The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

1,631 decisions in the archive
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Concern raised over online disclosure - The Qalipu Mi’kmaq First Nation Band

Aboriginal Affairs and Northern Development Canada (AANDC)

A woman complained to the OPC that Aboriginal Affairs and Northern Development Canada (AANDC) was putting her at risk of identity theft by publishing her full name and date of birth in the Canada Gazette, which is available online. This information was published as part of the enrollment process for the Qalipu Mi’kmaq First Nation Band. The OPC investigated whether this disclosure was consistent with the Privacy Act. The OPC determined that the disclosure was for the purpose for which the information was originally collected, which was for the identification and recognition of Band members. Therefore, the disclosure was permissible under the Privacy Act without the individual's consent. The complaint was found to be not well-founded, but the OPC recommended AANDC explore future options to mitigate identity theft risks.

Quick view

Privacy ActNot well-founded

Concern raised over online disclosure - The Qalipu Mi’kmaq First Nation Band

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained to the OPC that Aboriginal Affairs and Northern Development Canada (AANDC) was putting her at risk of identity theft by publishing her full name and date of birth in the Canada Gazette, which is available online. This information was published as part of the enrollment process for the Qalipu Mi’kmaq First Nation Band. The OPC investigated whether this disclosure was consistent with the Privacy Act. The OPC determined that the disclosure was for the purpose for which the information was originally collected, which was for the identification and recognition of Band members. Therefore, the disclosure was permissible under the Privacy Act without the individual's consent. The complaint was found to be not well-founded, but the OPC recommended AANDC explore future options to mitigate identity theft risks.

Key Issues
  • Whether the disclosure of full name and date of birth in the Canada Gazette was consistent with the Privacy Act
  • Whether personal information can be disclosed without consent when it is for the purpose for which it was originally collected
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Canada Revenue Agency employee accesses tax file without authorization

Canada Revenue Agency (CRA)

A complainant alleged that the Canada Revenue Agency (CRA) contravened the Privacy Act when an employee accessed his tax file without authorization in 2005 and 2006. The complainant became suspicious after community members showed knowledge of his financial information. An audit trail report revealed that a CRA employee had accessed his T1 tax account twice, viewing sensitive personal information including his Social Insurance Number, income, and family details. The OPC's investigation confirmed that the employee accessed the account without authorization and beyond the scope of their duties. The complaint was found to be well-founded, and CRA confirmed the employee no longer has access to taxpayer information.

Quick view

Privacy ActWell-founded

Canada Revenue Agency employee accesses tax file without authorization

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that the Canada Revenue Agency (CRA) contravened the Privacy Act when an employee accessed his tax file without authorization in 2005 and 2006. The complainant became suspicious after community members showed knowledge of his financial information. An audit trail report revealed that a CRA employee had accessed his T1 tax account twice, viewing sensitive personal information including his Social Insurance Number, income, and family details. The OPC's investigation confirmed that the employee accessed the account without authorization and beyond the scope of their duties. The complaint was found to be well-founded, and CRA confirmed the employee no longer has access to taxpayer information.

Key Issues
  • Whether a CRA employee accessed the complainant's tax file without authorization
  • Whether the unauthorized access contravened the use and disclosure provisions of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Estranged wife accessed husband’s medical records

National Defence (DND)

A sergeant complained that his estranged wife, a civilian employee at a Canadian Forces Base, had unauthorized access to his military health records. The sergeant provided an audit log showing his wife accessed his Canadian Forces Health Information Services (CFHIS) account and deleted a physiotherapy appointment. National Defence (DND) confirmed the unauthorized access and noted she also accessed a paper physiotherapy file. DND determined she willfully breached departmental rules and implemented system restrictions to bar her access. The OPC found the access and use of medical information inconsistent with its original purpose and not a permissible use under the Privacy Act, upholding the complaint as well-founded. DND has since implemented new CFHIS controls and is evaluating its systems and practices for health information.

