The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

615 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Aug 4, 2020PIPEDA Findings #2020-001Indexed Jun 30, 2026

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

TD Canada Trust

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

Aug 4, 2020PIPEDA Findings #2020-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Key Issues
  • Whether TD was required to obtain additional consent for transferring personal information to a third-party service provider in India for fraud claims processing (Principle 4.3 PIPEDA)
  • Whether TD was required to offer customers an opt-out for the transfer of personal information to a third-party service provider in India for fraud claims processing
  • Whether TD was sufficiently open about its practice of transferring personal information to a third-party service provider in a foreign jurisdiction for processing (Principle 4.8 PIPEDA)
  • Whether TD ensured a comparable level of protection for personal information processed by the third-party service provider in India (Principle 4.1.3 PIPEDA)
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jul 14, 2020Indexed Jun 30, 2026

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Canada Border Services Agency (CBSA)

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Quick view

Privacy ActNot well-founded

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Jul 14, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Key Issues
  • Did the CBSA disclose the complainant’s personal information?
  • Was any disclosed information “publicly available”, such that subsection 69(2) of the Act excludes application of sections 7 and 8?
  • If not, was the disclosure permitted under subsection 8(2) of the Act?
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 9, 2020PIPEDA Findings #2020-003Indexed Jun 30, 2026

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Dell Inc.

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Jul 9, 2020PIPEDA Findings #2020-003
Adjudicator: Daniel Therrien
Plain-Language Summary

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Key Issues
  • Whether Dell adequately safeguarded personal information under its control while using a service provider (PIPEDA Principle 4.1.3 and 4.7).
  • Whether the personal information transferred to the service provider was sensitive enough to require a high degree of protection.
  • Whether Dell's access controls were sufficient to protect customer information.
  • Whether Dell's logging and monitoring practices were adequate to detect anomalous employee requests for customer information.
  • Whether Dell's technical measures, such as USB drive restrictions, were sufficient.
  • Whether Dell adequately investigated the circumstances and scope of the June 2017 breach.
  • Whether Dell adequately responded to customer complaints about potential privacy breaches (PIPEDA Principle 4.10.4).
  • Whether Dell remained responsible for personal information transferred to a third party for processing.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 30, 2020PIPEDA Findings #2020-002Indexed Jun 30, 2026

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

RateMDs.com

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

Jun 30, 2020PIPEDA Findings #2020-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Key Issues
  • Whether RateMDs collected, used, or disclosed the complainant's business contact information without consent (Principle 4.3)
  • Whether the business contact information exemption under s.4.01 of PIPEDA applied to RateMDs' use of the complainant's business contact information
  • Whether the complainant's business contact information was publicly available under s.7(1)(d), 7(2)(c.1), and 7(3)(h.1) of PIPEDA and its Regulations
  • Whether the reviews and ratings posted on RateMDs constituted the complainant's personal information
  • Whether the reviews and ratings also constituted the personal information of the users who posted them
  • Whether RateMDs required the complainant's consent to publish the reviews and ratings about her (Principle 4.3)
  • Whether a balancing of interests was required when the privacy rights of multiple individuals conflicted regarding the same personal information
  • Whether RateMDs ensured the accuracy of information and provided a fair and accessible process for health professionals to challenge and correct inaccurate information (Principle 4.6, 4.9.5)
  • Whether RateMDs made readily available specific information about its policies and practices relating to the management of personal information, particularly regarding review removal and correction (Principle 4.8)
  • Whether RateMDs' "pay-for-takedown" service, allowing subscribers to hide negative reviews for a fee, constituted an appropriate purpose for collecting, using, or disclosing personal information under s.5(3) of PIPEDA
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Jun 25, 20202020 OIC 5Indexed Jun 30, 2026

Department of Justice Canada (Re), 2020 OIC 5

Department of Justice Canada

The complainant challenged the Department of Justice Canada's (Justice) decision to withhold an entire Memorandum of Understanding (MOU) for legal services under section 23 of the Access to Information Act. Justice claimed the entire MOU was protected by solicitor-client privilege. The Commissioner found that Justice failed to demonstrate that general identifying information, such as the title and signature blocks, fell under this privilege. Furthermore, the Commissioner determined that Justice had waived its solicitor-client privilege over certain information within the MOU. Consequently, the Commissioner concluded that the complaint was well founded and recommended the release of part of the record. Justice indicated its intention to implement this recommendation.

