The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

11 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Aug 4, 2020PIPEDA Findings #2020-001Indexed Jun 30, 2026

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

TD Canada Trust

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

Aug 4, 2020PIPEDA Findings #2020-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Key Issues
  • Whether TD was required to obtain additional consent for transferring personal information to a third-party service provider in India for fraud claims processing (Principle 4.3 PIPEDA)
  • Whether TD was required to offer customers an opt-out for the transfer of personal information to a third-party service provider in India for fraud claims processing
  • Whether TD was sufficiently open about its practice of transferring personal information to a third-party service provider in a foreign jurisdiction for processing (Principle 4.8 PIPEDA)
  • Whether TD ensured a comparable level of protection for personal information processed by the third-party service provider in India (Principle 4.1.3 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Dec 9, 2019PIPEDA Findings #2019-007Indexed Jun 30, 2026

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Trans Union of Canada, Inc.

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Dec 9, 2019PIPEDA Findings #2019-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Key Issues
  • Whether TransUnion disclosed the complainant's credit file information to Statistics Canada without requisite consent
  • Whether TransUnion was authorized to disclose personal information without consent under PIPEDA subparagraph 7(3)(c.1)(iii)
  • Whether Statistics Canada identified its lawful authority to obtain the information
  • Whether the disclosure was requested to administer a law of Canada (the Statistics Act)
  • Whether Statistics Canada subsequently disclosed the complainant's credit file information to other government institutions for debt collection
  • Whether there was sufficient evidence to support the allegation of information misuse for debt collection
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Nov 2, 2017PIPEDA Report of Findings #2017-009Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-009: Airline relies on access exemption to refuse traveler’s access to their personal information

An airline

A traveler complained that an airline failed to provide complete access to his personal information, specifically documents and correspondence related to being denied boarding in 2015. The airline invoked exemptions under PIPEDA, arguing the information was collected to investigate a breach of agreement or contravention of law (s.7(1)(b)) and disclosed to a government institution for law enforcement purposes (s.7(3)(c.1)(ii)). The OPC found that the collection without consent was justified under s.7(1)(b) because it was for investigating potential non-compliance with the Immigration and Refugee Protection Act, and that requiring consent would have compromised the investigation. The OPC also found the disclosure to a government institution was permissible under s.7(3)(c.1)(ii). Furthermore, the OPC determined that the airline was prohibited from providing access to the requested information under s.9(2.4) because the government institution objected to its release. Therefore, the OPC concluded that the airline properly relied on the exemptions.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Report of Findings #2017-009: Airline relies on access exemption to refuse traveler’s access to their personal information

Nov 2, 2017PIPEDA Report of Findings #2017-009
Adjudicator: Daniel Therrien
Plain-Language Summary

A traveler complained that an airline failed to provide complete access to his personal information, specifically documents and correspondence related to being denied boarding in 2015. The airline invoked exemptions under PIPEDA, arguing the information was collected to investigate a breach of agreement or contravention of law (s.7(1)(b)) and disclosed to a government institution for law enforcement purposes (s.7(3)(c.1)(ii)). The OPC found that the collection without consent was justified under s.7(1)(b) because it was for investigating potential non-compliance with the Immigration and Refugee Protection Act, and that requiring consent would have compromised the investigation. The OPC also found the disclosure to a government institution was permissible under s.7(3)(c.1)(ii). Furthermore, the OPC determined that the airline was prohibited from providing access to the requested information under s.9(2.4) because the government institution objected to its release. Therefore, the OPC concluded that the airline properly relied on the exemptions.

