The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

1,639 decisions in the archive
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Personal data of 191 EI claimants disclosed

Human Resources and Skills Development Canada

The Office of the Privacy Commissioner of Canada (OPC) received 82 complaints after Human Resources and Skills Development Canada (HRSDC) inadvertently disclosed the personal information of 191 Employment Insurance (EI) claimants to another individual. The disclosure occurred when an individual appealing an EI claim denial received an appeal docket that included names, dates of birth, employee identification numbers, and Social Insurance Numbers of 191 fellow employees, along with a second list of employment and leave statuses. The OPC's investigation confirmed that in 79 instances, the information was indeed released, leading to well-founded findings. HRSDC took immediate steps to retrieve the data, notify affected parties, and advise on identity theft prevention. They also implemented measures to prevent future recurrences, including reminding officials of proper procedures for protecting personal information during appeals.

Quick view

Privacy ActWell-founded

Personal data of 191 EI claimants disclosed

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) received 82 complaints after Human Resources and Skills Development Canada (HRSDC) inadvertently disclosed the personal information of 191 Employment Insurance (EI) claimants to another individual. The disclosure occurred when an individual appealing an EI claim denial received an appeal docket that included names, dates of birth, employee identification numbers, and Social Insurance Numbers of 191 fellow employees, along with a second list of employment and leave statuses. The OPC's investigation confirmed that in 79 instances, the information was indeed released, leading to well-founded findings. HRSDC took immediate steps to retrieve the data, notify affected parties, and advise on identity theft prevention. They also implemented measures to prevent future recurrences, including reminding officials of proper procedures for protecting personal information during appeals.

Key Issues
  • Whether Human Resources and Skills Development Canada inadvertently disclosed personal information of EI claimants
  • Whether the disclosure of names, dates of birth, employee identification numbers, and Social Insurance Numbers constituted a contravention of the Privacy Act
  • Whether the disclosure of employment and leave status constituted a contravention of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Internet posting highlights inappropriate access to tax records by CRA workers

Canada Revenue Agency (CRA)

The Commissioner initiated an investigation following media allegations that a Canada Revenue Agency (CRA) employee posted personal tax information of high-profile sports figures to an Internet chat group. The investigation confirmed that a former CRA employee had posted such information, and that other CRA employees had inappropriately accessed the tax information of these athletes, likely out of curiosity. While there was no evidence that these employees disclosed the information to outside sources, accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act. Consequently, the portion of the complaint concerning the improper use of personal information by CRA employees was found to be well-founded. The CRA took corrective measures, including suspending one employee, firing two others, and modernizing its audit trail system to monitor access to taxpayer information.

Quick view

Privacy ActWell-founded

Internet posting highlights inappropriate access to tax records by CRA workers

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Commissioner initiated an investigation following media allegations that a Canada Revenue Agency (CRA) employee posted personal tax information of high-profile sports figures to an Internet chat group. The investigation confirmed that a former CRA employee had posted such information, and that other CRA employees had inappropriately accessed the tax information of these athletes, likely out of curiosity. While there was no evidence that these employees disclosed the information to outside sources, accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act. Consequently, the portion of the complaint concerning the improper use of personal information by CRA employees was found to be well-founded. The CRA took corrective measures, including suspending one employee, firing two others, and modernizing its audit trail system to monitor access to taxpayer information.

Key Issues
  • Whether CRA employees inappropriately accessed personal tax information
  • Whether CRA employees disclosed personal tax information to outside sources
  • Whether accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Toronto Port Authority worker misuses personal data for political fundraiser

Toronto Port Authority

A Member of Parliament complained that an employee of the Toronto Port Authority (TPA) misused the organization's email database to invite people to a political fundraising event. The investigation found that a TPA employee sent an email to approximately 60 people, soliciting donations and inviting participation in a fundraiser for another MP. The employee obtained these email addresses from business cards collected by the TPA, including both business and personal addresses. The OPC determined that the employee used this personal information without the TPA's knowledge or authorization and for reasons unrelated to the organization's business activities. The complaint was found to be well-founded, but the TPA took corrective measures, including reminding employees of their responsibilities and pledging Privacy Act training.

