The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

607 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 21, 2016PIPEDA Report of Findings #2016-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Compu-Finder (3510395 Canada Inc.)

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Apr 21, 2016PIPEDA Report of Findings #2016-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Key Issues
  • Whether Compu-Finder's collection and use of email addresses constituted "personal information" under PIPEDA.
  • Whether the business contact information carve-out under s. 4.01 PIPEDA applied to Compu-Finder's activities.
  • Whether Compu-Finder obtained meaningful express consent for collecting email addresses via telemarketing (Principles 4.2, 4.3, 4.3.2).
  • Whether Compu-Finder collected personal information by fair and lawful means (Principle 4.4).
  • Whether Compu-Finder obtained meaningful implied consent for collecting email addresses from publicly available sources (Principle 4.3.6).
  • Whether the "publicly available information" exemption (s. 7(1)(d), 7(2)(c.1) PIPEDA and s. 1 of the Regulations) applied to Compu-Finder's collection and use of email addresses.
  • Whether the address harvesting provisions (s. 7.1(2) PIPEDA) prohibited the use of email addresses collected via software before the provision came into force.
  • Whether Compu-Finder had a designated individual accountable for PIPEDA compliance (Principle 4.1).
  • Whether Compu-Finder implemented policies and practices to give effect to PIPEDA principles (Principle 4.1.4).
  • Whether Compu-Finder was open about its personal information management policies and practices (Principles 4.8.1, 4.8.2).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2016PIPEDA Case Summary #2016-012Indexed Jun 30, 2026

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

A bank associated with a retailer

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

Mar 31, 2016PIPEDA Case Summary #2016-012
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Key Issues
  • Whether the bank obtained valid consent for a credit card application and credit check under Principle 4.3
  • Whether the bank ensured the accuracy of personal information collected under Principle 4.6
  • Whether the bank had adequate procedures to give effect to PIPEDA principles under Principle 4.1.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 10, 2016PIPEDA Case Summary #2016-009Indexed Jun 30, 2026

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

An international trucking company

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

Mar 10, 2016PIPEDA Case Summary #2016-009
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Key Issues
  • Whether the disclosure of drug test results to the WCB without consent contravened PIPEDA Principles 4.3 and 4.5
  • Whether the employer had a legal obligation to disclose the drug test results to the WCB under the provincial Workers' Compensation Act, thereby qualifying for an exception to consent under paragraph 7(3)(i) of PIPEDA
  • Whether the employer disclosed the drug test results to co-workers without consent
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 24, 2016Incident Summary #12Indexed Jun 30, 2026

Incident Summary #12: Break with security procedures exposes financial planner’s client to privacy breach

A financial management firm

A financial management firm's employees breached internal security procedures by sending a client's detailed financial plan and federal income tax notice of assessment, containing sensitive personal information including her social insurance number, to her personal email account without secure messaging tools. The client's email account was subsequently hacked, and the alleged hacker used the obtained information to pose as the client and request a significant transfer from her investment account. An employee processed this transfer without following authentication procedures. Although the client's money was not stolen, the firm investigated the incident, advised the client to change passwords, informed the RCMP, and offered credit monitoring. The firm also took measures with the responsible employees, provided additional privacy training to staff, and reviewed its internal processes. The OPC considered the firm's response appropriate.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #12: Break with security procedures exposes financial planner’s client to privacy breach

Feb 24, 2016Incident Summary #12
Adjudicator: Daniel Therrien
Plain-Language Summary

A financial management firm's employees breached internal security procedures by sending a client's detailed financial plan and federal income tax notice of assessment, containing sensitive personal information including her social insurance number, to her personal email account without secure messaging tools. The client's email account was subsequently hacked, and the alleged hacker used the obtained information to pose as the client and request a significant transfer from her investment account. An employee processed this transfer without following authentication procedures. Although the client's money was not stolen, the firm investigated the incident, advised the client to change passwords, informed the RCMP, and offered credit monitoring. The firm also took measures with the responsible employees, provided additional privacy training to staff, and reviewed its internal processes. The OPC considered the firm's response appropriate.