Key Issues
  • Whether the airline's collection of personal information without consent was justified under paragraph 7(1)(b) of PIPEDA
  • Whether the airline's disclosure of personal information without consent was justified under subparagraph 7(3)(c.1)(ii) of PIPEDA
  • Whether the airline was required to provide access to the requested personal information under Principle 4.9 of Schedule 1, given the exemptions under section 9 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Jan 11, 2017PIPEDA Case Summary #2017-004Indexed Jun 30, 2026

PIPEDA Case Summary #2017-004: Consent provided extends to third-party doctor hired to evaluate accident insurance claim

A doctor hired by an independent medical evaluation firm

An individual complained that a doctor collected, used, and disclosed his personal information without consent. The complainant had been in a car accident and his insurance company hired an independent medical evaluation (IME) firm to assess his claim for catastrophic impairment. The doctor in question was hired by the IME firm to compile a summary report based on assessments from other doctors. The complainant argued he had not consented to this specific doctor, though he had consented to other doctors involved in his claim. The doctor contended that the complainant had provided consent through signed accident benefit forms (OCF-1 and OCF-19). The OPC found that the signed forms included explicit consent for health professionals to collect, use, and disclose personal information for the purpose of investigating and processing the insurance claim. The OPC concluded that the doctor's actions were within the scope of the consent provided.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Case Summary #2017-004: Consent provided extends to third-party doctor hired to evaluate accident insurance claim

Jan 11, 2017PIPEDA Case Summary #2017-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a doctor collected, used, and disclosed his personal information without consent. The complainant had been in a car accident and his insurance company hired an independent medical evaluation (IME) firm to assess his claim for catastrophic impairment. The doctor in question was hired by the IME firm to compile a summary report based on assessments from other doctors. The complainant argued he had not consented to this specific doctor, though he had consented to other doctors involved in his claim. The doctor contended that the complainant had provided consent through signed accident benefit forms (OCF-1 and OCF-19). The OPC found that the signed forms included explicit consent for health professionals to collect, use, and disclose personal information for the purpose of investigating and processing the insurance claim. The OPC concluded that the doctor's actions were within the scope of the consent provided.

Key Issues
  • Whether the doctor collected, used, and disclosed the complainant's personal information without consent
  • Whether the consent provided in OCF-1 and OCF-19 forms extended to the doctor preparing the summary report
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 23, 2015PIPEDA Report of Findings #2015-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

An investment brokerage

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 23, 2015PIPEDA Report of Findings #2015-006
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Key Issues
  • Whether the collection of net worth, marital status, and spouse's occupation was necessary for opening a self-directed investment account under Principle 4.4 PIPEDA
  • Whether the purposes for collecting the personal information were explicitly specified under Principle 4.2 PIPEDA
  • Whether the purposes for collecting the personal information were legitimate and appropriate under subsection 5(3) PIPEDA
  • Whether the organization required consent to the collection of information beyond that required for explicitly specified and legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Oct 31, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-013Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-013: Organization could reasonably assume customer's implied consent for disclosure in dispute resolution situation

An Internet service provider (ISP)

A complainant alleged that his Internet service provider (ISP) disclosed his personal information without consent to a newspaper columnist. The complainant had contacted the columnist for assistance in resolving a service dispute with the ISP. The ISP argued it had implied consent to disclose information relevant to the dispute. The OPC found that the personal information disclosed was not sensitive and that, given the complainant's actions and familiarity with the columnist's work, it was reasonable for the ISP to infer implied consent. The ISP also limited its disclosure to information relevant to the complaint. Therefore, the OPC concluded that the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Commissioner’s Findings - PIPEDA Report of Findings #2014-013: Organization could reasonably assume customer's implied consent for disclosure in dispute resolution situation

Oct 31, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-013
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that his Internet service provider (ISP) disclosed his personal information without consent to a newspaper columnist. The complainant had contacted the columnist for assistance in resolving a service dispute with the ISP. The ISP argued it had implied consent to disclose information relevant to the dispute. The OPC found that the personal information disclosed was not sensitive and that, given the complainant's actions and familiarity with the columnist's work, it was reasonable for the ISP to infer implied consent. The ISP also limited its disclosure to information relevant to the complaint. Therefore, the OPC concluded that the complaint was not well-founded.

