The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

3 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 22, 2016PIPEDA Report of Findings #2016-005Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Avid Life Media Inc. (ALM)

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Aug 22, 2016PIPEDA Report of Findings #2016-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Key Issues
  • Whether ALM's security safeguards were appropriate to the sensitivity of the information under PIPEDA Principle 4.7.
  • Whether ALM implemented policies and practices to give effect to the Principles, including procedures to protect personal information, under PIPEDA Principle 4.1.4.
  • Whether ALM's indefinite retention of personal information for deactivated or inactive accounts contravened PIPEDA Principle 4.5.
  • Whether ALM's failure to establish maximum retention periods for personal information contravened PIPEDA Principle 4.5.2.
  • Whether ALM's practice of charging a fee for the complete deletion of personal information contravened an individual's right to withdraw consent under PIPEDA Principle 4.3.8.
  • Whether ALM took reasonable steps to ensure personal information (email addresses) was accurate, complete, and up-to-date as necessary for its purposes, taking into account the interests of the individual, under PIPEDA Principle 4.6 and 4.6.1.
  • Whether ALM's consent for the collection, use, or disclosure of personal information was valid, given the nature, purpose, and consequences, under PIPEDA s.6.1 and Principle 4.3.
  • Whether ALM made information about its personal information handling policies and practices readily available and understandable, and did not obtain consent through deception, under PIPEDA Principle 4.8, 4.8.1, and 4.3.5.
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Jun 16, 2016Indexed Jun 30, 2026

The importance of leadership

Parks Canada

In 2015-2016, the Commissioner conducted a systemic investigation into Parks Canada's approach to processing access to information requests. The investigation highlighted the importance of collaboration between institutions and the Commissioner to achieve positive systemic changes for access rights. This case illustrated how an institution's engagement during an investigation could lead to improvements in its access to information practices. The Commissioner's findings focused on the institution's overall approach rather than specific exemptions or individual complaints. The outcome emphasized the benefits of leadership and cooperation in addressing systemic issues related to access to information.

Quick view

Access to Information ActSystemic Investigation

The importance of leadership

Jun 16, 2016
Adjudicator: Suzanne Legault
Plain-Language Summary

In 2015-2016, the Commissioner conducted a systemic investigation into Parks Canada's approach to processing access to information requests. The investigation highlighted the importance of collaboration between institutions and the Commissioner to achieve positive systemic changes for access rights. This case illustrated how an institution's engagement during an investigation could lead to improvements in its access to information practices. The Commissioner's findings focused on the institution's overall approach rather than specific exemptions or individual complaints. The outcome emphasized the benefits of leadership and cooperation in addressing systemic issues related to access to information.

Key Issues
  • Parks Canada's approach to processing access requests
  • Systemic issues in access to information practices
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 18, 2016Incident Summary #13Indexed Jun 30, 2026

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

A Canadian financial institution

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

Feb 18, 2016Incident Summary #13
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Key Issues
  • Whether the financial institution adequately protected customer personal information from unauthorized disclosure by a fraudster
  • Whether the financial institution took appropriate steps to mitigate the impact of the breach and prevent recurrence