Quick view

Privacy ActWell-founded

Toronto Port Authority worker misuses personal data for political fundraiser

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A Member of Parliament complained that an employee of the Toronto Port Authority (TPA) misused the organization's email database to invite people to a political fundraising event. The investigation found that a TPA employee sent an email to approximately 60 people, soliciting donations and inviting participation in a fundraiser for another MP. The employee obtained these email addresses from business cards collected by the TPA, including both business and personal addresses. The OPC determined that the employee used this personal information without the TPA's knowledge or authorization and for reasons unrelated to the organization's business activities. The complaint was found to be well-founded, but the TPA took corrective measures, including reminding employees of their responsibilities and pledging Privacy Act training.

Key Issues
  • Whether a Toronto Port Authority employee misused personal information for a political fundraiser
  • Whether email addresses obtained from business cards constitute personal information
  • Whether the use of personal information was without the knowledge or authorization of the institution
  • Whether the use of personal information was for reasons unrelated to the organization's business activities
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Mechanical malfunction, compounded by human error, leads to data spill

Human Resources and Skills Development Canada

In March 2009, Human Resources and Skills Development Canada (HRSDC) mailed 11,900 forms for the Guaranteed Income Supplement. Due to a mechanical malfunction and human error, some individuals received forms intended for others, containing names, addresses, and Social Insurance Numbers (SINs). The OPC initiated a complaint after HRSDC notified them of 44 reported cases of mix-ups. The investigation found that a technician failed to stop the mailing despite noticing errors and did not report the issue to management. The OPC determined the complaint was well-founded, highlighting both mechanical failure and human error. HRSDC conducted its own investigation, improved equipment, and strengthened quality control procedures. The OPC recommended better employee sensitization to privacy obligations, which HRSDC committed to implementing.

Quick view

Privacy ActWell-founded

Mechanical malfunction, compounded by human error, leads to data spill

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

In March 2009, Human Resources and Skills Development Canada (HRSDC) mailed 11,900 forms for the Guaranteed Income Supplement. Due to a mechanical malfunction and human error, some individuals received forms intended for others, containing names, addresses, and Social Insurance Numbers (SINs). The OPC initiated a complaint after HRSDC notified them of 44 reported cases of mix-ups. The investigation found that a technician failed to stop the mailing despite noticing errors and did not report the issue to management. The OPC determined the complaint was well-founded, highlighting both mechanical failure and human error. HRSDC conducted its own investigation, improved equipment, and strengthened quality control procedures. The OPC recommended better employee sensitization to privacy obligations, which HRSDC committed to implementing.

Key Issues
  • Whether personal information was inappropriately disclosed due to mechanical malfunction
  • Whether personal information was inappropriately disclosed due to human error
  • Whether the institution adequately safeguarded personal information during mass mailings
  • Whether employees were sufficiently sensitized to their obligations to safeguard personal information
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

RCMP and private polling firm safeguarded data on gun licensees

Royal Canadian Mounted Police (RCMP)

The Commissioner initiated a complaint against the RCMP regarding its handling of personal information collected by the Canadian Firearms Program and used by EKOS Research Associates Inc. to survey firearms licensees. The RCMP provided contact information to EKOS, which then collected demographic data and information on guns owned by respondents. The investigation found that EKOS did not provide identifying data in its report to the firearms program and met all contractual requirements for secure data handling. The Assistant Commissioner determined that the collection and use of information for a client-satisfaction survey was consistent with the purpose for which it was initially collected under the Privacy Act. The RCMP was also found compliant in providing information to EKOS, as the contract included appropriate confidentiality and security provisions. The complaint was therefore deemed not well-founded, though the OPC recommended the RCMP clarify its public information on data uses and conduct Privacy Impact Assessments.