Key Issues
  • Whether the ISP had the complainant's consent to disclose information to the newspaper columnist
  • Whether the personal information disclosed was sensitive
  • Whether implied consent was appropriate in the circumstances
  • Whether the ISP limited its disclosure to relevant information
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Feb 10, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-012Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-012: Investment Firm Justified in its Collection of "Know Your Client" Information

An investment firm

A customer complained that his investment firm required an unreasonable amount of personal information on its "Know Your Client" (KYC) form as a condition for maintaining his Tax Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP). The firm requested details such as investment experience, annual income, spouse's income, dependents, assets, liabilities, and net worth. The firm argued this information was necessary to comply with the Investment Industry Regulatory Organization of Canada (IIROC) KYC and suitability requirements. The OPC assessed whether the firm contravened PIPEDA Principle 4.3.3 by requiring consent for information beyond explicitly specified and legitimate purposes. The OPC found that the firm had explicitly specified its purposes, which were legitimate given IIROC's regulatory framework. The OPC also concluded that the requested information, including details beyond IIROC's standard Form 2, was necessary for the firm to meet its regulatory obligations. Therefore, the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Commissioner’s Findings - PIPEDA Report of Findings #2014-012: Investment Firm Justified in its Collection of "Know Your Client" Information

Feb 10, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-012
Adjudicator: Chantal Bernier
Plain-Language Summary

A customer complained that his investment firm required an unreasonable amount of personal information on its "Know Your Client" (KYC) form as a condition for maintaining his Tax Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP). The firm requested details such as investment experience, annual income, spouse's income, dependents, assets, liabilities, and net worth. The firm argued this information was necessary to comply with the Investment Industry Regulatory Organization of Canada (IIROC) KYC and suitability requirements. The OPC assessed whether the firm contravened PIPEDA Principle 4.3.3 by requiring consent for information beyond explicitly specified and legitimate purposes. The OPC found that the firm had explicitly specified its purposes, which were legitimate given IIROC's regulatory framework. The OPC also concluded that the requested information, including details beyond IIROC's standard Form 2, was necessary for the firm to meet its regulatory obligations. Therefore, the complaint was not well-founded.

Key Issues
  • Whether the investment firm explicitly specified the purposes for collecting personal information under Principle 4.2 PIPEDA
  • Whether the purposes for collecting personal information were legitimate under subsection 5(3) PIPEDA
  • Whether the investment firm required more personal information than necessary to achieve the legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA
  • Whether the collection of personal information was limited to that which was necessary for the identified purposes under Principle 4.4 PIPEDA
  • Whether information on investment experience was necessary to validate investment knowledge and assess risk tolerance
  • Whether spouse's or partner's annual income was necessary to assess overall financial position and suitability
  • Whether detailed assets and liabilities were necessary to establish net worth and understand financial situation
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 2, 2007Executive SummaryIndexed Jun 30, 2026

Executive Summary: Privacy Commissioner of Canada v. SWIFT

SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication)

The Privacy Commissioner of Canada launched an investigation into SWIFT SCRL following allegations that it disclosed personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) via administrative subpoenas. SWIFT provides messaging services to financial institutions globally, and some messages contain personal information. The Commissioner determined that SWIFT was subject to PIPEDA due to its operations and significant presence in Canada. While acknowledging SWIFT's compliance with US laws, the Commissioner found that SWIFT had not contravened PIPEDA, as the Act allows for disclosure without consent in response to a subpoena from a body with jurisdiction to compel information. The Commissioner emphasized that organizations operating in Canada must still abide by PIPEDA, even when subject to foreign laws. She also recommended that US authorities use existing information-sharing mechanisms with built-in privacy protections rather than subpoenas for Canadian-related financial information.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Executive Summary: Privacy Commissioner of Canada v. SWIFT

Apr 2, 2007Executive Summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Privacy Commissioner of Canada launched an investigation into SWIFT SCRL following allegations that it disclosed personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) via administrative subpoenas. SWIFT provides messaging services to financial institutions globally, and some messages contain personal information. The Commissioner determined that SWIFT was subject to PIPEDA due to its operations and significant presence in Canada. While acknowledging SWIFT's compliance with US laws, the Commissioner found that SWIFT had not contravened PIPEDA, as the Act allows for disclosure without consent in response to a subpoena from a body with jurisdiction to compel information. The Commissioner emphasized that organizations operating in Canada must still abide by PIPEDA, even when subject to foreign laws. She also recommended that US authorities use existing information-sharing mechanisms with built-in privacy protections rather than subpoenas for Canadian-related financial information.

