The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

17 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 25, 2013Early resolved case summary #2013-01Indexed Jun 30, 2026

Early resolved case summary #2013-01: Property management company alters its rental application form to make clear that Social Insurance Number is optional

A property management company

An individual complained that a property management company was over-collecting personal information on rental application forms, specifically requesting Social Insurance Numbers (SINs), driver's licence information, and banking details as a condition of application. The complainant also noted the absence of a privacy policy on the company's website. The OPC contacted the company, which stated its website was under construction and would include a privacy policy. The company used third-party generated forms and believed SINs were necessary for credit checks, a point the OPC disputed. The OPC suggested marking SIN requests as 'optional' and advised against collecting unique driver's licence numbers. The company committed to updating its forms and website, satisfying the complainant. The OPC later confirmed these changes were implemented.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Early resolved case summary #2013-01: Property management company alters its rental application form to make clear that Social Insurance Number is optional

Apr 25, 2013Early resolved case summary #2013-01
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a property management company was over-collecting personal information on rental application forms, specifically requesting Social Insurance Numbers (SINs), driver's licence information, and banking details as a condition of application. The complainant also noted the absence of a privacy policy on the company's website. The OPC contacted the company, which stated its website was under construction and would include a privacy policy. The company used third-party generated forms and believed SINs were necessary for credit checks, a point the OPC disputed. The OPC suggested marking SIN requests as 'optional' and advised against collecting unique driver's licence numbers. The company committed to updating its forms and website, satisfying the complainant. The OPC later confirmed these changes were implemented.

Key Issues
  • Whether the collection of Social Insurance Numbers (SINs) was appropriate
  • Whether the collection of driver's licence numbers was appropriate
  • Whether the collection of banking information was appropriate
  • Whether the organization made its privacy policy readily available as required by PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 15, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-002Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-002: Bank misinformed client of purpose of requesting personal information for picking up credit card

A Canadian bank

A bank customer complained after being asked to provide his driver's license to pick up a replacement credit card, despite having other identification on file and being known to staff. The bank initially cited anti-money laundering regulations (PCMLTFA) but later admitted this rationale was incorrect. The OPC investigated two issues: whether the bank improperly demanded to record information (collection) and whether it could explain the purpose of collection. Since the customer refused to provide his driver's license, no actual collection occurred, so that aspect of the complaint was not well-founded. However, the bank's inaccurate explanation for requesting the information contravened Principle 4.2.5. The bank revised its procedures and circulated new guidelines to staff, leading to a well-founded and resolved outcome for the latter issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-002: Bank misinformed client of purpose of requesting personal information for picking up credit card

Apr 15, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-002
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A bank customer complained after being asked to provide his driver's license to pick up a replacement credit card, despite having other identification on file and being known to staff. The bank initially cited anti-money laundering regulations (PCMLTFA) but later admitted this rationale was incorrect. The OPC investigated two issues: whether the bank improperly demanded to record information (collection) and whether it could explain the purpose of collection. Since the customer refused to provide his driver's license, no actual collection occurred, so that aspect of the complaint was not well-founded. However, the bank's inaccurate explanation for requesting the information contravened Principle 4.2.5. The bank revised its procedures and circulated new guidelines to staff, leading to a well-founded and resolved outcome for the latter issue.

Key Issues
  • Whether the bank limited its collection of personal information to that which was necessary for the purposes identified by the organization (Principle 4.4 PIPEDA)
  • Whether the bank ensured its employees were able to explain the purposes for which personal information was being collected (Principle 4.2.5 PIPEDA)