The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

8 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Sep 11, 2023Indexed Jun 30, 2026

Investigation of Immigration, Refugees and Citizenship Canada’s disclosure of personal information to the Canada Border Services Agency

Immigration, Refugees and Citizenship Canada (IRCC)

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) inappropriately disclosed his Permanent Resident Card (PRC) renewal paperwork to the Canada Border Services Agency (CBSA), which was then used in a cessation application, contrary to the purpose for which it was collected. The OPC investigated whether IRCC was authorized to disclose this personal information to the CBSA under paragraph 8(2)(a) of the Privacy Act, which permits disclosure for a consistent use. IRCC and CBSA argued that their information sharing for the administration and enforcement of the Immigration and Refugee Protection Act (IRPA) constitutes a consistent use. The OPC found that the privacy notice on the PRC renewal application and the relevant Personal Information Bank (PIB) explicitly stated that information might be shared with CBSA for investigations related to immigration legislation. Therefore, the OPC concluded that the disclosure was for a consistent use, and the complaints against both departments were not well-founded.

Quick view

Privacy ActNot well-founded

Investigation of Immigration, Refugees and Citizenship Canada’s disclosure of personal information to the Canada Border Services Agency

Sep 11, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Immigration, Refugees and Citizenship Canada (IRCC) inappropriately disclosed his Permanent Resident Card (PRC) renewal paperwork to the Canada Border Services Agency (CBSA), which was then used in a cessation application, contrary to the purpose for which it was collected. The OPC investigated whether IRCC was authorized to disclose this personal information to the CBSA under paragraph 8(2)(a) of the Privacy Act, which permits disclosure for a consistent use. IRCC and CBSA argued that their information sharing for the administration and enforcement of the Immigration and Refugee Protection Act (IRPA) constitutes a consistent use. The OPC found that the privacy notice on the PRC renewal application and the relevant Personal Information Bank (PIB) explicitly stated that information might be shared with CBSA for investigations related to immigration legislation. Therefore, the OPC concluded that the disclosure was for a consistent use, and the complaints against both departments were not well-founded.

Key Issues
  • Whether IRCC's disclosure of the complainant's personal information to CBSA was authorized under paragraph 8(2)(a) of the Privacy Act
  • Whether the use of the personal information by CBSA in a cessation application was consistent with the purpose for which it was collected by IRCC
  • Whether the complainant could reasonably expect the disclosure of his PRC renewal application to CBSA for immigration investigations
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Jun 28, 20232023 OIC 24Indexed Jun 30, 2026

Library and Archives Canada (Re), 2023 OIC 24

Library and Archives Canada

The complainant alleged that Library and Archives Canada (LAC) took an unreasonable extension of time to respond to an access request for records related to "Project Anecdote." LAC claimed a 1,095-day extension under paragraphs 9(1)(a) and (b) of the Access to Information Act, setting the response deadline to June 20, 2025. During the investigation, LAC demonstrated that its calculation for the extension was logical and supportable, and that providing the records sooner would unreasonably interfere with its operations. LAC also showed that necessary consultations could not be completed within 30 days. The Office of the Information Commissioner concluded that LAC met all the requirements for the extension under paragraphs 9(1)(a) and (b). Consequently, the extension was deemed valid, and the complaint was found to be not well founded.

Quick view

Access to Information ActNot well-founded

Library and Archives Canada (Re), 2023 OIC 24

Jun 28, 20232023 OIC 24
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Library and Archives Canada (LAC) took an unreasonable extension of time to respond to an access request for records related to "Project Anecdote." LAC claimed a 1,095-day extension under paragraphs 9(1)(a) and (b) of the Access to Information Act, setting the response deadline to June 20, 2025. During the investigation, LAC demonstrated that its calculation for the extension was logical and supportable, and that providing the records sooner would unreasonably interfere with its operations. LAC also showed that necessary consultations could not be completed within 30 days. The Office of the Information Commissioner concluded that LAC met all the requirements for the extension under paragraphs 9(1)(a) and (b). Consequently, the extension was deemed valid, and the complaint was found to be not well founded.