Key Issues
  • Whether SWIFT is subject to PIPEDA
  • Whether SWIFT contravened PIPEDA by disclosing personal information to the US Department of the Treasury
  • Whether the exception to consent for disclosures in response to a subpoena applies
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 2, 2007Report of FindingsIndexed Jun 30, 2026

Report of Findings: Privacy Commissioner of Canada v. SWIFT

SWIFT SCRL

The Privacy Commissioner of Canada initiated a complaint against SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication) for allegedly disclosing personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) in response to administrative subpoenas. SWIFT, a global financial messaging service, argued it was legally compelled to comply with valid US subpoenas and had negotiated privacy protections with the UST. The OPC first determined that the Personal Information Protection and Electronic Documents Act (PIPEDA) applied to SWIFT due to its significant presence and commercial activities in Canada. The key issue was whether SWIFT's disclosure without consent complied with PIPEDA, specifically the exception for subpoenas under paragraph 7(3)(c) and the appropriateness of the disclosure under subsection 5(3). The Commissioner concluded that paragraph 7(3)(c) allows for compliance with valid foreign subpoenas when an organization operates in multiple jurisdictions and legitimately stores data abroad, and that the disclosure was appropriate given the legal compulsion and privacy safeguards SWIFT negotiated. Consequently, the complaint was found not well-founded, as SWIFT's actions did not contravene PIPEDA. The Commissioner, however, recommended that the Canadian government engage with US counterparts to encourage the use of existing information-sharing mechanisms with built-in privacy protections, and noted SWIFT's efforts to explore enhanced privacy solutions.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Report of Findings: Privacy Commissioner of Canada v. SWIFT

Apr 2, 2007Report of Findings
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Privacy Commissioner of Canada initiated a complaint against SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication) for allegedly disclosing personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) in response to administrative subpoenas. SWIFT, a global financial messaging service, argued it was legally compelled to comply with valid US subpoenas and had negotiated privacy protections with the UST. The OPC first determined that the Personal Information Protection and Electronic Documents Act (PIPEDA) applied to SWIFT due to its significant presence and commercial activities in Canada. The key issue was whether SWIFT's disclosure without consent complied with PIPEDA, specifically the exception for subpoenas under paragraph 7(3)(c) and the appropriateness of the disclosure under subsection 5(3). The Commissioner concluded that paragraph 7(3)(c) allows for compliance with valid foreign subpoenas when an organization operates in multiple jurisdictions and legitimately stores data abroad, and that the disclosure was appropriate given the legal compulsion and privacy safeguards SWIFT negotiated. Consequently, the complaint was found not well-founded, as SWIFT's actions did not contravene PIPEDA. The Commissioner, however, recommended that the Canadian government engage with US counterparts to encourage the use of existing information-sharing mechanisms with built-in privacy protections, and noted SWIFT's efforts to explore enhanced privacy solutions.

Key Issues
  • Whether the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to SWIFT’s collection, use, and disclosure of personal information in the course of its operations in Canada.
  • Whether SWIFT is engaged in a commercial activity within Canada under paragraph 4(1)(a) of PIPEDA.
  • Whether personal information collected by SWIFT from Canadian financial institutions was disclosed to US authorities in accordance with PIPEDA.
  • Whether the disclosure of personal information without knowledge or consent was permitted under paragraph 7(3)(c) of PIPEDA (subpoena exception).
  • Whether a "subpoena or warrant" under paragraph 7(3)(c) must be issued only by a body within Canada.
  • Whether SWIFT’s disclosure to the UST was appropriate in the circumstances, as per subsection 5(3) of PIPEDA.
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Nov 7, 2003PIPEDA Case Summary #2003-243Indexed Jun 30, 2026

