The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

47 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-004Indexed Jun 30, 2026

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Fido Solutions Inc. (a subsidiary of Rogers Communications Inc.)

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Mar 30, 2021PIPEDA Findings #2021-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Key Issues
  • Whether Fido adequately safeguarded the Complainant’s personal information under Principle 4.7
  • Whether Fido responded to the Complainant’s access request in a generally understandable format under Principle 4.9 and 4.9.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 29, 2021PIPEDA Findings #2021-002Indexed Jun 30, 2026

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

CoreFour Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

Mar 29, 2021PIPEDA Findings #2021-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Key Issues
  • Whether CoreFour's security safeguards were appropriate to the sensitivity and volume of personal information under Principle 4.7 PIPEDA
  • Whether CoreFour's weak password requirements for certain Edsby parental accounts constituted an inadequate safeguard
  • Whether CoreFour's safeguards to protect against unauthorized access to thumbnail images of student profile pictures were adequate
  • Whether Edsby's failure to scan for malware when uploading content from third-party applications constituted a safeguard weakness
  • Whether CoreFour lacked a robust overarching information security framework, contravening Principle 4.1.4 and 4.7-4.7.3 PIPEDA
  • Whether CoreFour had an adequate mechanism for handling and reporting privacy breaches under PIPEDA
  • Whether CoreFour was required to report the password management vulnerability, given it occurred before mandatory breach reporting came into effect
  • Whether the student image vulnerability created a "real risk of significant harm" requiring mandatory reporting and notification under s.10.1 PIPEDA
  • Whether CoreFour maintained a breach register as required under s.10.3 PIPEDA
  • Whether CoreFour lacked a privacy management framework, including appropriate written internal policies and practices (e.g., complaint handling, data retention), contravening Principle 4.1.4 PIPEDA
  • Whether CoreFour provided adequate privacy training to its employees, consultants, contractors, and students
  • Whether CoreFour's Privacy Policy was unclear regarding the characterization of personal information, its responsibility for security, and the sharing of user information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 24, 2021PIPEDA Findings #2021-007Indexed Jun 30, 2026

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

A computer services company

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

Mar 24, 2021PIPEDA Findings #2021-007
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Key Issues
  • Whether the respondent obtained meaningful consent prior to remotely accessing laptops
  • Whether the respondent had adequate safeguards to prevent unauthorized access to customers’ personal information by its personnel
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 22, 2021PIPEDA Findings #2021-008Indexed Jun 30, 2026

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Oculus Transport Ltd.

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Mar 22, 2021PIPEDA Findings #2021-008
Adjudicator: Daniel Therrien
Plain-Language Summary

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Key Issues
  • Whether the collection and use of personal information via audio surveillance technology was for purposes that a reasonable person would consider appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the personal information collected was sensitive
  • Whether the organization's purpose represented a legitimate need / bona fide business interest
  • Whether the collection, use and disclosure would be effective in meeting the organization’s need
  • Whether there are less privacy invasive means of achieving the same ends at comparable cost and with comparable benefits
  • Whether the loss of privacy is proportional to the benefits
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Mar 18, 20215819-00626Indexed Jun 30, 2026

Innovation, Science and Economic Development Canada (Re), 2021 OIC 8

Innovation, Science and Economic Development Canada

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) took an unreasonable extension of time to respond to an access request related to the Competition Bureau’s bread price-fixing investigation. ISED claimed a 1,460-day extension under paragraph 9(1)(a) of the Access to Information Act, citing the large volume of records (over 75 million pages) and the need to search 100 terabytes of information. The OIC found that the request involved a large number of records and that meeting the 30-day deadline would unreasonably interfere with ISED's operations. The OIC also determined that ISED applied sufficient rigour in calculating the extension, considering the time needed by the program area and the Access to Information and Privacy Office, and the complexity of the records. Consequently, the OIC concluded that the 1,460-day extension was reasonable and justified. The complaint was not well founded, and the OIC invited ISED to consider disclosing completed packages of records as they become available.

