The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

26 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 16, 2014Indexed Jun 30, 2026

Canada Revenue Agency and the Canadian Broadcasting Corporation (CBC) - 2015

Canadian Broadcasting Corporation (CBC)

This report addresses complaints against the Canadian Broadcasting Corporation (CBC) regarding its publication of personal information inadvertently disclosed by the Canada Revenue Agency (CRA). The CRA mistakenly mailed a spreadsheet containing taxpayers' personal information to a CBC journalist. The CBC subsequently published an article detailing the breach, identifying several affected individuals, and including their photographs. Complainants alleged the CBC contravened the Privacy Act by disclosing this information. The CBC argued that the information was obtained legally and that the Privacy Act does not apply to information collected, used, or disclosed for journalistic purposes under section 69.1 of the Act. The OPC found that the CBC's actions were purely journalistic and therefore fell under this exclusion, meaning the Privacy Act did not apply to the CBC's handling of the information.

Quick view

Privacy ActNot well-founded

Canada Revenue Agency and the Canadian Broadcasting Corporation (CBC) - 2015

Dec 16, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

This report addresses complaints against the Canadian Broadcasting Corporation (CBC) regarding its publication of personal information inadvertently disclosed by the Canada Revenue Agency (CRA). The CRA mistakenly mailed a spreadsheet containing taxpayers' personal information to a CBC journalist. The CBC subsequently published an article detailing the breach, identifying several affected individuals, and including their photographs. Complainants alleged the CBC contravened the Privacy Act by disclosing this information. The CBC argued that the information was obtained legally and that the Privacy Act does not apply to information collected, used, or disclosed for journalistic purposes under section 69.1 of the Act. The OPC found that the CBC's actions were purely journalistic and therefore fell under this exclusion, meaning the Privacy Act did not apply to the CBC's handling of the information.

Key Issues
  • Whether the information published by the CBC constituted personal information under section 3 of the Privacy Act
  • Whether the CBC's collection, use, and disclosure of the personal information was for journalistic purposes
  • Whether the exclusion provision under section 69.1 of the Privacy Act applied to the CBC's actions
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 3, 2014Indexed Jun 30, 2026

Canada Revenue Agency and the Canadian Broadcasting Corporation (CRA) - 2015

Canada Revenue Agency

The Canada Revenue Agency (CRA) inadvertently mailed the personal information of approximately 1,000 individuals to a Canadian Broadcasting Corporation (CBC) journalist. This occurred due to an ATIP clerk mistakenly switching cover letters for two different response packages. The disclosed information included names, addresses, and details of donations. The CBC refused the CRA's requests to return the information, leading the CRA to initiate legal action. The OPC found that the CRA disclosed personal information without consent, contravening the Privacy Act. While the OPC noted the CRA's immediate remedial actions and action plan, it concluded that the disclosure did not meet the requirements of the Act.

Quick view

Privacy ActWell-founded

Canada Revenue Agency and the Canadian Broadcasting Corporation (CRA) - 2015

Dec 3, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canada Revenue Agency (CRA) inadvertently mailed the personal information of approximately 1,000 individuals to a Canadian Broadcasting Corporation (CBC) journalist. This occurred due to an ATIP clerk mistakenly switching cover letters for two different response packages. The disclosed information included names, addresses, and details of donations. The CBC refused the CRA's requests to return the information, leading the CRA to initiate legal action. The OPC found that the CRA disclosed personal information without consent, contravening the Privacy Act. While the OPC noted the CRA's immediate remedial actions and action plan, it concluded that the disclosure did not meet the requirements of the Act.

