The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

148 decisions matching
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
Jun 10, 20225819-05031Indexed Apr 21, 2026

Royal Canadian Mounted Police, 5819-05031

The Information Commissioner ordered Royal Canadian Mounted Police to provide a final response to the access request forthwith.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Royal Canadian Mounted Police, 5819-05031

Jun 10, 20225819-05031

The Information Commissioner ordered Royal Canadian Mounted Police to provide a final response to the access request forthwith.

Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Jun 8, 20225820-02055Indexed Jun 30, 2026

5820-02055 — Immigration and Refugee Board of Canada

Immigration and Refugee Board of Canada

The complainant alleged that the Immigration and Refugee Board of Canada (IRB) failed to conduct a reasonable search for records in response to a request for "all final decisions rendered pursuant to section 37 of the Immigration and Refugee Protection Act (IRPA) from January 2018 until June 2020." The IRB provided only written decisions, stating that audio recordings are only provided when specifically requested. However, the OIC found that the IRB's ATIP office had erroneously informed its Office of Primary Interest that only written decisions were sought, thereby reducing the scope of the request without the complainant's approval. The Commissioner determined that "all final decisions" includes audio recordings, as a record under the Act means any documentary material regardless of medium or form. Consequently, the Commissioner found that the IRB did not perform a reasonable search.

Quick view

Access to Information ActWell-founded

5820-02055 — Immigration and Refugee Board of Canada

Jun 8, 20225820-02055
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Immigration and Refugee Board of Canada (IRB) failed to conduct a reasonable search for records in response to a request for "all final decisions rendered pursuant to section 37 of the Immigration and Refugee Protection Act (IRPA) from January 2018 until June 2020." The IRB provided only written decisions, stating that audio recordings are only provided when specifically requested. However, the OIC found that the IRB's ATIP office had erroneously informed its Office of Primary Interest that only written decisions were sought, thereby reducing the scope of the request without the complainant's approval. The Commissioner determined that "all final decisions" includes audio recordings, as a record under the Act means any documentary material regardless of medium or form. Consequently, the Commissioner found that the IRB did not perform a reasonable search.

Key Issues
  • Whether the institution conducted a reasonable search for records
  • Whether audio recordings fall within the scope of "all final decisions"
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
Jun 7, 20225821-06992Indexed Apr 21, 2026

National Defence, 5821-06992

The Information Commissioner ordered National Defence to provide a final response to the access request as soon as possible and no later than July 19, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5821-06992

Jun 7, 20225821-06992

The Information Commissioner ordered National Defence to provide a final response to the access request as soon as possible and no later than July 19, 2022.

Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Jun 6, 20225821-01212Indexed Jun 30, 2026

Public Health Agency of Canada (Re), 2022 OIC 26

Public Health Agency of Canada

The complainant alleged that the Public Health Agency of Canada (PHAC) took an unreasonable extension of time to respond to an access request for all correspondence, including emails, MS Teams messages, texts, and phone messages, sent and received by Iain Stewart between June 14 and June 21, 2021. PHAC notified the complainant of a 1,950-day extension under paragraphs 9(1)(a) and 9(1)(b) of the Access to Information Act. The Commissioner found that PHAC demonstrated the request involved a large volume of records (30,000 pages) and that meeting the 30-day deadline would unreasonably interfere with its operations, particularly given its role in the COVID-19 pandemic response and increased ATIP workload. The Commissioner also found that consultations were necessary and could not be completed within 30 days. Despite the lengthy extension, the Commissioner concluded that PHAC's calculation was reasonable given the circumstances, including the complexity of the records and the institution's processing capacity. Therefore, the complaint was not well founded.

