The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

21 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Dec 29, 2016PIPEDA findings #2016-013Indexed Jun 30, 2026

PIPEDA findings #2016-013: Company’s disclosure of information about a debt owed is not covered under exemption to consent

A sports facilities company

An individual complained that a sports facilities company disclosed his personal information, specifically details about an outstanding debt, to a related sports association on two occasions without his consent. The company did not deny the disclosures but argued they were made in response to direct questions and with an expectation of privacy. The OPC found that information about a debt owed by an identifiable individual is personal and sensitive, requiring consent for disclosure unless a specific exemption applies. The OPC determined that the disclosures were not for the purpose of collecting the debt, thus the exemption under paragraph 7(3)(b) of PIPEDA did not apply. The company's reliance on an 'expectation of privacy' or being asked directly was not a valid substitute for obtaining consent. The complaint was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA findings #2016-013: Company’s disclosure of information about a debt owed is not covered under exemption to consent

Dec 29, 2016PIPEDA findings #2016-013
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a sports facilities company disclosed his personal information, specifically details about an outstanding debt, to a related sports association on two occasions without his consent. The company did not deny the disclosures but argued they were made in response to direct questions and with an expectation of privacy. The OPC found that information about a debt owed by an identifiable individual is personal and sensitive, requiring consent for disclosure unless a specific exemption applies. The OPC determined that the disclosures were not for the purpose of collecting the debt, thus the exemption under paragraph 7(3)(b) of PIPEDA did not apply. The company's reliance on an 'expectation of privacy' or being asked directly was not a valid substitute for obtaining consent. The complaint was found to be well-founded.

Key Issues
  • Whether the disclosure of debt information without consent contravened Principle 4.3 of PIPEDA
  • Whether the disclosure was exempt from consent under paragraph 7(3)(b) of PIPEDA for debt collection purposes
  • Whether an 'expectation of privacy' or responding to a direct question constitutes a valid exception to consent requirements
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 20, 2016Indexed Jun 30, 2026

The PBC refuses to process requests for record suspension information

Parole Board of Canada

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Quick view

Privacy ActWell-founded

The PBC refuses to process requests for record suspension information

Dec 20, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Key Issues
  • Whether an individual can make a request under the Privacy Act to confirm that no personal information relating to record suspensions exists.
  • Whether the PBC properly applied the exemption under paragraph 22(1)(b) of the Privacy Act to refuse access requests for record suspension information.
  • Whether the disclosure of record suspension information under the Privacy Act would injure the enforcement of the Criminal Records Act.
  • Whether the PBC's requirement for additional identification (FPS number, PBC reference number, criminal record copy) is necessary to adequately identify a requester under the Privacy Act.
  • Whether the company's record suspension verification service circumvents the vulnerable sector verification process under the CRA.
  • Whether the consent obtained by the company for its service is valid.
  • Whether the proposed use of personal information by the company violates human rights legislation.
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Sep 23, 2016Early resolved case summary #2016-01Indexed Jun 30, 2026

Early resolved case summary #2016-01: Access to personal information request revised to accommodate both requestor and organization

A condominium developer

A condominium owner filed a complaint after his request for access to his personal information was met with a demand for payment for photocopies or an offer to view documents at the organization's lawyer's office. The individual argued that this was not access at "minimal or no cost" as required by PIPEDA Principle 4.9.4. The OPC's early resolution unit intervened, and the organization initially offered free viewing with the option to select pages for free copies. The complainant, citing a disability, found viewing 1000 pages unreasonable. The OPC proposed that the individual narrow his request, which he accepted. Consequently, the organization agreed to provide free copies of the specific documents containing his personal information, leading to the complainant's satisfaction.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2016-01: Access to personal information request revised to accommodate both requestor and organization

Sep 23, 2016Early resolved case summary #2016-01
Adjudicator: Daniel Therrien
Plain-Language Summary

A condominium owner filed a complaint after his request for access to his personal information was met with a demand for payment for photocopies or an offer to view documents at the organization's lawyer's office. The individual argued that this was not access at "minimal or no cost" as required by PIPEDA Principle 4.9.4. The OPC's early resolution unit intervened, and the organization initially offered free viewing with the option to select pages for free copies. The complainant, citing a disability, found viewing 1000 pages unreasonable. The OPC proposed that the individual narrow his request, which he accepted. Consequently, the organization agreed to provide free copies of the specific documents containing his personal information, leading to the complainant's satisfaction.