Key Issues
  • Whether the inadvertent mailing of personal information to a journalist constituted a disclosure without consent under the Privacy Act
  • Whether the information disclosed was 'personal information' as defined by section 3 of the Privacy Act
  • Whether the disclosure met the requirements of section 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2014Indexed Jun 30, 2026

Collection of RCMP member's health information unnecessary (RCMP) - November 17, 2014

Royal Canadian Mounted Police (RCMP)

A former RCMP member complained that the RCMP inappropriately collected her personal medical and financial information from Veterans Affairs Canada (VAC) after she was awarded a disability pension. The complainant alleged that the RCMP's National Compensation Policy Centre had no need for this sensitive information. The OPC found that the 2002 Memorandum of Understanding (MOU) between the RCMP and VAC transferred responsibility for pension administration to VAC, meaning the RCMP's National Compensation Policy Centre did not require the detailed medical diagnosis or financial information. The OPC concluded that the collection of this information by the RCMP was not for a purpose consistent with section 4 of the Privacy Act. The complaint was found to be well-founded, and the OPC recommended updating the MOU and reviewing RCMP's internal policies on access to medical records.

Quick view

Privacy ActWell-founded

Collection of RCMP member's health information unnecessary (RCMP) - November 17, 2014

Nov 17, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A former RCMP member complained that the RCMP inappropriately collected her personal medical and financial information from Veterans Affairs Canada (VAC) after she was awarded a disability pension. The complainant alleged that the RCMP's National Compensation Policy Centre had no need for this sensitive information. The OPC found that the 2002 Memorandum of Understanding (MOU) between the RCMP and VAC transferred responsibility for pension administration to VAC, meaning the RCMP's National Compensation Policy Centre did not require the detailed medical diagnosis or financial information. The OPC concluded that the collection of this information by the RCMP was not for a purpose consistent with section 4 of the Privacy Act. The complaint was found to be well-founded, and the OPC recommended updating the MOU and reviewing RCMP's internal policies on access to medical records.

Key Issues
  • Whether the collection of the complainant's financial information by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of the complainant's medical diagnosis/pensioned disability by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of the complainant's disability percentage by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of personal information by the RCMP's National Compensation Policy Centre was consistent with the RCMP's own internal policies restricting access to sensitive medical information
  • Whether the MOU between VAC and the RCMP adequately addressed information sharing practices for sensitive personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2014Indexed Jun 30, 2026

Collection of RCMP member's health information unnecessary (VAC) - November 17, 2014

Veterans Affairs Canada (VAC)

A former RCMP member complained that Veterans Affairs Canada (VAC) inappropriately disclosed her medical diagnosis, disability percentage, and financial information to the RCMP's National Compensation Policy Centre. VAC argued the disclosure was a 'consistent use' under the Privacy Act, citing the RCMP's responsibility for members' health services and an MOU between the two institutions. The OPC found that the information provided to the complainant at the time of application was inadequate to establish informed consent for such disclosure. Furthermore, the MOU did not explicitly authorize the sharing of detailed medical and financial information with the RCMP's National Compensation Policy Centre. The OPC concluded that the disclosure was not a consistent use and therefore contravened the Privacy Act, noting the systemic nature of this issue affecting many RCMP employees.

Quick view

Privacy ActWell-founded

Collection of RCMP member's health information unnecessary (VAC) - November 17, 2014

Nov 17, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A former RCMP member complained that Veterans Affairs Canada (VAC) inappropriately disclosed her medical diagnosis, disability percentage, and financial information to the RCMP's National Compensation Policy Centre. VAC argued the disclosure was a 'consistent use' under the Privacy Act, citing the RCMP's responsibility for members' health services and an MOU between the two institutions. The OPC found that the information provided to the complainant at the time of application was inadequate to establish informed consent for such disclosure. Furthermore, the MOU did not explicitly authorize the sharing of detailed medical and financial information with the RCMP's National Compensation Policy Centre. The OPC concluded that the disclosure was not a consistent use and therefore contravened the Privacy Act, noting the systemic nature of this issue affecting many RCMP employees.