Quick view

Access to Information ActNot well-founded

Public Health Agency of Canada (Re), 2022 OIC 26

Jun 6, 20225821-01212
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Public Health Agency of Canada (PHAC) took an unreasonable extension of time to respond to an access request for all correspondence, including emails, MS Teams messages, texts, and phone messages, sent and received by Iain Stewart between June 14 and June 21, 2021. PHAC notified the complainant of a 1,950-day extension under paragraphs 9(1)(a) and 9(1)(b) of the Access to Information Act. The Commissioner found that PHAC demonstrated the request involved a large volume of records (30,000 pages) and that meeting the 30-day deadline would unreasonably interfere with its operations, particularly given its role in the COVID-19 pandemic response and increased ATIP workload. The Commissioner also found that consultations were necessary and could not be completed within 30 days. Despite the lengthy extension, the Commissioner concluded that PHAC's calculation was reasonable given the circumstances, including the complexity of the records and the institution's processing capacity. Therefore, the complaint was not well founded.

Key Issues
  • Whether the extension of time under s.9(1)(a) was unreasonable
  • Whether the request was for a large number of records or required searching through a large number of records
  • Whether meeting the 30-day deadline would unreasonably interfere with the institution’s operations
  • Whether the extension of time under s.9(1)(a) was for a reasonable period, given the circumstances
  • Whether the extension of time under s.9(1)(b) was unreasonable
  • Whether the institution needed to carry out consultations on the requested records
  • Whether the consultations could reasonably be completed within 30 days
  • Whether the extension of time under s.9(1)(b) was for a reasonable period, given the circumstances
  • Whether the time extension was validly claimed
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Jun 2, 20225819-00768Indexed Jun 30, 2026

5819-00768 — Innovation, Science and Economic Development Canada

Innovation, Science and Economic Development Canada

An anonymous applicant complained that Innovation, Science and Economic Development Canada (ISED) improperly withheld "Total Repayment figures" related to several projects under the Technology Partnerships Canada (TPC) program, involving 21 third parties. ISED initially relied on paragraph 20(1)(c) of the Access to Information Act, while some third parties also raised paragraphs 20(1)(b) and 20(1)(d). The Commissioner found that the information was financial and commercial but not objectively confidential under paragraph 20(1)(b), as there was no reasonable expectation of non-disclosure for public funds, nor would confidentiality foster public benefit. For paragraph 20(1)(c), the Commissioner determined that neither ISED nor the third parties demonstrated a clear and direct connection between disclosure and a reasonable expectation of material financial harm or injury to competitive position, deeming their arguments speculative. Similarly, for paragraph 20(1)(d), insufficient evidence was provided to show that disclosure would interfere with contractual negotiations. Consequently, the complaint was found to be well-founded, and the Commissioner ordered ISED to disclose all the Total Repayments figures at issue.

Quick view

Access to Information ActWell-founded

5819-00768 — Innovation, Science and Economic Development Canada

Jun 2, 20225819-00768
Adjudicator: Caroline Maynard
Plain-Language Summary

An anonymous applicant complained that Innovation, Science and Economic Development Canada (ISED) improperly withheld "Total Repayment figures" related to several projects under the Technology Partnerships Canada (TPC) program, involving 21 third parties. ISED initially relied on paragraph 20(1)(c) of the Access to Information Act, while some third parties also raised paragraphs 20(1)(b) and 20(1)(d). The Commissioner found that the information was financial and commercial but not objectively confidential under paragraph 20(1)(b), as there was no reasonable expectation of non-disclosure for public funds, nor would confidentiality foster public benefit. For paragraph 20(1)(c), the Commissioner determined that neither ISED nor the third parties demonstrated a clear and direct connection between disclosure and a reasonable expectation of material financial harm or injury to competitive position, deeming their arguments speculative. Similarly, for paragraph 20(1)(d), insufficient evidence was provided to show that disclosure would interfere with contractual negotiations. Consequently, the complaint was found to be well-founded, and the Commissioner ordered ISED to disclose all the Total Repayments figures at issue.

