BreachOfPrivacy
Decisions/Federal (Canada)

Federal (Canada) Privacy Decisions

Browse privacy decisions from Federal (Canada) — with AI-generated plain-language summaries for every ruling.

5 decisions matching
Federal (Canada)Privacy ActWell-founded & resolved
May 30, 2023· Indexed Apr 12, 2026

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

Treasury Board of Canada Secretariat

This investigation examined the COVID-19 vaccination attestation requirements for federal public servants. The OPC found that the collection of vaccination status was directly related to the employer's health and safety obligations. However, the Treasury Board of Canada Secretariat (TBS) contravened the Act by failing to update its index of personal information banks within the required timeframe. The OPC also assessed the necessity and proportionality of the measures, concluding they were justified given the pandemic context, though TBS's documentation and response during the investigation were found to be lacking.

Quick View

Privacy ActWell-founded & resolved

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

This investigation examined the COVID-19 vaccination attestation requirements for federal public servants. The OPC found that the collection of vaccination status was directly related to the employer's health and safety obligations. However, the Treasury Board of Canada Secretariat (TBS) contravened the Act by failing to update its index of personal information banks within the required timeframe. The OPC also assessed the necessity and proportionality of the measures, concluding they were justified given the pandemic context, though TBS's documentation and response during the investigation were found to be lacking.

Key Issues
  • Whether the collection of employee vaccination status was directly related to an operating program or activity.
  • Whether institutions met transparency requirements under the Act.
  • Whether disclosures of personal information were authorized.
  • Necessity and proportionality of the vaccination attestation measures.
Federal (Canada)Privacy ActNot well-founded
May 30, 2023· Indexed Apr 12, 2026

Investigation into the collection and use of de-identified mobility data in the course of the COVID-19 pandemic

Public Health Agency of Canada

This investigation examined whether mobility data collected by the Public Health Agency of Canada (PHAC) during the COVID-19 pandemic contained personal information as defined under the Privacy Act. The investigation found that the de-identification techniques and safeguards against re-identification implemented by PHAC and its data providers reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were deemed not well-founded, as PHAC did not contravene the Privacy Act.

Quick View

Privacy ActNot well-founded

Investigation into the collection and use of de-identified mobility data in the course of the COVID-19 pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

This investigation examined whether mobility data collected by the Public Health Agency of Canada (PHAC) during the COVID-19 pandemic contained personal information as defined under the Privacy Act. The investigation found that the de-identification techniques and safeguards against re-identification implemented by PHAC and its data providers reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were deemed not well-founded, as PHAC did not contravene the Privacy Act.

Key Issues
  • Whether the mobility data collected constituted personal information under the Privacy Act.
  • The adequacy of de-identification and aggregation techniques to prevent re-identification.
  • Whether access to data within a provider's system constitutes collection under the Act.
  • The need for transparency regarding the use of de-identified data.
Federal (Canada)Privacy ActNot well-founded
May 30, 2023· Indexed Apr 12, 2026

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

Various Federal Separate Employers

This investigation examined whether COVID-19 vaccination attestation requirements implemented by several federal separate employers for their employees complied with the Privacy Act. The OPC found that the collection and use of vaccination status information, including for accommodation requests, was authorized under the Act and directly related to the employers' operating programs, specifically workplace health and safety during the pandemic. While not a strict legal requirement of the Act, the OPC also assessed the necessity and proportionality of these measures and found them to be reasonable given the exceptional circumstances of the pandemic.

Quick View

Privacy ActNot well-founded

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

This investigation examined whether COVID-19 vaccination attestation requirements implemented by several federal separate employers for their employees complied with the Privacy Act. The OPC found that the collection and use of vaccination status information, including for accommodation requests, was authorized under the Act and directly related to the employers' operating programs, specifically workplace health and safety during the pandemic. While not a strict legal requirement of the Act, the OPC also assessed the necessity and proportionality of these measures and found them to be reasonable given the exceptional circumstances of the pandemic.

