The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

1,639 decisions in the archive
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 22, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-004Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account

A cellular-telephone service provider

An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account

Aug 22, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-004
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.

Key Issues
  • Whether the cellular service provider disclosed personal information without consent to an imposter, contravening Principle 4.3 PIPEDA
  • Whether the cellular service provider adequately responded to the complainant's access request for personal information under Principle 4.9 PIPEDA
  • Whether the cellular service provider responded to the access request within the 30-day timeframe as per s.8(3) PIPEDA
  • Whether the redaction of the CSR's name from the transcript was permissible under s.9(1) PIPEDA
  • Whether the company was required to provide an audio recording of the conversation in addition to a transcript under s.10 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 14, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-010Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings # 2012-010: Telecommunications firm adopts additional accountability measures to ensure a consistent approach in handling access requests

A telecommunications firm

A complainant alleged that a telecommunications firm failed to provide her with access to her personal information, specifically notes and transcripts of recorded conversations related to an account dispute. The firm acknowledged receiving the access request but mistakenly believed it was not necessary to provide the information due to ongoing settlement negotiations. The OPC found that the firm failed to respond to the access request within 30 days and did not issue an extension notice, thus contravening PIPEDA subsections 8(3), 8(4), and 8(5). Furthermore, the firm purged the requested audio records, violating subsection 8(8) and Principles 4.9 and 4.9.4. The firm's internal policies were found to be unclear and staff training inadequate, leading to the erroneous deletion of records. The OPC made several recommendations, which the firm accepted and implemented, including amending policies and providing staff training. As a result, the complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings # 2012-010: Telecommunications firm adopts additional accountability measures to ensure a consistent approach in handling access requests

Aug 14, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a telecommunications firm failed to provide her with access to her personal information, specifically notes and transcripts of recorded conversations related to an account dispute. The firm acknowledged receiving the access request but mistakenly believed it was not necessary to provide the information due to ongoing settlement negotiations. The OPC found that the firm failed to respond to the access request within 30 days and did not issue an extension notice, thus contravening PIPEDA subsections 8(3), 8(4), and 8(5). Furthermore, the firm purged the requested audio records, violating subsection 8(8) and Principles 4.9 and 4.9.4. The firm's internal policies were found to be unclear and staff training inadequate, leading to the erroneous deletion of records. The OPC made several recommendations, which the firm accepted and implemented, including amending policies and providing staff training. As a result, the complaint was deemed well-founded and resolved.

Key Issues
  • Whether the telecommunications firm responded to the access request within the 30-day time limit under subsection 8(3) PIPEDA
  • Whether the telecommunications firm issued a notice of extension for the access request under subsection 8(4) PIPEDA
  • Whether the telecommunications firm was deemed to have refused the access request under subsection 8(5) PIPEDA
  • Whether the telecommunications firm provided access to personal information as required by Principle 4.9 PIPEDA
  • Whether the telecommunications firm responded to the access request within a reasonable time and at minimal or no cost under Principle 4.9.4 PIPEDA
  • Whether the telecommunications firm retained personal information that was the subject of an access request for as long as necessary to allow the individual to exhaust any recourse under subsection 8(8) PIPEDA
  • Whether the telecommunications firm implemented policies and practices to give effect to the principles, including training staff and communicating policies and practices under Principle 4.1.4(c) PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Errant report sparks procedural changes at prison

Correctional Service of Canada

Two prisoners at the Correctional Service of Canada’s Grande Cache Institution filed complaints after a prison report containing their personal information was found among a fellow inmate's personal effects. An investigation revealed that a contract worker had printed the report, which listed personal information of all inmates, and given it to a welding instructor. The report was later discovered in an offender's belongings, though it was unclear how it got there. Correctional Service officials acknowledged the privacy breach and implemented several corrective measures, including restricting the printing of such reports and reinforcing training on safeguarding personal information. The OPC's investigation confirmed a breach of the complainants' privacy rights. Due to the corrective actions already taken, the OPC did not require further action.

Quick view

Privacy ActWell-founded

Errant report sparks procedural changes at prison

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

Two prisoners at the Correctional Service of Canada’s Grande Cache Institution filed complaints after a prison report containing their personal information was found among a fellow inmate's personal effects. An investigation revealed that a contract worker had printed the report, which listed personal information of all inmates, and given it to a welding instructor. The report was later discovered in an offender's belongings, though it was unclear how it got there. Correctional Service officials acknowledged the privacy breach and implemented several corrective measures, including restricting the printing of such reports and reinforcing training on safeguarding personal information. The OPC's investigation confirmed a breach of the complainants' privacy rights. Due to the corrective actions already taken, the OPC did not require further action.

