMP reconsider its retention policies, but the RCMP indicated it would continue its current practice.

Key Issues
  • Whether the disclosure of informal disciplinary records to the Crown is consistent with R. v. McNeil
  • Whether the RCMP's retention period for disciplinary records is appropriate
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Employment and Social Development Canada (ESDC)

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Quick view

Privacy ActWell-founded & resolved

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Key Issues
  • Whether Employment and Social Development Canada (ESDC) adequately protected personal information on a lost USB key
  • Whether Justice Canada adequately protected personal information on a lost USB key while in its custody
  • Whether physical controls for personal information were adequate
  • Whether technological controls (encryption, password protection) for personal information were adequate
  • Whether administrative controls for personal information were adequate
  • Whether personnel controls for personal information were adequate
  • Whether ESDC translated its privacy and security policies into meaningful business practices
  • Whether Justice Canada translated its privacy and security policies into meaningful business practices
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Woman fails in attempt to return personal information to Canada Revenue Agency

Canada Revenue Agency (CRA)

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Quick view

Privacy ActWell-founded

Woman fails in attempt to return personal information to Canada Revenue Agency

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Key Issues
  • Whether the Canada Revenue Agency breached the privacy rights of taxpayers by mistakenly sending confidential personal information to an unauthorized individual
  • Whether the Canada Revenue Agency's procedures for handling misdirected mail and breach reporting were adequate
  • Whether the Canada Revenue Agency's client service channels were accessible for reporting privacy breaches
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Oct 21, 2014Discontinued Case Summary #2014-004Indexed Jun 30, 2026

Discontinued Case Summary #2014-004: Complaint discontinued on the basis of bad faith as complainant had released the retailer from liability

A retailer

An individual filed a complaint against a retailer, alleging a failure to provide access to personal information under PIPEDA. This complaint arose after the complainant and the retailer had settled a small claims court dispute. As part of that settlement, the complainant had signed a mutual release, receiving financial compensation in exchange for releasing the retailer from all claims and complaints, including those arising under statute, related to events prior to the release date. The OPC found that the complaint was made in bad faith, given the existence of this mutual release. Consequently, the investigation was discontinued under paragraph 12.2(1)(b) of PIPEDA.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Discontinued Case Summary #2014-004: Complaint discontinued on the basis of bad faith as complainant had released the retailer from liability

Oct 21, 2014Discontinued Case Summary #2014-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual filed a complaint against a retailer, alleging a failure to provide access to personal information under PIPEDA. This complaint arose after the complainant and the retailer had settled a small claims court dispute. As part of that settlement, the complainant had signed a mutual release, receiving financial compensation in exchange for releasing the retailer from all claims and complaints, including those arising under statute, related to events prior to the release date. The OPC found that the complaint was made in bad faith, given the existence of this mutual release. Consequently, the investigation was discontinued under paragraph 12.2(1)(b) of PIPEDA.

Key Issues
  • Whether the complaint was made in bad faith under paragraph 12.2(1)(b) of PIPEDA
  • Whether a mutual release agreement impacts the validity of a subsequent privacy complaint
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Sep 16, 2014Indexed Jun 30, 2026

Name tags for border officers not a violation - September 16, 2014

Canada Border Services Agency (CBSA)

A group of Canada Border Services Agency (CBSA) employees complained that a new policy requiring them to wear name tags displaying their surnames, instead of badge numbers, violated sections 7 and 8 of the Privacy Act. They argued this constituted an unreasonable invasion of privacy and made them vulnerable to violence and intimidation, as their names could be used to find personal information. The CBSA contended that the name tags were part of a service excellence initiative, promoted professionalism and accountability, and that an employee's name on a name tag falls under an exception to the definition of personal information in the Act. The OPC found that while a surname on a name tag is information about an identifiable individual, it falls under paragraph (j) of the definition of personal information, which excludes information relating to the position or functions of a government employee for the purposes of sections 7 and 8. Therefore, the OPC concluded that the policy did not violate the Act.

Quick view

Privacy ActNot well-founded

Name tags for border officers not a violation - September 16, 2014

Sep 16, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A group of Canada Border Services Agency (CBSA) employees complained that a new policy requiring them to wear name tags displaying their surnames, instead of badge numbers, violated sections 7 and 8 of the Privacy Act. They argued this constituted an unreasonable invasion of privacy and made them vulnerable to violence and intimidation, as their names could be used to find personal information. The CBSA contended that the name tags were part of a service excellence initiative, promoted professionalism and accountability, and that an employee's name on a name tag falls under an exception to the definition of personal information in the Act. The OPC found that while a surname on a name tag is information about an identifiable individual, it falls under paragraph (j) of the definition of personal information, which excludes information relating to the position or functions of a government employee for the purposes of sections 7 and 8. Therefore, the OPC concluded that the policy did not violate the Act.

Key Issues
  • Whether the surname of a Border Services Officer (BSO) displayed on a name tag constitutes "personal information" under section 3 of the Privacy Act
  • Whether the surname on a name tag falls within the exception to the definition of personal information under paragraph (j) of section 3 of the Privacy Act
  • Whether the CBSA's requirement for BSOs to wear name tags displaying their surnames violates sections 7 and 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 5, 2014Indexed Jun 30, 2026

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Aboriginal Affairs and Northern Development Canada (AANDC)

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Quick view

Privacy ActWell-founded

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Sep 5, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Key Issues
  • Whether the document contained personal information under s.3 of the Privacy Act
  • Whether all AANDC officials who accessed the document had a need-to-know the identity of the requesters under s.7(a) of the Privacy Act and TBS Policy on Access to Information s.6.2.3
  • Whether the disclosure of the information to La Presse constituted a contravention of s.8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 9, 2014Indexed Jun 30, 2026

Sharing of health information unjustified - July 9, 2014

Public Service Commission of Canada (PSC)

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Quick view

Privacy ActWell-founded

Sharing of health information unjustified - July 9, 2014

Jul 9, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Key Issues
  • Whether the disclosure of the complainant's medical information to witnesses was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the PSC's interpretation of "affected person" and the requirements of procedural fairness justified the disclosure of sensitive medical information to all witnesses
  • Whether the PSC contravened subsection 8(1) of the Privacy Act by disclosing personal information without consent or a valid exception
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
May 22, 2014PIPEDA findings #2014-020Indexed Jun 30, 2026

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

A videographer

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

May 22, 2014PIPEDA findings #2014-020
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Key Issues
  • Whether the use of personal information constituted commercial activity
  • Whether the videographer had consent for this use
  • Whether the videographer needed consent for this use
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apple Canada Inc.

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Key Issues
  • Whether Apple's privacy policy adequately identified the purposes for collecting date of birth information for authentication (Principle 4.2 PIPEDA)
  • Whether Apple's collection of date of birth was limited to what was necessary for identified purposes (Principle 4.4 PIPEDA)
  • Whether Apple made information about its policies and practices concerning the collection of credit card information readily available to individuals (Principle 4.8 PIPEDA)
  • Whether Apple's practices resulted in the over-collection of sensitive payment information (Principle 4.4 PIPEDA)