Quick view

Privacy ActNot well-founded

RCMP and private polling firm safeguarded data on gun licensees

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Commissioner initiated a complaint against the RCMP regarding its handling of personal information collected by the Canadian Firearms Program and used by EKOS Research Associates Inc. to survey firearms licensees. The RCMP provided contact information to EKOS, which then collected demographic data and information on guns owned by respondents. The investigation found that EKOS did not provide identifying data in its report to the firearms program and met all contractual requirements for secure data handling. The Assistant Commissioner determined that the collection and use of information for a client-satisfaction survey was consistent with the purpose for which it was initially collected under the Privacy Act. The RCMP was also found compliant in providing information to EKOS, as the contract included appropriate confidentiality and security provisions. The complaint was therefore deemed not well-founded, though the OPC recommended the RCMP clarify its public information on data uses and conduct Privacy Impact Assessments.

Key Issues
  • Whether the collection of personal information by the Canadian Firearms Program for a client-satisfaction survey was consistent with the purpose for which it was initially collected under the Privacy Act
  • Whether the disclosure of personal information by the RCMP to EKOS Research Associates Inc. for the survey was compliant with the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Innocent targets of whistleblower law should learn of vindication

Public Works and Government Services Canada

A public servant complained that Public Works and Government Services Canada (PWGSC) refused to provide her with personal information collected during an investigation under the Public Servants Disclosure Protection Act, which had exonerated her. The OPC found that PWGSC correctly applied section 22.3 of the Privacy Act, which mandates refusal to disclose information created for whistleblower disclosures or related investigations. Therefore, the complaint was not well-founded regarding access to information. However, the OPC was concerned that individuals cleared of wrongdoing were not informed of their vindication. The OPC urged PWGSC to inform subjects when allegations are unsubstantiated, and PWGSC subsequently did so for the complainant. The Commissioner also asked the Treasury Board Secretariat to develop guidelines for all departments to inform individuals when allegations of wrongdoing are unsubstantiated, citing procedural fairness and natural justice.

Quick view

Privacy ActNot well-founded

Innocent targets of whistleblower law should learn of vindication

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A public servant complained that Public Works and Government Services Canada (PWGSC) refused to provide her with personal information collected during an investigation under the Public Servants Disclosure Protection Act, which had exonerated her. The OPC found that PWGSC correctly applied section 22.3 of the Privacy Act, which mandates refusal to disclose information created for whistleblower disclosures or related investigations. Therefore, the complaint was not well-founded regarding access to information. However, the OPC was concerned that individuals cleared of wrongdoing were not informed of their vindication. The OPC urged PWGSC to inform subjects when allegations are unsubstantiated, and PWGSC subsequently did so for the complainant. The Commissioner also asked the Treasury Board Secretariat to develop guidelines for all departments to inform individuals when allegations of wrongdoing are unsubstantiated, citing procedural fairness and natural justice.

Key Issues
  • Whether the complainant had a right to access personal information collected during a whistleblower investigation
  • Whether section 22.3 of the Privacy Act was correctly applied to refuse disclosure
  • Whether individuals cleared of wrongdoing in whistleblower investigations should be informed of their vindication
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jan 6, 2010Settled Case summary #2010-001Indexed Jun 30, 2026

Settled Case summary #2010-001: Dental benefit information available to parents with daughter’s consent (January 6, 2010)

A dental plan administrator

The parents of a 17-year-old dependent complained that they could not access their daughter's online dental benefit information from their group dental plan administrator. The administrator's policy required consent from individuals aged 16 or older before their information could be accessed by another plan member, even parents. The administrator defended its policy by citing PIPEDA's consent requirements, the lack of a national age of majority consensus, and the distinction between age of majority and age of consent. The policy was based on the Ontario Health Care Consent Act, which suggests 16 as an age for health care consent. The mother was satisfied with the explanation and understood that she could access her daughter's account if her daughter provided consent by sharing her password.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #2010-001: Dental benefit information available to parents with daughter’s consent (January 6, 2010)