Key Issues
  • Whether the disclosure of the complainant's medical and financial information by VAC to the RCMP was authorized by consent under subsection 8(1) of the Privacy Act
  • Whether the disclosure of the complainant's medical and financial information by VAC to the RCMP was for a consistent use under paragraph 8(2)(a) of the Privacy Act
  • Whether the information provided to disability pension applicants by VAC was sufficient to establish informed consent for disclosure to the RCMP
  • Whether the Memorandum of Understanding (MOU) between VAC and the RCMP authorized the detailed sharing of personal medical and financial information
  • Whether the RCMP's National Compensation Policy Centre had a 'need to know' the complainant's detailed medical and financial information
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Nov 13, 2014Indexed Jun 30, 2026

Video surveillance of employees vs. right to privacy - a delicate balance - November 13, 2014

Canada Border Services Agency (CBSA)

An employee of the Canada Border Services Agency (CBSA) complained on behalf of colleagues that the CBSA was using video monitoring to collect personal information for the purpose of monitoring employee conduct and performance, beyond the original safety and security purposes. The complainant also alleged insufficient signage. The OPC found the signage issue was resolved early in the investigation as the CBSA added more signs. Regarding the use of video for monitoring conduct and performance, the CBSA updated its policy to clarify that video technology would not be used for performance monitoring. The OPC accepted the CBSA's rationale for using video recordings to investigate serious misconduct, finding it met the standard for collection under section 4 of the Privacy Act. However, the resolution was conditional on the CBSA providing updated guidelines for implementing its policy.

Quick view

Privacy ActResolved

Video surveillance of employees vs. right to privacy - a delicate balance - November 13, 2014

Nov 13, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee of the Canada Border Services Agency (CBSA) complained on behalf of colleagues that the CBSA was using video monitoring to collect personal information for the purpose of monitoring employee conduct and performance, beyond the original safety and security purposes. The complainant also alleged insufficient signage. The OPC found the signage issue was resolved early in the investigation as the CBSA added more signs. Regarding the use of video for monitoring conduct and performance, the CBSA updated its policy to clarify that video technology would not be used for performance monitoring. The OPC accepted the CBSA's rationale for using video recordings to investigate serious misconduct, finding it met the standard for collection under section 4 of the Privacy Act. However, the resolution was conditional on the CBSA providing updated guidelines for implementing its policy.

Key Issues
  • Whether the CBSA's use of video monitoring for employee conduct and performance monitoring contravened the Privacy Act
  • Whether the collection of personal information via video technology was necessary and related directly to an operating program or activity of the institution under section 4 of the Privacy Act
  • Whether the CBSA had sufficient signage to inform employees of video monitoring
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Oct 31, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-013Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-013: Organization could reasonably assume customer's implied consent for disclosure in dispute resolution situation

An Internet service provider (ISP)

A complainant alleged that his Internet service provider (ISP) disclosed his personal information without consent to a newspaper columnist. The complainant had contacted the columnist for assistance in resolving a service dispute with the ISP. The ISP argued it had implied consent to disclose information relevant to the dispute. The OPC found that the personal information disclosed was not sensitive and that, given the complainant's actions and familiarity with the columnist's work, it was reasonable for the ISP to infer implied consent. The ISP also limited its disclosure to information relevant to the complaint. Therefore, the OPC concluded that the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Commissioner’s Findings - PIPEDA Report of Findings #2014-013: Organization could reasonably assume customer's implied consent for disclosure in dispute resolution situation

Oct 31, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-013
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that his Internet service provider (ISP) disclosed his personal information without consent to a newspaper columnist. The complainant had contacted the columnist for assistance in resolving a service dispute with the ISP. The ISP argued it had implied consent to disclose information relevant to the dispute. The OPC found that the personal information disclosed was not sensitive and that, given the complainant's actions and familiarity with the columnist's work, it was reasonable for the ISP to infer implied consent. The ISP also limited its disclosure to information relevant to the complaint. Therefore, the OPC concluded that the complaint was not well-founded.

