The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

1,631 decisions in the archive
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Apr 10, 2014Indexed Jun 30, 2026

Interference with Access to Information: Part 2

Public Works and Government Services Canada

The Information Commissioner initiated a systemic investigation under section 39 of the Access to Information Act into Public Works and Government Services Canada (PWGSC). The investigation focused on the processing of eight access to information or consultation requests received by PWGSC between July 22, 2008, and January 19, 2010. The primary concern was the possibility of interference in the processing of these requests. This report, titled "Interference with Access to Information: Part 2," details the Commissioner's findings regarding the alleged interference. The investigation aimed to determine if the institution's handling of these requests was appropriate or if there were instances of improper influence or obstruction.

Quick view

Access to Information ActSystemic Investigation

Interference with Access to Information: Part 2

Apr 10, 2014
Adjudicator: Suzanne Legault
Plain-Language Summary

The Information Commissioner initiated a systemic investigation under section 39 of the Access to Information Act into Public Works and Government Services Canada (PWGSC). The investigation focused on the processing of eight access to information or consultation requests received by PWGSC between July 22, 2008, and January 19, 2010. The primary concern was the possibility of interference in the processing of these requests. This report, titled "Interference with Access to Information: Part 2," details the Commissioner's findings regarding the alleged interference. The investigation aimed to determine if the institution's handling of these requests was appropriate or if there were instances of improper influence or obstruction.

Key Issues
  • Whether there was interference in the processing of access to information requests at Public Works and Government Services Canada
  • Whether Public Works and Government Services Canada properly processed eight specific access to information or consultation requests
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2014Indexed Jun 30, 2026

IP54-56/2014 — Employment and Social Development Canada

Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Quick view

Privacy ActWell-founded

IP54-56/2014 — Employment and Social Development Canada

Mar 24, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Key Issues
  • Whether ESDC failed to implement adequate physical security controls for personal information stored on portable media.
  • Whether ESDC failed to implement adequate technical security controls, such as encryption and risk assessments, for personal information on portable media.
  • Whether ESDC failed to implement adequate administrative controls, including asset inventory, information classification, and lifecycle management, for personal information.
  • Whether ESDC failed to implement adequate personnel security controls, such as employee training, awareness, and accountability, regarding personal information.
  • Whether ESDC contravened subsection 6(3) of the Privacy Act by failing to properly dispose of personal information.
  • Whether ESDC contravened section 7 of the Privacy Act regarding the use of personal information.
  • Whether ESDC contravened section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether the delay in notifying affected individuals of the breach was reasonable.
  • Whether the scope of personal information reported to affected individuals in the notification letters was complete.
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Mar 21, 2014Incident Summary #5Indexed Jun 30, 2026

Incident Summary #5: Life insurance company employs best practices in responding to mass mailing error that risked exposing personal information - March 21, 2014

A life insurance company

A life insurance company discovered that a mass mailing error risked exposing the personal information of 53 pension plan members. The new window envelopes used were larger, potentially revealing certificate numbers, SINs, dates of birth, spouse's names, and beneficiaries if statements shifted. Upon discovering the incident, the company promptly notified affected individuals, apologized, explained the incident, and offered a free one-year credit monitoring service. They also advised members to take harm-reducing steps and ceased using the problematic envelopes. The company informed the OPC about the incident and its response. The OPC concluded that the company demonstrated best practices in its incident response.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #5: Life insurance company employs best practices in responding to mass mailing error that risked exposing personal information - March 21, 2014

Mar 21, 2014Incident Summary #5
Adjudicator: Chantal Bernier
Plain-Language Summary

A life insurance company discovered that a mass mailing error risked exposing the personal information of 53 pension plan members. The new window envelopes used were larger, potentially revealing certificate numbers, SINs, dates of birth, spouse's names, and beneficiaries if statements shifted. Upon discovering the incident, the company promptly notified affected individuals, apologized, explained the incident, and offered a free one-year credit monitoring service. They also advised members to take harm-reducing steps and ceased using the problematic envelopes. The company informed the OPC about the incident and its response. The OPC concluded that the company demonstrated best practices in its incident response.

