The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

81 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 6, 2009Indexed Jun 30, 2026

No proof Human Rights Commission accessed woman's Internet connection

Canadian Human Rights Commission (CHRC)

A woman complained that the Canadian Human Rights Commission (CHRC) improperly collected and used her personal information by allegedly accessing her wireless Internet connection to post messages on a white supremacist website during an investigation. An Internet Service Provider, responding to a subpoena, linked an IP address associated with the alleged CHRC activity to the complainant. The OPC's investigation found no evidence that the CHRC collected, used, or disclosed any personal information about the complainant or was even aware of her prior to the tribunal hearing. Technological experts suggested the IP address association was a third-party mismatch. The complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

No proof Human Rights Commission accessed woman's Internet connection

Oct 6, 2009
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained that the Canadian Human Rights Commission (CHRC) improperly collected and used her personal information by allegedly accessing her wireless Internet connection to post messages on a white supremacist website during an investigation. An Internet Service Provider, responding to a subpoena, linked an IP address associated with the alleged CHRC activity to the complainant. The OPC's investigation found no evidence that the CHRC collected, used, or disclosed any personal information about the complainant or was even aware of her prior to the tribunal hearing. Technological experts suggested the IP address association was a third-party mismatch. The complaint was found to be not well-founded.

Key Issues
  • Whether the Canadian Human Rights Commission improperly collected and used the complainant's personal information
  • Whether the CHRC accessed the complainant's wireless Internet connection
  • Whether an IP address can be considered personal information
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jan 29, 2009Indexed Jun 30, 2026

Investigation finds no evidence that Canadian Human Rights Commission accessed individual's Internet connection

Canadian Human Rights Commission (CHRC)

An individual complained that the Canadian Human Rights Commission (CHRC) improperly collected and used her personal information by accessing her wireless internet connection to post messages on a white supremacist website. The OPC investigated whether the CHRC contravened sections 4 to 8 of the Privacy Act. The investigation first determined that the complainant's IP address, when linked to her identity via a subpoena, constituted personal information under section 3 of the Act. However, the OPC found no evidence that the CHRC ever collected or had knowledge of the complainant's personal information prior to the allegations. Technological experts suggested the association of the complainant's IP address with the CHRC was likely a third-party mismatch. Consequently, the Assistant Privacy Commissioner concluded there was no contravention of the Privacy Act.

Quick view

Privacy ActNot well-founded

Investigation finds no evidence that Canadian Human Rights Commission accessed individual's Internet connection

Jan 29, 2009
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that the Canadian Human Rights Commission (CHRC) improperly collected and used her personal information by accessing her wireless internet connection to post messages on a white supremacist website. The OPC investigated whether the CHRC contravened sections 4 to 8 of the Privacy Act. The investigation first determined that the complainant's IP address, when linked to her identity via a subpoena, constituted personal information under section 3 of the Act. However, the OPC found no evidence that the CHRC ever collected or had knowledge of the complainant's personal information prior to the allegations. Technological experts suggested the association of the complainant's IP address with the CHRC was likely a third-party mismatch. Consequently, the Assistant Privacy Commissioner concluded there was no contravention of the Privacy Act.

Key Issues
  • Whether the complainant's IP address constituted personal information under section 3 of the Privacy Act
  • Whether the CHRC collected the complainant's personal information
  • Whether the CHRC improperly used, disclosed, or retained the complainant's personal information in contravention of sections 4 to 8 of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 2, 2007Report of FindingsIndexed Jun 30, 2026

Report of Findings: Privacy Commissioner of Canada v. SWIFT

SWIFT SCRL

The Privacy Commissioner of Canada initiated a complaint against SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication) for allegedly disclosing personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) in response to administrative subpoenas. SWIFT, a global financial messaging service, argued it was legally compelled to comply with valid US subpoenas and had negotiated privacy protections with the UST. The OPC first determined that the Personal Information Protection and Electronic Documents Act (PIPEDA) applied to SWIFT due to its significant presence and commercial activities in Canada. The key issue was whether SWIFT's disclosure without consent complied with PIPEDA, specifically the exception for subpoenas under paragraph 7(3)(c) and the appropriateness of the disclosure under subsection 5(3). The Commissioner concluded that paragraph 7(3)(c) allows for compliance with valid foreign subpoenas when an organization operates in multiple jurisdictions and legitimately stores data abroad, and that the disclosure was appropriate given the legal compulsion and privacy safeguards SWIFT negotiated. Consequently, the complaint was found not well-founded, as SWIFT's actions did not contravene PIPEDA. The Commissioner, however, recommended that the Canadian government engage with US counterparts to encourage the use of existing information-sharing mechanisms with built-in privacy protections, and noted SWIFT's efforts to explore enhanced privacy solutions.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Report of Findings: Privacy Commissioner of Canada v. SWIFT