Key Issues
  • Whether the 1,095-day extension of time taken by Library and Archives Canada was reasonable under s.9(1) of the Access to Information Act
  • Whether the calculation of the time extension was sufficiently logical and supportable under s.9(1)(a) and (b)
  • Whether providing access within a materially lesser period would unreasonably interfere with operations under s.9(1)(a)
  • Whether consultations could reasonably be completed within 30 days under s.9(1)(b)
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Jun 14, 20235821-00288Indexed Jun 30, 2026

Department of Justice Canada (Re), 2023 OIC 29

Department of Justice Canada

The complainant alleged that the Department of Justice Canada (Justice) failed to conduct a reasonable search for a 2009 workplace report prepared by a consultant. Justice tasked its Ontario Regional Office and the Deputy Minister’s Office, both of which reported no responsive records, citing a five-year retention period for such documents, which had expired seven years prior to the request. The OIC investigated whether Justice was required to contact the consultant directly to fulfill the request. Justice maintained that it was not reasonable to expect them to task the consultant, as the business need for the report was time-limited, copies should no longer be with the contractor, and the matter was no longer active. The OIC concluded that Justice conducted a reasonable search based on its internal efforts and retention policies. The complaint was therefore deemed not well founded.

Quick view

Access to Information ActNot well-founded

Department of Justice Canada (Re), 2023 OIC 29

Jun 14, 20235821-00288
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Department of Justice Canada (Justice) failed to conduct a reasonable search for a 2009 workplace report prepared by a consultant. Justice tasked its Ontario Regional Office and the Deputy Minister’s Office, both of which reported no responsive records, citing a five-year retention period for such documents, which had expired seven years prior to the request. The OIC investigated whether Justice was required to contact the consultant directly to fulfill the request. Justice maintained that it was not reasonable to expect them to task the consultant, as the business need for the report was time-limited, copies should no longer be with the contractor, and the matter was no longer active. The OIC concluded that Justice conducted a reasonable search based on its internal efforts and retention policies. The complaint was therefore deemed not well founded.

Key Issues
  • Whether the Department of Justice Canada conducted a reasonable search for records
  • Whether the institution was required to contact a consultant directly to conduct a reasonable search
  • Whether the institution's application of its record retention policy was appropriate in determining search scope
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

Multiple federal separate employers

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints from federal public service employees against several separate employers regarding COVID-19 vaccination attestation requirements. Employees alleged that the collection, use, and disclosure of their vaccination status and accommodation requests contravened the Privacy Act. The OPC examined whether the information collected related directly to an operating program or activity (s.4) and if its uses and disclosures were authorized (s.7 and s.8). The OPC found that the collection was directly related to the employers' occupational health and safety programs and that uses and disclosures were consistent with the purpose of collection. Additionally, the OPC assessed the necessity and proportionality of these measures, concluding they were necessary and proportional given the emergency context of the pandemic. Consequently, the OPC found the complaints to be not well-founded. However, the OPC recommended that Canada Post Corporation refine its access controls for sensitive information and that all institutions conduct structured necessity and proportionality analyses for future privacy-invasive programs.

Quick view

Privacy ActNot well-founded

Investigation into COVID-19 vaccination attestation requirements established by certain separate employers of the federal public service

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints from federal public service employees against several separate employers regarding COVID-19 vaccination attestation requirements. Employees alleged that the collection, use, and disclosure of their vaccination status and accommodation requests contravened the Privacy Act. The OPC examined whether the information collected related directly to an operating program or activity (s.4) and if its uses and disclosures were authorized (s.7 and s.8). The OPC found that the collection was directly related to the employers' occupational health and safety programs and that uses and disclosures were consistent with the purpose of collection. Additionally, the OPC assessed the necessity and proportionality of these measures, concluding they were necessary and proportional given the emergency context of the pandemic. Consequently, the OPC found the complaints to be not well-founded. However, the OPC recommended that Canada Post Corporation refine its access controls for sensitive information and that all institutions conduct structured necessity and proportionality analyses for future privacy-invasive programs.

