The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

2 decisions matching
Federal (Canada)Access to Information ActDiscontinued
Federal (Canada) flag
Jun 20, 20262026 OIC 45Indexed Jun 30, 2026

Decision under section 30, 2026 OIC 45

A federal institution

The Information Commissioner received a complaint alleging that the titles of certain briefing notes published on the Open Canada website were improperly withheld. The complaint did not arise from an access request made under Part 1 of the Access to Information Act (ATIA). The Commissioner reviewed the complaint under section 30 of the ATIA, which outlines the types of complaints that can be investigated. It was determined that the complaint did not fall under paragraphs 30(1)(a) to (d.1) as it did not relate to an access request. Furthermore, it did not fall under paragraph 30(1)(e) or 30(1)(f) as it did not concern a matter relating to requesting or obtaining access to records under Part 1 of the ATIA. The Commissioner noted that subsection 91(1) of the ATIA specifically precludes her from exercising powers related to the proactive publication of information under Part 2 of the Act. Consequently, the complaint was found inadmissible, and the Commissioner declined to investigate due to a lack of authority.

Quick view

Access to Information ActDiscontinued

Decision under section 30, 2026 OIC 45

Jun 20, 20262026 OIC 45
Adjudicator: Caroline Maynard
Plain-Language Summary

The Information Commissioner received a complaint alleging that the titles of certain briefing notes published on the Open Canada website were improperly withheld. The complaint did not arise from an access request made under Part 1 of the Access to Information Act (ATIA). The Commissioner reviewed the complaint under section 30 of the ATIA, which outlines the types of complaints that can be investigated. It was determined that the complaint did not fall under paragraphs 30(1)(a) to (d.1) as it did not relate to an access request. Furthermore, it did not fall under paragraph 30(1)(e) or 30(1)(f) as it did not concern a matter relating to requesting or obtaining access to records under Part 1 of the ATIA. The Commissioner noted that subsection 91(1) of the ATIA specifically precludes her from exercising powers related to the proactive publication of information under Part 2 of the Act. Consequently, the complaint was found inadmissible, and the Commissioner declined to investigate due to a lack of authority.

Key Issues
  • Whether the complaint fell within the scope of section 30(1)(a) to (d.1) of the ATIA (complaints related to access requests)
  • Whether the complaint fell within the scope of section 30(1)(e) or (f) of the ATIA (other matters relating to requesting or obtaining access under Part 1)
  • Whether the Commissioner has authority to investigate complaints related to proactive publication under Part 2 of the ATIA (s.91(1))
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Mar 25, 2026Indexed Jun 30, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Nova Scotia Power

This document is a compliance letter from Nova Scotia Power to the OPC, outlining actions taken and commitments made following a significant data breach that occurred in March 2025. The breach, caused by malware, led to the exfiltration of personal information belonging to approximately 375,000 current and 540,000 former customers. The compromised data included names, contact information, financial details, driver's license numbers, and SINs. The OPC received numerous complaints regarding the breach, including concerns about the collection and retention of SINs and the timeliness and method of notification to affected individuals. Nova Scotia Power has committed to deleting customer SINs (subject to legal requirements) and undergoing an external security assessment by October 2026. Upon satisfactory fulfillment of these commitments, the OPC's investigation will be discontinued.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

This document is a compliance letter from Nova Scotia Power to the OPC, outlining actions taken and commitments made following a significant data breach that occurred in March 2025. The breach, caused by malware, led to the exfiltration of personal information belonging to approximately 375,000 current and 540,000 former customers. The compromised data included names, contact information, financial details, driver's license numbers, and SINs. The OPC received numerous complaints regarding the breach, including concerns about the collection and retention of SINs and the timeliness and method of notification to affected individuals. Nova Scotia Power has committed to deleting customer SINs (subject to legal requirements) and undergoing an external security assessment by October 2026. Upon satisfactory fulfillment of these commitments, the OPC's investigation will be discontinued.

Key Issues
  • Whether Nova Scotia Power's security safeguards were adequate to protect personal information
  • Whether Nova Scotia Power's collection and retention of Social Insurance Numbers (SINs) was appropriate
  • Whether Nova Scotia Power's notification of affected individuals was timely and appropriate
  • Whether Nova Scotia Power has taken sufficient corrective measures to address the breach and prevent future incidents