The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

1,639 decisions in the archive
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Woman fails in attempt to return personal information to Canada Revenue Agency

Canada Revenue Agency (CRA)

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Quick view

Privacy ActWell-founded

Woman fails in attempt to return personal information to Canada Revenue Agency

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Key Issues
  • Whether the Canada Revenue Agency breached the privacy rights of taxpayers by mistakenly sending confidential personal information to an unauthorized individual
  • Whether the Canada Revenue Agency's procedures for handling misdirected mail and breach reporting were adequate
  • Whether the Canada Revenue Agency's client service channels were accessible for reporting privacy breaches
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Public Service school called upon to better protect confidentiality

Canada School of Public Service

The Canada School of Public Service (the School) received a letter from the Public Sector Integrity Commissioner (PSIC) detailing allegations of wrongdoing against seven employees. The School then hand-delivered copies of this letter, which identified the seven individuals and the alleged wrongdoings, to each of the named employees. One of these employees complained to the OPC, alleging that the disclosure of his name via this letter violated the Privacy Act. The OPC found the complaint to be well-founded, concluding that the School had improperly disclosed personal information. Following the OPC's recommendations, the School developed new procedures to protect the confidentiality of information related to the Public Servants Disclosure Protection Act and a plan for addressing privacy breaches.

Quick view

Privacy ActWell-founded

Public Service school called upon to better protect confidentiality

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canada School of Public Service (the School) received a letter from the Public Sector Integrity Commissioner (PSIC) detailing allegations of wrongdoing against seven employees. The School then hand-delivered copies of this letter, which identified the seven individuals and the alleged wrongdoings, to each of the named employees. One of these employees complained to the OPC, alleging that the disclosure of his name via this letter violated the Privacy Act. The OPC found the complaint to be well-founded, concluding that the School had improperly disclosed personal information. Following the OPC's recommendations, the School developed new procedures to protect the confidentiality of information related to the Public Servants Disclosure Protection Act and a plan for addressing privacy breaches.

Key Issues
  • Whether the Canada School of Public Service disclosed personal information contrary to the Privacy Act by hand-delivering a letter from the Public Sector Integrity Commissioner to employees named in it
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Oct 21, 2014Discontinued Case Summary #2014-004Indexed Jun 30, 2026

Discontinued Case Summary #2014-004: Complaint discontinued on the basis of bad faith as complainant had released the retailer from liability

A retailer

An individual filed a complaint against a retailer, alleging a failure to provide access to personal information under PIPEDA. This complaint arose after the complainant and the retailer had settled a small claims court dispute. As part of that settlement, the complainant had signed a mutual release, receiving financial compensation in exchange for releasing the retailer from all claims and complaints, including those arising under statute, related to events prior to the release date. The OPC found that the complaint was made in bad faith, given the existence of this mutual release. Consequently, the investigation was discontinued under paragraph 12.2(1)(b) of PIPEDA.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Discontinued Case Summary #2014-004: Complaint discontinued on the basis of bad faith as complainant had released the retailer from liability

Oct 21, 2014Discontinued Case Summary #2014-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual filed a complaint against a retailer, alleging a failure to provide access to personal information under PIPEDA. This complaint arose after the complainant and the retailer had settled a small claims court dispute. As part of that settlement, the complainant had signed a mutual release, receiving financial compensation in exchange for releasing the retailer from all claims and complaints, including those arising under statute, related to events prior to the release date. The OPC found that the complaint was made in bad faith, given the existence of this mutual release. Consequently, the investigation was discontinued under paragraph 12.2(1)(b) of PIPEDA.