Key Issues
  • Whether the information collected by the respondents related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act
  • Whether uses and disclosures of information relating to employee vaccination status and requests for accommodation were authorized under sections 7 and 8 of the Privacy Act
  • Whether the information collected was necessary and proportional
  • Whether the measure was demonstrably necessary to meet a specific need
  • Whether the measure was likely to be effective in meeting that need
  • Whether there was a less privacy-intrusive way of achieving the same end
  • Whether the loss of privacy was proportional to the need
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by Department of National Defence for members of the Canadian Armed Forces

Department of National Defence / Canadian Armed Forces

The Office of the Privacy Commissioner of Canada (OPC) investigated 16 complaints against the Department of National Defence (DND) and the Canadian Armed Forces (CAF) regarding their COVID-19 vaccination attestation requirements. Complainants alleged unreasonable collection, improper use, insufficient access controls in the Monitor MASS system leading to unauthorized disclosure, and inaccurate data. The OPC found that the collection of vaccination status information, including for accommodation requests, directly related to DND's operating programs for health and safety and operational readiness, satisfying section 4 of the Privacy Act. The use of this information was also deemed consistent with the purposes for which it was collected, in line with section 7. While concerns were raised about Monitor MASS access controls, the OPC found no evidence of actual unauthorized disclosures, thus deeming this allegation not well-founded, though it did recommend improved oversight which DND declined. Furthermore, DND was found to have taken reasonable steps to ensure the accuracy of vaccination status data under section 6(2). The OPC also concluded that the measures were necessary and proportional given the pandemic context and the CAF's unique operational role.

Quick view

Privacy ActNot well-founded

Investigation into COVID-19 vaccination attestation requirements established by Department of National Defence for members of the Canadian Armed Forces

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 16 complaints against the Department of National Defence (DND) and the Canadian Armed Forces (CAF) regarding their COVID-19 vaccination attestation requirements. Complainants alleged unreasonable collection, improper use, insufficient access controls in the Monitor MASS system leading to unauthorized disclosure, and inaccurate data. The OPC found that the collection of vaccination status information, including for accommodation requests, directly related to DND's operating programs for health and safety and operational readiness, satisfying section 4 of the Privacy Act. The use of this information was also deemed consistent with the purposes for which it was collected, in line with section 7. While concerns were raised about Monitor MASS access controls, the OPC found no evidence of actual unauthorized disclosures, thus deeming this allegation not well-founded, though it did recommend improved oversight which DND declined. Furthermore, DND was found to have taken reasonable steps to ensure the accuracy of vaccination status data under section 6(2). The OPC also concluded that the measures were necessary and proportional given the pandemic context and the CAF's unique operational role.

Key Issues
  • Whether the collection of personal information, including vaccination status and accommodation request details, by DND/CAF related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act.
  • Whether the use of the personal information collected under the Directive was authorized under section 7 of the Privacy Act, specifically for applying administrative consequences.
  • Whether the use of Monitor MASS for collection and storage of CAF members' vaccination status resulted in unauthorized disclosure of information due to insufficient access controls, contrary to section 8(1) of the Privacy Act.
  • Whether DND took reasonable steps to ensure that personal information used for determining the COVID-19 vaccination status of CAF members was accurate, up-to-date, and complete as required by section 6(2) of the Privacy Act.
  • Whether the COVID-19 vaccination attestation requirements and associated information collection were necessary and proportional, applying the OPC's four-part test.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Vaccine mandates for domestic travel