Key Issues
  • Whether the organization's initial response to an access request met the "minimal or no cost" requirement under Principle 4.9.4 of PIPEDA
  • Whether an offer to view documents without free copies constitutes adequate access under PIPEDA
  • Whether the organization's proposed solution of viewing documents at a lawyer's office was reasonable given the complainant's disability
  • Whether narrowing the scope of an access request can facilitate resolution and compliance with PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Aug 10, 2016Early resolved case summary #2016-02Indexed Jun 30, 2026

Early resolved case summary #2016-02: Organization’s technical glitch results in the disclosure of a client’s personal information to another client

An online service company

An individual complained to the OPC after an online service company failed to resolve a technical glitch that caused another person's personal information to appear in his account. Despite months of attempts, the company's customer service and IT specialists could not fix the issue, nor could the individual escalate his concerns to a privacy officer. The OPC intervened, prompting the company to investigate and discover the glitch originated from another organization's software interface. The online company, in collaboration with the other organization, corrected the technical glitch for all users. The online company also revised its internal policies to include an escalation process for privacy concerns and established a new contractual agreement with the other organization to prevent future issues and enhance PIPEDA compliance. The complainant confirmed the issue was resolved to his satisfaction.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2016-02: Organization’s technical glitch results in the disclosure of a client’s personal information to another client

Aug 10, 2016Early resolved case summary #2016-02
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after an online service company failed to resolve a technical glitch that caused another person's personal information to appear in his account. Despite months of attempts, the company's customer service and IT specialists could not fix the issue, nor could the individual escalate his concerns to a privacy officer. The OPC intervened, prompting the company to investigate and discover the glitch originated from another organization's software interface. The online company, in collaboration with the other organization, corrected the technical glitch for all users. The online company also revised its internal policies to include an escalation process for privacy concerns and established a new contractual agreement with the other organization to prevent future issues and enhance PIPEDA compliance. The complainant confirmed the issue was resolved to his satisfaction.

Key Issues
  • Whether an online service company adequately addressed a technical glitch leading to unauthorized disclosure of personal information
  • Whether the online service company had appropriate internal policies for escalating privacy concerns
  • Whether the online service company had adequate contractual agreements with third-party service providers regarding privacy and data breaches
Federal (Canada)Personal Information Protection and Electronic Documents ActNo jurisdiction
Federal (Canada) flag
Jul 18, 2016PIPEDA Case Summary #2016-011Indexed Jun 30, 2026

PIPEDA Case Summary #2016-011: Defending against a civil lawsuit not considered a commercial activity

A psychiatrist retained by an independent medical evaluation provider

An individual (the plaintiff) filed a complaint after a psychiatrist, retained by an insurance company to assess the plaintiff's well-being for a civil lawsuit, did not provide full access to his personal information. The plaintiff had requested access to his personal information held by the psychiatrist and received only a redacted report, leading to concerns about the completeness and accuracy of the information. The OPC investigated whether the psychiatrist's collection and use of the plaintiff's personal information constituted a "commercial activity" under PIPEDA. The OPC determined that defending against a civil lawsuit is not a commercial activity, and therefore, PIPEDA did not apply. The complaint was ultimately dismissed due to lack of jurisdiction.