Key Issues
  • Whether the firm adequately protected personal information by sending sensitive documents via unsecure email
  • Whether the firm had adequate procedures for authenticating clients for financial transactions
  • Whether the firm's response to the privacy breach was appropriate
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 19, 2016Incident Summary #11Indexed Jun 30, 2026

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

A financial institution

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

Feb 19, 2016Incident Summary #11
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Key Issues
  • Whether the financial institution adequately safeguarded personal information during mass mail-outs
  • Whether the financial institution responded appropriately to a privacy breach involving misdirected mail
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 19, 2016PIPEDA Report of Findings #2016-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

A property management company

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

Feb 19, 2016PIPEDA Report of Findings #2016-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Key Issues
  • Whether the collection, use, and disclosure of personal information for a "bad tenant list" was for purposes that a reasonable person would consider appropriate in the circumstances (s.5(3) PIPEDA)
  • Whether the property management company was acting as an unlicensed credit reporting agency under provincial legislation
  • Whether meaningful knowledge and consent of individuals were obtained for the collection, use, and disclosure of their personal information for the "bad tenant list" (Principle 4.3, 4.3.2 PIPEDA)
  • Whether the personal information on the "bad tenant list" was accurate, complete, and up-to-date (Principle 4.6, 4.6.1 PIPEDA)
  • Whether individuals had the ability to challenge the accuracy of information about them on the list (Principle 4.10 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 12, 2016PIPEDA Report of Findings #2016-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

An insurance company

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

Feb 12, 2016PIPEDA Report of Findings #2016-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Key Issues
  • Whether the insurance company contravened Principles 4.9 and 4.9.1 by refusing access to personal information without severing third-party information
  • Whether the insurance company's internal ombudsman office constitutes a "formal dispute resolution process" under PIPEDA s.9(3)(d)
  • Whether the activities of the internal ombudsman office fall under the definition of "commercial activity" under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 9, 2016PIPEDA Case Summary #2016-007Indexed Jun 30, 2026

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

A collection agency

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

Feb 9, 2016PIPEDA Case Summary #2016-007
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the organization refused to provide access to personal information
  • Whether the organization responded to access requests within the required timeframe
  • Whether the organization followed its own privacy policies and procedures for access requests
  • Whether the organization maintained records of access request processing
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Feb 8, 2016Indexed Jun 30, 2026

Canada Post collection of online signatures for mail tracking draws complaint

Canada Post Corporation

A complaint was filed against Canada Post Corporation (CPC) regarding its collection, use, and disclosure of electronic signatures for parcel tracking. The complainant raised concerns about the clarity of information provided to addressees regarding their option to opt-out of having their signature displayed online, and the absence of labels on signature devices at a specific postal outlet. The investigation also examined the privacy and security controls of CPC's online tracking website. CPC argued that disclosure of signatures to senders was authorized under the Privacy Act and that it provided an opt-out option. The OPC found that the collection and disclosure of signatures for parcel tracking were consistent with the Act, but raised concerns about the adequacy of security controls for online signatures. CPC committed to implementing enhanced security measures.

Quick view

Privacy ActNot well-founded

Canada Post collection of online signatures for mail tracking draws complaint

Feb 8, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Canada Post Corporation (CPC) regarding its collection, use, and disclosure of electronic signatures for parcel tracking. The complainant raised concerns about the clarity of information provided to addressees regarding their option to opt-out of having their signature displayed online, and the absence of labels on signature devices at a specific postal outlet. The investigation also examined the privacy and security controls of CPC's online tracking website. CPC argued that disclosure of signatures to senders was authorized under the Privacy Act and that it provided an opt-out option. The OPC found that the collection and disclosure of signatures for parcel tracking were consistent with the Act, but raised concerns about the adequacy of security controls for online signatures. CPC committed to implementing enhanced security measures.

Key Issues
  • Whether the collection of electronic signatures by CPC contravenes the Privacy Act
  • Whether the disclosure of electronic signatures to the sender of a parcel contravenes the Privacy Act
  • Whether the disclosure of electronic signatures online contravenes the Privacy Act
  • Whether CPC adequately safeguards digitized signatures displayed online
  • Whether the information provided to addressees about opting out of online signature display is sufficiently clear
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Jan 25, 2016Incident Summary #10Indexed Jun 30, 2026

Incident Summary #10: Cable provider removes personal information posted online of customers with overdue accounts

A cable provider

The OPC was alerted to a cable provider posting a list of customers with overdue accounts and the amounts owed on a municipal Facebook page. The cable provider believed this practice was permissible, citing municipal tax arrears publications as an example. The OPC informed the provider that publicly disseminating personal information for debt collection without consent is not permitted under PIPEDA, even though disclosure to a third-party debt collector may be. The cable provider subsequently removed the posting. The OPC also clarified with the NWT Commissioner that municipal tax arrears publications are mandated by territorial law, unlike the cable provider's actions. The OPC explained that PIPEDA's debt collection exemption does not authorize public disclosure.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #10: Cable provider removes personal information posted online of customers with overdue accounts