Key Issues
  • Whether the complaint was made in bad faith under paragraph 12.2(1)(b) of PIPEDA
  • Whether a mutual release agreement impacts the validity of a subsequent privacy complaint
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Sep 16, 2014Indexed Jun 30, 2026

Name tags for border officers not a violation - September 16, 2014

Canada Border Services Agency (CBSA)

A group of Canada Border Services Agency (CBSA) employees complained that a new policy requiring them to wear name tags displaying their surnames, instead of badge numbers, violated sections 7 and 8 of the Privacy Act. They argued this constituted an unreasonable invasion of privacy and made them vulnerable to violence and intimidation, as their names could be used to find personal information. The CBSA contended that the name tags were part of a service excellence initiative, promoted professionalism and accountability, and that an employee's name on a name tag falls under an exception to the definition of personal information in the Act. The OPC found that while a surname on a name tag is information about an identifiable individual, it falls under paragraph (j) of the definition of personal information, which excludes information relating to the position or functions of a government employee for the purposes of sections 7 and 8. Therefore, the OPC concluded that the policy did not violate the Act.

Quick view

Privacy ActNot well-founded

Name tags for border officers not a violation - September 16, 2014

Sep 16, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A group of Canada Border Services Agency (CBSA) employees complained that a new policy requiring them to wear name tags displaying their surnames, instead of badge numbers, violated sections 7 and 8 of the Privacy Act. They argued this constituted an unreasonable invasion of privacy and made them vulnerable to violence and intimidation, as their names could be used to find personal information. The CBSA contended that the name tags were part of a service excellence initiative, promoted professionalism and accountability, and that an employee's name on a name tag falls under an exception to the definition of personal information in the Act. The OPC found that while a surname on a name tag is information about an identifiable individual, it falls under paragraph (j) of the definition of personal information, which excludes information relating to the position or functions of a government employee for the purposes of sections 7 and 8. Therefore, the OPC concluded that the policy did not violate the Act.

Key Issues
  • Whether the surname of a Border Services Officer (BSO) displayed on a name tag constitutes "personal information" under section 3 of the Privacy Act
  • Whether the surname on a name tag falls within the exception to the definition of personal information under paragraph (j) of section 3 of the Privacy Act
  • Whether the CBSA's requirement for BSOs to wear name tags displaying their surnames violates sections 7 and 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 5, 2014Indexed Jun 30, 2026

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Aboriginal Affairs and Northern Development Canada (AANDC)

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Quick view

Privacy ActWell-founded

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Sep 5, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Key Issues
  • Whether the document contained personal information under s.3 of the Privacy Act
  • Whether all AANDC officials who accessed the document had a need-to-know the identity of the requesters under s.7(a) of the Privacy Act and TBS Policy on Access to Information s.6.2.3
  • Whether the disclosure of the information to La Presse constituted a contravention of s.8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 9, 2014Indexed Jun 30, 2026

Sharing of health information unjustified - July 9, 2014

Public Service Commission of Canada (PSC)

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Quick view

Privacy ActWell-founded

Sharing of health information unjustified - July 9, 2014

Jul 9, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Key Issues
  • Whether the disclosure of the complainant's medical information to witnesses was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the PSC's interpretation of "affected person" and the requirements of procedural fairness justified the disclosure of sensitive medical information to all witnesses
  • Whether the PSC contravened subsection 8(1) of the Privacy Act by disclosing personal information without consent or a valid exception
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
May 22, 2014PIPEDA findings #2014-020Indexed Jun 30, 2026

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

A videographer

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

May 22, 2014PIPEDA findings #2014-020
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Key Issues
  • Whether the use of personal information constituted commercial activity
  • Whether the videographer had consent for this use
  • Whether the videographer needed consent for this use
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apple Canada Inc.

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Key Issues
  • Whether Apple's privacy policy adequately identified the purposes for collecting date of birth information for authentication (Principle 4.2 PIPEDA)
  • Whether Apple's collection of date of birth was limited to what was necessary for identified purposes (Principle 4.4 PIPEDA)
  • Whether Apple made information about its policies and practices concerning the collection of credit card information readily available to individuals (Principle 4.8 PIPEDA)
  • Whether Apple's practices resulted in the over-collection of sensitive payment information (Principle 4.4 PIPEDA)
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Apr 10, 2014Indexed Jun 30, 2026

Interference with Access to Information: Part 2

Public Works and Government Services Canada

The Information Commissioner initiated a systemic investigation under section 39 of the Access to Information Act into Public Works and Government Services Canada (PWGSC). The investigation focused on the processing of eight access to information or consultation requests received by PWGSC between July 22, 2008, and January 19, 2010. The primary concern was the possibility of interference in the processing of these requests. This report, titled "Interference with Access to Information: Part 2," details the Commissioner's findings regarding the alleged interference. The investigation aimed to determine if the institution's handling of these requests was appropriate or if there were instances of improper influence or obstruction.

