BreachOfPrivacy
Decisions/Federal (Canada)

Federal (Canada) Privacy Decisions

Browse privacy decisions from Federal (Canada) — with AI-generated plain-language summaries for every ruling.

3 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Aug 22, 2016PIPEDA Report of Findings #2016-005· Indexed Apr 12, 2026

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Avid Life Media Inc. (ALM)

This report details a joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and the Australian Office of the Information Commissioner (OAIC) into Avid Life Media Inc. (ALM), the operator of Ashley Madison. The investigation followed a significant data breach where personal information of millions of users was exposed. The OPC found that ALM contravened PIPEDA regarding information security, indefinite retention of user data, accuracy of email addresses, and transparency with users. ALM has entered into a compliance agreement with the OPC to address these issues.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Aug 22, 2016PIPEDA Report of Findings #2016-005
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details a joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and the Australian Office of the Information Commissioner (OAIC) into Avid Life Media Inc. (ALM), the operator of Ashley Madison. The investigation followed a significant data breach where personal information of millions of users was exposed. The OPC found that ALM contravened PIPEDA regarding information security, indefinite retention of user data, accuracy of email addresses, and transparency with users. ALM has entered into a compliance agreement with the OPC to address these issues.

Key Issues
  • Adequacy of information security safeguards
  • Indefinite retention of user data
  • Accuracy of collected email addresses
  • Transparency and user consent regarding data handling practices
Federal (Canada)Access to Information Act
Jun 16, 2016· Indexed May 4, 2026

The importance of leadership

Parks Canada

This document is a systemic investigation into Parks Canada's approach to processing access requests, completed in 2015-2016. It highlights how cooperation with the Information Commissioner's Office can lead to positive systemic changes in how access rights are managed. The report uses Parks Canada's practices as an example for improvement.

Quick View

Access to Information Act

The importance of leadership

Jun 16, 2016
Adjudicator: Suzanne Legault
Plain-Language Summary

This document is a systemic investigation into Parks Canada's approach to processing access requests, completed in 2015-2016. It highlights how cooperation with the Information Commissioner's Office can lead to positive systemic changes in how access rights are managed. The report uses Parks Canada's practices as an example for improvement.

Key Issues
  • Effectiveness of Parks Canada's access to information request processing
  • Impact of leadership and collaboration on access rights
  • Systemic changes in access to information practices
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Feb 18, 2016Incident Summary #13· Indexed Apr 12, 2026

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

A Canadian financial institution

This report details an incident where a fraudster impersonated an unknown individual to trick a financial institution's employees into revealing customer contact information. The fraudster then used this information to extract further personal details from approximately 100 customers, increasing their risk of identity theft. The financial institution took immediate steps to mitigate the breach, including offering credit monitoring and enhancing staff training.

Quick View

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

Feb 18, 2016Incident Summary #13
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details an incident where a fraudster impersonated an unknown individual to trick a financial institution's employees into revealing customer contact information. The fraudster then used this information to extract further personal details from approximately 100 customers, increasing their risk of identity theft. The financial institution took immediate steps to mitigate the breach, including offering credit monitoring and enhancing staff training.

Key Issues
  • Effectiveness of internal controls to prevent unauthorized disclosure of personal information
  • Adequacy of breach response and mitigation measures
  • Risks of identity theft and fraud due to personal information disclosure