Quick view

Privacy ActWell-founded

Estranged wife accessed husband’s medical records

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A sergeant complained that his estranged wife, a civilian employee at a Canadian Forces Base, had unauthorized access to his military health records. The sergeant provided an audit log showing his wife accessed his Canadian Forces Health Information Services (CFHIS) account and deleted a physiotherapy appointment. National Defence (DND) confirmed the unauthorized access and noted she also accessed a paper physiotherapy file. DND determined she willfully breached departmental rules and implemented system restrictions to bar her access. The OPC found the access and use of medical information inconsistent with its original purpose and not a permissible use under the Privacy Act, upholding the complaint as well-founded. DND has since implemented new CFHIS controls and is evaluating its systems and practices for health information.

Key Issues
  • Whether the estranged wife's access to the sergeant's medical records was authorized
  • Whether the access and use of medical information was consistent with the purpose for which it was originally intended
  • Whether the access and use met permissible uses defined in the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

National Defence employee accesses someone’s personal health records for her own personal reasons

National Defence

A complainant alleged that a Canadian Forces (CF) employee, with whom he had a prior personal relationship, inappropriately accessed his personal health information. The investigation found that the employee accessed the complainant’s health information in the Canadian Forces Health Information System (CFHIS) multiple times after receiving an anonymous message about the complainant's health. The employee admitted to accessing and using the information for personal reasons, which was inconsistent with the purpose for its collection. The complaint was found to be well-founded. As a result, National Defence acknowledged the importance of privacy awareness and training, implemented new controls in CFHIS, updated its health service policy, and provided training to CF healthcare staff.

Quick view

Privacy ActWell-founded

National Defence employee accesses someone’s personal health records for her own personal reasons

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a Canadian Forces (CF) employee, with whom he had a prior personal relationship, inappropriately accessed his personal health information. The investigation found that the employee accessed the complainant’s health information in the Canadian Forces Health Information System (CFHIS) multiple times after receiving an anonymous message about the complainant's health. The employee admitted to accessing and using the information for personal reasons, which was inconsistent with the purpose for its collection. The complaint was found to be well-founded. As a result, National Defence acknowledged the importance of privacy awareness and training, implemented new controls in CFHIS, updated its health service policy, and provided training to CF healthcare staff.

Key Issues
  • Whether a National Defence employee inappropriately accessed personal health information for personal reasons
  • Whether the access was inconsistent with the purpose for which the information was collected
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 2, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-005Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-005: Beneficiary’s access to estate information is limited to his own personal information under PIPEDA

A legal firm

An individual, claiming to be a beneficiary of two estates, sought access under PIPEDA to estate information from a legal firm that had acted as an agent for another firm administering the estates. The complainant requested information pertaining to himself as a beneficiary and general beneficiary entitlements. The legal firm initially failed to respond to the access requests, leading to a complaint with the OPC. The firm later responded, stating it held no personal information about the complainant and that neither he nor the estates were clients. The OPC found that the firm contravened PIPEDA by not responding within the 30-day time limit. However, the OPC also determined that the complainant was only entitled to access information specifically about himself, not general estate information, and was satisfied that the firm had conducted a reasonable search for his personal information. The complaint was deemed well-founded and resolved due to the firm's initial failure to respond.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-005: Beneficiary’s access to estate information is limited to his own personal information under PIPEDA

Oct 2, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-005
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual, claiming to be a beneficiary of two estates, sought access under PIPEDA to estate information from a legal firm that had acted as an agent for another firm administering the estates. The complainant requested information pertaining to himself as a beneficiary and general beneficiary entitlements. The legal firm initially failed to respond to the access requests, leading to a complaint with the OPC. The firm later responded, stating it held no personal information about the complainant and that neither he nor the estates were clients. The OPC found that the firm contravened PIPEDA by not responding within the 30-day time limit. However, the OPC also determined that the complainant was only entitled to access information specifically about himself, not general estate information, and was satisfied that the firm had conducted a reasonable search for his personal information. The complaint was deemed well-founded and resolved due to the firm's initial failure to respond.