Quick view

Access to Information ActSystemic Investigation

Interference with Access to Information: Part 2

Apr 10, 2014
Adjudicator: Suzanne Legault
Plain-Language Summary

The Information Commissioner initiated a systemic investigation under section 39 of the Access to Information Act into Public Works and Government Services Canada (PWGSC). The investigation focused on the processing of eight access to information or consultation requests received by PWGSC between July 22, 2008, and January 19, 2010. The primary concern was the possibility of interference in the processing of these requests. This report, titled "Interference with Access to Information: Part 2," details the Commissioner's findings regarding the alleged interference. The investigation aimed to determine if the institution's handling of these requests was appropriate or if there were instances of improper influence or obstruction.

Key Issues
  • Whether there was interference in the processing of access to information requests at Public Works and Government Services Canada
  • Whether Public Works and Government Services Canada properly processed eight specific access to information or consultation requests
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2014Indexed Jun 30, 2026

IP54-56/2014 — Employment and Social Development Canada

Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Quick view

Privacy ActWell-founded

IP54-56/2014 — Employment and Social Development Canada

Mar 24, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Key Issues
  • Whether ESDC failed to implement adequate physical security controls for personal information stored on portable media.
  • Whether ESDC failed to implement adequate technical security controls, such as encryption and risk assessments, for personal information on portable media.
  • Whether ESDC failed to implement adequate administrative controls, including asset inventory, information classification, and lifecycle management, for personal information.
  • Whether ESDC failed to implement adequate personnel security controls, such as employee training, awareness, and accountability, regarding personal information.
  • Whether ESDC contravened subsection 6(3) of the Privacy Act by failing to properly dispose of personal information.
  • Whether ESDC contravened section 7 of the Privacy Act regarding the use of personal information.
  • Whether ESDC contravened section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether the delay in notifying affected individuals of the breach was reasonable.
  • Whether the scope of personal information reported to affected individuals in the notification letters was complete.
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Mar 21, 2014Incident Summary #5Indexed Jun 30, 2026

Incident Summary #5: Life insurance company employs best practices in responding to mass mailing error that risked exposing personal information - March 21, 2014

A life insurance company

A life insurance company discovered that a mass mailing error risked exposing the personal information of 53 pension plan members. The new window envelopes used were larger, potentially revealing certificate numbers, SINs, dates of birth, spouse's names, and beneficiaries if statements shifted. Upon discovering the incident, the company promptly notified affected individuals, apologized, explained the incident, and offered a free one-year credit monitoring service. They also advised members to take harm-reducing steps and ceased using the problematic envelopes. The company informed the OPC about the incident and its response. The OPC concluded that the company demonstrated best practices in its incident response.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #5: Life insurance company employs best practices in responding to mass mailing error that risked exposing personal information - March 21, 2014

Mar 21, 2014Incident Summary #5
Adjudicator: Chantal Bernier
Plain-Language Summary

A life insurance company discovered that a mass mailing error risked exposing the personal information of 53 pension plan members. The new window envelopes used were larger, potentially revealing certificate numbers, SINs, dates of birth, spouse's names, and beneficiaries if statements shifted. Upon discovering the incident, the company promptly notified affected individuals, apologized, explained the incident, and offered a free one-year credit monitoring service. They also advised members to take harm-reducing steps and ceased using the problematic envelopes. The company informed the OPC about the incident and its response. The OPC concluded that the company demonstrated best practices in its incident response.