Key Issues
  • Whether the personal information of inmates was inappropriately disclosed
  • Whether the Correctional Service of Canada adequately safeguarded personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Psychiatric nurse forgets ex-inmate’s treatment file on bus

Correctional Service of Canada (Keele Community Correctional Centre)

A former inmate at Toronto's Keele Community Correctional Centre complained after a psychiatric nurse employed by the facility left an envelope containing his treatment notes on public transit. The director of the centre acknowledged the privacy breach, apologized, and stated that internal actions were taken to prevent recurrence. The nurse was reminded of his duty to safeguard personal information and not to transport patient files from the office unless encrypted. The OPC's investigation confirmed the privacy breach and found the complaint to be well-founded. However, the OPC also concluded that the facility had taken appropriate corrective measures following the incident.

Quick view

Privacy ActWell-founded

Psychiatric nurse forgets ex-inmate’s treatment file on bus

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A former inmate at Toronto's Keele Community Correctional Centre complained after a psychiatric nurse employed by the facility left an envelope containing his treatment notes on public transit. The director of the centre acknowledged the privacy breach, apologized, and stated that internal actions were taken to prevent recurrence. The nurse was reminded of his duty to safeguard personal information and not to transport patient files from the office unless encrypted. The OPC's investigation confirmed the privacy breach and found the complaint to be well-founded. However, the OPC also concluded that the facility had taken appropriate corrective measures following the incident.

Key Issues
  • Whether the psychiatric nurse's actions constituted a privacy breach
  • Whether the institution took appropriate corrective measures after the breach
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Hiring program for ex-military staff makes proper use of information

Public Service Commission of Canada

An individual complained that the Public Service Commission of Canada (PSC) improperly collected and disclosed personal information about his medical release from the Canadian Forces. This information was collected for a program that grants priority consideration to former military personnel for federal public service positions. The OPC's investigation found that the complainant had provided written consent for the collection and disclosure of his medical release record for this specific hiring program. All aspects of the process were determined to be in full conformity with the Privacy Act. Consequently, the complaint was dismissed.

Quick view

Privacy ActNot well-founded

Hiring program for ex-military staff makes proper use of information

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that the Public Service Commission of Canada (PSC) improperly collected and disclosed personal information about his medical release from the Canadian Forces. This information was collected for a program that grants priority consideration to former military personnel for federal public service positions. The OPC's investigation found that the complainant had provided written consent for the collection and disclosure of his medical release record for this specific hiring program. All aspects of the process were determined to be in full conformity with the Privacy Act. Consequently, the complaint was dismissed.

Key Issues
  • Whether the Public Service Commission of Canada improperly collected personal information about the complainant's medical release from the Canadian Forces
  • Whether the Public Service Commission of Canada improperly disclosed personal information about the complainant's medical release from the Canadian Forces
  • Whether the collection and disclosure of personal information conformed with the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Custodian of Social Insurance Numbers loses list of them

Human Resources and Skills Development Canada (HRSDC)

A woman complained to the OPC after an attendance sheet containing her Social Insurance Number (SIN), name, and telephone number, along with those of 31 other employment insurance (EI) claimants, went missing from an HRSDC information session. HRSDC officials notified affected individuals, apologized, and provided information on identity theft protection. The OPC investigated and found that HRSDC had failed to properly safeguard the personal information. The OPC was particularly concerned that the breach involved SINs, which are highly vulnerable to misuse. HRSDC subsequently directed officials to black out SINs on attendance sheets for future sessions.

Quick view

Privacy ActWell-founded

Custodian of Social Insurance Numbers loses list of them

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained to the OPC after an attendance sheet containing her Social Insurance Number (SIN), name, and telephone number, along with those of 31 other employment insurance (EI) claimants, went missing from an HRSDC information session. HRSDC officials notified affected individuals, apologized, and provided information on identity theft protection. The OPC investigated and found that HRSDC had failed to properly safeguard the personal information. The OPC was particularly concerned that the breach involved SINs, which are highly vulnerable to misuse. HRSDC subsequently directed officials to black out SINs on attendance sheets for future sessions.