Key Issues
  • Whether the Total Repayment figures are financial or commercial information under s.20(1)(b) ATIA
  • Whether the Total Repayment figures are confidential under s.20(1)(b) ATIA
  • Whether the circumstances of communication gave rise to a reasonable expectation of non-disclosure for the Total Repayment figures under s.20(1)(b) ATIA
  • Whether confidential communication of the Total Repayment figures would foster the relationship between third parties and ISED for public benefit under s.20(1)(b) ATIA
  • Whether disclosure of the Total Repayment figures could reasonably be expected to result in material financial loss or gain to a third party under s.20(1)(c) ATIA
  • Whether disclosure of the Total Repayment figures could reasonably be expected to injure the competitive position of a third party under s.20(1)(c) ATIA
  • Whether a clear and direct connection between disclosure and harm was demonstrated for s.20(1)(c) ATIA
  • Whether arguments of public misunderstanding justify withholding information under s.20(1)(c) ATIA
  • Whether disclosure of the Total Repayment figures could reasonably be expected to interfere with contractual or other negotiations of a third party under s.20(1)(d) ATIA
  • Whether a clear and direct connection between disclosure and interference (obstruction) was demonstrated for s.20(1)(d) ATIA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 1, 2022PIPEDA Findings #2022-001Indexed Jun 30, 2026

PIPEDA Findings #2022-001: Joint investigation into location tracking by the Tim Hortons App

The TDL Group Corp. (Tim Hortons)

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-001: Joint investigation into location tracking by the Tim Hortons App

Jun 1, 2022PIPEDA Findings #2022-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

Key Issues
  • Whether Tim Hortons collected or used personal information for an appropriate purpose under the Acts.
  • Whether Tim Hortons obtained valid consent for the collection and use of granular location data.
  • Adequacy of contractual protections for personal information transferred to third-party service providers.
  • Tim Hortons' accountability and implementation of a privacy management program.
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01407Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01407

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 5, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01407

May 20, 20225820-01407

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 5, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01406Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01406

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 25, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01406

May 20, 20225820-01406

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 25, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01401Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01401

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 7, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01401

May 20, 20225820-01401

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 7, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01405Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01405

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 11, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01405

May 20, 20225820-01405

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 11, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01404Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01404

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by July 29, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01404

May 20, 20225820-01404

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by July 29, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01403Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01403

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 23, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01403

May 20, 20225820-01403

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 23, 2022.

Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 20, 2022Indexed Jun 30, 2026

Investigation into a privacy breach at a Canada Border Services Agency contractor

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at a Canada Border Services Agency contractor

May 20, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Key Issues
  • Whether licence plate image files, including associated metadata (jurisdiction, characters, date, time, border crossing site, lane number), constitute personal information under Section 3 of the Privacy Act.
  • Whether the unauthorized access and disclosure of these licence plate image files constituted an improper disclosure under Section 8 of the Privacy Act.
  • Whether the Canada Border Services Agency (CBSA) had adequate security safeguards in place, particularly in its contractual arrangements with a third-party contractor, to protect personal information.
  • Whether the data retention practices for licence plate image files by the CBSA and its contractor were appropriate and compliant with the Privacy Act.
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 19, 20225821-01019Indexed Apr 21, 2026

Communications Security Establishment Canada, 5821-01019

The Information Commissioner ordered Communications Security Establishment Canada to provide a final response to the access request no later than July 24, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Communications Security Establishment Canada, 5821-01019

May 19, 20225821-01019

The Information Commissioner ordered Communications Security Establishment Canada to provide a final response to the access request no later than July 24, 2022.

Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2022PIPEDA Findings #2022-004Indexed Jun 30, 2026

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

MGM Resorts International

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

May 19, 2022PIPEDA Findings #2022-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Key Issues
  • Whether MGM had the obligation to report the breach to the OPC and notify affected Canadians
  • Whether the MGM breach met the RROSH reporting and notification threshold
  • Whether the personal information involved was sensitive
  • Whether there was a high probability of misuse of the personal information
  • Whether MGM notified the OPC and affected Canadians as soon as feasible