Key Issues
  • Whether a mass mailing error led to the potential exposure of personal information
  • Whether the life insurance company's response to the incident constituted best practices
Federal (Canada)Privacy ActNo jurisdiction
Federal (Canada) flag
Mar 4, 2014Indexed Jun 30, 2026

Retroactive removal of Privacy Act provisions leaves gun registry complainant with no recourse - 2015

Royal Canadian Mounted Police (RCMP)

The complainant alleged that the RCMP continued to retain and use personal information from the national long-gun registry, which should have been destroyed under the Ending the Long-Gun Registry Act. Specific allegations included a High River RCMP member's statement about locating firearms and an email from a Langley RCMP member referring to non-restricted firearm registration. The RCMP stated that electronic records were destroyed in October 2012 and hard copies by December 2013 (except for Quebec records). They also argued that information extracted from the registry before its destruction and retained in case files could be used consistent with its original purpose. The OPC found no evidence of contravention, noting that recent legislative amendments retroactively excluded the application of the Privacy Act to certain long-gun registry records, preventing further investigation into specific examples.

Quick view

Privacy ActNo jurisdiction

Retroactive removal of Privacy Act provisions leaves gun registry complainant with no recourse - 2015

Mar 4, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The complainant alleged that the RCMP continued to retain and use personal information from the national long-gun registry, which should have been destroyed under the Ending the Long-Gun Registry Act. Specific allegations included a High River RCMP member's statement about locating firearms and an email from a Langley RCMP member referring to non-restricted firearm registration. The RCMP stated that electronic records were destroyed in October 2012 and hard copies by December 2013 (except for Quebec records). They also argued that information extracted from the registry before its destruction and retained in case files could be used consistent with its original purpose. The OPC found no evidence of contravention, noting that recent legislative amendments retroactively excluded the application of the Privacy Act to certain long-gun registry records, preventing further investigation into specific examples.

Key Issues
  • Whether the RCMP continued to retain and use personal information from the national long-gun registry after it was required to be destroyed
  • Whether the High River RCMP used personal information from the long-gun registry in June 2013
  • Whether other RCMP detachments continued to use personal information from the long-gun registry after electronic records were destroyed in October 2012
  • Whether copies of the long-gun registry containing personal information still exist in the possession of the RCMP or other police services
  • Whether the use of personal information from the long-gun registry, retained in case files prior to the Ending the Long-gun Registry Act, is consistent with section 7 of the Privacy Act
  • Whether the retroactive exclusion of the Privacy Act by Bill C-59 affects the investigation
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 20, 2014Early resolved case summary #10Indexed Jun 30, 2026

Early resolved case summary #10: Bank improves its credit card account verification practices after challenge from customer - February 20, 2014

A financial institution

An individual complained that her bank required the last six digits of her Social Insurance Number (SIN) to set up a "verified credit account" for online purchases. She believed this practice was inappropriate and that an alternative method not requiring SIN information should be available. The bank initially stated an alternative existed through commercial websites, but the complainant noted this was not clearly communicated. The OPC highlighted a comparable case where a lack of transparency regarding authentication alternatives was found. Following this, the bank decided to discontinue the SIN-based authentication method entirely and update its website. The complainant was satisfied with this resolution, and the OPC confirmed the website changes.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Early resolved case summary #10: Bank improves its credit card account verification practices after challenge from customer - February 20, 2014

Feb 20, 2014Early resolved case summary #10
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that her bank required the last six digits of her Social Insurance Number (SIN) to set up a "verified credit account" for online purchases. She believed this practice was inappropriate and that an alternative method not requiring SIN information should be available. The bank initially stated an alternative existed through commercial websites, but the complainant noted this was not clearly communicated. The OPC highlighted a comparable case where a lack of transparency regarding authentication alternatives was found. Following this, the bank decided to discontinue the SIN-based authentication method entirely and update its website. The complainant was satisfied with this resolution, and the OPC confirmed the website changes.