Quick view

Personal Information Protection and Electronic Documents ActNo jurisdiction

PIPEDA Case Summary #2016-011: Defending against a civil lawsuit not considered a commercial activity

Jul 18, 2016PIPEDA Case Summary #2016-011
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual (the plaintiff) filed a complaint after a psychiatrist, retained by an insurance company to assess the plaintiff's well-being for a civil lawsuit, did not provide full access to his personal information. The plaintiff had requested access to his personal information held by the psychiatrist and received only a redacted report, leading to concerns about the completeness and accuracy of the information. The OPC investigated whether the psychiatrist's collection and use of the plaintiff's personal information constituted a "commercial activity" under PIPEDA. The OPC determined that defending against a civil lawsuit is not a commercial activity, and therefore, PIPEDA did not apply. The complaint was ultimately dismissed due to lack of jurisdiction.

Key Issues
  • Whether the collection and use of a plaintiff’s personal information for the purpose of defending against a civil lawsuit constitutes a "commercial activity" under PIPEDA
  • Whether PIPEDA applies to the activities of a third-party retained to carry out an activity exempt from PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 14, 2016PIPEDA Case Summary #2016-008Indexed Jun 30, 2026

PIPEDA Case Summary #2016-008: Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties

A telecommunications company

An individual complained that a telecommunications company (telco) provided an incomplete response to her access request for information about disclosures of her personal information to other parties, including law enforcement. The telco initially responded by stating it was in compliance with specific PIPEDA subsections, without confirming or denying disclosures. The OPC found that the telco's response did not meet its obligation under Principle 4.9 of PIPEDA, which requires organizations to inform individuals of the existence, use, and disclosure of their personal information. The OPC clarified that an organization must provide a clear 'yes' or 'no' answer regarding disclosures, unless a government institution objects to such disclosure under PIPEDA s.9(2.4). Following the OPC's recommendation, the telco provided a complete response to the complainant and updated its policy for handling future access requests. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-008: Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties

Jul 14, 2016PIPEDA Case Summary #2016-008
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a telecommunications company (telco) provided an incomplete response to her access request for information about disclosures of her personal information to other parties, including law enforcement. The telco initially responded by stating it was in compliance with specific PIPEDA subsections, without confirming or denying disclosures. The OPC found that the telco's response did not meet its obligation under Principle 4.9 of PIPEDA, which requires organizations to inform individuals of the existence, use, and disclosure of their personal information. The OPC clarified that an organization must provide a clear 'yes' or 'no' answer regarding disclosures, unless a government institution objects to such disclosure under PIPEDA s.9(2.4). Following the OPC's recommendation, the telco provided a complete response to the complainant and updated its policy for handling future access requests. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the telco's initial response to an access request for disclosure information met its obligations under Principle 4.9 of PIPEDA
  • Whether the telco's practice of stating compliance with PIPEDA s.9(2.1)-(2.4) was sufficient for access requests
  • Whether the telco had an obligation to provide a 'yes' or 'no' answer regarding disclosures to all third parties, including those not covered by PIPEDA s.9(2.1)-(2.4)
  • How an organization should respond to an access request for disclosure information when a government institution objects under PIPEDA s.9(2.4)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 7, 2016PIPEDA Case Summary #2016-010Indexed Jun 30, 2026

PIPEDA Case Summary #2016-010: Credit reporting agency takes remedial action after failing to maintain accurate records

A credit reporting agency

An individual complained to the OPC after discovering inaccuracies in his credit file, including two unrecognized credit inquiries and a notation that his account had been automatically combined with others. The credit reporting agency acknowledged that his file had been manually combined with another individual's due to similar names and addresses. The OPC investigated two main issues: unauthorized use/disclosure and accuracy of personal information. The OPC found no unauthorized use or disclosure, as the inquiries occurred before the files were combined and only the other individual's information was used. However, the OPC determined that the agency failed to maintain accurate personal information, as combining files compromised accuracy and led to incorrect information being attributed to the complainant. The agency rectified the error by separating the files, notifying creditors of corrections, and committing to enhanced employee training. Consequently, the accuracy issue was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-010: Credit reporting agency takes remedial action after failing to maintain accurate records