Quick view

Access to Information ActWell-founded

Department of Justice Canada (Re), 2020 OIC 5

Jun 25, 20202020 OIC 5
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant challenged the Department of Justice Canada's (Justice) decision to withhold an entire Memorandum of Understanding (MOU) for legal services under section 23 of the Access to Information Act. Justice claimed the entire MOU was protected by solicitor-client privilege. The Commissioner found that Justice failed to demonstrate that general identifying information, such as the title and signature blocks, fell under this privilege. Furthermore, the Commissioner determined that Justice had waived its solicitor-client privilege over certain information within the MOU. Consequently, the Commissioner concluded that the complaint was well founded and recommended the release of part of the record. Justice indicated its intention to implement this recommendation.

Key Issues
  • Whether the entire Memorandum of Understanding (MOU) was protected by solicitor-client privilege under s.23 ATIA
  • Whether general identifying information (title, signature blocks) in the MOU was protected by solicitor-client privilege
  • Whether solicitor-client privilege had been waived over any information in the MOU
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
May 25, 20202020 OIC 4Indexed Jun 30, 2026

3218-00001 — National Defence

National Defence

The complainant alleged that National Defence (DND) failed to respond to an access to information request within the statutory time limits. DND argued that the request did not meet the requirements of section 6 of the Access to Information Act, which stipulates that a request must be for a record under the control of a government institution. The OIC investigated whether DND's decision not to process the request was justified. The Commissioner found that DND had made numerous attempts to clarify the request with the applicant, but the applicant did not provide the necessary clarification to enable DND to identify the records sought. Consequently, the Commissioner concluded that DND was not obligated to process a request that did not adequately describe the records. The complaint was therefore deemed not well-founded.

Quick view

Access to Information ActNot well-founded

3218-00001 — National Defence

May 25, 20202020 OIC 4
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that National Defence (DND) failed to respond to an access to information request within the statutory time limits. DND argued that the request did not meet the requirements of section 6 of the Access to Information Act, which stipulates that a request must be for a record under the control of a government institution. The OIC investigated whether DND's decision not to process the request was justified. The Commissioner found that DND had made numerous attempts to clarify the request with the applicant, but the applicant did not provide the necessary clarification to enable DND to identify the records sought. Consequently, the Commissioner concluded that DND was not obligated to process a request that did not adequately describe the records. The complaint was therefore deemed not well-founded.

Key Issues
  • Whether the access request met the requirements of section 6 of the Access to Information Act
  • Whether National Defence was justified in not processing the request due to lack of clarity
  • Whether National Defence failed to respond within the statutory time limits
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 3, 20203215-00087Indexed Jun 30, 2026

Canadian Human Rights Commission (Re), 2020 OIC 3

Canadian Human Rights Commission

The complainant challenged the Canadian Human Rights Commission's (CHRC) decision to withhold information under subsections 19(1) (personal information), section 22 (testing/auditing procedures), and section 23 (solicitor-client privilege) of the Access to Information Act. During the investigation, the CHRC agreed to release all information previously withheld under section 22 and some under section 23. The OIC found that while some information met the requirements for personal information under s.19(1), specific file numbers did not, as their disclosure would not identify an individual. Regarding solicitor-client privilege, the OIC found that certain draft investigation reports were not shown to have received legal review or advice, thus not meeting the exemption's criteria. The Commissioner recommended the disclosure of the file numbers and the draft investigation reports. The CHRC agreed to the recommendations and released the additional information.

Quick view

Access to Information ActWell-founded

Canadian Human Rights Commission (Re), 2020 OIC 3

Apr 3, 20203215-00087
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant challenged the Canadian Human Rights Commission's (CHRC) decision to withhold information under subsections 19(1) (personal information), section 22 (testing/auditing procedures), and section 23 (solicitor-client privilege) of the Access to Information Act. During the investigation, the CHRC agreed to release all information previously withheld under section 22 and some under section 23. The OIC found that while some information met the requirements for personal information under s.19(1), specific file numbers did not, as their disclosure would not identify an individual. Regarding solicitor-client privilege, the OIC found that certain draft investigation reports were not shown to have received legal review or advice, thus not meeting the exemption's criteria. The Commissioner recommended the disclosure of the file numbers and the draft investigation reports. The CHRC agreed to the recommendations and released the additional information.