PIPEDA Case Summary #2003-243 — telecommunications company "B"

telecommunications company "B"

An individual complained that a telecommunications company failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the company did not adequately inform customers about its practice of sharing data with affiliates for marketing, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The company maintained that its privacy policy, code, and activation process provided a sufficient basis for customer knowledge and consent, and that it complied with CRTC restrictions on disclosing personal information. The investigation found that the company's privacy documents and activation process constituted a reasonable effort to advise individuals of secondary purposes and that customers could refuse or withdraw consent. The Assistant Commissioner concluded that the company was in compliance with PIPEDA.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Case Summary #2003-243 — telecommunications company "B"

Nov 7, 2003PIPEDA Case Summary #2003-243
Adjudicator: Robert Marleau
Plain-Language Summary

An individual complained that a telecommunications company failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the company did not adequately inform customers about its practice of sharing data with affiliates for marketing, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The company maintained that its privacy policy, code, and activation process provided a sufficient basis for customer knowledge and consent, and that it complied with CRTC restrictions on disclosing personal information. The investigation found that the company's privacy documents and activation process constituted a reasonable effort to advise individuals of secondary purposes and that customers could refuse or withdraw consent. The Assistant Commissioner concluded that the company was in compliance with PIPEDA.

Key Issues
  • Whether the telecommunications company obtained adequate knowledge and consent for the collection, use, or disclosure of personal information for secondary marketing purposes under Principle 4.3
  • Whether the company specified identified purposes at or before the time of collection as per Principle 4.2.3
  • Whether the company made a reasonable effort to ensure individuals were advised of the purposes for which information would be used, as required by Principle 4.3.2
  • Whether the form of consent sought by the organization was appropriate given the circumstances and type of information, considering Principle 4.3.4
  • Whether the reasonable expectations of the individual were considered in obtaining consent, as per Principle 4.3.5
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Oct 16, 2002PIPEDA Case Summary #2002-82Indexed Jun 30, 2026

PIPEDA Case Summary #2002-82: Alleged disclosure of personal information without consent for secondary marketing purposes by a bank

A bank

An individual complained that a bank failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the bank did not adequately inform customers of its data sharing practices with affiliates, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The OPC investigated the bank's privacy materials and processes, finding that the bank provided two privacy documents to customers and had a detailed privacy code available online or in paper format. The bank also had a process where representatives drew attention to privacy policies and recorded customer preferences regarding disclosure to affiliates. The Commissioner found that the bank's materials and processes constituted a reasonable effort to inform individuals and allow them to refuse or withdraw consent. The complaint was therefore found to be not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Case Summary #2002-82: Alleged disclosure of personal information without consent for secondary marketing purposes by a bank

Oct 16, 2002PIPEDA Case Summary #2002-82
Adjudicator: George Radwanski
Plain-Language Summary

An individual complained that a bank failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the bank did not adequately inform customers of its data sharing practices with affiliates, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The OPC investigated the bank's privacy materials and processes, finding that the bank provided two privacy documents to customers and had a detailed privacy code available online or in paper format. The bank also had a process where representatives drew attention to privacy policies and recorded customer preferences regarding disclosure to affiliates. The Commissioner found that the bank's materials and processes constituted a reasonable effort to inform individuals and allow them to refuse or withdraw consent. The complaint was therefore found to be not well-founded.

Key Issues
  • Whether the bank obtained adequate knowledge and consent for secondary marketing purposes under Principle 4.3
  • Whether the bank made a reasonable effort to advise individuals of the purposes for which information would be used, as required by Principle 4.3.2
  • Whether the purposes were stated in a manner that individuals could reasonably understand, as per Principle 4.3.2
  • Whether the bank considered the reasonable expectations of the individual in obtaining consent, as per Principle 4.3.5