Jan 6, 2010Settled Case summary #2010-001
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The parents of a 17-year-old dependent complained that they could not access their daughter's online dental benefit information from their group dental plan administrator. The administrator's policy required consent from individuals aged 16 or older before their information could be accessed by another plan member, even parents. The administrator defended its policy by citing PIPEDA's consent requirements, the lack of a national age of majority consensus, and the distinction between age of majority and age of consent. The policy was based on the Ontario Health Care Consent Act, which suggests 16 as an age for health care consent. The mother was satisfied with the explanation and understood that she could access her daughter's account if her daughter provided consent by sharing her password.

Key Issues
  • Whether a dental plan administrator requires consent from a 17-year-old dependent to disclose her dental benefit information to her parents
  • Whether the age of majority or age of consent impacts the requirement for consent under PIPEDA for minors
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 21, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-024Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2009-024: Bank Disclosed Personal Information without Consent

A Canadian bank

A married couple applied for a joint mortgage. The husband alleged that a bank mortgage specialist disclosed his account information to his wife without his consent during the application process. The bank argued there was implicit consent given the joint mortgage application. The Assistant Commissioner found that the bank did not make a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed to each other. Therefore, the bank did not have meaningful consent for the disclosure. Although the incident was a one-time error by an employee, the complaint was found to be well-founded and resolved as the bank had adopted reasonable practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Case Summary #2009-024: Bank Disclosed Personal Information without Consent

Dec 21, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-024
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A married couple applied for a joint mortgage. The husband alleged that a bank mortgage specialist disclosed his account information to his wife without his consent during the application process. The bank argued there was implicit consent given the joint mortgage application. The Assistant Commissioner found that the bank did not make a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed to each other. Therefore, the bank did not have meaningful consent for the disclosure. Although the incident was a one-time error by an employee, the complaint was found to be well-founded and resolved as the bank had adopted reasonable practices.

Key Issues
  • Whether the bank had the husband's implicit or explicit consent to disclose his account information to his wife
  • Whether the bank made a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed
  • Whether the bank's mortgage specialist followed the bank's usual practice for informing joint mortgage applicants
  • Whether the presumption of implied consent remained reasonable after the wife's reaction to the initial disclosure
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 16, 2009Indexed Jun 30, 2026

Investigation finds that RCMP handled polling appropriately - December 16, 2009

Royal Canadian Mounted Police (RCMP)

The OPC investigated a complaint against the RCMP regarding the use and disclosure of personal information from the Canadian Firearms Program (CFP) to EKOS Research Associates Inc. for a survey of firearms licensees. The investigation examined whether the RCMP improperly used or disclosed personal information in contravention of sections 7 and 8 of the Privacy Act. The OPC found that the use of information for a client-satisfaction survey to improve CFP services was consistent with the original collection purpose, thus not contravening section 7. Furthermore, the disclosure to EKOS, acting as an agent under a contract with confidentiality and security provisions, did not contravene section 8. The complaint was therefore deemed not well-founded. The OPC noted that the CFP committed to updating its InfoSource entry and website to better inform the public about information use for surveys and acknowledged that a Privacy Impact Assessment would have been beneficial.

Quick view

Privacy ActNot well-founded

Investigation finds that RCMP handled polling appropriately - December 16, 2009

Dec 16, 2009
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated a complaint against the RCMP regarding the use and disclosure of personal information from the Canadian Firearms Program (CFP) to EKOS Research Associates Inc. for a survey of firearms licensees. The investigation examined whether the RCMP improperly used or disclosed personal information in contravention of sections 7 and 8 of the Privacy Act. The OPC found that the use of information for a client-satisfaction survey to improve CFP services was consistent with the original collection purpose, thus not contravening section 7. Furthermore, the disclosure to EKOS, acting as an agent under a contract with confidentiality and security provisions, did not contravene section 8. The complaint was therefore deemed not well-founded. The OPC noted that the CFP committed to updating its InfoSource entry and website to better inform the public about information use for surveys and acknowledged that a Privacy Impact Assessment would have been beneficial.

