The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

6 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Dec 16, 2005Settled Case summary #17Indexed Jun 30, 2026

Settled case summary #17 — A not-for-profit association

A not-for-profit association

A member of a not-for-profit association complained that the association required a second piece of identification, in addition to his membership card, to obtain member discounts. The complainant believed his membership card should be sufficient and that collecting further personal information was unwarranted. The association explained that it had legal agreements with vendors requiring it to sell discounted products only to current members. Due to some members loaning their cards to non-members, which caused legal and revenue issues, the association implemented the supplementary identification requirement to confirm identity and prevent misuse. The association also noted that members could choose their secondary identification and that this information was not recorded. The complainant was satisfied with this explanation, and the complaint was settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #17 — A not-for-profit association

Dec 16, 2005Settled Case summary #17
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A member of a not-for-profit association complained that the association required a second piece of identification, in addition to his membership card, to obtain member discounts. The complainant believed his membership card should be sufficient and that collecting further personal information was unwarranted. The association explained that it had legal agreements with vendors requiring it to sell discounted products only to current members. Due to some members loaning their cards to non-members, which caused legal and revenue issues, the association implemented the supplementary identification requirement to confirm identity and prevent misuse. The association also noted that members could choose their secondary identification and that this information was not recorded. The complainant was satisfied with this explanation, and the complaint was settled.

Key Issues
  • Whether requiring supplementary identification for member discounts was an unwarranted collection of personal information
  • Whether the membership card alone was sufficient identification
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 21, 2005Settled Case summary #16Indexed Jun 30, 2026

Settled Case summary #16: Personal information on receipts removed, information collected when goods returned is limited (November 21, 2005)

A retail chain

An individual complained about a retail chain's practice of printing personal information on receipts and collecting excessive information for returns. The complainant was concerned that the printing of name, credit card number, and expiry date on receipts, and the recording of driver's license and credit card information for refunds, constituted unnecessary collection of personal information. During the investigation, the company updated its point-of-sale equipment to mask personal information on receipts. For returns, the company committed to continuing to collect name, address, and telephone number, but would no longer record identification information, only asking to see it. Credit card information would only be requested if a credit card was used for the original purchase. The company also committed to training its employees on these new procedures. Both the complainant and the OPC were satisfied with these changes.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #16: Personal information on receipts removed, information collected when goods returned is limited (November 21, 2005)

Nov 21, 2005Settled Case summary #16
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained about a retail chain's practice of printing personal information on receipts and collecting excessive information for returns. The complainant was concerned that the printing of name, credit card number, and expiry date on receipts, and the recording of driver's license and credit card information for refunds, constituted unnecessary collection of personal information. During the investigation, the company updated its point-of-sale equipment to mask personal information on receipts. For returns, the company committed to continuing to collect name, address, and telephone number, but would no longer record identification information, only asking to see it. Credit card information would only be requested if a credit card was used for the original purchase. The company also committed to training its employees on these new procedures. Both the complainant and the OPC were satisfied with these changes.

Key Issues
  • Whether printing customer's name, credit card number, and expiry date on receipts constituted unnecessary collection of personal information under PIPEDA
  • Whether requiring and recording a driver's license and credit card for returns constituted unnecessary collection of personal information under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jul 29, 2005Settled Case summaryIndexed Jun 30, 2026

Settled Case summary: Disclosure of personal information to estranged spouse - July 29, 2005

A bank

An individual complained that a bank employee improperly disclosed her bank account balance to her estranged husband. The husband subsequently withheld a support payment, causing financial difficulty for the complainant. The bank apologized and acknowledged that its employee likely contravened Principle 4.3 of PIPEDA by disclosing personal information without consent. Although the employee denied the specific recollection, the bank found no evidence to suggest the allegations were false. The bank and the complainant reached a private settlement regarding compensation. The OPC concluded that there was no systemic problem, as the bank had adequate privacy policies and training in place.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary: Disclosure of personal information to estranged spouse - July 29, 2005