Key Issues
  • Whether a legal firm must respond to an access request within 30 days, even if it holds no personal information about the requester
  • Whether a beneficiary of an estate is entitled under PIPEDA to access general estate information
  • Whether the requested information (e.g., statements of accounts, money received, disbursements) constitutes the complainant's personal information under PIPEDA
  • Whether the legal firm conducted a reasonable search for the complainant's personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActDeclined to investigate
Federal (Canada) flag
Sep 11, 2013Declined to Investigate Case Summary #2013-001Indexed Jun 30, 2026

Declined to Investigate Case Summary #2013-001: Court procedures provided a more appropriate means to address access issues in ongoing litigation between complainant and retailer

A retailer

An individual filed a complaint against a retailer, alleging that the retailer withheld access to her personal information, contravening subsection 8(3) and Principle 4.9 of PIPEDA. The complainant and retailer were involved in ongoing small claims court litigation, and the complainant stated the information was necessary for her case. The retailer refused access, citing litigation privilege and prior disclosure. The OPC declined to investigate the complaint, finding that the court's procedures provided a more appropriate means for the complainant to address the access issues. This decision was based on avoiding conflict with provincial court rules and ensuring judicious use of public resources.

Quick view

Personal Information Protection and Electronic Documents ActDeclined to investigate

Declined to Investigate Case Summary #2013-001: Court procedures provided a more appropriate means to address access issues in ongoing litigation between complainant and retailer

Sep 11, 2013Declined to Investigate Case Summary #2013-001
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual filed a complaint against a retailer, alleging that the retailer withheld access to her personal information, contravening subsection 8(3) and Principle 4.9 of PIPEDA. The complainant and retailer were involved in ongoing small claims court litigation, and the complainant stated the information was necessary for her case. The retailer refused access, citing litigation privilege and prior disclosure. The OPC declined to investigate the complaint, finding that the court's procedures provided a more appropriate means for the complainant to address the access issues. This decision was based on avoiding conflict with provincial court rules and ensuring judicious use of public resources.

Key Issues
  • Whether the complaint could more appropriately be dealt with by means of a procedure provided for under the laws of a province under paragraph 12(1)(b) of PIPEDA
  • Whether the retailer withheld access to personal information in contravention of subsection 8(3) of PIPEDA
  • Whether the retailer withheld access to personal information in contravention of Principle 4.9 of Schedule 1 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 11, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-003Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-003: Profiles on PositiveSingles.com dating website turn up on other affiliated dating websites

SuccessfulMatch Inc. (operating PositiveSingles.com)

Three individuals complained that their dating profiles, containing sensitive medical information, posted on PositiveSingles.com appeared on numerous other affiliated dating websites without their knowledge or consent. The complainants were assured of privacy but found their profiles on sites targeting different demographics, causing distress. The OPC's investigation found that PositiveSingles.com, operated by SuccessfulMatch Inc., used a single database across a network of affiliated sites, making profiles automatically available. The OPC concluded that the organization failed to obtain meaningful consent for this use, lacked openness about its network structure, and had inadequate safeguards, as some personal information was accessible via search engines. Following the OPC's recommendations, SuccessfulMatch revamped its website to provide explicit information about the network, ensure informed consent at registration, and improve safeguards. The complaint was found well-founded and resolved due to these corrective measures.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-003: Profiles on PositiveSingles.com dating website turn up on other affiliated dating websites

Jul 11, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-003
Adjudicator: Jennifer Stoddart
Plain-Language Summary

Three individuals complained that their dating profiles, containing sensitive medical information, posted on PositiveSingles.com appeared on numerous other affiliated dating websites without their knowledge or consent. The complainants were assured of privacy but found their profiles on sites targeting different demographics, causing distress. The OPC's investigation found that PositiveSingles.com, operated by SuccessfulMatch Inc., used a single database across a network of affiliated sites, making profiles automatically available. The OPC concluded that the organization failed to obtain meaningful consent for this use, lacked openness about its network structure, and had inadequate safeguards, as some personal information was accessible via search engines. Following the OPC's recommendations, SuccessfulMatch revamped its website to provide explicit information about the network, ensure informed consent at registration, and improve safeguards. The complaint was found well-founded and resolved due to these corrective measures.

