The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

36 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 18, 2026Indexed Jun 30, 2026

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Treasury Board of Canada Secretariat

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Treasury Board of Canada Secretariat (TBS) regarding its personal information practices for monitoring employee on-site presence under the federal government's hybrid work model. The complainant alleged invasive collection, use, and disclosure of personal information, questioning TBS's compliance with sections 4, 6, 7, and 8 of the Privacy Act, as well as transparency, necessity, proportionality, and Privacy Impact Assessment (PIA) requirements. The OPC found that TBS's collection of aggregated data for organizational compliance was for non-administrative purposes, authorized by existing statutes, and appropriately de-identified to fall outside the scope of the Act for disclosure. For individual compliance, managers primarily relied on observation and self-reporting, supported by internal guidance. While TBS's practices were largely compliant, the OPC encouraged TBS to update its Personal Information Bank (PIB) description for Physical Access Controls (PSU 907) to explicitly reflect the potential use of access logs in formal investigations and to clearly communicate this to employees. Overall, the OPC concluded that TBS's personal information handling practices were compliant with the Privacy Act.

Quick view

Privacy ActNot well-founded

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Mar 18, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Treasury Board of Canada Secretariat (TBS) regarding its personal information practices for monitoring employee on-site presence under the federal government's hybrid work model. The complainant alleged invasive collection, use, and disclosure of personal information, questioning TBS's compliance with sections 4, 6, 7, and 8 of the Privacy Act, as well as transparency, necessity, proportionality, and Privacy Impact Assessment (PIA) requirements. The OPC found that TBS's collection of aggregated data for organizational compliance was for non-administrative purposes, authorized by existing statutes, and appropriately de-identified to fall outside the scope of the Act for disclosure. For individual compliance, managers primarily relied on observation and self-reporting, supported by internal guidance. While TBS's practices were largely compliant, the OPC encouraged TBS to update its Personal Information Bank (PIB) description for Physical Access Controls (PSU 907) to explicitly reflect the potential use of access logs in formal investigations and to clearly communicate this to employees. Overall, the OPC concluded that TBS's personal information handling practices were compliant with the Privacy Act.

Key Issues
  • Whether the collection of employees' personal information for on-site presence monitoring was related directly to TBS's operating programs or activities under section 4 of the Privacy Act.
  • Whether TBS's retention and disposal practices for personal information collected for on-site presence monitoring complied with section 6 of the Privacy Act, specifically subsections 6(1) and 6(3).
  • Whether TBS's use of personal information for on-site presence monitoring was a 'consistent use' authorized under section 7(a) of the Privacy Act.
  • Whether TBS's disclosure of aggregated on-site presence data to senior management constituted personal information under section 3 of the Privacy Act and complied with section 8.
  • Whether TBS's transparency and openness related to its hybrid compliance monitoring approach, including standard Personal Information Banks (PIBs), was adequate under sections 10 and 11 of the Privacy Act.
  • Whether TBS's personal information practices for on-site presence monitoring complied with the necessity and proportionality data principles.
  • Whether TBS was required to complete a Privacy Impact Assessment (PIA) for its verification regime.
  • Whether managers' practices for monitoring individual compliance with the hybrid work model contravened the Privacy Act.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 12, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Quick view

Privacy ActNot well-founded

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Mar 12, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Key Issues
  • Whether the CBSA authorized contractors to access personal information collected through ArriveCAN without the required security clearance, in contravention of sections 7 and 8 of the Privacy Act
  • Whether ArriveCAN contracts and Task Authorizations (TAs) contained appropriate clauses to ensure the protection of travellers’ personal information that contractors had access to
  • Whether security requirements identified in contracts and TAs were accurate and specific
  • Whether the CBSA complied with organizational security screening requirements for vendors
  • Whether the CBSA complied with personnel security screening requirements for contractors
  • Whether the CBSA implemented adequate administrative safeguards to protect personal information accessed by contractors
  • Whether the CBSA implemented adequate technical safeguards to protect personal information accessed by contractors
  • Whether the CBSA restricted contractor permissions and access to personal information to what was strictly necessary
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jun 26, 2024Indexed Jun 30, 2026