Key Issues
  • Whether the ISP had the complainant's consent to disclose information to the newspaper columnist
  • Whether the personal information disclosed was sensitive
  • Whether implied consent was appropriate in the circumstances
  • Whether the ISP limited its disclosure to relevant information
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Oct 30, 2014Early resolved case summary #9Indexed Jun 30, 2026

Early resolved case summary #9: Equipment store ends practice of photocopying driver’s licences as a condition of renting equipment - October 30, 2014

An equipment store

An individual complained that an equipment store required a scanned copy of his driver's license and a photograph as a condition for renting equipment. The store justified this practice by citing past losses of expensive rental equipment. The OPC informed the store that collecting driver's license information in this manner was generally inappropriate due to the excessive personal information contained on the license and its limited value in theft investigations. The OPC provided guidance on appropriate collection practices. As a result of the OPC's intervention, the store implemented a less privacy-invasive solution and trained its staff. The complainant was satisfied with the outcome.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #9: Equipment store ends practice of photocopying driver’s licences as a condition of renting equipment - October 30, 2014

Oct 30, 2014Early resolved case summary #9
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an equipment store required a scanned copy of his driver's license and a photograph as a condition for renting equipment. The store justified this practice by citing past losses of expensive rental equipment. The OPC informed the store that collecting driver's license information in this manner was generally inappropriate due to the excessive personal information contained on the license and its limited value in theft investigations. The OPC provided guidance on appropriate collection practices. As a result of the OPC's intervention, the store implemented a less privacy-invasive solution and trained its staff. The complainant was satisfied with the outcome.

Key Issues
  • Whether requiring a scanned copy of a driver's license and a photograph for equipment rental constitutes appropriate collection of personal information under PIPEDA
  • Whether the collection of driver's license information is justified for addressing customer theft
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Public Service school called upon to better protect confidentiality

Canada School of Public Service

The Canada School of Public Service (the School) received a letter from the Public Sector Integrity Commissioner (PSIC) detailing allegations of wrongdoing against seven employees. The School then hand-delivered copies of this letter, which identified the seven individuals and the alleged wrongdoings, to each of the named employees. One of these employees complained to the OPC, alleging that the disclosure of his name via this letter violated the Privacy Act. The OPC found the complaint to be well-founded, concluding that the School had improperly disclosed personal information. Following the OPC's recommendations, the School developed new procedures to protect the confidentiality of information related to the Public Servants Disclosure Protection Act and a plan for addressing privacy breaches.

Quick view

Privacy ActWell-founded

Public Service school called upon to better protect confidentiality

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canada School of Public Service (the School) received a letter from the Public Sector Integrity Commissioner (PSIC) detailing allegations of wrongdoing against seven employees. The School then hand-delivered copies of this letter, which identified the seven individuals and the alleged wrongdoings, to each of the named employees. One of these employees complained to the OPC, alleging that the disclosure of his name via this letter violated the Privacy Act. The OPC found the complaint to be well-founded, concluding that the School had improperly disclosed personal information. Following the OPC's recommendations, the School developed new procedures to protect the confidentiality of information related to the Public Servants Disclosure Protection Act and a plan for addressing privacy breaches.

Key Issues
  • Whether the Canada School of Public Service disclosed personal information contrary to the Privacy Act by hand-delivering a letter from the Public Sector Integrity Commissioner to employees named in it
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Woman fails in attempt to return personal information to Canada Revenue Agency

Canada Revenue Agency (CRA)

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Quick view

Privacy ActWell-founded

Woman fails in attempt to return personal information to Canada Revenue Agency

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Key Issues
  • Whether the Canada Revenue Agency breached the privacy rights of taxpayers by mistakenly sending confidential personal information to an unauthorized individual
  • Whether the Canada Revenue Agency's procedures for handling misdirected mail and breach reporting were adequate
  • Whether the Canada Revenue Agency's client service channels were accessible for reporting privacy breaches
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Employment and Social Development Canada (ESDC)

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Quick view

Privacy ActWell-founded & resolved

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Key Issues
  • Whether Employment and Social Development Canada (ESDC) adequately protected personal information on a lost USB key
  • Whether Justice Canada adequately protected personal information on a lost USB key while in its custody
  • Whether physical controls for personal information were adequate
  • Whether technological controls (encryption, password protection) for personal information were adequate
  • Whether administrative controls for personal information were adequate
  • Whether personnel controls for personal information were adequate
  • Whether ESDC translated its privacy and security policies into meaningful business practices
  • Whether Justice Canada translated its privacy and security policies into meaningful business practices
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