Key Issues
  • Whether PositiveSingles.com obtained meaningful consent for the use of personal information across its network of affiliated sites (Principle 4.3, 4.3.2, 4.3.5 PIPEDA)
  • Whether PositiveSingles.com was sufficiently open about its personal information management policies and practices, particularly regarding its network structure (Principle 4.8, 4.8.1 PIPEDA)
  • Whether PositiveSingles.com implemented adequate security safeguards to protect sensitive personal information from unauthorized access (Principle 4.7, 4.7.1 PIPEDA)
  • Whether PositiveSingles.com's use of cookies, potentially for online behavioral advertising, required express consent given the sensitive nature of the information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 28, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-017Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-017: Apple called upon to provide greater clarity on its use and disclosure of unique device identifiers for targeted advertising

Apple

An individual complained that Apple was using and sharing her unique device identifier (UDID) without her knowledge and consent for tracking and targeted advertising. The OPC determined that UDIDs, and later Advertising IDs (Ad IDs), constituted personal information because Apple could link them to identifiable individuals. While Apple's use of UDIDs for administrative purposes was deemed to have implied consent, the OPC initially found Apple's explanations for using and disclosing UDIDs for targeted advertising to be insufficient for meaningful consent. During the investigation, Apple phased out the use of UDIDs for advertising, introduced the resettable Ad ID, and improved its privacy policy explanations and opt-out mechanisms. Consequently, the OPC found that Apple's updated practices provided sufficient information for meaningful consent regarding the use and disclosure of Ad IDs for advertising. The complaint was found to be well-founded but resolved due to Apple's corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-017: Apple called upon to provide greater clarity on its use and disclosure of unique device identifiers for targeted advertising

Jun 28, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-017
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Apple was using and sharing her unique device identifier (UDID) without her knowledge and consent for tracking and targeted advertising. The OPC determined that UDIDs, and later Advertising IDs (Ad IDs), constituted personal information because Apple could link them to identifiable individuals. While Apple's use of UDIDs for administrative purposes was deemed to have implied consent, the OPC initially found Apple's explanations for using and disclosing UDIDs for targeted advertising to be insufficient for meaningful consent. During the investigation, Apple phased out the use of UDIDs for advertising, introduced the resettable Ad ID, and improved its privacy policy explanations and opt-out mechanisms. Consequently, the OPC found that Apple's updated practices provided sufficient information for meaningful consent regarding the use and disclosure of Ad IDs for advertising. The complaint was found to be well-founded but resolved due to Apple's corrective actions.

Key Issues
  • Whether Unique Device Identifiers (UDID) constitute personal information under PIPEDA.
  • Whether Advertising Identifiers (Ad ID) constitute personal information under PIPEDA.
  • Whether Apple obtained meaningful consent for its use of UDID for administration and maintenance purposes (Principle 4.3 PIPEDA).
  • Whether Apple obtained meaningful consent for its use of UDID and Ad ID for targeted advertising purposes (Principle 4.3 PIPEDA).
  • Whether Apple obtained meaningful consent for its disclosure of UDID and Ad ID to third-party app developers (Principle 4.3 PIPEDA).
  • Whether Apple's explanations regarding the use and disclosure of UDID and Ad ID were sufficiently clear and understandable to ensure meaningful consent (Principle 4.3.2 PIPEDA).
  • Whether the sensitivity of UDID and Ad ID in the context of user profiling and online behavioural advertising required express consent (Principle 4.3.6 PIPEDA).
  • Whether the reasonable expectations of the individual were met regarding the use and disclosure of UDID and Ad ID (Principle 4.3.5 PIPEDA).
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 25, 2013Early resolved case summary #2013-01Indexed Jun 30, 2026