Key Issues
  • Whether a mass mailing error led to the potential exposure of personal information
  • Whether the life insurance company's response to the incident constituted best practices
Federal (Canada)Privacy ActNo jurisdiction
Federal (Canada) flag
Mar 4, 2014Indexed Jun 30, 2026

Retroactive removal of Privacy Act provisions leaves gun registry complainant with no recourse - 2015

Royal Canadian Mounted Police (RCMP)

The complainant alleged that the RCMP continued to retain and use personal information from the national long-gun registry, which should have been destroyed under the Ending the Long-Gun Registry Act. Specific allegations included a High River RCMP member's statement about locating firearms and an email from a Langley RCMP member referring to non-restricted firearm registration. The RCMP stated that electronic records were destroyed in October 2012 and hard copies by December 2013 (except for Quebec records). They also argued that information extracted from the registry before its destruction and retained in case files could be used consistent with its original purpose. The OPC found no evidence of contravention, noting that recent legislative amendments retroactively excluded the application of the Privacy Act to certain long-gun registry records, preventing further investigation into specific examples.

Quick view

Privacy ActNo jurisdiction

Retroactive removal of Privacy Act provisions leaves gun registry complainant with no recourse - 2015

Mar 4, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The complainant alleged that the RCMP continued to retain and use personal information from the national long-gun registry, which should have been destroyed under the Ending the Long-Gun Registry Act. Specific allegations included a High River RCMP member's statement about locating firearms and an email from a Langley RCMP member referring to non-restricted firearm registration. The RCMP stated that electronic records were destroyed in October 2012 and hard copies by December 2013 (except for Quebec records). They also argued that information extracted from the registry before its destruction and retained in case files could be used consistent with its original purpose. The OPC found no evidence of contravention, noting that recent legislative amendments retroactively excluded the application of the Privacy Act to certain long-gun registry records, preventing further investigation into specific examples.

Key Issues
  • Whether the RCMP continued to retain and use personal information from the national long-gun registry after it was required to be destroyed
  • Whether the High River RCMP used personal information from the long-gun registry in June 2013
  • Whether other RCMP detachments continued to use personal information from the long-gun registry after electronic records were destroyed in October 2012
  • Whether copies of the long-gun registry containing personal information still exist in the possession of the RCMP or other police services
  • Whether the use of personal information from the long-gun registry, retained in case files prior to the Ending the Long-gun Registry Act, is consistent with section 7 of the Privacy Act
  • Whether the retroactive exclusion of the Privacy Act by Bill C-59 affects the investigation
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 20, 2014Early resolved case summary #10Indexed Jun 30, 2026

Early resolved case summary #10: Bank improves its credit card account verification practices after challenge from customer - February 20, 2014

A financial institution

An individual complained that her bank required the last six digits of her Social Insurance Number (SIN) to set up a "verified credit account" for online purchases. She believed this practice was inappropriate and that an alternative method not requiring SIN information should be available. The bank initially stated an alternative existed through commercial websites, but the complainant noted this was not clearly communicated. The OPC highlighted a comparable case where a lack of transparency regarding authentication alternatives was found. Following this, the bank decided to discontinue the SIN-based authentication method entirely and update its website. The complainant was satisfied with this resolution, and the OPC confirmed the website changes.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Early resolved case summary #10: Bank improves its credit card account verification practices after challenge from customer - February 20, 2014

Feb 20, 2014Early resolved case summary #10
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that her bank required the last six digits of her Social Insurance Number (SIN) to set up a "verified credit account" for online purchases. She believed this practice was inappropriate and that an alternative method not requiring SIN information should be available. The bank initially stated an alternative existed through commercial websites, but the complainant noted this was not clearly communicated. The OPC highlighted a comparable case where a lack of transparency regarding authentication alternatives was found. Following this, the bank decided to discontinue the SIN-based authentication method entirely and update its website. The complainant was satisfied with this resolution, and the OPC confirmed the website changes.