Investigation into the denial of access to a child’s personal information by Immigration, Refugees and Citizenship Canada

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant, a father involved in a custody dispute, submitted an ATIP request to Immigration, Refugees and Citizenship Canada (IRCC) for his minor child's passport application, which had been submitted by his former spouse. He provided a court order authorizing him to obtain his children's information from third parties. IRCC denied the request, stating that the child's consent was required. The complainant alleged that IRCC improperly denied access despite the court order. The OPC investigated whether the complainant had a right of access under paragraph 10(a) of the Privacy Regulations, which allows access on behalf of a minor under certain conditions. The OPC found that while the child was a minor and the complainant had legal authorization to administer the child's affairs, the request was not made on the child's behalf, but rather for the complainant's own interests. Therefore, the third condition of paragraph 10(a) was not met, and IRCC's denial was deemed reasonable.

Quick view

Privacy ActNot well-founded

Investigation into the denial of access to a child’s personal information by Immigration, Refugees and Citizenship Canada

Jun 26, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant, a father involved in a custody dispute, submitted an ATIP request to Immigration, Refugees and Citizenship Canada (IRCC) for his minor child's passport application, which had been submitted by his former spouse. He provided a court order authorizing him to obtain his children's information from third parties. IRCC denied the request, stating that the child's consent was required. The complainant alleged that IRCC improperly denied access despite the court order. The OPC investigated whether the complainant had a right of access under paragraph 10(a) of the Privacy Regulations, which allows access on behalf of a minor under certain conditions. The OPC found that while the child was a minor and the complainant had legal authorization to administer the child's affairs, the request was not made on the child's behalf, but rather for the complainant's own interests. Therefore, the third condition of paragraph 10(a) was not met, and IRCC's denial was deemed reasonable.

Key Issues
  • Whether the complainant had a right of access to his child’s personal information under section 10 of the Privacy Regulations
  • Whether the child was a minor at the time of the ATIP request
  • Whether the complainant had legal authorization to administer the child's affairs
  • Whether the complainant exercised the right of access on the minor’s behalf
  • Whether the child had the decision-making capacity to provide consent for the release of their personal information
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Feb 28, 2024Indexed Jun 30, 2026

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Department of National Defence

A representative, on behalf of a deceased member's estate executor, requested personal information from the Department of National Defence (DND) related to an investigation into allegations against the deceased. DND processed the request informally and disclosed some information under subparagraph 8(2)(m)(i) of the Privacy Act, but did not explicitly state its refusal to process the request formally under paragraph 10(b) of the Privacy Regulations. The OPC investigated whether the representative was entitled to make the request for the purpose of administering the estate. The OPC found that while the representative was authorized to administer the estate, they did not sufficiently demonstrate a connection between the requested information and the administration of the estate. Therefore, the complaint was not well-founded, as the representative failed to meet the requirements of paragraph 10(b) of the Regulations.

Quick view

Privacy ActNot well-founded

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Feb 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

A representative, on behalf of a deceased member's estate executor, requested personal information from the Department of National Defence (DND) related to an investigation into allegations against the deceased. DND processed the request informally and disclosed some information under subparagraph 8(2)(m)(i) of the Privacy Act, but did not explicitly state its refusal to process the request formally under paragraph 10(b) of the Privacy Regulations. The OPC investigated whether the representative was entitled to make the request for the purpose of administering the estate. The OPC found that while the representative was authorized to administer the estate, they did not sufficiently demonstrate a connection between the requested information and the administration of the estate. Therefore, the complaint was not well-founded, as the representative failed to meet the requirements of paragraph 10(b) of the Regulations.