Quick view

Access to Information ActNot well-founded

Innovation, Science and Economic Development Canada (Re), 2021 OIC 8

Mar 18, 20215819-00626
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) took an unreasonable extension of time to respond to an access request related to the Competition Bureau’s bread price-fixing investigation. ISED claimed a 1,460-day extension under paragraph 9(1)(a) of the Access to Information Act, citing the large volume of records (over 75 million pages) and the need to search 100 terabytes of information. The OIC found that the request involved a large number of records and that meeting the 30-day deadline would unreasonably interfere with ISED's operations. The OIC also determined that ISED applied sufficient rigour in calculating the extension, considering the time needed by the program area and the Access to Information and Privacy Office, and the complexity of the records. Consequently, the OIC concluded that the 1,460-day extension was reasonable and justified. The complaint was not well founded, and the OIC invited ISED to consider disclosing completed packages of records as they become available.

Key Issues
  • Whether the request was for a large number of records or required searching through a large number of records under paragraph 9(1)(a)
  • Whether meeting the 30-day deadline would unreasonably interfere with the institution’s operations under paragraph 9(1)(a)
  • Whether the extension of time was for a reasonable period, given the circumstances, under paragraph 9(1)(a)
  • Whether the institution validly claimed the extension of time by notifying the requester within 30 days
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Mar 16, 20213217-01373Indexed Jun 30, 2026

3217-01373 — Public Safety Canada and Royal Canadian Mounted Police

Public Safety Canada

The complainant alleged that Public Safety Canada (Public Safety) improperly refused to process an access request for records related to keywords such as 'counter-radicalization' and 'cyber radicalization', including associated metadata. Public Safety argued that portions of the request did not meet the requirements of section 6 of the Access to Information Act due to the expansive volume of records and the complexity of identifying relevant information. The Commissioner agreed that some parts of the request were too broad, but found that other parts (Paragraph 1 and Schedule A) were sufficiently detailed and should have been processed. The Commissioner also determined that Public Safety failed to meet its legislated obligations by not claiming an extension of time and by refusing to process any part of the request. The complaint was found to be well founded, and Public Safety committed to processing the valid portions of the request at a rate of 5,000 pages per year.

Quick view

Access to Information ActWell-founded

3217-01373 — Public Safety Canada and Royal Canadian Mounted Police

Mar 16, 20213217-01373
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Public Safety Canada (Public Safety) improperly refused to process an access request for records related to keywords such as 'counter-radicalization' and 'cyber radicalization', including associated metadata. Public Safety argued that portions of the request did not meet the requirements of section 6 of the Access to Information Act due to the expansive volume of records and the complexity of identifying relevant information. The Commissioner agreed that some parts of the request were too broad, but found that other parts (Paragraph 1 and Schedule A) were sufficiently detailed and should have been processed. The Commissioner also determined that Public Safety failed to meet its legislated obligations by not claiming an extension of time and by refusing to process any part of the request. The complaint was found to be well founded, and Public Safety committed to processing the valid portions of the request at a rate of 5,000 pages per year.

Key Issues
  • Whether the request provided sufficient detail to enable an experienced employee to identify records with reasonable effort (s.6 ATIA)
  • Whether Public Safety was justified in refusing to process the entire request if only parts of it met s.6 ATIA requirements
  • Whether Public Safety complied with its obligation to claim an extension of time under s.9(1) ATIA
  • Whether Public Safety made every reasonable effort to assist the requester (s.4(2.1) ATIA)
  • Whether Public Safety was required to consult on the term 'metadata' and provide records in the requested format
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 15, 2021PIPEDA Findings #2021-005Indexed Jun 30, 2026

PIPEDA Findings #2021-005: Staying signed in by default to email services poses serious privacy concerns for users accessing their email on a public or shared computer

Yahoo! Canada

The complainant alleged that Yahoo! Canada's default "Stay signed in" setting for Yahoo Mail, particularly for Rogers Yahoo Mail users, posed significant privacy concerns on public or shared computers. The OPC investigated whether Yahoo adequately safeguarded against unauthorized access and obtained valid consent for potential disclosures. The OPC found that Yahoo's safeguards were not appropriate for the sensitivity of email content and that its consent for the "Stay signed in" setting was not meaningful. Yahoo committed to changing the setting to opt-in and providing clearer information about privacy implications. Rogers, while not a respondent, also agreed to implement measures for Rogers Yahoo Mail users. The complaint was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-005: Staying signed in by default to email services poses serious privacy concerns for users accessing their email on a public or shared computer