Key Issues
  • Whether the collection of COVID-19 vaccination status information was directly related to an operating program or activity of the institutions.
  • Whether the use and disclosure of vaccination status information, including for accommodation requests, was authorized under the Privacy Act.
  • The necessity and proportionality of the vaccination attestation measures in the context of the COVID-19 pandemic.
Federal (Canada)Privacy ActNot well-founded
May 30, 2023· Indexed Apr 12, 2026

Investigation into COVID-19 vaccination attestation requirements established by Department of National Defence for members of the Canadian Armed Forces

Department of National Defence

This investigation examined the COVID-19 vaccination attestation requirements established by the Department of National Defence (DND) for members of the Canadian Armed Forces (CAF). The Office of the Privacy Commissioner of Canada (OPC) found that DND/CAF had the authority to collect this information under the National Defence Act and Part II of the Canada Labour Code. The use and disclosure of the information were generally consistent with the purposes for which it was collected. Although DND declined to implement a recommendation to strengthen oversight of access controls in the Monitor MASS system, the OPC found no instances of inappropriate access or disclosure. The OPC also determined that DND took reasonable steps to ensure the accuracy of the vaccination status information collected.

Quick View

Privacy ActNot well-founded

Investigation into COVID-19 vaccination attestation requirements established by Department of National Defence for members of the Canadian Armed Forces

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

This investigation examined the COVID-19 vaccination attestation requirements established by the Department of National Defence (DND) for members of the Canadian Armed Forces (CAF). The Office of the Privacy Commissioner of Canada (OPC) found that DND/CAF had the authority to collect this information under the National Defence Act and Part II of the Canada Labour Code. The use and disclosure of the information were generally consistent with the purposes for which it was collected. Although DND declined to implement a recommendation to strengthen oversight of access controls in the Monitor MASS system, the OPC found no instances of inappropriate access or disclosure. The OPC also determined that DND took reasonable steps to ensure the accuracy of the vaccination status information collected.

Key Issues
  • Whether DND/CAF's collection of COVID-19 vaccination status information directly related to an operating program or activity of the institution.
  • Whether the use of collected vaccination status information was authorized under section 7 of the Privacy Act.
  • Whether the use of the Monitor MASS system resulted in unauthorized disclosure of information.
  • Whether DND/CAF took reasonable steps to ensure the accuracy of vaccination status information.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
May 30, 2023· Indexed Apr 12, 2026

Protecting privacy in a pandemic

Office of the Privacy Commissioner of Canada

This Special Report to Parliament details the OPC's investigations into federal government privacy practices during the COVID-19 pandemic. It examined vaccine mandates for travel and employment, the ArriveCAN app, and the use of mobility data. While most government measures complied with the Privacy Act, the OPC identified areas for improvement, including the need for clearer objectives in mandates and better documentation of less privacy-intrusive alternatives. An error in the ArriveCAN app led to incorrect quarantine notifications, and a PIPEDA investigation found a private company misused a traveller's contact information for marketing.

Quick View

Privacy ActWell-founded & conditionally resolved

Protecting privacy in a pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

This Special Report to Parliament details the OPC's investigations into federal government privacy practices during the COVID-19 pandemic. It examined vaccine mandates for travel and employment, the ArriveCAN app, and the use of mobility data. While most government measures complied with the Privacy Act, the OPC identified areas for improvement, including the need for clearer objectives in mandates and better documentation of less privacy-intrusive alternatives. An error in the ArriveCAN app led to incorrect quarantine notifications, and a PIPEDA investigation found a private company misused a traveller's contact information for marketing.

Key Issues
  • Compliance of COVID-19 measures with the Privacy Act
  • Necessity and proportionality of personal information collection
  • Accuracy of personal information used in administrative decisions (ArriveCAN)
  • Use of de-identified mobility data and PIPEDA compliance