Key Issues
  • Whether collecting a partial SIN for credit card account verification was appropriate under PIPEDA
  • Whether the bank provided adequate transparency regarding alternative verification methods
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Feb 10, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-012Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-012: Investment Firm Justified in its Collection of "Know Your Client" Information

An investment firm

A customer complained that his investment firm required an unreasonable amount of personal information on its "Know Your Client" (KYC) form as a condition for maintaining his Tax Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP). The firm requested details such as investment experience, annual income, spouse's income, dependents, assets, liabilities, and net worth. The firm argued this information was necessary to comply with the Investment Industry Regulatory Organization of Canada (IIROC) KYC and suitability requirements. The OPC assessed whether the firm contravened PIPEDA Principle 4.3.3 by requiring consent for information beyond explicitly specified and legitimate purposes. The OPC found that the firm had explicitly specified its purposes, which were legitimate given IIROC's regulatory framework. The OPC also concluded that the requested information, including details beyond IIROC's standard Form 2, was necessary for the firm to meet its regulatory obligations. Therefore, the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Commissioner’s Findings - PIPEDA Report of Findings #2014-012: Investment Firm Justified in its Collection of "Know Your Client" Information

Feb 10, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-012
Adjudicator: Chantal Bernier
Plain-Language Summary

A customer complained that his investment firm required an unreasonable amount of personal information on its "Know Your Client" (KYC) form as a condition for maintaining his Tax Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP). The firm requested details such as investment experience, annual income, spouse's income, dependents, assets, liabilities, and net worth. The firm argued this information was necessary to comply with the Investment Industry Regulatory Organization of Canada (IIROC) KYC and suitability requirements. The OPC assessed whether the firm contravened PIPEDA Principle 4.3.3 by requiring consent for information beyond explicitly specified and legitimate purposes. The OPC found that the firm had explicitly specified its purposes, which were legitimate given IIROC's regulatory framework. The OPC also concluded that the requested information, including details beyond IIROC's standard Form 2, was necessary for the firm to meet its regulatory obligations. Therefore, the complaint was not well-founded.

Key Issues
  • Whether the investment firm explicitly specified the purposes for collecting personal information under Principle 4.2 PIPEDA
  • Whether the purposes for collecting personal information were legitimate under subsection 5(3) PIPEDA
  • Whether the investment firm required more personal information than necessary to achieve the legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA
  • Whether the collection of personal information was limited to that which was necessary for the identified purposes under Principle 4.4 PIPEDA
  • Whether information on investment experience was necessary to validate investment knowledge and assess risk tolerance
  • Whether spouse's or partner's annual income was necessary to assess overall financial position and suitability
  • Whether detailed assets and liabilities were necessary to establish net worth and understand financial situation
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jan 23, 2014Early resolved case summary #5Indexed Jun 30, 2026

Early resolved case summary #5: Web posting that was removed by individual retained by Internet search engine - January 23, 2014

An Internet search engine

An individual posted her résumé on a job website, which included her address. After having the job website remove the information, she discovered her résumé was still searchable via an Internet search engine. The individual contacted the search engine's Web administrator multiple times to request removal of her personal information, but the search engine did not comply. She then filed a complaint with the OPC. The OPC intervened directly with the search engine, which subsequently removed the cached copy of the individual's information from its search results using its URL removal tool. The complainant was satisfied with the outcome, and the complaint was closed.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #5: Web posting that was removed by individual retained by Internet search engine - January 23, 2014

Jan 23, 2014Early resolved case summary #5
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual posted her résumé on a job website, which included her address. After having the job website remove the information, she discovered her résumé was still searchable via an Internet search engine. The individual contacted the search engine's Web administrator multiple times to request removal of her personal information, but the search engine did not comply. She then filed a complaint with the OPC. The OPC intervened directly with the search engine, which subsequently removed the cached copy of the individual's information from its search results using its URL removal tool. The complainant was satisfied with the outcome, and the complaint was closed.

Key Issues
  • Whether an Internet search engine was obligated to remove cached personal information after the original source was deleted
  • Whether the search engine's refusal to remove the information constituted a contravention of PIPEDA