Mar 15, 2021PIPEDA Findings #2021-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Yahoo! Canada's default "Stay signed in" setting for Yahoo Mail, particularly for Rogers Yahoo Mail users, posed significant privacy concerns on public or shared computers. The OPC investigated whether Yahoo adequately safeguarded against unauthorized access and obtained valid consent for potential disclosures. The OPC found that Yahoo's safeguards were not appropriate for the sensitivity of email content and that its consent for the "Stay signed in" setting was not meaningful. Yahoo committed to changing the setting to opt-in and providing clearer information about privacy implications. Rogers, while not a respondent, also agreed to implement measures for Rogers Yahoo Mail users. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether Yahoo's safeguards against unauthorized third-party access to email content on public or shared computers were adequate under Principle 4.7 PIPEDA
  • Whether Yahoo obtained valid and meaningful consent for the disclosure of personal information to others who subsequently access emails via the "Stay signed in" setting under Principle 4.3 PIPEDA
  • Whether the "Stay signed in" setting was clearly and prominently displayed
  • Whether a reasonable person would understand the "Stay signed in" setting to be "on" by default
  • Whether the "Stay signed in" setting is consistent with industry standards
  • Whether Yahoo's additional safeguards (algorithm, sign-out option, session expiration, password reset, security information) were effective
  • Whether express opt-in consent was required for the "Stay signed in" setting due to sensitivity of information, reasonable expectations, and risk of harm
  • Whether the language "stay signed in" provided users with key information for meaningful consent
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Mar 12, 20215820-00869Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2021 OIC 6

Royal Canadian Mounted Police

The complainant alleged that the Royal Canadian Mounted Police (RCMP) improperly withheld information under subsection 19(1) of the Access to Information Act, concerning a follow-up investigation related to a Code of Conduct decision against the complainant. During the investigation, the RCMP conceded that some of the withheld information was not personal information and issued a supplementary release. However, the RCMP maintained the application of subsection 19(1) on the remaining information. The Office of the Information Commissioner (OIC) found that the remaining withheld information was indeed personal information about another individual, meeting the requirements of the exemption. The OIC also concluded that none of the circumstances under subsection 19(2) that would warrant disclosure existed. Therefore, the complaint was found to be well founded because the RCMP initially withheld information that was not personal information, but the OIC upheld the exemption for the remaining records.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2021 OIC 6

Mar 12, 20215820-00869
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Royal Canadian Mounted Police (RCMP) improperly withheld information under subsection 19(1) of the Access to Information Act, concerning a follow-up investigation related to a Code of Conduct decision against the complainant. During the investigation, the RCMP conceded that some of the withheld information was not personal information and issued a supplementary release. However, the RCMP maintained the application of subsection 19(1) on the remaining information. The Office of the Information Commissioner (OIC) found that the remaining withheld information was indeed personal information about another individual, meeting the requirements of the exemption. The OIC also concluded that none of the circumstances under subsection 19(2) that would warrant disclosure existed. Therefore, the complaint was found to be well founded because the RCMP initially withheld information that was not personal information, but the OIC upheld the exemption for the remaining records.

Key Issues
  • Whether the information initially withheld by the RCMP constituted personal information under s.19(1) ATIA
  • Whether the remaining withheld information was personal information about another individual under s.19(1) ATIA
  • Whether the circumstances for disclosure under s.19(2) ATIA existed
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Mar 12, 2021PIPEDA Findings #2021-006Indexed Jun 30, 2026

PIPEDA Findings #2021-006: A short-term lender collects online banking credentials in the course of payday loan applications

CashHere (2124478 Ontario Corporation)