Key Issues
  • Whether the use of personal information for a client-satisfaction survey was consistent with the purpose for which it was obtained or compiled under s.7(a) of the Privacy Act
  • Whether the disclosure of personal information to EKOS Research Associates Inc. for the survey contravened s.8 of the Privacy Act
  • Whether the personal information collected by the RCMP related directly to an operating program or activity of the institution under s.4 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 6, 2009Indexed Jun 30, 2026

Personal information leaked from DFAIT database

Department of Foreign Affairs and International Trade (DFAIT)

The OPC investigated a complaint regarding the leak of a Canadian citizen's personal information from a DFAIT database, which was reported in the media in spring 2008. The investigation confirmed the information was held in an official consular record within DFAIT's computer system. A significant concern was that 1,231 DFAIT employees had access to these files, and the system lacked audit trail capabilities or mechanisms to restrict access to specific records. Consequently, the OPC could not identify the source of the leak. The complaint was found to be well-founded, and DFAIT agreed to implement corrective measures.

Quick view

Privacy ActWell-founded

Personal information leaked from DFAIT database

Oct 6, 2009
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated a complaint regarding the leak of a Canadian citizen's personal information from a DFAIT database, which was reported in the media in spring 2008. The investigation confirmed the information was held in an official consular record within DFAIT's computer system. A significant concern was that 1,231 DFAIT employees had access to these files, and the system lacked audit trail capabilities or mechanisms to restrict access to specific records. Consequently, the OPC could not identify the source of the leak. The complaint was found to be well-founded, and DFAIT agreed to implement corrective measures.

Key Issues
  • Whether personal information was leaked from a DFAIT database
  • Whether DFAIT's security safeguards were adequate to protect personal information
  • Whether DFAIT's computer system had sufficient audit trail capabilities
  • Whether DFAIT's computer system had mechanisms to restrict access to particular files
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 6, 2009Indexed Jun 30, 2026

No proof Human Rights Commission accessed woman's Internet connection

Canadian Human Rights Commission (CHRC)

A woman complained that the Canadian Human Rights Commission (CHRC) improperly collected and used her personal information by allegedly accessing her wireless Internet connection to post messages on a white supremacist website during an investigation. An Internet Service Provider, responding to a subpoena, linked an IP address associated with the alleged CHRC activity to the complainant. The OPC's investigation found no evidence that the CHRC collected, used, or disclosed any personal information about the complainant or was even aware of her prior to the tribunal hearing. Technological experts suggested the IP address association was a third-party mismatch. The complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

No proof Human Rights Commission accessed woman's Internet connection

Oct 6, 2009
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained that the Canadian Human Rights Commission (CHRC) improperly collected and used her personal information by allegedly accessing her wireless Internet connection to post messages on a white supremacist website during an investigation. An Internet Service Provider, responding to a subpoena, linked an IP address associated with the alleged CHRC activity to the complainant. The OPC's investigation found no evidence that the CHRC collected, used, or disclosed any personal information about the complainant or was even aware of her prior to the tribunal hearing. Technological experts suggested the IP address association was a third-party mismatch. The complaint was found to be not well-founded.