Jul 7, 2016PIPEDA Case Summary #2016-010
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after discovering inaccuracies in his credit file, including two unrecognized credit inquiries and a notation that his account had been automatically combined with others. The credit reporting agency acknowledged that his file had been manually combined with another individual's due to similar names and addresses. The OPC investigated two main issues: unauthorized use/disclosure and accuracy of personal information. The OPC found no unauthorized use or disclosure, as the inquiries occurred before the files were combined and only the other individual's information was used. However, the OPC determined that the agency failed to maintain accurate personal information, as combining files compromised accuracy and led to incorrect information being attributed to the complainant. The agency rectified the error by separating the files, notifying creditors of corrections, and committing to enhanced employee training. Consequently, the accuracy issue was found to be well-founded and resolved.

Key Issues
  • Whether the credit reporting agency improperly disclosed the complainant's personal information without consent
  • Whether the credit reporting agency failed to maintain accurate personal information as required by PIPEDA Principle 4.6
  • Whether the credit reporting agency failed to maintain accurate personal information as required by PIPEDA Principle 4.6.3
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 6, 2016Indexed Jun 30, 2026

TV show raises numerous questions of consent

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Quick view

Privacy ActWell-founded

TV show raises numerous questions of consent

Jun 6, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Key Issues
  • Whether the CBSA, as a federal institution, could contract out of its obligations under the Privacy Act
  • Whether the CBSA's collection of personal information in connection with the TV Program related directly to an operating program or activity of the institution (s.4 Privacy Act)
  • Whether the CBSA was involved in the collection of personal information for the purposes of the TV Program
  • Whether there was a real-time disclosure of personal information by the CBSA to Force Four for the purpose of filming the TV Program
  • Whether the CBSA obtained valid, meaningful, and freely given consent from individuals, including the complainant, for the disclosure of their personal information to Force Four (s.8 Privacy Act)
  • Whether the "Voluntary Appearance Release Form" (Waiver) effectively waived individuals' rights under the Privacy Act
  • Whether the practice of "silent filming" by the production crew was consistent with obtaining valid consent
  • Whether the CBSA disclosed personal information of an intended subject to Force Four in advance of filming without authorization (s.8 Privacy Act)
  • Whether the personal information of the intended subject was publicly available at the time of disclosure
  • Whether the facial blurring and other identity concealment techniques used in the TV Program were sufficient to prevent the identification of individuals who had not provided written consent
  • Whether the CBSA demonstrated how the disclosure of personal information of individuals without written consent was consistent with section 8 of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 17, 2016Indexed Jun 30, 2026

Canada Revenue Agency takes adequate measures to ensure personal information not moved to U.S.

Canada Revenue Agency (CRA)

A complainant raised concerns that the Canada Revenue Agency (CRA) outsourced the storage of Canadian taxpayer information to Mobilshred Inc., which the complainant believed was a division of a US-based company, Recall. The complainant was concerned that this could make the personal information vulnerable to disclosure under the USA PATRIOT Act. The OPC investigated whether the CRA had properly safeguarded personal information from unauthorized disclosure. The CRA clarified that Mobilshred Inc. is a Canadian company, and the contract explicitly requires all physical records to remain in Canada. The OPC found that the CRA took appropriate steps to mitigate risks by ensuring all information remained in Canada and that Mobilshred Inc. is a Canadian entity. The complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

Canada Revenue Agency takes adequate measures to ensure personal information not moved to U.S.

