The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

3 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Sep 23, 2025PIPEDA Findings #2025-003Indexed Jun 30, 2026

PIPEDA Findings #2025-003: Joint investigation of TikTok Pte. Ltd. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, and the Office of the Information and Privacy Commissioner of Alberta

TikTok Pte. Ltd.

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and provincial privacy regulators (CAI, OIPC BC, OIPC AB) examined TikTok Pte. Ltd.'s compliance with federal and provincial private sector privacy laws. The investigation focused on TikTok's collection, use, and disclosure of personal information for ad targeting and content personalization, with a particular emphasis on practices affecting children. The Offices found that TikTok's age assurance measures were inadequate, leading to the collection and use of sensitive personal information from a large number of underage users for purposes deemed inappropriate. Furthermore, TikTok failed to obtain valid and meaningful consent from both adult and youth users due to unclear, inaccessible, and incomplete privacy communications, including regarding biometric information and cross-border data transfers. The CAI specifically identified contraventions related to Quebec's transparency and privacy-by-default obligations. While TikTok disagreed with the findings, it committed to implementing enhanced age assurance mechanisms, improving privacy communications, and limiting ad targeting for under-18 users. The Offices concluded the matter as well-founded and conditionally resolved, contingent on TikTok's satisfactory implementation of these significant commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2025-003: Joint investigation of TikTok Pte. Ltd. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, and the Office of the Information and Privacy Commissioner of Alberta

Sep 23, 2025PIPEDA Findings #2025-003
Adjudicator: Philippe Dufresne
Plain-Language Summary

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and provincial privacy regulators (CAI, OIPC BC, OIPC AB) examined TikTok Pte. Ltd.'s compliance with federal and provincial private sector privacy laws. The investigation focused on TikTok's collection, use, and disclosure of personal information for ad targeting and content personalization, with a particular emphasis on practices affecting children. The Offices found that TikTok's age assurance measures were inadequate, leading to the collection and use of sensitive personal information from a large number of underage users for purposes deemed inappropriate. Furthermore, TikTok failed to obtain valid and meaningful consent from both adult and youth users due to unclear, inaccessible, and incomplete privacy communications, including regarding biometric information and cross-border data transfers. The CAI specifically identified contraventions related to Quebec's transparency and privacy-by-default obligations. While TikTok disagreed with the findings, it committed to implementing enhanced age assurance mechanisms, improving privacy communications, and limiting ad targeting for under-18 users. The Offices concluded the matter as well-founded and conditionally resolved, contingent on TikTok's satisfactory implementation of these significant commitments.

Key Issues
  • Whether TikTok was collecting, using, and disclosing personal information, particularly with respect to children, for an appropriate, reasonable, and legitimate purpose.
  • Whether TikTok's age assurance mechanisms were effective in preventing underage users from accessing the platform.
  • Whether TikTok obtained valid and meaningful consent from its users for tracking, profiling, targeting, and content personalization.
  • Whether TikTok's privacy communications provided sufficient upfront, clear, and comprehensive information to adult users to ensure meaningful consent.
  • Whether TikTok adequately explained its collection and use of users' biometric information to ensure meaningful consent.
  • Whether TikTok's privacy communications were adequate to obtain meaningful consent from youth (13-17), considering their cognitive development and potential harms from targeted ads.
  • Whether TikTok met its obligations under Quebec's Private Sector Act to inform persons concerned about the collection and use of personal information for user profiles, ad targeting, and content personalization.
  • Whether TikTok ensured that privacy settings provided the highest level of privacy by default under Quebec's Private Sector Act.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 20, 2025PIPEDA Findings #2025-001Indexed Jun 30, 2026

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

23andMe Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

Jun 20, 2025PIPEDA Findings #2025-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Key Issues
  • Whether 23andMe had appropriate safeguards to protect highly sensitive personal information under its control, specifically against credential stuffing attacks.
  • Whether 23andMe's prevention measures, including mandatory Multi-factor Authentication (MFA), compromised-password checks, and minimum password requirements, were adequate.
  • Whether 23andMe's detection measures, including detection systems, digital fingerprinting, and device history, were adequate to identify ongoing attacks.
  • Whether 23andMe adequately investigated anomalies and claims of breach prior to public disclosure.
  • Whether 23andMe's breach response, including the timeliness of disabling active user sessions, disabling raw DNA download features, and implementing mandatory MFA, was adequate.
  • Whether 23andMe adequately notified the OPC about the breach, including the completeness of information provided and timeliness.
  • Whether 23andMe adequately notified affected individuals about the breach, including the completeness of information provided and timeliness.
  • Whether the data breach created a real risk of significant harm to affected individuals, triggering notification obligations.
  • Whether 23andMe's methodology for identifying and notifying individuals whose raw DNA was downloaded by the Threat Actor was adequate.
Federal (Canada)Privacy ActWell-founded & unresolved
Federal (Canada) flag
Mar 11, 2025Indexed Jun 30, 2026

Investigation of the loss of an unencrypted Universal Serial Bus (USB) storage device by the Royal Canadian Mounted Police

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP) following the loss of an unencrypted USB storage device containing sensitive personal information of 1,741 individuals. The investigation focused on whether the RCMP contravened section 8 of the Privacy Act regarding disclosure, the appropriateness of its breach response, and the sufficiency of its safeguards for USB devices. The OPC found that the RCMP contravened section 8 due to unauthorized disclosure, as the device was lost, unencrypted, and its contents were copied and offered for sale. While the RCMP's notification to affected individuals and mitigation steps were generally appropriate after discovery, the initial reporting of the loss was significantly delayed. Furthermore, the RCMP failed to implement adequate safeguards, as its own policies for procurement, inventory, and encryption of USB devices were not followed, and security awareness training was insufficient. Despite the RCMP accepting the OPC's recommendations to strengthen safeguards, audit procedures, and awareness programs, it refused to commit to specific timelines for implementation. Consequently, the complaint was found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded & unresolved

Investigation of the loss of an unencrypted Universal Serial Bus (USB) storage device by the Royal Canadian Mounted Police

Mar 11, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP) following the loss of an unencrypted USB storage device containing sensitive personal information of 1,741 individuals. The investigation focused on whether the RCMP contravened section 8 of the Privacy Act regarding disclosure, the appropriateness of its breach response, and the sufficiency of its safeguards for USB devices. The OPC found that the RCMP contravened section 8 due to unauthorized disclosure, as the device was lost, unencrypted, and its contents were copied and offered for sale. While the RCMP's notification to affected individuals and mitigation steps were generally appropriate after discovery, the initial reporting of the loss was significantly delayed. Furthermore, the RCMP failed to implement adequate safeguards, as its own policies for procurement, inventory, and encryption of USB devices were not followed, and security awareness training was insufficient. Despite the RCMP accepting the OPC's recommendations to strengthen safeguards, audit procedures, and awareness programs, it refused to commit to specific timelines for implementation. Consequently, the complaint was found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP disclosed personal information in contravention of section 8 of the Privacy Act
  • Whether the RCMP's response to the privacy breach was appropriate in the circumstances
  • Whether the RCMP's measures to protect personal information contained on USB storage devices were sufficient
  • Whether RCMP personnel failed to report the loss of the USB storage device to authorities in a timely manner
  • Whether the RCMP's policies and procedures for procurement, inventory, and encryption of USB devices were followed and enforced
  • Whether the RCMP's security and privacy awareness training for members was effective and sufficient
  • Whether the RCMP's policy compliance monitoring for USB device use was adequate