Key Issues
  • Whether the Canadian Human Rights Commission improperly collected and used the complainant's personal information
  • Whether the CHRC accessed the complainant's wireless Internet connection
  • Whether an IP address can be considered personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jul 27, 2009Report of FindingsIndexed Jun 30, 2026

Report of Findings: Complaint under PIPEDA against Accusearch Inc., doing business as Abika.com

Accusearch Inc., doing business as Abika.com

CIPPIC complained that Abika.com, a U.S. company, collected, used, and disclosed Canadians' personal information without consent, compiled and disclosed inaccurate personal information through its "psychological profile" service, and used personal information for inappropriate purposes. The OPC initially declined jurisdiction, but the Federal Court ordered the investigation to proceed. The OPC found that Abika collected and disclosed personal information, including telephone records, of Canadians without their knowledge or consent, often for inappropriate purposes such as investigating partners. While the OPC found the accuracy complaint not well-founded due to lack of verifiable evidence, it concluded that Abika contravened PIPEDA Principles 4.3 and subsection 5(3). Abika failed to respond adequately to the OPC's recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Report of Findings: Complaint under PIPEDA against Accusearch Inc., doing business as Abika.com

Jul 27, 2009Report of Findings
Adjudicator: Jennifer Stoddart
Plain-Language Summary

CIPPIC complained that Abika.com, a U.S. company, collected, used, and disclosed Canadians' personal information without consent, compiled and disclosed inaccurate personal information through its "psychological profile" service, and used personal information for inappropriate purposes. The OPC initially declined jurisdiction, but the Federal Court ordered the investigation to proceed. The OPC found that Abika collected and disclosed personal information, including telephone records, of Canadians without their knowledge or consent, often for inappropriate purposes such as investigating partners. While the OPC found the accuracy complaint not well-founded due to lack of verifiable evidence, it concluded that Abika contravened PIPEDA Principles 4.3 and subsection 5(3). Abika failed to respond adequately to the OPC's recommendations.

Key Issues
  • Whether Abika collected, used, and disclosed personal information of individuals living in Canada without their knowledge and consent, in contravention of Principle 4.3
  • Whether Abika compiled and disclosed inaccurate personal information through its "psychological profile" service, in contravention of Principle 4.6
  • Whether Abika collected, used, and disclosed personal information about Canadians for inappropriate purposes, in contravention of subsection 5(3)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 16, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-008Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2009-008: Report of Findings: CIPPIC v. Facebook Inc.

Facebook Inc.

The Canadian Internet Policy and Public Interest Clinic (CIPPIC) filed a comprehensive complaint against Facebook Inc., alleging 24 contraventions of PIPEDA across 12 subjects, including default privacy settings, advertising practices, third-party applications, and the handling of personal information for deactivated, deceased, and non-users. The Office of the Privacy Commissioner (OPC) focused its investigation on meaningful consent, retention, and security safeguards. The Assistant Commissioner found several allegations to be 'not well-founded', such as those concerning new uses of information, collection from other sources, Facebook Mobile safeguards, and deception. Other allegations, including those related to date of birth collection, default privacy settings, advertising, and monitoring for anomalous activity, were found 'well-founded and resolved' due to Facebook's agreement to implement corrective measures. However, significant issues regarding third-party applications, indefinite retention of deactivated account data, inadequate notification for deceased users' accounts, and the collection/retention of non-users' personal information were found 'well-founded' but remained unresolved, as Facebook declined to implement key recommendations. The OPC indicated it would follow up on all recommendations and consider further action for unresolved issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Case Summary #2009-008: Report of Findings: CIPPIC v. Facebook Inc.

Jul 16, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-008
Adjudicator: Elizabeth Denham
Plain-Language Summary

The Canadian Internet Policy and Public Interest Clinic (CIPPIC) filed a comprehensive complaint against Facebook Inc., alleging 24 contraventions of PIPEDA across 12 subjects, including default privacy settings, advertising practices, third-party applications, and the handling of personal information for deactivated, deceased, and non-users. The Office of the Privacy Commissioner (OPC) focused its investigation on meaningful consent, retention, and security safeguards. The Assistant Commissioner found several allegations to be 'not well-founded', such as those concerning new uses of information, collection from other sources, Facebook Mobile safeguards, and deception. Other allegations, including those related to date of birth collection, default privacy settings, advertising, and monitoring for anomalous activity, were found 'well-founded and resolved' due to Facebook's agreement to implement corrective measures. However, significant issues regarding third-party applications, indefinite retention of deactivated account data, inadequate notification for deceased users' accounts, and the collection/retention of non-users' personal information were found 'well-founded' but remained unresolved, as Facebook declined to implement key recommendations. The OPC indicated it would follow up on all recommendations and consider further action for unresolved issues.

