
Environment and Climate Change Canada, 5820-01404
The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by July 29, 2022.
Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by July 29, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 23, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 11, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 25, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 7, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 5, 2022.

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

The Information Commissioner ordered Communications Security Establishment Canada to provide a final response to the access request no later than July 24, 2022.

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

The complainant alleged that Shared Services Canada (SSC) improperly refused to process an access request for records related to informal official language complaints. SSC argued that the request, even after being narrowed to a one-year timeframe and specific keywords in email subject lines, did not meet the requirements of section 6 of the Access to Information Act because it would require tasking over 8,300 employees and create an unreasonable administrative burden. The Information Commissioner disagreed, stating that the term "reasonable effort" in section 6 refers to identifying records, not limiting the number of individuals tasked. The Commissioner also noted that the Act provides for time extensions for large requests and that the potential for redacting personal information under section 19 is not a valid reason to refuse processing. The Commissioner concluded that the request was sufficiently detailed and ordered SSC to process it.

The complainant alleged that Biron Health Group (Biron) sent him promotional emails without his consent after he underwent mandatory COVID-19 testing upon arrival at Montreal Trudeau Airport. He provided his email solely for test results. Biron initially believed it had implicit consent due to an established business relationship. The OPC found that Biron could not reasonably assume implicit consent, as travellers had no choice but to use Biron for mandatory testing and would not expect their health information to be used for marketing. Biron ceased the practice and deleted affected email addresses from its marketing database. The complaint was settled during the investigation.

The complainant alleged that Public Services and Procurement Canada (PSPC) failed to provide records in response to an access request concerning a contract awarded to Brookfield Global Integrated Solutions (BGIS) and a related subcontract. PSPC initially stated it could not identify relevant records, arguing the subcontract was not under its control. The investigation found that while the records were not in PSPC's physical possession, they were under its control for the purposes of the Access to Information Act, based on the legal relationship between PSPC and BGIS and the terms of their contract. The Commissioner concluded that PSPC did not conduct a reasonable search because it made no effort to obtain the subcontract and related documents from BGIS. The complaint was found to be well founded, and the Commissioner recommended PSPC retrieve and process the records. However, PSPC declined to implement the recommendations.

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) improperly withheld information under paragraph 20(1)(c) of the Access to Information Act. The request sought records related to job creation estimates and estimated jobs maintained figures for projects that received assistance between 2011 and 2018. The complaint's scope was narrowed to information concerning eleven third parties, with only Toyota Motor Manufacturing Canada (Toyota) providing representations to support the exemption claim. The Commissioner found that neither Toyota nor ISED demonstrated a clear and direct connection between disclosure and a risk of material financial loss or harm to Toyota's competitive position, beyond mere speculation. Arguments regarding potential public misunderstanding were also deemed insufficient to meet the legal test for harm under s.20(1)(c), especially given that an explanatory note could address such concerns. Consequently, the Commissioner concluded that the information did not qualify for the exemption. The complaint was found to be well founded, and the Commissioner recommended full disclosure, though ISED indicated it would not fully implement the recommendation for some Toyota-related information.

The Information Commissioner initiated a systemic investigation into Library and Archives Canada's (LAC) delayed responses to access requests. This investigation was prompted by a long-standing trend of LAC failing to meet legislative deadlines for responding to access requests, which worsened during the COVID-19 pandemic. The investigation found that during the period under review, nearly 80% of requests completed by LAC did not comply with the timeframes set out in the Access to Information Act. The Commissioner informed the Minister of Canadian Heritage, as the head of LAC, of these findings and made ten recommendations. A special report was subsequently tabled in Parliament, highlighting issues within LAC and broader challenges in Canada's access to information system, specifically regarding inter-institutional consultations and the absence of a government-wide declassification framework.