Key Issues
  • Whether collecting a partial SIN for credit card account verification was appropriate under PIPEDA
  • Whether the bank provided adequate transparency regarding alternative verification methods
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Feb 10, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-012Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-012: Investment Firm Justified in its Collection of "Know Your Client" Information

An investment firm

A customer complained that his investment firm required an unreasonable amount of personal information on its "Know Your Client" (KYC) form as a condition for maintaining his Tax Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP). The firm requested details such as investment experience, annual income, spouse's income, dependents, assets, liabilities, and net worth. The firm argued this information was necessary to comply with the Investment Industry Regulatory Organization of Canada (IIROC) KYC and suitability requirements. The OPC assessed whether the firm contravened PIPEDA Principle 4.3.3 by requiring consent for information beyond explicitly specified and legitimate purposes. The OPC found that the firm had explicitly specified its purposes, which were legitimate given IIROC's regulatory framework. The OPC also concluded that the requested information, including details beyond IIROC's standard Form 2, was necessary for the firm to meet its regulatory obligations. Therefore, the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Commissioner’s Findings - PIPEDA Report of Findings #2014-012: Investment Firm Justified in its Collection of "Know Your Client" Information

Feb 10, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-012
Adjudicator: Chantal Bernier
Plain-Language Summary

A customer complained that his investment firm required an unreasonable amount of personal information on its "Know Your Client" (KYC) form as a condition for maintaining his Tax Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP). The firm requested details such as investment experience, annual income, spouse's income, dependents, assets, liabilities, and net worth. The firm argued this information was necessary to comply with the Investment Industry Regulatory Organization of Canada (IIROC) KYC and suitability requirements. The OPC assessed whether the firm contravened PIPEDA Principle 4.3.3 by requiring consent for information beyond explicitly specified and legitimate purposes. The OPC found that the firm had explicitly specified its purposes, which were legitimate given IIROC's regulatory framework. The OPC also concluded that the requested information, including details beyond IIROC's standard Form 2, was necessary for the firm to meet its regulatory obligations. Therefore, the complaint was not well-founded.

Key Issues
  • Whether the investment firm explicitly specified the purposes for collecting personal information under Principle 4.2 PIPEDA
  • Whether the purposes for collecting personal information were legitimate under subsection 5(3) PIPEDA
  • Whether the investment firm required more personal information than necessary to achieve the legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA
  • Whether the collection of personal information was limited to that which was necessary for the identified purposes under Principle 4.4 PIPEDA
  • Whether information on investment experience was necessary to validate investment knowledge and assess risk tolerance
  • Whether spouse's or partner's annual income was necessary to assess overall financial position and suitability
  • Whether detailed assets and liabilities were necessary to establish net worth and understand financial situation
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jan 23, 2014Early resolved case summary #5Indexed Jun 30, 2026

Early resolved case summary #5: Web posting that was removed by individual retained by Internet search engine - January 23, 2014

An Internet search engine

An individual posted her résumé on a job website, which included her address. After having the job website remove the information, she discovered her résumé was still searchable via an Internet search engine. The individual contacted the search engine's Web administrator multiple times to request removal of her personal information, but the search engine did not comply. She then filed a complaint with the OPC. The OPC intervened directly with the search engine, which subsequently removed the cached copy of the individual's information from its search results using its URL removal tool. The complainant was satisfied with the outcome, and the complaint was closed.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #5: Web posting that was removed by individual retained by Internet search engine - January 23, 2014

Jan 23, 2014Early resolved case summary #5
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual posted her résumé on a job website, which included her address. After having the job website remove the information, she discovered her résumé was still searchable via an Internet search engine. The individual contacted the search engine's Web administrator multiple times to request removal of her personal information, but the search engine did not comply. She then filed a complaint with the OPC. The OPC intervened directly with the search engine, which subsequently removed the cached copy of the individual's information from its search results using its URL removal tool. The complainant was satisfied with the outcome, and the complaint was closed.

Key Issues
  • Whether an Internet search engine was obligated to remove cached personal information after the original source was deleted
  • Whether the search engine's refusal to remove the information constituted a contravention of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 14, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-001Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-001: Use of sensitive health information for targeting of Google ads raises privacy concerns

Google Inc.