Early resolved case summary #2013-01: Property management company alters its rental application form to make clear that Social Insurance Number is optional

A property management company

An individual complained that a property management company was over-collecting personal information on rental application forms, specifically requesting Social Insurance Numbers (SINs), driver's licence information, and banking details as a condition of application. The complainant also noted the absence of a privacy policy on the company's website. The OPC contacted the company, which stated its website was under construction and would include a privacy policy. The company used third-party generated forms and believed SINs were necessary for credit checks, a point the OPC disputed. The OPC suggested marking SIN requests as 'optional' and advised against collecting unique driver's licence numbers. The company committed to updating its forms and website, satisfying the complainant. The OPC later confirmed these changes were implemented.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Early resolved case summary #2013-01: Property management company alters its rental application form to make clear that Social Insurance Number is optional

Apr 25, 2013Early resolved case summary #2013-01
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a property management company was over-collecting personal information on rental application forms, specifically requesting Social Insurance Numbers (SINs), driver's licence information, and banking details as a condition of application. The complainant also noted the absence of a privacy policy on the company's website. The OPC contacted the company, which stated its website was under construction and would include a privacy policy. The company used third-party generated forms and believed SINs were necessary for credit checks, a point the OPC disputed. The OPC suggested marking SIN requests as 'optional' and advised against collecting unique driver's licence numbers. The company committed to updating its forms and website, satisfying the complainant. The OPC later confirmed these changes were implemented.

Key Issues
  • Whether the collection of Social Insurance Numbers (SINs) was appropriate
  • Whether the collection of driver's licence numbers was appropriate
  • Whether the collection of banking information was appropriate
  • Whether the organization made its privacy policy readily available as required by PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 15, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-002Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-002: Bank misinformed client of purpose of requesting personal information for picking up credit card

A Canadian bank

A bank customer complained after being asked to provide his driver's license to pick up a replacement credit card, despite having other identification on file and being known to staff. The bank initially cited anti-money laundering regulations (PCMLTFA) but later admitted this rationale was incorrect. The OPC investigated two issues: whether the bank improperly demanded to record information (collection) and whether it could explain the purpose of collection. Since the customer refused to provide his driver's license, no actual collection occurred, so that aspect of the complaint was not well-founded. However, the bank's inaccurate explanation for requesting the information contravened Principle 4.2.5. The bank revised its procedures and circulated new guidelines to staff, leading to a well-founded and resolved outcome for the latter issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-002: Bank misinformed client of purpose of requesting personal information for picking up credit card

Apr 15, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-002
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A bank customer complained after being asked to provide his driver's license to pick up a replacement credit card, despite having other identification on file and being known to staff. The bank initially cited anti-money laundering regulations (PCMLTFA) but later admitted this rationale was incorrect. The OPC investigated two issues: whether the bank improperly demanded to record information (collection) and whether it could explain the purpose of collection. Since the customer refused to provide his driver's license, no actual collection occurred, so that aspect of the complaint was not well-founded. However, the bank's inaccurate explanation for requesting the information contravened Principle 4.2.5. The bank revised its procedures and circulated new guidelines to staff, leading to a well-founded and resolved outcome for the latter issue.