May 17, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant raised concerns that the Canada Revenue Agency (CRA) outsourced the storage of Canadian taxpayer information to Mobilshred Inc., which the complainant believed was a division of a US-based company, Recall. The complainant was concerned that this could make the personal information vulnerable to disclosure under the USA PATRIOT Act. The OPC investigated whether the CRA had properly safeguarded personal information from unauthorized disclosure. The CRA clarified that Mobilshred Inc. is a Canadian company, and the contract explicitly requires all physical records to remain in Canada. The OPC found that the CRA took appropriate steps to mitigate risks by ensuring all information remained in Canada and that Mobilshred Inc. is a Canadian entity. The complaint was found to be not well-founded.

Key Issues
  • Whether the CRA properly safeguarded personal information entrusted to Mobilshred Inc. from unauthorized disclosure under the Privacy Act
  • Whether Canadian taxpayer information was vulnerable to disclosure to US authorities under the USA PATRIOT Act due to the contract with Mobilshred Inc.
  • Whether Mobilshred Inc. is a Canadian entity or affiliated with a US-based company
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
May 6, 2016Early resolution case summary #2016-03Indexed Jun 30, 2026

Early resolution case summary #2016-03: First Nation develops a privacy policy following allegations of lost doctor’s notes

First Nation band council

An employee of a First Nation band council complained that two doctor's notes he submitted for leave requests were lost by the band office, leading to non-payment for his leave. The complainant also filed a complaint under the Canada Labour Code. The OPC's Early Resolution Unit engaged with the band council, which, while not confirming the loss of the notes, agreed to develop a privacy policy and adopt best privacy practices. The OPC provided resources to assist in this development. The complainant was satisfied with the band council's commitment to a privacy policy, leading to an early resolution of the privacy complaint, with the issue of lost notes to be addressed via the Canada Labour Code complaint. The band council subsequently adopted a privacy policy with the OPC's guidance.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolution case summary #2016-03: First Nation develops a privacy policy following allegations of lost doctor’s notes

May 6, 2016Early resolution case summary #2016-03
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee of a First Nation band council complained that two doctor's notes he submitted for leave requests were lost by the band office, leading to non-payment for his leave. The complainant also filed a complaint under the Canada Labour Code. The OPC's Early Resolution Unit engaged with the band council, which, while not confirming the loss of the notes, agreed to develop a privacy policy and adopt best privacy practices. The OPC provided resources to assist in this development. The complainant was satisfied with the band council's commitment to a privacy policy, leading to an early resolution of the privacy complaint, with the issue of lost notes to be addressed via the Canada Labour Code complaint. The band council subsequently adopted a privacy policy with the OPC's guidance.

Key Issues
  • Whether a First Nation band council is a federal work, undertaking or business (FWUB) under PIPEDA
  • Whether the personal information of employees of a FWUB is protected under PIPEDA
  • Whether the First Nation band council adequately protected the complainant's medical information
  • Whether the First Nation band council had appropriate privacy policies and practices in place
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 21, 2016PIPEDA Report of Findings #2016-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Compu-Finder (3510395 Canada Inc.)

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Apr 21, 2016PIPEDA Report of Findings #2016-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Key Issues
  • Whether Compu-Finder's collection and use of email addresses constituted "personal information" under PIPEDA.
  • Whether the business contact information carve-out under s. 4.01 PIPEDA applied to Compu-Finder's activities.
  • Whether Compu-Finder obtained meaningful express consent for collecting email addresses via telemarketing (Principles 4.2, 4.3, 4.3.2).
  • Whether Compu-Finder collected personal information by fair and lawful means (Principle 4.4).
  • Whether Compu-Finder obtained meaningful implied consent for collecting email addresses from publicly available sources (Principle 4.3.6).
  • Whether the "publicly available information" exemption (s. 7(1)(d), 7(2)(c.1) PIPEDA and s. 1 of the Regulations) applied to Compu-Finder's collection and use of email addresses.
  • Whether the address harvesting provisions (s. 7.1(2) PIPEDA) prohibited the use of email addresses collected via software before the provision came into force.
  • Whether Compu-Finder had a designated individual accountable for PIPEDA compliance (Principle 4.1).
  • Whether Compu-Finder implemented policies and practices to give effect to PIPEDA principles (Principle 4.1.4).
  • Whether Compu-Finder was open about its personal information management policies and practices (Principles 4.8.1, 4.8.2).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2016PIPEDA Case Summary #2016-012Indexed Jun 30, 2026