RCMP retention period for disciplinary records questioned

Royal Canadian Mounted Police (RCMP)

A complaint was filed on behalf of RCMP members regarding the disclosure of informal disciplinary records to the Crown, arguing it was inconsistent with the Supreme Court's R. v. McNeil decision. The complainant contended that only records from formal disciplinary hearings should be disclosed. The RCMP maintained that both formal and informal misconduct records could be relevant under McNeil, and the OPC agreed with this interpretation, finding the complaint not well-founded. However, the OPC expressed serious concerns about the RCMP's policy of retaining disciplinary records until members reach 100 years of age, which is significantly longer than other police services. The OPC recommended the RCMP reconsider its retention policies, but the RCMP indicated it would continue its current practice.

Quick view

Privacy ActNot well-founded

RCMP retention period for disciplinary records questioned

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed on behalf of RCMP members regarding the disclosure of informal disciplinary records to the Crown, arguing it was inconsistent with the Supreme Court's R. v. McNeil decision. The complainant contended that only records from formal disciplinary hearings should be disclosed. The RCMP maintained that both formal and informal misconduct records could be relevant under McNeil, and the OPC agreed with this interpretation, finding the complaint not well-founded. However, the OPC expressed serious concerns about the RCMP's policy of retaining disciplinary records until members reach 100 years of age, which is significantly longer than other police services. The OPC recommended the RCMP reconsider its retention policies, but the RCMP indicated it would continue its current practice.

Key Issues
  • Whether the disclosure of informal disciplinary records to the Crown is consistent with R. v. McNeil
  • Whether the RCMP's retention period for disciplinary records is appropriate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Wanted by the CBSA Program

Canada Border Services Agency (CBSA)

The Canadian Council for Refugees complained that the Canada Border Services Agency (CBSA) improperly disclosed an individual's personal information on its "Wanted by the CBSA" website. The program aimed to solicit public help in locating individuals with Canada-wide warrants for removal, including those accused of war crimes. The OPC found that while the disclosure of personal information was permissible under the Privacy Act as a consistent use for immigration law enforcement, the CBSA failed to ensure the information was accurate, up-to-date, and complete. Specifically, the website implied a conviction for war crimes when the individual was only deemed inadmissible under immigration law. This led to a well-founded finding regarding the accuracy of the information. The CBSA accepted five recommendations, including revisiting the amount of personal information disclosed, clarifying the distinction between criminal conviction and immigration determination, and improving the timely removal of profiles.

Quick view

Privacy ActWell-founded

Wanted by the CBSA Program

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canadian Council for Refugees complained that the Canada Border Services Agency (CBSA) improperly disclosed an individual's personal information on its "Wanted by the CBSA" website. The program aimed to solicit public help in locating individuals with Canada-wide warrants for removal, including those accused of war crimes. The OPC found that while the disclosure of personal information was permissible under the Privacy Act as a consistent use for immigration law enforcement, the CBSA failed to ensure the information was accurate, up-to-date, and complete. Specifically, the website implied a conviction for war crimes when the individual was only deemed inadmissible under immigration law. This led to a well-founded finding regarding the accuracy of the information. The CBSA accepted five recommendations, including revisiting the amount of personal information disclosed, clarifying the distinction between criminal conviction and immigration determination, and improving the timely removal of profiles.