Key Issues
  • Whether the representative was authorized to make a request on behalf of the deceased under paragraph 10(b) of the Regulations
  • Whether the request related only to the administration of the deceased's estate under paragraph 10(b) of the Regulations
  • Whether DND complied with section 16 of the Privacy Act regarding refusal notifications
  • Whether DND properly processed the request informally without explicit written consent and notification of rights
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Sep 11, 2023Indexed Jun 30, 2026

Investigation of Immigration, Refugees and Citizenship Canada’s disclosure of personal information to the Canada Border Services Agency

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) inappropriately disclosed his Permanent Resident Card (PRC) renewal paperwork to the Canada Border Services Agency (CBSA), which was then used in a cessation application, contrary to the purpose for which it was collected. The OPC investigated whether IRCC was authorized to disclose this personal information to the CBSA under paragraph 8(2)(a) of the Privacy Act, which permits disclosure for a consistent use. IRCC and CBSA argued that their information sharing for the administration and enforcement of the Immigration and Refugee Protection Act (IRPA) constitutes a consistent use. The OPC found that the privacy notice on the PRC renewal application and the relevant Personal Information Bank (PIB) explicitly stated that information might be shared with CBSA for investigations related to immigration legislation. Therefore, the OPC concluded that the disclosure was for a consistent use, and the complaints against both departments were not well-founded.

Quick view

Privacy ActNot well-founded

Investigation of Immigration, Refugees and Citizenship Canada’s disclosure of personal information to the Canada Border Services Agency

Sep 11, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) inappropriately disclosed his Permanent Resident Card (PRC) renewal paperwork to the Canada Border Services Agency (CBSA), which was then used in a cessation application, contrary to the purpose for which it was collected. The OPC investigated whether IRCC was authorized to disclose this personal information to the CBSA under paragraph 8(2)(a) of the Privacy Act, which permits disclosure for a consistent use. IRCC and CBSA argued that their information sharing for the administration and enforcement of the Immigration and Refugee Protection Act (IRPA) constitutes a consistent use. The OPC found that the privacy notice on the PRC renewal application and the relevant Personal Information Bank (PIB) explicitly stated that information might be shared with CBSA for investigations related to immigration legislation. Therefore, the OPC concluded that the disclosure was for a consistent use, and the complaints against both departments were not well-founded.

Key Issues
  • Whether IRCC's disclosure of the complainant's personal information to CBSA was authorized under paragraph 8(2)(a) of the Privacy Act
  • Whether the use of the personal information by CBSA in a cessation application was consistent with the purpose for which it was collected by IRCC
  • Whether the complainant could reasonably expect the disclosure of his PRC renewal application to CBSA for immigration investigations
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into the collection and use of de-identified mobility data in the course of the COVID-19 pandemic

Public Health Agency of Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated 12 complaints against the Public Health Agency of Canada (PHAC) and Health Canada regarding their collection and use of de-identified mobility data during the COVID-19 pandemic. Complainants alleged PHAC secretly collected data on 33 million mobile devices. PHAC maintained it only used de-identified and aggregated data, arguing the Privacy Act did not apply as no personal information was collected. The OPC's primary issue was whether the mobility data constituted "personal information" under Section 3 of the Privacy Act, specifically if de-identification and safeguards reduced re-identification risk below the "serious possibility" threshold. The investigation examined two data streams, from TELUS and BlueDot, and assessed the de-identification techniques, aggregation levels, access controls, and contractual safeguards in place. The OPC concluded that the combination of these measures reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were found to be not well-founded, as the data did not meet the definition of personal information under the Act. Despite this finding, the OPC made several recommendations to PHAC concerning ongoing assessment of de-identification techniques, due diligence with data providers, and enhanced transparency, which PHAC accepted.

Quick view

Privacy ActNot well-founded

Investigation into the collection and use of de-identified mobility data in the course of the COVID-19 pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 12 complaints against the Public Health Agency of Canada (PHAC) and Health Canada regarding their collection and use of de-identified mobility data during the COVID-19 pandemic. Complainants alleged PHAC secretly collected data on 33 million mobile devices. PHAC maintained it only used de-identified and aggregated data, arguing the Privacy Act did not apply as no personal information was collected. The OPC's primary issue was whether the mobility data constituted "personal information" under Section 3 of the Privacy Act, specifically if de-identification and safeguards reduced re-identification risk below the "serious possibility" threshold. The investigation examined two data streams, from TELUS and BlueDot, and assessed the de-identification techniques, aggregation levels, access controls, and contractual safeguards in place. The OPC concluded that the combination of these measures reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were found to be not well-founded, as the data did not meet the definition of personal information under the Act. Despite this finding, the OPC made several recommendations to PHAC concerning ongoing assessment of de-identification techniques, due diligence with data providers, and enhanced transparency, which PHAC accepted.