Key Issues
  • Whether Human Resources and Skills Development Canada (HRSDC) properly safeguarded personal information, specifically Social Insurance Numbers (SINs), names, and telephone numbers, on an attendance sheet at an employment insurance information session.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Canada Post demands too much information for leave requests

Canada Post

An individual complained that Canada Post collected excessive personal information for special paid leave requests to care for an ailing relative. The application form, intended for supervisors, was mistakenly given to the complainant to complete, requiring extensive personal information about herself, the ill person, and third parties. Canada Post argued that arbitration rulings and fraud prevention concerns necessitated the collection of substantial information. The OPC found that more personal information was collected than necessary to establish leave entitlement, particularly regarding third parties. The complaint was upheld as well-founded, and the OPC recommended measures to address privacy concerns. Canada Post agreed to some changes, but insisted on collecting information about other family members working at Canada Post, which the OPC still had reservations about.

Quick view

Privacy ActWell-founded

Canada Post demands too much information for leave requests

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Canada Post collected excessive personal information for special paid leave requests to care for an ailing relative. The application form, intended for supervisors, was mistakenly given to the complainant to complete, requiring extensive personal information about herself, the ill person, and third parties. Canada Post argued that arbitration rulings and fraud prevention concerns necessitated the collection of substantial information. The OPC found that more personal information was collected than necessary to establish leave entitlement, particularly regarding third parties. The complaint was upheld as well-founded, and the OPC recommended measures to address privacy concerns. Canada Post agreed to some changes, but insisted on collecting information about other family members working at Canada Post, which the OPC still had reservations about.

Key Issues
  • Whether Canada Post collected excessive personal information for special paid leave requests
  • Whether the information collected about third parties was necessary
  • Whether the collection of information about other family members working at Canada Post was justified for fraud prevention
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Health Canada erred in withholding personal information

Health Canada

An individual complained after Health Canada refused to provide him with personal information collected during a fitness-for-work evaluation. Health Canada cited section 28 of the Privacy Act, arguing that disclosing information related to his physical or mental health would be contrary to his best interests. The OPC's investigation found that the requested information was not limited to sensitive health records. Therefore, section 28 did not provide a valid reason to withhold access. The complaint was upheld as well-founded, and Health Canada subsequently agreed to release the information, leading to a resolved outcome.

Quick view

Privacy ActWell-founded

Health Canada erred in withholding personal information

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained after Health Canada refused to provide him with personal information collected during a fitness-for-work evaluation. Health Canada cited section 28 of the Privacy Act, arguing that disclosing information related to his physical or mental health would be contrary to his best interests. The OPC's investigation found that the requested information was not limited to sensitive health records. Therefore, section 28 did not provide a valid reason to withhold access. The complaint was upheld as well-founded, and Health Canada subsequently agreed to release the information, leading to a resolved outcome.

Key Issues
  • Whether Health Canada erred in withholding personal information
  • Whether section 28 of the Privacy Act applied to the requested information
  • Whether the information was confined to sensitive records related to mental or physical health
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Minister’s suspicions about Wheat Board leaks unfounded

Canadian Wheat Board

The Minister of Agriculture and Agri-Food Canada filed a privacy complaint against the Canadian Wheat Board (CWB) following media reports about an internal audit. The audit raised concerns about potential improper disclosure of farmers' personal information, including Social Insurance Numbers (SINs), to third parties like grain handlers and the Canada Revenue Agency. The OPC's investigation found that the CWB had appropriate protocols, procedures, and agreements in place to manage personal information. Specifically, the CWB did not disclose SINs to third parties and only shared personal data with the tax agency when legally required. Consequently, the complaint was dismissed as not well-founded.

Quick view

Privacy ActNot well-founded

Minister’s suspicions about Wheat Board leaks unfounded

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Minister of Agriculture and Agri-Food Canada filed a privacy complaint against the Canadian Wheat Board (CWB) following media reports about an internal audit. The audit raised concerns about potential improper disclosure of farmers' personal information, including Social Insurance Numbers (SINs), to third parties like grain handlers and the Canada Revenue Agency. The OPC's investigation found that the CWB had appropriate protocols, procedures, and agreements in place to manage personal information. Specifically, the CWB did not disclose SINs to third parties and only shared personal data with the tax agency when legally required. Consequently, the complaint was dismissed as not well-founded.

Key Issues
  • Whether the Canadian Wheat Board improperly disclosed farmers' Social Insurance Numbers (SINs) to third parties
  • Whether the Canadian Wheat Board improperly disclosed other personal information of farmers to third parties
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Prison to put sensitive mail in envelopes after document intercepted

Correctional Service of Canada (Kent Institution)

An inmate at Kent Institution complained after a 10-page National Parole Board decision containing graphic details of his offence was intercepted and circulated among other inmates. The document was supposed to be delivered via internal mail but was only folded and stapled, not placed in an envelope. Prison officials acknowledged the breach and launched an investigation, which confirmed the document was viewed by various inmates. The OPC's investigation found that the disclosure violated the Privacy Act. As a result, the warden implemented changes to ensure confidential documents are now placed in sealed envelopes.