Key Issues
  • Whether the bank limited its collection of personal information to that which was necessary for the purposes identified by the organization (Principle 4.4 PIPEDA)
  • Whether the bank ensured its employees were able to explain the purposes for which personal information was being collected (Principle 4.2.5 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Oct 31, 2012Early resolved case summary #2Indexed Jun 30, 2026

Early resolved case summary #2: Telecommunications firm discloses individual’s personal information without consent when it merged two household accounts that shared an address

A telecommunications firm

A landlord complained that a telecommunications firm disclosed his personal account information, including debt details, to his tenant without consent. The firm had merged the landlord's existing account with the tenant's new account because they shared the same address. This led to the firm demanding payment from the tenant for services he had not ordered and disclosing the landlord's information during collection attempts. The tenant then confronted the landlord, accusing him of debt evasion and threatening to vacate. The landlord filed a complaint with the OPC, alleging unauthorized disclosure of his personal information.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2: Telecommunications firm discloses individual’s personal information without consent when it merged two household accounts that shared an address

Oct 31, 2012Early resolved case summary #2
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A landlord complained that a telecommunications firm disclosed his personal account information, including debt details, to his tenant without consent. The firm had merged the landlord's existing account with the tenant's new account because they shared the same address. This led to the firm demanding payment from the tenant for services he had not ordered and disclosing the landlord's information during collection attempts. The tenant then confronted the landlord, accusing him of debt evasion and threatening to vacate. The landlord filed a complaint with the OPC, alleging unauthorized disclosure of his personal information.

Key Issues
  • Whether the telecommunications firm disclosed the landlord's personal information without consent
  • Whether the firm was responsible for merging the accounts and the subsequent unauthorized disclosure
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

Veterans Affairs Improperly Reveals Severity of Disability - Twice

Veterans Affairs Canada

A Canadian Forces member complained that Veterans Affairs Canada (VAC) improperly disclosed the exact percentage of his disability pension to the Department of National Defence (DND) without his consent. This was the second such complaint from the same individual, with a similar complaint in 2008 having been found well-founded. The OPC's investigation found that an agreement between VAC and DND limited information sharing to five specific pieces of information, none of which included the disability percentage. VAC argued the disclosure was in the public interest under subsections 8(2)(m)(i) and 8(2)(m)(ii) of the Privacy Act, but the OPC found no evidence that the disclosure was deliberate or necessary for the complainant's treatment. The disclosure appeared to be an accidental forwarding of an internal email chain. The OPC found the complaint well-founded and made recommendations to VAC.

Quick view

Privacy ActWell-founded

Veterans Affairs Improperly Reveals Severity of Disability - Twice

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A Canadian Forces member complained that Veterans Affairs Canada (VAC) improperly disclosed the exact percentage of his disability pension to the Department of National Defence (DND) without his consent. This was the second such complaint from the same individual, with a similar complaint in 2008 having been found well-founded. The OPC's investigation found that an agreement between VAC and DND limited information sharing to five specific pieces of information, none of which included the disability percentage. VAC argued the disclosure was in the public interest under subsections 8(2)(m)(i) and 8(2)(m)(ii) of the Privacy Act, but the OPC found no evidence that the disclosure was deliberate or necessary for the complainant's treatment. The disclosure appeared to be an accidental forwarding of an internal email chain. The OPC found the complaint well-founded and made recommendations to VAC.

Key Issues
  • Whether Veterans Affairs Canada disclosed personal information (disability pension percentage) to the Department of National Defence without consent
  • Whether the disclosure was in accordance with the information-sharing agreement between VAC and DND
  • Whether the disclosure was useful or necessary to facilitate the complainant's medical treatment
  • Whether the disclosure qualified under the "public interest" provisions of subsections 8(2)(m)(i) and 8(2)(m)(ii) of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

Copying Google Result is Collecting Personal Information

Veterans Affairs Canada

An individual complained that Veterans Affairs Canada improperly collected his personal information. The individual had contacted Veterans Affairs and the National Capital Commission regarding a monument. Subsequently, a Veterans Affairs official searched the individual's email address on Google, finding a discussion page with personal information. The official then emailed the URL of this page to the entire email thread, stating the individual's email was "public domain." The OPC found that Veterans Affairs did not have a demonstrable need to collect the URL linking to the personal information. The collection of this URL was deemed a violation of the Privacy Act, as collected personal information must relate directly to an operating program or activity. The complaint was well-founded, and Veterans Affairs apologized and deleted the email from its systems.