Jan 25, 2016Incident Summary #10
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC was alerted to a cable provider posting a list of customers with overdue accounts and the amounts owed on a municipal Facebook page. The cable provider believed this practice was permissible, citing municipal tax arrears publications as an example. The OPC informed the provider that publicly disseminating personal information for debt collection without consent is not permitted under PIPEDA, even though disclosure to a third-party debt collector may be. The cable provider subsequently removed the posting. The OPC also clarified with the NWT Commissioner that municipal tax arrears publications are mandated by territorial law, unlike the cable provider's actions. The OPC explained that PIPEDA's debt collection exemption does not authorize public disclosure.

Key Issues
  • Whether publicly posting customer debt information on social media is permissible under PIPEDA
  • Whether the debt collection exemption under paragraph 7(3)(b) of PIPEDA authorizes public dissemination of personal information
  • Whether municipal practices of publishing tax arrears are comparable to private organizations publishing customer debt under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 9, 2016PIPEDA Case Summary #2016-004Indexed Jun 30, 2026

PIPEDA Case Summary #2016-004: Retailer shares customer’s in-store behaviour with the customer’s employer

A retail store

A customer complained that a retail store employee disclosed his personal information to his employer, including his name, in-store behavior, and statements made to staff. The store argued the information was not personal because it was made publicly, and that it had implied consent for the disclosure. The OPC found that information overheard by others is still personal information under PIPEDA. The OPC also determined that implied consent was not appropriate given the sensitive nature of the information, which had the potential to negatively affect the customer's employment. The store's disclosure without knowledge or consent contravened Principle 4.3 of PIPEDA. The complaint was found to be well-founded and resolved after the store implemented the OPC's recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-004: Retailer shares customer’s in-store behaviour with the customer’s employer

Jan 9, 2016PIPEDA Case Summary #2016-004
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a retail store employee disclosed his personal information to his employer, including his name, in-store behavior, and statements made to staff. The store argued the information was not personal because it was made publicly, and that it had implied consent for the disclosure. The OPC found that information overheard by others is still personal information under PIPEDA. The OPC also determined that implied consent was not appropriate given the sensitive nature of the information, which had the potential to negatively affect the customer's employment. The store's disclosure without knowledge or consent contravened Principle 4.3 of PIPEDA. The complaint was found to be well-founded and resolved after the store implemented the OPC's recommendations.

Key Issues
  • Whether the information shared was personal information under PIPEDA
  • Whether the customer provided implied consent for the disclosure of his personal information
  • Whether the disclosed information was sensitive
  • Whether the customer had a reasonable expectation that his information would be shared with his employer
  • Whether the publicly available information exception to consent applied
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Dec 18, 2015PIPEDA findings #2015-021Indexed Jun 30, 2026

PIPEDA findings #2015-021: Telecom company responsible for erroneous debt collection calls

A telecommunications company

An individual complained that a telecommunications company continued to report a debt to a credit-reporting agency and that a collection agency was still contacting her, despite the debt being discharged in bankruptcy years prior. This inaccurate reporting was hindering her ability to rebuild her credit score. The telecommunications company investigated and found that an internal manual process error had caused the information to be overlooked. The company subsequently corrected its records, notified the credit-reporting agency of the updated information, and ensured that all collection activities against the complainant would cease. The complainant expressed satisfaction with the resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

PIPEDA findings #2015-021: Telecom company responsible for erroneous debt collection calls

Dec 18, 2015PIPEDA findings #2015-021
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a telecommunications company continued to report a debt to a credit-reporting agency and that a collection agency was still contacting her, despite the debt being discharged in bankruptcy years prior. This inaccurate reporting was hindering her ability to rebuild her credit score. The telecommunications company investigated and found that an internal manual process error had caused the information to be overlooked. The company subsequently corrected its records, notified the credit-reporting agency of the updated information, and ensured that all collection activities against the complainant would cease. The complainant expressed satisfaction with the resolution.