The OPC initiated an investigation into CashHere, a short-term lender, after being alerted by the Ontario Ministry of Government and Consumer Services that it was collecting online banking credentials (passwords, usernames, security questions/answers) from loan applicants. The OPC found that while CashHere had a legitimate need to validate identity and income, collecting banking credentials was not an appropriate purpose under PIPEDA s. 5(3) due to less privacy-invasive alternatives and disproportionate privacy risks. The investigation also noted that a related entity, MoneyHome, appeared to be continuing the same practices. CashHere ceased responding to the OPC, and the matter was found to be well-founded and unresolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2021-006: A short-term lender collects online banking credentials in the course of payday loan applications

Mar 12, 2021PIPEDA Findings #2021-006
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated an investigation into CashHere, a short-term lender, after being alerted by the Ontario Ministry of Government and Consumer Services that it was collecting online banking credentials (passwords, usernames, security questions/answers) from loan applicants. The OPC found that while CashHere had a legitimate need to validate identity and income, collecting banking credentials was not an appropriate purpose under PIPEDA s. 5(3) due to less privacy-invasive alternatives and disproportionate privacy risks. The investigation also noted that a related entity, MoneyHome, appeared to be continuing the same practices. CashHere ceased responding to the OPC, and the matter was found to be well-founded and unresolved.

Key Issues
  • Whether CashHere's collection of online banking login credentials was for a purpose that a reasonable person would consider appropriate under s. 5(3) of PIPEDA
  • Whether the collection of banking credentials was effective in meeting CashHere's legitimate need
  • Whether there were less privacy-invasive means of achieving the same ends
  • Whether the loss of privacy was proportional to the benefits for CashHere
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Mar 5, 20212021 OIC 5Indexed Jun 30, 2026

Canadian Security Intelligence Service (Re), 2021 OIC 5

Canadian Security Intelligence Service

The complainant alleged that the Canadian Security Intelligence Service (CSIS) took an unreasonable time extension under paragraph 9(1)(b) of the Access to Information Act for consultations. CSIS justified a 240-day extension, citing the necessity of consulting with two other government institutions, the high classification and sensitivity of the records, the need for on-site review, and limited workplace access due to the pandemic. The Office of the Information Commissioner (OIC) found that CSIS made a serious effort to determine the extension's length based on the pandemic's realities. The OIC concluded that the time extension was reasonable given the circumstances and that CSIS met the three requirements for claiming such an extension. Therefore, the complaint was not well founded.

Quick view

Access to Information ActNot well-founded

Canadian Security Intelligence Service (Re), 2021 OIC 5

Mar 5, 20212021 OIC 5
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Canadian Security Intelligence Service (CSIS) took an unreasonable time extension under paragraph 9(1)(b) of the Access to Information Act for consultations. CSIS justified a 240-day extension, citing the necessity of consulting with two other government institutions, the high classification and sensitivity of the records, the need for on-site review, and limited workplace access due to the pandemic. The Office of the Information Commissioner (OIC) found that CSIS made a serious effort to determine the extension's length based on the pandemic's realities. The OIC concluded that the time extension was reasonable given the circumstances and that CSIS met the three requirements for claiming such an extension. Therefore, the complaint was not well founded.

Key Issues
  • Whether the time extension taken under paragraph 9(1)(b) for consultations was reasonable
  • Whether CSIS met the three requirements to claim the time extension
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Feb 24, 20212021 OIC 26Indexed Jun 30, 2026

Global Affairs Canada (Re), 2021 OIC 26

Global Affairs Canada

The Office of the Information Commissioner (OIC) received nine complaints regarding Global Affairs Canada's (GAC) failure to respond to nine access requests within the statutory deadlines or taking unreasonable time extensions. GAC cited the COVID-19 pandemic as a significant factor impacting its ability to process these requests. Despite the challenges, GAC committed to providing a final response for all nine files by October 15, 2021. The Commissioner found all nine complaints to be well founded, indicating that GAC improperly delayed access to the requested information. This decision highlights the institution's obligation to meet timelines under the Access to Information Act, even when facing operational difficulties.