Key Issues
  • Whether mobility data collected and used by PHAC constituted "personal information" as defined under Section 3 of the Privacy Act.
  • Whether de-identification techniques and safeguards against re-identification were sufficient to reduce the risk of an individual being identified below the "serious possibility" threshold.
  • Whether access to data within TELUS's system constituted "collection" under the Privacy Act.
  • Whether de-identification alone is sufficient to render mobility data non-personal.
  • Whether robust contractual and physical protections were in place to limit access and use of de-identified data.
  • Whether acceptable data aggregation levels and access controls existed for aggregated mobility data.
  • Whether PHAC was sufficiently transparent with the public about its use of mobility data.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Vaccine mandates for domestic travel

Transport Canada

The Office of the Privacy Commissioner (OPC) investigated 18 complaints regarding the collection, use, and disclosure of vaccination information by Transport Canada, VIA Rail, and CATSA for domestic air and rail travel mandates between November 2021 and June 2022. Complainants alleged unlawful privacy violations and unreasonable limitations on mobility. The OPC found that the collection of vaccination information by CATSA and VIA Rail was directly related to their operating programs and activities, specifically administering Ministerial Orders for transportation safety. Furthermore, the uses and disclosures of personal information by CATSA and VIA Rail, and the centralized collection and use by Transport Canada, complied with sections 4, 7, and 8 of the Privacy Act. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed these principles and found the collections were overall necessary and proportional. However, the OPC identified concerns with the broad scope of the Orders' objectives and Transport Canada's limited documentation of less privacy-invasive alternatives. Consequently, the complaints were deemed not well-founded, but Transport Canada accepted recommendations for future similar measures to better define objectives and document alternative assessments. This report highlights the need to better reflect necessity and proportionality in public sector privacy law.

Quick view

Privacy ActNot well-founded

Vaccine mandates for domestic travel

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated 18 complaints regarding the collection, use, and disclosure of vaccination information by Transport Canada, VIA Rail, and CATSA for domestic air and rail travel mandates between November 2021 and June 2022. Complainants alleged unlawful privacy violations and unreasonable limitations on mobility. The OPC found that the collection of vaccination information by CATSA and VIA Rail was directly related to their operating programs and activities, specifically administering Ministerial Orders for transportation safety. Furthermore, the uses and disclosures of personal information by CATSA and VIA Rail, and the centralized collection and use by Transport Canada, complied with sections 4, 7, and 8 of the Privacy Act. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed these principles and found the collections were overall necessary and proportional. However, the OPC identified concerns with the broad scope of the Orders' objectives and Transport Canada's limited documentation of less privacy-invasive alternatives. Consequently, the complaints were deemed not well-founded, but Transport Canada accepted recommendations for future similar measures to better define objectives and document alternative assessments. This report highlights the need to better reflect necessity and proportionality in public sector privacy law.

Key Issues
  • Whether the vaccination information collected by CATSA and VIA Rail was directly related to their operating programs or activities, as required by section 4 of the Privacy Act
  • Whether the uses or disclosures of personal information by CATSA and VIA Rail were compliant with sections 4, 7, and 8 of the Privacy Act
  • Whether the centralized collection and use of personal information by Transport Canada was compliant with sections 4, 7, and 8 of the Privacy Act
  • Whether the collection of information was demonstrably necessary to meet a specific need
  • Whether the collection of information was likely to be effective in meeting that need
  • Whether there were less privacy-intrusive ways of achieving the same end
  • Whether the loss of privacy was proportional to the need
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

Multiple federal separate employers

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints from federal public service employees against several separate employers regarding COVID-19 vaccination attestation requirements. Employees alleged that the collection, use, and disclosure of their vaccination status and accommodation requests contravened the Privacy Act. The OPC examined whether the information collected related directly to an operating program or activity (s.4) and if its uses and disclosures were authorized (s.7 and s.8). The OPC found that the collection was directly related to the employers' occupational health and safety programs and that uses and disclosures were consistent with the purpose of collection. Additionally, the OPC assessed the necessity and proportionality of these measures, concluding they were necessary and proportional given the emergency context of the pandemic. Consequently, the OPC found the complaints to be not well-founded. However, the OPC recommended that Canada Post Corporation refine its access controls for sensitive information and that all institutions conduct structured necessity and proportionality analyses for future privacy-invasive programs.