Transport Canada

The Office of the Privacy Commissioner (OPC) investigated 18 complaints regarding the collection, use, and disclosure of vaccination information by Transport Canada, VIA Rail, and CATSA for domestic air and rail travel mandates between November 2021 and June 2022. Complainants alleged unlawful privacy violations and unreasonable limitations on mobility. The OPC found that the collection of vaccination information by CATSA and VIA Rail was directly related to their operating programs and activities, specifically administering Ministerial Orders for transportation safety. Furthermore, the uses and disclosures of personal information by CATSA and VIA Rail, and the centralized collection and use by Transport Canada, complied with sections 4, 7, and 8 of the Privacy Act. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed these principles and found the collections were overall necessary and proportional. However, the OPC identified concerns with the broad scope of the Orders' objectives and Transport Canada's limited documentation of less privacy-invasive alternatives. Consequently, the complaints were deemed not well-founded, but Transport Canada accepted recommendations for future similar measures to better define objectives and document alternative assessments. This report highlights the need to better reflect necessity and proportionality in public sector privacy law.

Quick view

Privacy ActNot well-founded

Vaccine mandates for domestic travel

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated 18 complaints regarding the collection, use, and disclosure of vaccination information by Transport Canada, VIA Rail, and CATSA for domestic air and rail travel mandates between November 2021 and June 2022. Complainants alleged unlawful privacy violations and unreasonable limitations on mobility. The OPC found that the collection of vaccination information by CATSA and VIA Rail was directly related to their operating programs and activities, specifically administering Ministerial Orders for transportation safety. Furthermore, the uses and disclosures of personal information by CATSA and VIA Rail, and the centralized collection and use by Transport Canada, complied with sections 4, 7, and 8 of the Privacy Act. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed these principles and found the collections were overall necessary and proportional. However, the OPC identified concerns with the broad scope of the Orders' objectives and Transport Canada's limited documentation of less privacy-invasive alternatives. Consequently, the complaints were deemed not well-founded, but Transport Canada accepted recommendations for future similar measures to better define objectives and document alternative assessments. This report highlights the need to better reflect necessity and proportionality in public sector privacy law.

Key Issues
  • Whether the vaccination information collected by CATSA and VIA Rail was directly related to their operating programs or activities, as required by section 4 of the Privacy Act
  • Whether the uses or disclosures of personal information by CATSA and VIA Rail were compliant with sections 4, 7, and 8 of the Privacy Act
  • Whether the centralized collection and use of personal information by Transport Canada was compliant with sections 4, 7, and 8 of the Privacy Act
  • Whether the collection of information was demonstrably necessary to meet a specific need
  • Whether the collection of information was likely to be effective in meeting that need
  • Whether there were less privacy-intrusive ways of achieving the same end
  • Whether the loss of privacy was proportional to the need
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into the collection and use of de-identified mobility data in the course of the COVID-19 pandemic

Public Health Agency of Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated 12 complaints against the Public Health Agency of Canada (PHAC) and Health Canada regarding their collection and use of de-identified mobility data during the COVID-19 pandemic. Complainants alleged PHAC secretly collected data on 33 million mobile devices. PHAC maintained it only used de-identified and aggregated data, arguing the Privacy Act did not apply as no personal information was collected. The OPC's primary issue was whether the mobility data constituted "personal information" under Section 3 of the Privacy Act, specifically if de-identification and safeguards reduced re-identification risk below the "serious possibility" threshold. The investigation examined two data streams, from TELUS and BlueDot, and assessed the de-identification techniques, aggregation levels, access controls, and contractual safeguards in place. The OPC concluded that the combination of these measures reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were found to be not well-founded, as the data did not meet the definition of personal information under the Act. Despite this finding, the OPC made several recommendations to PHAC concerning ongoing assessment of de-identification techniques, due diligence with data providers, and enhanced transparency, which PHAC accepted.