Key Issues
  • Whether the disclosure of personal information on the "Wanted by the CBSA" website was permissible under the Privacy Act as a consistent use
  • Whether the CBSA took all reasonable steps to ensure the personal information was accurate, up-to-date, and complete as required by the Privacy Act
  • Whether the CBSA should have conducted a Privacy Impact Assessment before launching the program
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Oct 21, 2014Discontinued Case Summary #2014-004Indexed Jun 30, 2026

Discontinued Case Summary #2014-004: Complaint discontinued on the basis of bad faith as complainant had released the retailer from liability

A retailer

An individual filed a complaint against a retailer, alleging a failure to provide access to personal information under PIPEDA. This complaint arose after the complainant and the retailer had settled a small claims court dispute. As part of that settlement, the complainant had signed a mutual release, receiving financial compensation in exchange for releasing the retailer from all claims and complaints, including those arising under statute, related to events prior to the release date. The OPC found that the complaint was made in bad faith, given the existence of this mutual release. Consequently, the investigation was discontinued under paragraph 12.2(1)(b) of PIPEDA.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Discontinued Case Summary #2014-004: Complaint discontinued on the basis of bad faith as complainant had released the retailer from liability

Oct 21, 2014Discontinued Case Summary #2014-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual filed a complaint against a retailer, alleging a failure to provide access to personal information under PIPEDA. This complaint arose after the complainant and the retailer had settled a small claims court dispute. As part of that settlement, the complainant had signed a mutual release, receiving financial compensation in exchange for releasing the retailer from all claims and complaints, including those arising under statute, related to events prior to the release date. The OPC found that the complaint was made in bad faith, given the existence of this mutual release. Consequently, the investigation was discontinued under paragraph 12.2(1)(b) of PIPEDA.

Key Issues
  • Whether the complaint was made in bad faith under paragraph 12.2(1)(b) of PIPEDA
  • Whether a mutual release agreement impacts the validity of a subsequent privacy complaint
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Sep 16, 2014Indexed Jun 30, 2026

Name tags for border officers not a violation - September 16, 2014

Canada Border Services Agency (CBSA)

A group of Canada Border Services Agency (CBSA) employees complained that a new policy requiring them to wear name tags displaying their surnames, instead of badge numbers, violated sections 7 and 8 of the Privacy Act. They argued this constituted an unreasonable invasion of privacy and made them vulnerable to violence and intimidation, as their names could be used to find personal information. The CBSA contended that the name tags were part of a service excellence initiative, promoted professionalism and accountability, and that an employee's name on a name tag falls under an exception to the definition of personal information in the Act. The OPC found that while a surname on a name tag is information about an identifiable individual, it falls under paragraph (j) of the definition of personal information, which excludes information relating to the position or functions of a government employee for the purposes of sections 7 and 8. Therefore, the OPC concluded that the policy did not violate the Act.

Quick view

Privacy ActNot well-founded

Name tags for border officers not a violation - September 16, 2014

Sep 16, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A group of Canada Border Services Agency (CBSA) employees complained that a new policy requiring them to wear name tags displaying their surnames, instead of badge numbers, violated sections 7 and 8 of the Privacy Act. They argued this constituted an unreasonable invasion of privacy and made them vulnerable to violence and intimidation, as their names could be used to find personal information. The CBSA contended that the name tags were part of a service excellence initiative, promoted professionalism and accountability, and that an employee's name on a name tag falls under an exception to the definition of personal information in the Act. The OPC found that while a surname on a name tag is information about an identifiable individual, it falls under paragraph (j) of the definition of personal information, which excludes information relating to the position or functions of a government employee for the purposes of sections 7 and 8. Therefore, the OPC concluded that the policy did not violate the Act.

Key Issues
  • Whether the surname of a Border Services Officer (BSO) displayed on a name tag constitutes "personal information" under section 3 of the Privacy Act
  • Whether the surname on a name tag falls within the exception to the definition of personal information under paragraph (j) of section 3 of the Privacy Act
  • Whether the CBSA's requirement for BSOs to wear name tags displaying their surnames violates sections 7 and 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 5, 2014Indexed Jun 30, 2026

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Aboriginal Affairs and Northern Development Canada (AANDC)

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Quick view

Privacy ActWell-founded

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Sep 5, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Key Issues
  • Whether the document contained personal information under s.3 of the Privacy Act
  • Whether all AANDC officials who accessed the document had a need-to-know the identity of the requesters under s.7(a) of the Privacy Act and TBS Policy on Access to Information s.6.2.3
  • Whether the disclosure of the information to La Presse constituted a contravention of s.8 of the Privacy Act