Quick view

Privacy ActNot well-founded

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints from federal public service employees against several separate employers regarding COVID-19 vaccination attestation requirements. Employees alleged that the collection, use, and disclosure of their vaccination status and accommodation requests contravened the Privacy Act. The OPC examined whether the information collected related directly to an operating program or activity (s.4) and if its uses and disclosures were authorized (s.7 and s.8). The OPC found that the collection was directly related to the employers' occupational health and safety programs and that uses and disclosures were consistent with the purpose of collection. Additionally, the OPC assessed the necessity and proportionality of these measures, concluding they were necessary and proportional given the emergency context of the pandemic. Consequently, the OPC found the complaints to be not well-founded. However, the OPC recommended that Canada Post Corporation refine its access controls for sensitive information and that all institutions conduct structured necessity and proportionality analyses for future privacy-invasive programs.

Key Issues
  • Whether the information collected by the respondents related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act
  • Whether uses and disclosures of information relating to employee vaccination status and requests for accommodation were authorized under sections 7 and 8 of the Privacy Act
  • Whether the information collected was necessary and proportional
  • Whether the measure was demonstrably necessary to meet a specific need
  • Whether the measure was likely to be effective in meeting that need
  • Whether there was a less privacy-intrusive way of achieving the same end
  • Whether the loss of privacy was proportional to the need
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by Department of National Defence for members of the Canadian Armed Forces

Department of National Defence / Canadian Armed Forces

The Office of the Privacy Commissioner of Canada (OPC) investigated 16 complaints against the Department of National Defence (DND) and the Canadian Armed Forces (CAF) regarding their COVID-19 vaccination attestation requirements. Complainants alleged unreasonable collection, improper use, insufficient access controls in the Monitor MASS system leading to unauthorized disclosure, and inaccurate data. The OPC found that the collection of vaccination status information, including for accommodation requests, directly related to DND's operating programs for health and safety and operational readiness, satisfying section 4 of the Privacy Act. The use of this information was also deemed consistent with the purposes for which it was collected, in line with section 7. While concerns were raised about Monitor MASS access controls, the OPC found no evidence of actual unauthorized disclosures, thus deeming this allegation not well-founded, though it did recommend improved oversight which DND declined. Furthermore, DND was found to have taken reasonable steps to ensure the accuracy of vaccination status data under section 6(2). The OPC also concluded that the measures were necessary and proportional given the pandemic context and the CAF's unique operational role.

Quick view

Privacy ActNot well-founded

Investigation into COVID-19 vaccination attestation requirements established by Department of National Defence for members of the Canadian Armed Forces

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 16 complaints against the Department of National Defence (DND) and the Canadian Armed Forces (CAF) regarding their COVID-19 vaccination attestation requirements. Complainants alleged unreasonable collection, improper use, insufficient access controls in the Monitor MASS system leading to unauthorized disclosure, and inaccurate data. The OPC found that the collection of vaccination status information, including for accommodation requests, directly related to DND's operating programs for health and safety and operational readiness, satisfying section 4 of the Privacy Act. The use of this information was also deemed consistent with the purposes for which it was collected, in line with section 7. While concerns were raised about Monitor MASS access controls, the OPC found no evidence of actual unauthorized disclosures, thus deeming this allegation not well-founded, though it did recommend improved oversight which DND declined. Furthermore, DND was found to have taken reasonable steps to ensure the accuracy of vaccination status data under section 6(2). The OPC also concluded that the measures were necessary and proportional given the pandemic context and the CAF's unique operational role.