Key Issues
  • Whether requiring date of birth as a condition of registration contravened Principle 4.3.3
  • Whether Facebook adequately explained the purposes for collecting and using date of birth under Principle 4.3.2
  • Whether default privacy settings constituted improper opt-out consent for sensitive information under Principle 4.3.6
  • Whether Facebook made reasonable efforts to advise users of purposes and extent of information use/disclosure via default settings under Principles 4.2.3 and 4.3.2
  • Whether default settings for photo albums met users' reasonable expectations under Principle 4.3.5
  • Whether default settings for public search listings met users' reasonable expectations under Principle 4.3.5
  • Whether Facebook made reasonable efforts to notify users of advertising purposes under Principle 4.3.2
  • Whether Social Ads improperly used opt-out consent for sensitive information under Principle 4.3.6
  • Whether users could opt out of Facebook Ads under Principle 4.3.8
  • Whether requiring consent to Facebook Ads as a condition of service violated Principle 4.3.3
  • Whether Facebook adequately informed users of the purpose for disclosing personal information to third-party application developers under Principles 4.2.2 and 4.2.5
  • Whether Facebook provided third-party application developers with access to personal information beyond what was necessary under Principle 4.4.1
  • Whether Facebook required consent to disclosure beyond what was necessary to run an application under Principle 4.3.3
  • Whether Facebook adequately safeguarded personal information transferred to third-party applications under Principle 4.7
  • Whether Facebook obtained meaningful consent for disclosure of personal information to application developers when users or their friends added applications under Principles 4.2, 4.2.3, 4.3.2, 4.3.4, 4.3.5, 4.3.6, and subsection 5(3)
  • Whether Facebook failed to notify users of new purposes for collecting, using, or disclosing personal information under Principle 4.2.4
  • Whether Facebook failed to provide specific information and obtain meaningful consent for collecting personal information from sources outside Facebook under Principle 4.3
  • Whether Facebook inappropriately deprived users of a means to delete all personal information from the site
  • Whether Facebook's indefinite retention of personal information in deactivated accounts contravened Principles 4.5 and 4.5.3
  • Whether Facebook obtained meaningful consent for memorializing deceased users' profiles under Principle 4.3.3
  • Whether memorializing profiles was an unnecessary condition of service under Principle 4.3.3
  • Whether Facebook adequately informed users of its practice of account memorialization under Principles 4.2.1, 4.2.3, 4.3.2, and 4.8
  • Whether Facebook obtained consent from non-users for uploading their personal information (e.g., tagging, invitations) under Principle 4.3
  • Whether Facebook's retention of non-users' email addresses beyond the initial purpose contravened Principle 4.5
  • Whether Facebook Mobile's use of a persistent cookie constituted inadequate safeguarding of personal information under Principles 4.7, 4.7.1, and 4.7.3
  • Whether Facebook adequately informed users of its practice of monitoring for anomalous activity under Principle 4.8
  • Whether Facebook misrepresented its purpose or users' control over personal information under Principles 4.3.2 and 4.4.2
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jan 29, 2009Indexed Jun 30, 2026

Investigation finds no evidence that Canadian Human Rights Commission accessed individual's Internet connection

Canadian Human Rights Commission (CHRC)

An individual complained that the Canadian Human Rights Commission (CHRC) improperly collected and used her personal information by accessing her wireless internet connection to post messages on a white supremacist website. The OPC investigated whether the CHRC contravened sections 4 to 8 of the Privacy Act. The investigation first determined that the complainant's IP address, when linked to her identity via a subpoena, constituted personal information under section 3 of the Act. However, the OPC found no evidence that the CHRC ever collected or had knowledge of the complainant's personal information prior to the allegations. Technological experts suggested the association of the complainant's IP address with the CHRC was likely a third-party mismatch. Consequently, the Assistant Privacy Commissioner concluded there was no contravention of the Privacy Act.