Quick view

Privacy ActNot well-founded

Investigation into the collection and use of de-identified mobility data in the course of the COVID-19 pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 12 complaints against the Public Health Agency of Canada (PHAC) and Health Canada regarding their collection and use of de-identified mobility data during the COVID-19 pandemic. Complainants alleged PHAC secretly collected data on 33 million mobile devices. PHAC maintained it only used de-identified and aggregated data, arguing the Privacy Act did not apply as no personal information was collected. The OPC's primary issue was whether the mobility data constituted "personal information" under Section 3 of the Privacy Act, specifically if de-identification and safeguards reduced re-identification risk below the "serious possibility" threshold. The investigation examined two data streams, from TELUS and BlueDot, and assessed the de-identification techniques, aggregation levels, access controls, and contractual safeguards in place. The OPC concluded that the combination of these measures reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were found to be not well-founded, as the data did not meet the definition of personal information under the Act. Despite this finding, the OPC made several recommendations to PHAC concerning ongoing assessment of de-identification techniques, due diligence with data providers, and enhanced transparency, which PHAC accepted.

Key Issues
  • Whether mobility data collected and used by PHAC constituted "personal information" as defined under Section 3 of the Privacy Act.
  • Whether de-identification techniques and safeguards against re-identification were sufficient to reduce the risk of an individual being identified below the "serious possibility" threshold.
  • Whether access to data within TELUS's system constituted "collection" under the Privacy Act.
  • Whether de-identification alone is sufficient to render mobility data non-personal.
  • Whether robust contractual and physical protections were in place to limit access and use of de-identified data.
  • Whether acceptable data aggregation levels and access controls existed for aggregated mobility data.
  • Whether PHAC was sufficiently transparent with the public about its use of mobility data.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Vaccine mandates for entry into Canada

Public Health Agency of Canada (PHAC) and Canada Border Services Agency (CBSA)

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints regarding the collection, use, retention, and disclosure of personal information, including vaccination status, by the Public Health Agency of Canada (PHAC) and Canada Border Services Agency (CBSA) under Emergency Orders for entry into Canada during the COVID-19 pandemic. Complainants argued the measures were unlawful, unnecessary, and disproportionate. The OPC found that the collection of personal information was directly related to an operating program or activity of PHAC and CBSA, and its use and disclosure were for the purpose collected or consistent with it, or authorized by an Act of Parliament. The OPC also determined that the retention and disposal of information complied with the Privacy Act and related regulations. While necessity and proportionality are not explicit requirements of the Privacy Act, the OPC assessed these principles and found the collection overall to be necessary and proportional. However, the OPC identified gaps in PHAC's assessment and documentation of less privacy-intrusive alternatives and clarity of objectives in the final six months of the Orders. All complaints alleging contraventions of the Privacy Act were found to be not well-founded.

Quick view

Privacy ActNot well-founded

Vaccine mandates for entry into Canada

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints regarding the collection, use, retention, and disclosure of personal information, including vaccination status, by the Public Health Agency of Canada (PHAC) and Canada Border Services Agency (CBSA) under Emergency Orders for entry into Canada during the COVID-19 pandemic. Complainants argued the measures were unlawful, unnecessary, and disproportionate. The OPC found that the collection of personal information was directly related to an operating program or activity of PHAC and CBSA, and its use and disclosure were for the purpose collected or consistent with it, or authorized by an Act of Parliament. The OPC also determined that the retention and disposal of information complied with the Privacy Act and related regulations. While necessity and proportionality are not explicit requirements of the Privacy Act, the OPC assessed these principles and found the collection overall to be necessary and proportional. However, the OPC identified gaps in PHAC's assessment and documentation of less privacy-intrusive alternatives and clarity of objectives in the final six months of the Orders. All complaints alleging contraventions of the Privacy Act were found to be not well-founded.

Key Issues
  • Whether the personal information collected was directly related to an operating program or activity of PHAC and CBSA (s.4 Privacy Act)
  • Whether the personal information was used or disclosed for the purpose for which it was compiled/obtained, or in accordance with an Act of Parliament (s.7, s.8 Privacy Act)
  • Whether the personal information was disposed of in accordance with the Privacy Regulations and the Directive on Privacy Practices (s.6(3) Privacy Act)
  • Whether the collection of personal information under the Emergency Orders was necessary
  • Whether the collection of personal information under the Emergency Orders was effective
  • Whether there were less privacy-intrusive ways of achieving the same end
  • Whether the loss of privacy was proportional to the need