Key Issues
  • Whether the collection of personal information, including vaccination status and accommodation request details, by DND/CAF related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act.
  • Whether the use of the personal information collected under the Directive was authorized under section 7 of the Privacy Act, specifically for applying administrative consequences.
  • Whether the use of Monitor MASS for collection and storage of CAF members' vaccination status resulted in unauthorized disclosure of information due to insufficient access controls, contrary to section 8(1) of the Privacy Act.
  • Whether DND took reasonable steps to ensure that personal information used for determining the COVID-19 vaccination status of CAF members was accurate, up-to-date, and complete as required by section 6(2) of the Privacy Act.
  • Whether the COVID-19 vaccination attestation requirements and associated information collection were necessary and proportional, applying the OPC's four-part test.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Vaccine mandates for entry into Canada

Public Health Agency of Canada (PHAC) and Canada Border Services Agency (CBSA)

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints regarding the collection, use, retention, and disclosure of personal information, including vaccination status, by the Public Health Agency of Canada (PHAC) and Canada Border Services Agency (CBSA) under Emergency Orders for entry into Canada during the COVID-19 pandemic. Complainants argued the measures were unlawful, unnecessary, and disproportionate. The OPC found that the collection of personal information was directly related to an operating program or activity of PHAC and CBSA, and its use and disclosure were for the purpose collected or consistent with it, or authorized by an Act of Parliament. The OPC also determined that the retention and disposal of information complied with the Privacy Act and related regulations. While necessity and proportionality are not explicit requirements of the Privacy Act, the OPC assessed these principles and found the collection overall to be necessary and proportional. However, the OPC identified gaps in PHAC's assessment and documentation of less privacy-intrusive alternatives and clarity of objectives in the final six months of the Orders. All complaints alleging contraventions of the Privacy Act were found to be not well-founded.

Quick view

Privacy ActNot well-founded

Vaccine mandates for entry into Canada

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints regarding the collection, use, retention, and disclosure of personal information, including vaccination status, by the Public Health Agency of Canada (PHAC) and Canada Border Services Agency (CBSA) under Emergency Orders for entry into Canada during the COVID-19 pandemic. Complainants argued the measures were unlawful, unnecessary, and disproportionate. The OPC found that the collection of personal information was directly related to an operating program or activity of PHAC and CBSA, and its use and disclosure were for the purpose collected or consistent with it, or authorized by an Act of Parliament. The OPC also determined that the retention and disposal of information complied with the Privacy Act and related regulations. While necessity and proportionality are not explicit requirements of the Privacy Act, the OPC assessed these principles and found the collection overall to be necessary and proportional. However, the OPC identified gaps in PHAC's assessment and documentation of less privacy-intrusive alternatives and clarity of objectives in the final six months of the Orders. All complaints alleging contraventions of the Privacy Act were found to be not well-founded.

Key Issues
  • Whether the personal information collected was directly related to an operating program or activity of PHAC and CBSA (s.4 Privacy Act)
  • Whether the personal information was used or disclosed for the purpose for which it was compiled/obtained, or in accordance with an Act of Parliament (s.7, s.8 Privacy Act)
  • Whether the personal information was disposed of in accordance with the Privacy Regulations and the Directive on Privacy Practices (s.6(3) Privacy Act)
  • Whether the collection of personal information under the Emergency Orders was necessary
  • Whether the collection of personal information under the Emergency Orders was effective
  • Whether there were less privacy-intrusive ways of achieving the same end
  • Whether the loss of privacy was proportional to the need
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Aug 6, 2020Indexed Jun 30, 2026

PA-055322 (PCO) et PA-055323 (DOJ) — Privy Council Office (PCO) and Department of Justice (DOJ)

Privy Council Office (PCO) and Department of Justice (DOJ)

The OPC investigated a complaint regarding the unauthorized disclosure of personal information about Supreme Court candidate Chief Justice Glenn Joyal. Media reports claimed an anonymous source revealed a disagreement between the Prime Minister's Office (PMO) and the former Attorney General over Joyal's nomination. The complainant alleged breaches of the Privacy Act by the Privy Council Office (PCO), Department of Justice (DOJ), Office of the Commissioner of Federal Judicial Affairs (CFJA), and the PMO. The OPC determined it lacked jurisdiction over the CFJA and PMO, focusing its investigation on the PCO and DOJ. The investigation found no evidence that either the PCO or the DOJ had access to the specific information that was leaked, nor that the disclosure originated from these institutions. While no contravention was found, the OPC highlighted that Chief Justice Joyal's privacy was compromised and called for legislative reform to extend the Privacy Act's coverage to all government institutions, including Ministers' Offices and the PMO.