A complainant alleged that Google's AdSense service displayed targeted advertisements for sleep apnea devices on unrelated websites after he searched for medical devices online. He viewed his online activities related to sleep apnea as sensitive information requiring express consent for targeted advertising. The OPC's technical analysis confirmed that Google was delivering these ads through online behavioural advertising (OBA) and that they persisted over time. Google initially attributed this to a technical issue but later confirmed it was due to 'remarketed ads,' a form of interest-based advertising. The OPC found that Google's practice of delivering tailored ads based on sensitive health information without express consent contravened PIPEDA Principles 4.3 and 4.3.6. Google committed to several remedial measures, including rejecting relevant remarketing campaigns, revising its policies, developing new internal training, and increasing monitoring.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Report of Findings #2014-001: Use of sensitive health information for targeting of Google ads raises privacy concerns

Jan 14, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-001
Adjudicator: Chantal Bernier
Plain-Language Summary

A complainant alleged that Google's AdSense service displayed targeted advertisements for sleep apnea devices on unrelated websites after he searched for medical devices online. He viewed his online activities related to sleep apnea as sensitive information requiring express consent for targeted advertising. The OPC's technical analysis confirmed that Google was delivering these ads through online behavioural advertising (OBA) and that they persisted over time. Google initially attributed this to a technical issue but later confirmed it was due to 'remarketed ads,' a form of interest-based advertising. The OPC found that Google's practice of delivering tailored ads based on sensitive health information without express consent contravened PIPEDA Principles 4.3 and 4.3.6. Google committed to several remedial measures, including rejecting relevant remarketing campaigns, revising its policies, developing new internal training, and increasing monitoring.

Key Issues
  • Whether the delivery of targeted advertisements based on online searches for medical devices constitutes online behavioural advertising (OBA)
  • Whether information related to online searches for medical devices is sensitive personal information
  • Whether express consent is required for the collection and use of sensitive personal health information for OBA purposes
  • Whether Google obtained appropriate consent under Principle 4.3 and 4.3.6 for the use of sensitive health information for targeted advertising
  • Whether Google's privacy policy accurately reflected its practices regarding sensitive categories in tailored ads
  • Whether Google's monitoring tools for preventing policy abuses were scalable and effective
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014Indexed Jun 30, 2026

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

An online dating service

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Key Issues
  • Whether the organization denied the complainant access to his personal information in violation of Principle 4.9
  • Whether the organization failed to respect the 30-day time limit for access requests under subsection 8(3)
  • Whether the organization contravened subsection 8(8) by destroying photographs, limiting the complainant's recourse
  • Whether the organization retained the complainant's information longer than necessary in contravention of Principle 4.5.3
  • Whether the organization continued to use the complainant's personal information for marketing after consent withdrawal, contravening Principle 4.3.8
  • Whether the organization lacked a privacy policy in contravention of Principle 4.1.4(d)
  • Whether the organization failed to safeguard the complainant's personal information as required by Principle 4.7.1
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Nov 28, 2013Indexed Jun 30, 2026

Access to information at risk from instant messaging

Crown-Indigenous Relations and Northern Affairs / Indigenous Services

In August 2012, the Information Commissioner launched a systemic investigation into the use and preservation of non-email, text-based messages on government-issued wireless devices, specifically instant messaging and PINs. This investigation was prompted by a complaint against Indian and Northern Affairs Canada (now Aboriginal Affairs and Northern Development Canada) where a complainant received an email suggesting the use of "pin" instead of email for communication. During the investigation of that complaint, it was discovered that relevant BlackBerry devices had been replaced and destroyed, leading to the permanent loss of potentially responsive information. Due to this incident and a rise in similar complaints about missing records, the Commissioner initiated a self-complaint under section 30(1)(f) of the ATIA to examine the impact of instant messaging on access to information. The investigation focused on 11 federal institutions to assess their practices regarding the retention of these types of communications.

Quick view

Access to Information ActSystemic Investigation

Access to information at risk from instant messaging

Nov 28, 2013
Adjudicator: Suzanne Legault
Plain-Language Summary

In August 2012, the Information Commissioner launched a systemic investigation into the use and preservation of non-email, text-based messages on government-issued wireless devices, specifically instant messaging and PINs. This investigation was prompted by a complaint against Indian and Northern Affairs Canada (now Aboriginal Affairs and Northern Development Canada) where a complainant received an email suggesting the use of "pin" instead of email for communication. During the investigation of that complaint, it was discovered that relevant BlackBerry devices had been replaced and destroyed, leading to the permanent loss of potentially responsive information. Due to this incident and a rise in similar complaints about missing records, the Commissioner initiated a self-complaint under section 30(1)(f) of the ATIA to examine the impact of instant messaging on access to information. The investigation focused on 11 federal institutions to assess their practices regarding the retention of these types of communications.