Quick view

Privacy ActWell-founded

Copying Google Result is Collecting Personal Information

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Veterans Affairs Canada improperly collected his personal information. The individual had contacted Veterans Affairs and the National Capital Commission regarding a monument. Subsequently, a Veterans Affairs official searched the individual's email address on Google, finding a discussion page with personal information. The official then emailed the URL of this page to the entire email thread, stating the individual's email was "public domain." The OPC found that Veterans Affairs did not have a demonstrable need to collect the URL linking to the personal information. The collection of this URL was deemed a violation of the Privacy Act, as collected personal information must relate directly to an operating program or activity. The complaint was well-founded, and Veterans Affairs apologized and deleted the email from its systems.

Key Issues
  • Whether the collection of a URL linking to publicly available personal information constitutes collection under the Privacy Act
  • Whether the collected personal information related directly to an operating program or activity of Veterans Affairs Canada under section 4 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

Canada Revenue Agency gave personal information to a third party without consent

Canada Revenue Agency

A woman complained that the Canada Revenue Agency (CRA) disclosed her personal information to a third party without her consent. The complainant, who had not updated her family name in the CRA system, was applying for an adjustment. A CRA employee, attempting to locate her in the system, sent a letter containing the complainant's Social Insurance Number and other personal information to her niece, who shared a similar name and address. The OPC found that this disclosure was due to human error, as the employee failed to follow established procedures for verifying addresses. The CRA acknowledged its mistake and implemented measures to prevent similar incidents. The complaint was found to be well-founded.

Quick view

Privacy ActWell-founded

Canada Revenue Agency gave personal information to a third party without consent

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained that the Canada Revenue Agency (CRA) disclosed her personal information to a third party without her consent. The complainant, who had not updated her family name in the CRA system, was applying for an adjustment. A CRA employee, attempting to locate her in the system, sent a letter containing the complainant's Social Insurance Number and other personal information to her niece, who shared a similar name and address. The OPC found that this disclosure was due to human error, as the employee failed to follow established procedures for verifying addresses. The CRA acknowledged its mistake and implemented measures to prevent similar incidents. The complaint was found to be well-founded.

Key Issues
  • Whether the Canada Revenue Agency disclosed personal information without consent
  • Whether the disclosure was due to human error and failure to follow procedures
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

RCMP Names Murder Suspect at Community Meeting

Royal Canadian Mounted Police (RCMP)

An individual complained that an RCMP staff sergeant inappropriately disclosed personal information about him at a community meeting. The sergeant, invited to discuss a decade-old murder case, named the complainant as a "person of interest" and stated he had declined a polygraph test. The complainant alleged he was not fully informed about the subject matter of the discussion. The RCMP presumed consent based on the complainant's attendance and assurances from community group representatives. The OPC found that the RCMP had a responsibility to actively obtain consent for the disclosure, rather than presuming it. The complaint was upheld as well-founded.

Quick view

Privacy ActWell-founded

RCMP Names Murder Suspect at Community Meeting

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that an RCMP staff sergeant inappropriately disclosed personal information about him at a community meeting. The sergeant, invited to discuss a decade-old murder case, named the complainant as a "person of interest" and stated he had declined a polygraph test. The complainant alleged he was not fully informed about the subject matter of the discussion. The RCMP presumed consent based on the complainant's attendance and assurances from community group representatives. The OPC found that the RCMP had a responsibility to actively obtain consent for the disclosure, rather than presuming it. The complaint was upheld as well-founded.

Key Issues
  • Whether the RCMP inappropriately disclosed personal information about the complainant at a community meeting
  • Whether the RCMP obtained valid consent for the disclosure of personal information