Quick view

Privacy ActNot well-founded

PA-055322 (PCO) et PA-055323 (DOJ) — Privy Council Office (PCO) and Department of Justice (DOJ)

Aug 6, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated a complaint regarding the unauthorized disclosure of personal information about Supreme Court candidate Chief Justice Glenn Joyal. Media reports claimed an anonymous source revealed a disagreement between the Prime Minister's Office (PMO) and the former Attorney General over Joyal's nomination. The complainant alleged breaches of the Privacy Act by the Privy Council Office (PCO), Department of Justice (DOJ), Office of the Commissioner of Federal Judicial Affairs (CFJA), and the PMO. The OPC determined it lacked jurisdiction over the CFJA and PMO, focusing its investigation on the PCO and DOJ. The investigation found no evidence that either the PCO or the DOJ had access to the specific information that was leaked, nor that the disclosure originated from these institutions. While no contravention was found, the OPC highlighted that Chief Justice Joyal's privacy was compromised and called for legislative reform to extend the Privacy Act's coverage to all government institutions, including Ministers' Offices and the PMO.

Key Issues
  • Whether the Office of the Commissioner of Federal Judicial Affairs (CFJA) is a 'government institution' under the Privacy Act
  • Whether the Prime Minister's Office (PMO) is a 'government institution' under the Privacy Act
  • Whether the Privy Council Office (PCO) was responsible for the unauthorized disclosure of Chief Justice Joyal's personal information under section 8 of the Privacy Act
  • Whether the Department of Justice (DOJ) was responsible for the unauthorized disclosure of Chief Justice Joyal's personal information under section 8 of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jul 14, 2020Indexed Jun 30, 2026

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Canada Border Services Agency (CBSA)

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Quick view

Privacy ActNot well-founded

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Jul 14, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Key Issues
  • Did the CBSA disclose the complainant’s personal information?
  • Was any disclosed information “publicly available”, such that subsection 69(2) of the Act excludes application of sections 7 and 8?
  • If not, was the disclosure permitted under subsection 8(2) of the Act?
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jan 15, 2020Indexed Jun 30, 2026

Public disclosure of medical information during military trial consistent with Privacy Act

Department of National Defence

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

Public disclosure of medical information during military trial consistent with Privacy Act

Jan 15, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Key Issues
  • Whether the Privacy Act applies to military summary trial proceedings conducted by the Canadian Forces
  • Whether the disclosure of the complainant's medical information during the summary trial was made in accordance with section 8 of the Privacy Act
  • Whether the information became publicly available under section 69(2) of the Privacy Act once disclosed in an open court proceeding
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 30, 2019Indexed Jun 30, 2026

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Department of National Defence and Department of Justice

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Quick view

Privacy ActNot well-founded

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Dec 30, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Key Issues
  • Whether the collection of the complainant's personal medical information by the DOJ from the DND contravened the Privacy Act
  • Whether the disclosure of the complainant's personal medical information by the DND to the DOJ contravened the Privacy Act
  • Whether the collection by DOJ related directly to an operating program or activity of the institution under s.4 of the Privacy Act
  • Whether the collection by DOJ was permissible under s.5(1) of the Privacy Act given the disclosure under s.8(2)(d)
  • Whether the disclosure by DND was to the Attorney General of Canada under s.8(2)(d) of the Privacy Act
  • Whether the disclosure by DND was for use in legal proceedings involving the Crown in right of Canada or the Government of Canada under s.8(2)(d) of the Privacy Act
  • Whether the sensitivity of medical information impacts the permissibility of disclosure under the Privacy Act
  • Whether doctor-patient confidentiality prevents disclosure under the Privacy Act for litigation purposes
  • Whether the safeguarding measures for the disclosed information were adequate
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 9, 2019Statistics CanadaIndexed Jun 30, 2026