Key Issues
  • Impact of instant messaging on the right of access to information
  • Preservation of non-email, text-based messages on government-issued wireless devices
  • Retention policies and practices for instant messages and PIN communications
  • Loss of records due to device replacement and destruction
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Criminal background check on tenant

Royal Canadian Mounted Police (RCMP)

A woman complained that two RCMP employee landlords performed a criminal background check on her using the Canadian Police Information Centre (CPIC) database when she applied to rent a basement apartment. The landlords requested personal identification to "look into" prospective tenants. An internal RCMP investigation confirmed that one officer accessed CPIC for personal reasons, citing the applicant being from "out of town" and concerns for officer safety and organizational security. The OPC found that the CPIC database contains personal information and its use is restricted to legitimate law enforcement purposes. The investigation concluded that the officer's access was for personal reasons, not authorized operational purposes. The complaint was found to be well-founded, and the RCMP took remedial actions including an apology to the complainant and a communiqué to employees regarding CPIC use policies.

Quick view

Privacy ActWell-founded

Criminal background check on tenant

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained that two RCMP employee landlords performed a criminal background check on her using the Canadian Police Information Centre (CPIC) database when she applied to rent a basement apartment. The landlords requested personal identification to "look into" prospective tenants. An internal RCMP investigation confirmed that one officer accessed CPIC for personal reasons, citing the applicant being from "out of town" and concerns for officer safety and organizational security. The OPC found that the CPIC database contains personal information and its use is restricted to legitimate law enforcement purposes. The investigation concluded that the officer's access was for personal reasons, not authorized operational purposes. The complaint was found to be well-founded, and the RCMP took remedial actions including an apology to the complainant and a communiqué to employees regarding CPIC use policies.

Key Issues
  • Whether the CPIC database contains personal information under the Privacy Act
  • Whether the RCMP officer accessed the CPIC database for personal reasons
  • Whether the access to the CPIC database was for an authorized operational purpose
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed May 13, 2026

Denial was the starting point for Correctional Service of Canada

Correctional Service of Canada

An inmate at a maximum-security penitentiary requested video recordings of incidents involving officers. The Correctional Service of Canada (CSC) denied access, citing third-party information and security concerns. The OPC found complaints regarding 16 destroyed videos to be well-founded, as CSC had not even reviewed them before denial. For two other videos, which CSC claimed contained third-party information and posed security risks, the OPC found CSC correctly applied exemptions, thus resolving those complaints.

Quick view

Privacy ActWell-founded

Denial was the starting point for Correctional Service of Canada

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An inmate at a maximum-security penitentiary requested video recordings of incidents involving officers. The Correctional Service of Canada (CSC) denied access, citing third-party information and security concerns. The OPC found complaints regarding 16 destroyed videos to be well-founded, as CSC had not even reviewed them before denial. For two other videos, which CSC claimed contained third-party information and posed security risks, the OPC found CSC correctly applied exemptions, thus resolving those complaints.

Key Issues
  • Timeliness of responding to access to information requests
  • Destruction of records prior to fulfilling requests
  • Application of exemptions for security of penal institutions
  • Proper review of records before withholding information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Royal Canadian Mounted Police revealed absolute discharge

Royal Canadian Mounted Police (RCMP)

A man applied for a Transportation Security Clearance in July 2010, which was denied by Transport Canada (TC) in September 2011 based on information from the RCMP. The man complained that the RCMP improperly disclosed his personal information to TC. The RCMP had obtained information about an incident involving the complainant in 2009, which resulted in an absolute discharge a few months later. The RCMP provided this information to TC in 2011. The OPC found that the disclosure contravened the Criminal Records Act because more than a year had passed since the absolute discharge and no ministerial approval was obtained. The disclosure was also not authorized under the Privacy Act. The complaint was found to be well-founded.