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

A bank associated with a retailer

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

Mar 31, 2016PIPEDA Case Summary #2016-012
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Key Issues
  • Whether the bank obtained valid consent for a credit card application and credit check under Principle 4.3
  • Whether the bank ensured the accuracy of personal information collected under Principle 4.6
  • Whether the bank had adequate procedures to give effect to PIPEDA principles under Principle 4.1.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 10, 2016PIPEDA Case Summary #2016-009Indexed Jun 30, 2026

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

An international trucking company

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

Mar 10, 2016PIPEDA Case Summary #2016-009
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Key Issues
  • Whether the disclosure of drug test results to the WCB without consent contravened PIPEDA Principles 4.3 and 4.5
  • Whether the employer had a legal obligation to disclose the drug test results to the WCB under the provincial Workers' Compensation Act, thereby qualifying for an exception to consent under paragraph 7(3)(i) of PIPEDA
  • Whether the employer disclosed the drug test results to co-workers without consent
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 24, 2016Incident Summary #12Indexed Jun 30, 2026

Incident Summary #12: Break with security procedures exposes financial planner’s client to privacy breach

A financial management firm

A financial management firm's employees breached internal security procedures by sending a client's detailed financial plan and federal income tax notice of assessment, containing sensitive personal information including her social insurance number, to her personal email account without secure messaging tools. The client's email account was subsequently hacked, and the alleged hacker used the obtained information to pose as the client and request a significant transfer from her investment account. An employee processed this transfer without following authentication procedures. Although the client's money was not stolen, the firm investigated the incident, advised the client to change passwords, informed the RCMP, and offered credit monitoring. The firm also took measures with the responsible employees, provided additional privacy training to staff, and reviewed its internal processes. The OPC considered the firm's response appropriate.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #12: Break with security procedures exposes financial planner’s client to privacy breach

Feb 24, 2016Incident Summary #12
Adjudicator: Daniel Therrien
Plain-Language Summary

A financial management firm's employees breached internal security procedures by sending a client's detailed financial plan and federal income tax notice of assessment, containing sensitive personal information including her social insurance number, to her personal email account without secure messaging tools. The client's email account was subsequently hacked, and the alleged hacker used the obtained information to pose as the client and request a significant transfer from her investment account. An employee processed this transfer without following authentication procedures. Although the client's money was not stolen, the firm investigated the incident, advised the client to change passwords, informed the RCMP, and offered credit monitoring. The firm also took measures with the responsible employees, provided additional privacy training to staff, and reviewed its internal processes. The OPC considered the firm's response appropriate.

Key Issues
  • Whether the firm adequately protected personal information by sending sensitive documents via unsecure email
  • Whether the firm had adequate procedures for authenticating clients for financial transactions
  • Whether the firm's response to the privacy breach was appropriate
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 19, 2016PIPEDA Report of Findings #2016-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

A property management company

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

Feb 19, 2016PIPEDA Report of Findings #2016-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Key Issues
  • Whether the collection, use, and disclosure of personal information for a "bad tenant list" was for purposes that a reasonable person would consider appropriate in the circumstances (s.5(3) PIPEDA)
  • Whether the property management company was acting as an unlicensed credit reporting agency under provincial legislation
  • Whether meaningful knowledge and consent of individuals were obtained for the collection, use, and disclosure of their personal information for the "bad tenant list" (Principle 4.3, 4.3.2 PIPEDA)
  • Whether the personal information on the "bad tenant list" was accurate, complete, and up-to-date (Principle 4.6, 4.6.1 PIPEDA)
  • Whether individuals had the ability to challenge the accuracy of information about them on the list (Principle 4.10 PIPEDA)