Statistics Canada: Invasive data initiatives should be redesigned with privacy in mind

Statistics Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated over a hundred complaints against Statistics Canada concerning its Credit Information Project and Financial Transactions Project. These initiatives involved collecting detailed personal information from a credit bureau (TransUnion) and financial institutions without individuals' direct knowledge or consent. The OPC found that Statistics Canada had the legal authority under section 13 of the Statistics Act to collect information for the Credit Information Project, as TransUnion provided existing records, thus deeming this aspect of the complaints not well-founded. However, the OPC had serious concerns that the Financial Transactions Project, as originally designed, would have exceeded this authority by requiring financial institutions to create new records; no formal finding was made as the project was halted. While no contravention of the Privacy Act was found, the OPC identified significant privacy concerns regarding the necessity and proportionality of both projects, Statistics Canada's lack of transparency, and deficiencies in internal monitoring safeguards. Statistics Canada committed to implementing all six OPC recommendations, including redesigning both projects with privacy principles in mind, increasing transparency, and enhancing internal security measures. The OPC also called for legislative reform of the Statistics Act and Privacy Act to address modern data collection practices.

Quick view

Privacy ActNot well-founded

Statistics Canada: Invasive data initiatives should be redesigned with privacy in mind

Dec 9, 2019Statistics Canada
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated over a hundred complaints against Statistics Canada concerning its Credit Information Project and Financial Transactions Project. These initiatives involved collecting detailed personal information from a credit bureau (TransUnion) and financial institutions without individuals' direct knowledge or consent. The OPC found that Statistics Canada had the legal authority under section 13 of the Statistics Act to collect information for the Credit Information Project, as TransUnion provided existing records, thus deeming this aspect of the complaints not well-founded. However, the OPC had serious concerns that the Financial Transactions Project, as originally designed, would have exceeded this authority by requiring financial institutions to create new records; no formal finding was made as the project was halted. While no contravention of the Privacy Act was found, the OPC identified significant privacy concerns regarding the necessity and proportionality of both projects, Statistics Canada's lack of transparency, and deficiencies in internal monitoring safeguards. Statistics Canada committed to implementing all six OPC recommendations, including redesigning both projects with privacy principles in mind, increasing transparency, and enhancing internal security measures. The OPC also called for legislative reform of the Statistics Act and Privacy Act to address modern data collection practices.

Key Issues
  • Whether Statistics Canada's collection of personal information for the Credit Information Project was within its legal authority under section 13 of the Statistics Act.
  • Whether Statistics Canada's proposed collection of personal information for the Financial Transactions Project, as originally designed, would have been within its legal authority under section 13 of the Statistics Act.
  • Whether the collection of personal information for the Credit Information Project related directly to an operating program or activity of Statistics Canada under section 4 of the Privacy Act.
  • Whether the collection of personal information for the Financial Transactions Project related directly to an operating program or activity of Statistics Canada under section 4 of the Privacy Act.
  • Whether the Credit Information Project, as originally designed, met the principles of necessity and proportionality.
  • Whether the Financial Transactions Project, as originally designed, met the principles of necessity and proportionality.
  • Whether Statistics Canada provided adequate transparency to individuals regarding the collection of their personal information for the Projects.
  • Whether Statistics Canada had appropriate safeguards, specifically regarding logging and monitoring for internal unauthorized access, to protect personal information collected via the Projects.
  • Whether Statistics Canada's de-identification and encryption safeguards were adequate.
  • Whether Statistics Canada had proper procedures for individuals to access their personal information.
  • Whether there was a risk of personal information collected via the Projects being disclosed for secondary purposes.
  • Whether Statistics Canada's Directive on Discretionary Disclosures adequately considered individuals' privacy interests when making disclosures under section 17(2)(a) of the Statistics Act.