Quick view

Access to Information ActWell-founded

Global Affairs Canada (Re), 2021 OIC 26

Feb 24, 20212021 OIC 26
Adjudicator: Caroline Maynard
Plain-Language Summary

The Office of the Information Commissioner (OIC) received nine complaints regarding Global Affairs Canada's (GAC) failure to respond to nine access requests within the statutory deadlines or taking unreasonable time extensions. GAC cited the COVID-19 pandemic as a significant factor impacting its ability to process these requests. Despite the challenges, GAC committed to providing a final response for all nine files by October 15, 2021. The Commissioner found all nine complaints to be well founded, indicating that GAC improperly delayed access to the requested information. This decision highlights the institution's obligation to meet timelines under the Access to Information Act, even when facing operational difficulties.

Key Issues
  • Whether Global Affairs Canada failed to respond to access requests within the statutory deadlines
  • Whether Global Affairs Canada took unreasonable time extensions for access requests
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Feb 9, 20215820-00879Indexed Jun 30, 2026

5820-00879 — Royal Canadian Mounted Police

Royal Canadian Mounted Police

The complainant alleged that the Royal Canadian Mounted Police (RCMP) improperly withheld information under paragraph 16(1)(a) of the Access to Information Act. The requested information pertained to a complaint investigated by the RCMP. The OIC's investigation determined that the withheld information was obtained by the RCMP, an investigative body specified in the regulations, during a lawful investigation related to the detection, prevention, or suppression of crime. Furthermore, the information was created less than twenty years before the request. The OIC also found that the RCMP reasonably exercised its discretion by considering relevant factors for and against disclosure, including the purpose of the Act and the private interests of other individuals. Consequently, the OIC concluded that the information met the requirements for exemption under paragraph 16(1)(a) and that the institution's decision to withhold it was appropriate.

Quick view

Access to Information ActNot well-founded

5820-00879 — Royal Canadian Mounted Police

Feb 9, 20215820-00879
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Royal Canadian Mounted Police (RCMP) improperly withheld information under paragraph 16(1)(a) of the Access to Information Act. The requested information pertained to a complaint investigated by the RCMP. The OIC's investigation determined that the withheld information was obtained by the RCMP, an investigative body specified in the regulations, during a lawful investigation related to the detection, prevention, or suppression of crime. Furthermore, the information was created less than twenty years before the request. The OIC also found that the RCMP reasonably exercised its discretion by considering relevant factors for and against disclosure, including the purpose of the Act and the private interests of other individuals. Consequently, the OIC concluded that the information met the requirements for exemption under paragraph 16(1)(a) and that the institution's decision to withhold it was appropriate.

Key Issues
  • Whether the information was obtained or prepared by an investigative body listed in Schedule I of the Access to Information Regulations
  • Whether the information was obtained or prepared during a lawful investigation within the authority of the investigative body
  • Whether the investigation concerned the detection, prevention, or suppression of crime, enforcement of law, or threats to security of Canada
  • Whether the information was created less than 20 years before the access request
  • Whether the institution reasonably exercised its discretion to decide whether to release the information under s.16(1)(a)
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Feb 3, 20215819-01344Indexed Jun 30, 2026

5819-01344 — Canada Revenue Agency

Canada Revenue Agency

The complainant alleged that the Canada Revenue Agency (CRA) improperly withheld information under subsection 24(1) of the Access to Information Act. The request sought income-related information regarding business ownership for a specific individual. The CRA claimed that the information was exempt from disclosure because section 241 of the Income Tax Act (ITA) restricts its release. The Office of the Information Commissioner (OIC) found that the requested information constituted "taxpayer information" as defined in subsection 241(10) of the ITA, meaning it related to an identifiable taxpayer (not the complainant) and was obtained by the CRA for administering the ITA. Consequently, the OIC concluded that the information met the requirements for exemption under subsection 24(1) of the ATIA. The complaint was therefore deemed not well founded.