Quick view

Privacy ActWell-founded

Prison to put sensitive mail in envelopes after document intercepted

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An inmate at Kent Institution complained after a 10-page National Parole Board decision containing graphic details of his offence was intercepted and circulated among other inmates. The document was supposed to be delivered via internal mail but was only folded and stapled, not placed in an envelope. Prison officials acknowledged the breach and launched an investigation, which confirmed the document was viewed by various inmates. The OPC's investigation found that the disclosure violated the Privacy Act. As a result, the warden implemented changes to ensure confidential documents are now placed in sealed envelopes.

Key Issues
  • Whether the disclosure of the inmate's National Parole Board decision to other inmates violated the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Driver’s licence suitable ID for postal box rental

Canada Post

An individual complained that Canada Post required his driver's licence number to terminate his postal box rental. Canada Post stated it requires personal identification to prevent fraudulent use or closure of postal boxes and has used recorded ID to investigate illegal shipments. The OPC's investigation found that Canada Post has a statutory obligation to provide a secure postal service. The collection and use of personal information, including driver's licence numbers, was deemed consistent with this mandate. The OPC concluded that the collection of identification numbers was reasonable. The complaint was dismissed as not well-founded.

Quick view

Privacy ActNot well-founded

Driver’s licence suitable ID for postal box rental

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Canada Post required his driver's licence number to terminate his postal box rental. Canada Post stated it requires personal identification to prevent fraudulent use or closure of postal boxes and has used recorded ID to investigate illegal shipments. The OPC's investigation found that Canada Post has a statutory obligation to provide a secure postal service. The collection and use of personal information, including driver's licence numbers, was deemed consistent with this mandate. The OPC concluded that the collection of identification numbers was reasonable. The complaint was dismissed as not well-founded.

Key Issues
  • Whether requiring a driver's licence number to terminate a postal box rental is a reasonable collection of personal information under PIPEDA
  • Whether Canada Post's collection and use of personal information for security purposes is consistent with its statutory obligations
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Letter carrier accuses boss of intercepting and reading a document

Canada Post

A Canada Post letter carrier complained that his supervisor accessed and used his medical information without authorization. The complainant alleged he gave a sealed medical form for a disability insurance claim to his supervisor to forward to the insurer, but the supervisor opened and read it. The supervisor admitted she might have read the form but denied opening a sealed envelope. The investigation could not confirm if the envelope was sealed, but it did confirm the supervisor used the health information to challenge other medical documentation provided by the employee. The OPC concluded that the personal information was used for an inconsistent purpose without permission, finding the complaint well-founded. The OPC recommended Canada Post remind staff to submit forms directly to the insurer and managers to refuse to accept such forms.

Quick view

Privacy ActWell-founded

Letter carrier accuses boss of intercepting and reading a document

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A Canada Post letter carrier complained that his supervisor accessed and used his medical information without authorization. The complainant alleged he gave a sealed medical form for a disability insurance claim to his supervisor to forward to the insurer, but the supervisor opened and read it. The supervisor admitted she might have read the form but denied opening a sealed envelope. The investigation could not confirm if the envelope was sealed, but it did confirm the supervisor used the health information to challenge other medical documentation provided by the employee. The OPC concluded that the personal information was used for an inconsistent purpose without permission, finding the complaint well-founded. The OPC recommended Canada Post remind staff to submit forms directly to the insurer and managers to refuse to accept such forms.

Key Issues
  • Whether the supervisor gained unauthorized access to the medical form
  • Whether the personal information was used for a purpose inconsistent with its collection
  • Whether the use of information was without the complainant's permission
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 30, 2011Commissioner’s Findings - PIPEDA Report of Findings #2011-011Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2011-011: Public opinion research firm must better inform survey respondents about their personal information use; refrain from collecting full birth dates

A public opinion research firm

A complainant alleged that a public opinion research firm unnecessarily collected her full date of birth and failed to adequately inform her about the purpose of a profiling survey. The firm collected full birth dates for demographic purposes and to verify identity, arguing that month and year alone were insufficient. The OPC found that collecting the full date of birth was not necessary for the firm's stated purposes and that the consent language for profiling surveys was not sufficiently clear. While the firm agreed to clarify its consent language, it refused to stop collecting or delete the day of birth from its records. Consequently, the OPC found the complaint well-founded but partially unresolved regarding the collection of full birth dates.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Commissioner’s Findings - PIPEDA Report of Findings #2011-011: Public opinion research firm must better inform survey respondents about their personal information use; refrain from collecting full birth dates