Quick view

Privacy ActWell-founded

Royal Canadian Mounted Police revealed absolute discharge

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A man applied for a Transportation Security Clearance in July 2010, which was denied by Transport Canada (TC) in September 2011 based on information from the RCMP. The man complained that the RCMP improperly disclosed his personal information to TC. The RCMP had obtained information about an incident involving the complainant in 2009, which resulted in an absolute discharge a few months later. The RCMP provided this information to TC in 2011. The OPC found that the disclosure contravened the Criminal Records Act because more than a year had passed since the absolute discharge and no ministerial approval was obtained. The disclosure was also not authorized under the Privacy Act. The complaint was found to be well-founded.

Key Issues
  • Whether the RCMP's disclosure of personal information to Transport Canada contravened the Criminal Records Act
  • Whether the RCMP's disclosure of personal information to Transport Canada was authorized under the Privacy Act
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Correctional Service of Canada initially denies access to full report in favour of giving the “gist”

Correctional Service of Canada (CSC)

A complainant alleged that the Correctional Service of Canada (CSC) denied him full access to a report concerning his treatment and supervision. The complainant initially received a three-page summary, but later learned the full report was ten pages with more findings. The OPC's investigation confirmed the existence of the longer report. CSC stated they provided a condensed version because the full report was based on informal interviews. The OPC found that providing an abbreviated version misrepresented the information and was contrary to CSC's obligations under the Privacy Act to process all relevant information. After negotiations, CSC provided the full report with third-party personal information redacted and committed to reviewing its access request handling and educating staff on Privacy Act obligations.

Quick view

Privacy ActResolved

Correctional Service of Canada initially denies access to full report in favour of giving the “gist”

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that the Correctional Service of Canada (CSC) denied him full access to a report concerning his treatment and supervision. The complainant initially received a three-page summary, but later learned the full report was ten pages with more findings. The OPC's investigation confirmed the existence of the longer report. CSC stated they provided a condensed version because the full report was based on informal interviews. The OPC found that providing an abbreviated version misrepresented the information and was contrary to CSC's obligations under the Privacy Act to process all relevant information. After negotiations, CSC provided the full report with third-party personal information redacted and committed to reviewing its access request handling and educating staff on Privacy Act obligations.

Key Issues
  • Whether Correctional Service of Canada denied full access to a report
  • Whether providing a condensed version of a report constitutes a misrepresentation of information
  • Whether Correctional Service of Canada fulfilled its responsibility to identify and process all relevant information under the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Aboriginal Affairs and Northern Development Canada wrongly collects information from First Nations activist’s personal Facebook page

Aboriginal Affairs and Northern Development Canada and Department of Justice Canada

First Nations activist Cindy Blackstock complained that Aboriginal Affairs and Northern Development Canada (AANDC) and the Department of Justice Canada (DOJ) contravened the Privacy Act by collecting her personal information from her Facebook page. The departments argued that information posted publicly on Facebook was not personal. The OPC rejected this argument, finding that publicly available information can still be personal under the Privacy Act. The OPC found that the collection of personal information from Ms. Blackstock's personal Facebook page was not directly related to a government operating program or activity. Both departments accepted the OPC's recommendations to cease such collection, destroy previously collected personal information, and develop policies for social media monitoring.

Quick view

Privacy ActWell-founded

Aboriginal Affairs and Northern Development Canada wrongly collects information from First Nations activist’s personal Facebook page

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

First Nations activist Cindy Blackstock complained that Aboriginal Affairs and Northern Development Canada (AANDC) and the Department of Justice Canada (DOJ) contravened the Privacy Act by collecting her personal information from her Facebook page. The departments argued that information posted publicly on Facebook was not personal. The OPC rejected this argument, finding that publicly available information can still be personal under the Privacy Act. The OPC found that the collection of personal information from Ms. Blackstock's personal Facebook page was not directly related to a government operating program or activity. Both departments accepted the OPC's recommendations to cease such collection, destroy previously collected personal information, and develop policies for social media monitoring.

Key Issues
  • Whether information posted on a personal Facebook page constitutes "personal information" under the Privacy Act
  • Whether the public availability of personal information on the Internet renders it non-personal
  • Whether the collection of personal information from Ms. Blackstock's personal Facebook page was directly related to a government operating program or activity
  • Whether the monitoring of Ms. Blackstock's public speeches constituted collection of "personal information" under the Privacy Act
  • Whether repeated accessing of Ms. Blackstock's Indian status records was a contravention of the Privacy Act