Quick view

Privacy ActNot well-founded

Investigation finds no evidence that Canadian Human Rights Commission accessed individual's Internet connection

Jan 29, 2009
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that the Canadian Human Rights Commission (CHRC) improperly collected and used her personal information by accessing her wireless internet connection to post messages on a white supremacist website. The OPC investigated whether the CHRC contravened sections 4 to 8 of the Privacy Act. The investigation first determined that the complainant's IP address, when linked to her identity via a subpoena, constituted personal information under section 3 of the Act. However, the OPC found no evidence that the CHRC ever collected or had knowledge of the complainant's personal information prior to the allegations. Technological experts suggested the association of the complainant's IP address with the CHRC was likely a third-party mismatch. Consequently, the Assistant Privacy Commissioner concluded there was no contravention of the Privacy Act.

Key Issues
  • Whether the complainant's IP address constituted personal information under section 3 of the Privacy Act
  • Whether the CHRC collected the complainant's personal information
  • Whether the CHRC improperly used, disclosed, or retained the complainant's personal information in contravention of sections 4 to 8 of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
May 29, 2008Executive SummaryIndexed Jun 30, 2026

Executive Summary: Law School Admission Council Investigation

Law School Admission Council (LSAC)

A complainant objected to the Law School Admission Council's (LSAC) requirement for Canadian students to provide fingerprints to write the Law School Admission Test (LSAT). LSAC, a US-based non-profit, argued it was outside PIPEDA's jurisdiction and its activities were educational. The Assistant Privacy Commissioner found sufficient links to Canada for PIPEDA to apply and determined LSAC's activities were administrative, not educational. Applying a four-part test, the Assistant Commissioner found fingerprinting was not demonstrably necessary, effective, or proportional, and less privacy-invasive alternatives existed. LSAC agreed to cease fingerprint collection but reserved the right to reinstate it, proposing photographic evidence instead. The Assistant Commissioner found the complaint well-founded due to the disproportionate nature of fingerprint collection and LSAC's reservation to reinstate the policy.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Executive Summary: Law School Admission Council Investigation

May 29, 2008Executive Summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant objected to the Law School Admission Council's (LSAC) requirement for Canadian students to provide fingerprints to write the Law School Admission Test (LSAT). LSAC, a US-based non-profit, argued it was outside PIPEDA's jurisdiction and its activities were educational. The Assistant Privacy Commissioner found sufficient links to Canada for PIPEDA to apply and determined LSAC's activities were administrative, not educational. Applying a four-part test, the Assistant Commissioner found fingerprinting was not demonstrably necessary, effective, or proportional, and less privacy-invasive alternatives existed. LSAC agreed to cease fingerprint collection but reserved the right to reinstate it, proposing photographic evidence instead. The Assistant Commissioner found the complaint well-founded due to the disproportionate nature of fingerprint collection and LSAC's reservation to reinstate the policy.

Key Issues
  • Whether LSAC's activities fall within the scope of PIPEDA despite its non-profit status and US location
  • Whether LSAC's activities are educational in nature or serve administrative needs
  • Whether the collection of thumbprints is demonstrably necessary to meet a specific need
  • Whether the collection of thumbprints is likely to be effective in meeting that need
  • Whether the loss of privacy from thumbprint collection is proportional to the benefit gained
  • Whether there is a less privacy-invasive way of achieving the same end as thumbprint collection
  • Whether the collection of photographs as an alternative is acceptable under PIPEDA
  • Whether LSAC's reservation of the right to reinstate its fingerprint policy is compliant with PIPEDA