Jun 30, 2011Commissioner’s Findings - PIPEDA Report of Findings #2011-011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a public opinion research firm unnecessarily collected her full date of birth and failed to adequately inform her about the purpose of a profiling survey. The firm collected full birth dates for demographic purposes and to verify identity, arguing that month and year alone were insufficient. The OPC found that collecting the full date of birth was not necessary for the firm's stated purposes and that the consent language for profiling surveys was not sufficiently clear. While the firm agreed to clarify its consent language, it refused to stop collecting or delete the day of birth from its records. Consequently, the OPC found the complaint well-founded but partially unresolved regarding the collection of full birth dates.

Key Issues
  • Whether it is necessary for the Respondent to collect all three elements of the date of birth at registration
  • Whether it is necessary for the Respondent to confirm all three elements of the date of birth in profiling surveys
  • Whether the Respondent adequately informed the complainant of the purpose of the profiling survey
  • Whether consent under Principle 4.3 was meaningful
  • Whether the collection of personal information was limited to that which is necessary for the identified purposes under Principle 4.4
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 6, 2010Indexed Jun 30, 2026

Veteran’s complaint highlights significant privacy issues - October 6, 2010

Veterans Affairs Canada

A veteran complained that Veterans Affairs Canada (VAC) inappropriately used his personal information by including excessive medical details in briefing notes for the Minister and by transferring his medical file to a hospital without consent. The OPC investigation found that briefing notes contained sensitive medical information far beyond what was necessary for their stated purpose and that this information was widely shared within VAC on a non-need-to-know basis. It also found that VAC transferred the complainant's medical file to a hospital it administered without obtaining his consent, despite departmental guidelines requiring it. The OPC concluded that VAC's actions violated section 7 of the Privacy Act, which governs the use of personal information. The complaint was found to be well-founded, and the OPC issued several recommendations to VAC, including developing an enhanced privacy policy framework, revising information-management practices, providing employee training, and reviewing consent procedures for information transfers.

Quick view

Privacy ActWell-founded

Veteran’s complaint highlights significant privacy issues - October 6, 2010

Oct 6, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A veteran complained that Veterans Affairs Canada (VAC) inappropriately used his personal information by including excessive medical details in briefing notes for the Minister and by transferring his medical file to a hospital without consent. The OPC investigation found that briefing notes contained sensitive medical information far beyond what was necessary for their stated purpose and that this information was widely shared within VAC on a non-need-to-know basis. It also found that VAC transferred the complainant's medical file to a hospital it administered without obtaining his consent, despite departmental guidelines requiring it. The OPC concluded that VAC's actions violated section 7 of the Privacy Act, which governs the use of personal information. The complaint was found to be well-founded, and the OPC issued several recommendations to VAC, including developing an enhanced privacy policy framework, revising information-management practices, providing employee training, and reviewing consent procedures for information transfers.

Key Issues
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by including excessive medical details in briefing notes for the Minister.
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by widely sharing sensitive personal information within the department on a non-need-to-know basis.
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by transferring his medical file to a hospital without obtaining his consent.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Border authority absolved of improperly gathering personal data from blog

Canada Border Services Agency (CBSA)

An individual complained that the Canada Border Services Agency (CBSA) improperly collected information from his personal online blog after his term position ended. The complainant alleged that his tracking device showed visits from government computers. The OPC investigated whether the CBSA had inappropriately collected personal information. The investigation found that several CBSA employees had viewed the blog, but did so in a personal capacity, which was deemed to accord with the government's Acceptable Use Policy. The OPC found no evidence that the agency had collected personal information in connection with these visits. Therefore, the complaints were determined to be not well-founded.

Quick view

Privacy ActNot well-founded

Border authority absolved of improperly gathering personal data from blog

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that the Canada Border Services Agency (CBSA) improperly collected information from his personal online blog after his term position ended. The complainant alleged that his tracking device showed visits from government computers. The OPC investigated whether the CBSA had inappropriately collected personal information. The investigation found that several CBSA employees had viewed the blog, but did so in a personal capacity, which was deemed to accord with the government's Acceptable Use Policy. The OPC found no evidence that the agency had collected personal information in connection with these visits. Therefore, the complaints were determined to be not well-founded.

Key Issues
  • Whether the Canada Border Services Agency improperly collected personal information from the complainant's blog
  • Whether employees viewing a public blog from government workstations constitutes collection of personal information by the agency