Quick view

Access to Information ActNot well-founded

5819-01344 — Canada Revenue Agency

Feb 3, 20215819-01344
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Canada Revenue Agency (CRA) improperly withheld information under subsection 24(1) of the Access to Information Act. The request sought income-related information regarding business ownership for a specific individual. The CRA claimed that the information was exempt from disclosure because section 241 of the Income Tax Act (ITA) restricts its release. The Office of the Information Commissioner (OIC) found that the requested information constituted "taxpayer information" as defined in subsection 241(10) of the ITA, meaning it related to an identifiable taxpayer (not the complainant) and was obtained by the CRA for administering the ITA. Consequently, the OIC concluded that the information met the requirements for exemption under subsection 24(1) of the ATIA. The complaint was therefore deemed not well founded.

Key Issues
  • Whether the requested information falls under the definition of "taxpayer information" in subsection 241(10) of the Income Tax Act
  • Whether section 241 of the Income Tax Act restricts the disclosure of the requested information
  • Whether subsection 24(1) of the Access to Information Act applies to exempt the information from disclosure
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
Feb 2, 20215820-01453Indexed Apr 21, 2026

Correctional Service of Canada, 5820-01453

The Information Commissioner ordered Correctional Service of Canada to provide a final response to the access request submitted on December 3, 2018.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Correctional Service of Canada, 5820-01453

Feb 2, 20215820-01453

The Information Commissioner ordered Correctional Service of Canada to provide a final response to the access request submitted on December 3, 2018.

Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Feb 2, 2021PIPEDA Findings #2021-001Indexed Jun 30, 2026

PIPEDA Findings #2021-001: Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta

Clearview AI, Inc.

A joint investigation by Canadian privacy commissioners examined Clearview AI's facial recognition tool, which scraped billions of images from public websites to create a database for law enforcement and other users. Clearview argued that Canadian privacy laws did not apply due to a lack of jurisdiction and that the information was "publicly available," thus exempt from consent requirements. The Offices asserted jurisdiction, finding a real and substantial connection to Canada through Clearview's marketing and use by Canadian entities. They determined Clearview failed to obtain requisite consent, as the "publicly available" exception did not apply to sensitive biometric data scraped from social media for unrelated purposes. Furthermore, Clearview's mass collection and use of sensitive facial biometric information for commercial purposes were deemed inappropriate. In Quebec, Clearview also failed to report its biometric database and obtain express consent as required by law. The matter was found to be well-founded, with recommendations for Clearview to cease operations in Canada and delete Canadian data, which Clearview did not commit to implementing.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2021-001: Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta

Feb 2, 2021PIPEDA Findings #2021-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A joint investigation by Canadian privacy commissioners examined Clearview AI's facial recognition tool, which scraped billions of images from public websites to create a database for law enforcement and other users. Clearview argued that Canadian privacy laws did not apply due to a lack of jurisdiction and that the information was "publicly available," thus exempt from consent requirements. The Offices asserted jurisdiction, finding a real and substantial connection to Canada through Clearview's marketing and use by Canadian entities. They determined Clearview failed to obtain requisite consent, as the "publicly available" exception did not apply to sensitive biometric data scraped from social media for unrelated purposes. Furthermore, Clearview's mass collection and use of sensitive facial biometric information for commercial purposes were deemed inappropriate. In Quebec, Clearview also failed to report its biometric database and obtain express consent as required by law. The matter was found to be well-founded, with recommendations for Clearview to cease operations in Canada and delete Canadian data, which Clearview did not commit to implementing.

Key Issues
  • Whether the Canadian privacy commissioners had jurisdiction over Clearview AI's activities.
  • Whether Clearview AI obtained requisite consent for its collection, use, and disclosure of personal information under PIPEDA, PIPA AB, PIPA BC, and Quebec's Private Sector Act.
  • Whether the "publicly available" information exception applied to Clearview AI's collection of images from public websites.
  • Whether Clearview AI's collection, use, and disclosure of personal information was for an appropriate purpose under PIPEDA, PIPA AB, PIPA BC, and Quebec's Private Sector Act.
  • Whether Clearview AI satisfied its biometric obligations in Quebec, specifically regarding reporting the creation of a biometric database and obtaining express consent under the LCCJTI.
  • Whether Clearview AI's activities were protected by freedom of expression under the Canadian Charter of Rights and Freedoms.