Jul 29, 2005Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a bank employee improperly disclosed her bank account balance to her estranged husband. The husband subsequently withheld a support payment, causing financial difficulty for the complainant. The bank apologized and acknowledged that its employee likely contravened Principle 4.3 of PIPEDA by disclosing personal information without consent. Although the employee denied the specific recollection, the bank found no evidence to suggest the allegations were false. The bank and the complainant reached a private settlement regarding compensation. The OPC concluded that there was no systemic problem, as the bank had adequate privacy policies and training in place.

Key Issues
  • Whether a bank employee disclosed personal information without consent
  • Whether the disclosure of a bank account balance to an estranged spouse contravened Principle 4.3 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jun 24, 2005Settled Case summary #15Indexed Jun 30, 2026

Settled case summary #15 — A retail store and A financial institution

A retail store and A financial institution

An individual complained that a retail store inappropriately collected her personal information and disclosed it to a financial institution, and that the financial institution used and disclosed her information without consent. The complainant provided her information for a credit application but decided not to proceed, tearing up the contract. However, due to a salesperson's error, her information was entered into the system before her signature, leading to a credit card being issued. The financial institution apologized, removed inquiries from her credit file, and purged her information. The retail store implemented new procedures to ensure signatures are obtained before data entry. Both the complainant and the OPC were satisfied with the corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #15 — A retail store and A financial institution

Jun 24, 2005Settled Case summary #15
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a retail store inappropriately collected her personal information and disclosed it to a financial institution, and that the financial institution used and disclosed her information without consent. The complainant provided her information for a credit application but decided not to proceed, tearing up the contract. However, due to a salesperson's error, her information was entered into the system before her signature, leading to a credit card being issued. The financial institution apologized, removed inquiries from her credit file, and purged her information. The retail store implemented new procedures to ensure signatures are obtained before data entry. Both the complainant and the OPC were satisfied with the corrective actions.

Key Issues
  • Whether the retail store inappropriately collected and disclosed personal information without consent
  • Whether the financial institution used and disclosed personal information without consent
  • Whether the salesperson followed proper procedure for credit applications
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
May 17, 2005Settled Case summaryIndexed Jun 30, 2026

Settled case summary #13 — A company

A company

An individual complained that a company sent him an unsolicited commercial e-mail promoting its products. The company, which typically markets through a distributor network and commission sales agents, was unaware that one of its agents was using email for marketing. The company does not approve of this marketing technique. Upon learning of the issue, the company contacted the agent and instructed them to cease using email for marketing. The agent confirmed compliance and apologized to the complainant. The company, despite its small size, has a privacy policy and a designated privacy officer. The complainant was satisfied with the resolution.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #13 — A company

May 17, 2005Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a company sent him an unsolicited commercial e-mail promoting its products. The company, which typically markets through a distributor network and commission sales agents, was unaware that one of its agents was using email for marketing. The company does not approve of this marketing technique. Upon learning of the issue, the company contacted the agent and instructed them to cease using email for marketing. The agent confirmed compliance and apologized to the complainant. The company, despite its small size, has a privacy policy and a designated privacy officer. The complainant was satisfied with the resolution.

Key Issues
  • Whether sending unsolicited commercial email constitutes a contravention of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 18, 2005Incident Summary #2Indexed Jun 30, 2026

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

CIBC

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

Apr 18, 2005Incident Summary #2
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Key Issues
  • Whether CIBC's privacy practices adequately protected personal information from misdirected faxes
  • Whether CIBC effectively responded to notifications of misdirected faxes
  • Whether CIBC appropriately recovered misdirected personal information
  • Whether CIBC adequately notified affected customers of privacy breaches
  • Whether CIBC employees recognized misdirected faxes as privacy issues
  • Whether CIBC's internal privacy management structure was sufficient to address breaches