Key Issues
  • Whether the telecommunications company maintained sufficiently accurate personal information (Principle 4.6 PIPEDA)
  • Whether the telecommunications company appropriately disclosed accurate personal information to a third party (Principle 4.6 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 15, 2015PIPEDA Case Summary #2015-014Indexed Jun 30, 2026

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

A pension and benefit provider

An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

Dec 15, 2015PIPEDA Case Summary #2015-014
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.

Key Issues
  • Whether the provider disclosed the complainant's unique identifier to a third party without consent (Principle 4.3 PIPEDA)
  • Whether the provider failed to keep the complainant's address information accurate (Principle 4.6 PIPEDA)
  • Whether the provider failed to implement appropriate safeguards to protect personal information from unauthorized disclosure and modification (Principle 4.7 PIPEDA)
  • Whether proper authentication of the caller took place before the complainant's ID number was given out (Principle 4.7.1 PIPEDA)
  • Whether the provider's failure to detect and correct the erroneous address sooner constituted a contravention of Principle 4.6.1 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Dec 2, 2015Discontinued Case Summary #2015-001Indexed Jun 30, 2026

Discontinued Case Summary #2015-001: Real estate management company responds fairly and reasonably to surveillance camera concerns

A real estate management company

An individual complained that a real estate management company collected his personal information without consent through surveillance cameras. He alleged inadequate signage and over-collection when a camera was focused on him after a dispute about his service dog. The company responded by posting new, clearer signage about video surveillance at all entrances, including the one previously lacking. They also addressed the over-collection concern by explaining that a new security guard had mistakenly focused the camera, and provided additional training to staff regarding service animals. The OPC found the company's response to be fair and reasonable, addressing the complainant's concerns proactively. Consequently, the investigation was discontinued.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Discontinued Case Summary #2015-001: Real estate management company responds fairly and reasonably to surveillance camera concerns

Dec 2, 2015Discontinued Case Summary #2015-001
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a real estate management company collected his personal information without consent through surveillance cameras. He alleged inadequate signage and over-collection when a camera was focused on him after a dispute about his service dog. The company responded by posting new, clearer signage about video surveillance at all entrances, including the one previously lacking. They also addressed the over-collection concern by explaining that a new security guard had mistakenly focused the camera, and provided additional training to staff regarding service animals. The OPC found the company's response to be fair and reasonable, addressing the complainant's concerns proactively. Consequently, the investigation was discontinued.

Key Issues
  • Whether the organization collected personal information without adequate signage for video surveillance
  • Whether the organization over-collected personal information by focusing a camera on the complainant
  • Whether the organization's response to the concerns was fair and reasonable under paragraph 12.2(1)(c) of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 10, 2015PIPEDA Case Summary #2015-015Indexed Jun 30, 2026

PIPEDA Case Summary #2015-015: Roofing company takes measures to ensure sub-contractors follow its privacy policy

A roofing company (the "second roofer")

An individual complained that an estimator working for a roofing company (the "second roofer") disclosed his personal financial situation and contractual history to a competitor (the "first roofer") without his consent. The individual had engaged the second roofer for an estimate to fix issues with work done by the first roofer, and later cancelled a contract with the second roofer. The OPC found that the estimator was acting as an agent for the second roofer, making the second roofer responsible for the estimator's actions. The OPC concluded that the disclosure of personal information without the individual's knowledge or consent contravened Principle 4.3 of PIPEDA. The second roofer subsequently implemented recommendations to establish agreements with sub-contractors to adhere to its privacy policy and provide training. As a result, the complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2015-015: Roofing company takes measures to ensure sub-contractors follow its privacy policy

Nov 10, 2015PIPEDA Case Summary #2015-015
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an estimator working for a roofing company (the "second roofer") disclosed his personal financial situation and contractual history to a competitor (the "first roofer") without his consent. The individual had engaged the second roofer for an estimate to fix issues with work done by the first roofer, and later cancelled a contract with the second roofer. The OPC found that the estimator was acting as an agent for the second roofer, making the second roofer responsible for the estimator's actions. The OPC concluded that the disclosure of personal information without the individual's knowledge or consent contravened Principle 4.3 of PIPEDA. The second roofer subsequently implemented recommendations to establish agreements with sub-contractors to adhere to its privacy policy and provide training. As a result, the complaint was deemed well-founded and resolved.

Key Issues
  • Whether the estimator was acting as an agent of the second roofer
  • Whether the second roofer was responsible for the personal information handling practices of its estimator
  • Whether personal information was disclosed without the individual's knowledge or consent
  • Whether the disclosure contravened Principle 4.3 of PIPEDA