Key Issues
  • Whether s.19(1) personal information exemption applies to personal contact information of government employees, leave information, and names of CHRC complainants
  • Whether s.19(1) personal information exemption applies to file numbers
  • Whether the institution reasonably exercised discretion under s.19(2) for applicable personal information
  • Whether s.22 testing/auditing procedures exemption applies
  • Whether s.23 solicitor-client privilege exemption applies to communications between client and counsel for legal advice
  • Whether s.23 solicitor-client privilege exemption applies to draft investigation reports
  • Whether the institution reasonably exercised discretion under s.23 for applicable solicitor-client privileged information
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Mar 31, 2020Indexed Jun 30, 2026

CBSA should only retain travellers’ digital device passcodes when necessary

Canada Border Services Agency (CBSA)

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Quick view

Privacy ActResolved

CBSA should only retain travellers’ digital device passcodes when necessary

Mar 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Key Issues
  • Whether the CBSA has the authority to require a traveller to provide a passcode to unlock a digital device for inspection purposes under the Customs Act
  • Whether the CBSA officer followed internal policies regarding the collection and retention of personal information (passcodes)
  • Whether the CBSA's retention of the passcode was necessary beyond the examination process when no further action was taken
  • Whether passcodes constitute sensitive personal information
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Feb 18, 20202020 OIC 2Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2020 OIC 2

Royal Canadian Mounted Police

The Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request for over two years, leading to a deemed refusal under the Access to Information Act. During the investigation, the RCMP provided insufficient information regarding the records or the processing of the request to establish a reasonable response date. Due to the continued lack of response, the Information Commissioner found the complaint to be well-founded. The Commissioner ordered the RCMP to respond to the access request within 10 business days from the effective date of the order. However, the RCMP ultimately responded to the request before the order officially came into effect.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2020 OIC 2

Feb 18, 20202020 OIC 2
Adjudicator: Caroline Maynard
Plain-Language Summary

The Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request for over two years, leading to a deemed refusal under the Access to Information Act. During the investigation, the RCMP provided insufficient information regarding the records or the processing of the request to establish a reasonable response date. Due to the continued lack of response, the Information Commissioner found the complaint to be well-founded. The Commissioner ordered the RCMP to respond to the access request within 10 business days from the effective date of the order. However, the RCMP ultimately responded to the request before the order officially came into effect.

Key Issues
  • Whether the institution failed to respond to an access request within the statutory time limits (deemed refusal)
  • Whether the institution provided sufficient information to justify the delay
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 31, 2020Indexed Jun 30, 2026

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Employment and Social Development Canada (ESDC)

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Quick view

Privacy ActWell-founded

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Jan 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Key Issues
  • Whether the collection of video surveillance footage constituted personal information under s.3 of the Privacy Act
  • Whether the initial collection of video surveillance footage by ESDC was in compliance with s.4 of the Privacy Act
  • Whether ESDC informed individuals of the purpose for collecting personal information via video surveillance, as required by s.5 of the Privacy Act
  • Whether ESDC's use of video surveillance footage to monitor an employee's departure times was consistent with the purpose for which it was collected, as required by s.7(a) of the Privacy Act
  • Whether ESDC obtained consent for the use of video surveillance footage for purposes other than security, as required by s.7(a) of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jan 15, 2020Indexed Jun 30, 2026

Public disclosure of medical information during military trial consistent with Privacy Act

Department of National Defence

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

Public disclosure of medical information during military trial consistent with Privacy Act

Jan 15, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Key Issues
  • Whether the Privacy Act applies to military summary trial proceedings conducted by the Canadian Forces
  • Whether the disclosure of the complainant's medical information during the summary trial was made in accordance with section 8 of the Privacy Act
  • Whether the information became publicly available under section 69(2) of the Privacy Act once disclosed in an open court proceeding
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Jan 14, 20205819-00733Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2020 OIC 1

Royal Canadian Mounted Police

The complainant alleged that the Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request within the statutory time limits. The request, submitted on July 3, 2018, had a due date of August 2, 2018. The RCMP was deemed to have refused access under subsection 10(3) of the Act as it did not respond or take an extension. Despite multiple requests from the OIC for information regarding the delay and a proposed disclosure date, the RCMP provided no rationale for the delay, only citing high volume and resource pressures. The OIC found that the responsive records were not voluminous or complex and had been in the RCMP's possession since July 2018. An initial report with an intended order was sent to the Minister, but before the order could be issued, the RCMP released the records. Consequently, the complaint was found to be well-founded, but no order was issued as the records were released.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2020 OIC 1

