The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

3 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 14, 2020PIPEDA Findings #2020-005Indexed Jun 30, 2026

PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019

Desjardins

The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019

Dec 14, 2020PIPEDA Findings #2020-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.

Key Issues
  • Whether personal information held by Desjardins was protected throughout its life cycle by security safeguards appropriate to the sensitivity of the information as required by PIPEDA Safeguards Principle 4.7.
  • Whether Desjardins fulfilled its responsibilities to implement procedures to protect personal information and train its staff, as set out in Accountability Principle 4.1.
  • Whether the personal information of individuals was handled in accordance with the retention and destruction requirements as set out in PIPEDA Principle 4.5, limiting use, disclosure and retention.
  • Whether the mitigation measures offered by Desjardins to affected individuals were adequate to protect their personal information from unauthorized use, such as future identity theft, in accordance with PIPEDA Safeguards Principle 4.7.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Review of passport protection practices of four federal institutions

Immigration, Refugees and Citizenship Canada (IRCC)

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Quick view

Privacy ActWell-founded & conditionally resolved

Review of passport protection practices of four federal institutions

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Key Issues
  • Whether the institutions had adequate controls to prevent unauthorized disclosures of passports under s.8 of the Privacy Act
  • Whether the institutions had adequate measures to detect potential unauthorized disclosures of passports
  • Whether the institutions had adequate measures to remediate risks to individuals from unauthorized disclosures of passports
  • Whether the institutions consistently and appropriately assessed the "materiality" of passport-related breaches
  • Whether notifications to affected individuals regarding lost or stolen passports were timely
  • Whether concrete assistance, such as credit monitoring, was offered to individuals affected by lost or stolen passports
  • Whether incident assessment and investigation processes were robust enough to identify suspicious patterns and share lessons learned among relevant stakeholders
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Jul 22, 2020Indexed Jun 30, 2026

Access at issue: Nine recommendations regarding the processing of access requests at National Defence

National Defence

The Office of the Information Commissioner (OIC) conducted a systemic investigation into the processing of access to information requests at National Defence (DND). The investigation focused on the six offices of primary interest (OPIs) most frequently tasked with responding to requests between January 2017 and December 2018. OIC officials interviewed OPIs and DND's Directorate of Access to Information and Privacy (DAIP), and reviewed internal documents, manuals, and statistics. The Commissioner identified significant issues with DND's compliance with the Access to Information Act. The Minister of National Defence acknowledged the need for improvements and proposed corrective actions, which were accepted or built upon by the Commissioner. The Commissioner issued nine recommendations to the Minister, who agreed to implement them to address the identified shortcomings.

Quick view

Access to Information ActSystemic Investigation

Access at issue: Nine recommendations regarding the processing of access requests at National Defence

Jul 22, 2020
Adjudicator: Caroline Maynard
Plain-Language Summary

The Office of the Information Commissioner (OIC) conducted a systemic investigation into the processing of access to information requests at National Defence (DND). The investigation focused on the six offices of primary interest (OPIs) most frequently tasked with responding to requests between January 2017 and December 2018. OIC officials interviewed OPIs and DND's Directorate of Access to Information and Privacy (DAIP), and reviewed internal documents, manuals, and statistics. The Commissioner identified significant issues with DND's compliance with the Access to Information Act. The Minister of National Defence acknowledged the need for improvements and proposed corrective actions, which were accepted or built upon by the Commissioner. The Commissioner issued nine recommendations to the Minister, who agreed to implement them to address the identified shortcomings.

Key Issues
  • Processing of access to information requests at National Defence
  • Compliance with the Access to Information Act by National Defence
  • Efficiency and effectiveness of DND's Access to Information and Privacy (ATIP) processes