Jan 14, 20205819-00733
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request within the statutory time limits. The request, submitted on July 3, 2018, had a due date of August 2, 2018. The RCMP was deemed to have refused access under subsection 10(3) of the Act as it did not respond or take an extension. Despite multiple requests from the OIC for information regarding the delay and a proposed disclosure date, the RCMP provided no rationale for the delay, only citing high volume and resource pressures. The OIC found that the responsive records were not voluminous or complex and had been in the RCMP's possession since July 2018. An initial report with an intended order was sent to the Minister, but before the order could be issued, the RCMP released the records. Consequently, the complaint was found to be well-founded, but no order was issued as the records were released.

Key Issues
  • Whether the institution responded to the access request within the statutory time limits
  • Whether the institution was deemed to have refused access under subsection 10(3) of the Act
  • Whether the institution provided adequate rationale for the delay in responding
  • Whether the institution provided a reasonable disclosure date
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 30, 2019Indexed Jun 30, 2026

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Department of National Defence and Department of Justice

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Quick view

Privacy ActNot well-founded

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Dec 30, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Key Issues
  • Whether the collection of the complainant's personal medical information by the DOJ from the DND contravened the Privacy Act
  • Whether the disclosure of the complainant's personal medical information by the DND to the DOJ contravened the Privacy Act
  • Whether the collection by DOJ related directly to an operating program or activity of the institution under s.4 of the Privacy Act
  • Whether the collection by DOJ was permissible under s.5(1) of the Privacy Act given the disclosure under s.8(2)(d)
  • Whether the disclosure by DND was to the Attorney General of Canada under s.8(2)(d) of the Privacy Act
  • Whether the disclosure by DND was for use in legal proceedings involving the Crown in right of Canada or the Government of Canada under s.8(2)(d) of the Privacy Act
  • Whether the sensitivity of medical information impacts the permissibility of disclosure under the Privacy Act
  • Whether doctor-patient confidentiality prevents disclosure under the Privacy Act for litigation purposes
  • Whether the safeguarding measures for the disclosed information were adequate
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Dec 9, 2019PIPEDA Findings #2019-007Indexed Jun 30, 2026

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Trans Union of Canada, Inc.

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Dec 9, 2019PIPEDA Findings #2019-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Key Issues
  • Whether TransUnion disclosed the complainant's credit file information to Statistics Canada without requisite consent
  • Whether TransUnion was authorized to disclose personal information without consent under PIPEDA subparagraph 7(3)(c.1)(iii)
  • Whether Statistics Canada identified its lawful authority to obtain the information
  • Whether the disclosure was requested to administer a law of Canada (the Statistics Act)
  • Whether Statistics Canada subsequently disclosed the complainant's credit file information to other government institutions for debt collection
  • Whether there was sufficient evidence to support the allegation of information misuse for debt collection
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 21, 2019Indexed Jun 30, 2026

Crossing the line? The CBSA’s examination of digital devices at the border

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Quick view

Privacy ActWell-founded

Crossing the line? The CBSA’s examination of digital devices at the border

Oct 21, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Key Issues
  • Whether CBSA's collection of personal information via digital device searches contravened section 4 of the Privacy Act.
  • Whether the definition of "goods" under the Customs Act extends to electronic documents on digital devices.
  • Whether CBSA's authority to search digital devices is limited to information stored on the device.
  • Whether Border Services Officers (BSOs) complied with CBSA's internal policy (Operational Bulletin PRG-2015-31) regarding digital device examinations (e.g., airplane mode, note-taking, search threshold).
  • Whether the copying of content from a digital device by a BSO was consistent with CBSA's legal authority and policy.
  • Whether the CBSA complied with its obligations under subsection 6(1) of the Privacy Act to retain personal information used for administrative purposes.
  • Whether the CBSA's practices regarding training, awareness, and accountability mechanisms for digital device searches were adequate.
  • Whether the Customs Act requires amendment to include a clear legal framework and a higher threshold for digital device examinations.
  • Whether the threshold for digital device examinations should be "reasonable grounds to suspect".