Apr 2, 2007Report of Findings
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Privacy Commissioner of Canada initiated a complaint against SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication) for allegedly disclosing personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) in response to administrative subpoenas. SWIFT, a global financial messaging service, argued it was legally compelled to comply with valid US subpoenas and had negotiated privacy protections with the UST. The OPC first determined that the Personal Information Protection and Electronic Documents Act (PIPEDA) applied to SWIFT due to its significant presence and commercial activities in Canada. The key issue was whether SWIFT's disclosure without consent complied with PIPEDA, specifically the exception for subpoenas under paragraph 7(3)(c) and the appropriateness of the disclosure under subsection 5(3). The Commissioner concluded that paragraph 7(3)(c) allows for compliance with valid foreign subpoenas when an organization operates in multiple jurisdictions and legitimately stores data abroad, and that the disclosure was appropriate given the legal compulsion and privacy safeguards SWIFT negotiated. Consequently, the complaint was found not well-founded, as SWIFT's actions did not contravene PIPEDA. The Commissioner, however, recommended that the Canadian government engage with US counterparts to encourage the use of existing information-sharing mechanisms with built-in privacy protections, and noted SWIFT's efforts to explore enhanced privacy solutions.

Key Issues
  • Whether the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to SWIFT’s collection, use, and disclosure of personal information in the course of its operations in Canada.
  • Whether SWIFT is engaged in a commercial activity within Canada under paragraph 4(1)(a) of PIPEDA.
  • Whether personal information collected by SWIFT from Canadian financial institutions was disclosed to US authorities in accordance with PIPEDA.
  • Whether the disclosure of personal information without knowledge or consent was permitted under paragraph 7(3)(c) of PIPEDA (subpoena exception).
  • Whether a "subpoena or warrant" under paragraph 7(3)(c) must be issued only by a body within Canada.
  • Whether SWIFT’s disclosure to the UST was appropriate in the circumstances, as per subsection 5(3) of PIPEDA.
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 2, 2007Executive SummaryIndexed Jun 30, 2026

Executive Summary: Privacy Commissioner of Canada v. SWIFT

SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication)

The Privacy Commissioner of Canada launched an investigation into SWIFT SCRL following allegations that it disclosed personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) via administrative subpoenas. SWIFT provides messaging services to financial institutions globally, and some messages contain personal information. The Commissioner determined that SWIFT was subject to PIPEDA due to its operations and significant presence in Canada. While acknowledging SWIFT's compliance with US laws, the Commissioner found that SWIFT had not contravened PIPEDA, as the Act allows for disclosure without consent in response to a subpoena from a body with jurisdiction to compel information. The Commissioner emphasized that organizations operating in Canada must still abide by PIPEDA, even when subject to foreign laws. She also recommended that US authorities use existing information-sharing mechanisms with built-in privacy protections rather than subpoenas for Canadian-related financial information.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Executive Summary: Privacy Commissioner of Canada v. SWIFT

Apr 2, 2007Executive Summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Privacy Commissioner of Canada launched an investigation into SWIFT SCRL following allegations that it disclosed personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) via administrative subpoenas. SWIFT provides messaging services to financial institutions globally, and some messages contain personal information. The Commissioner determined that SWIFT was subject to PIPEDA due to its operations and significant presence in Canada. While acknowledging SWIFT's compliance with US laws, the Commissioner found that SWIFT had not contravened PIPEDA, as the Act allows for disclosure without consent in response to a subpoena from a body with jurisdiction to compel information. The Commissioner emphasized that organizations operating in Canada must still abide by PIPEDA, even when subject to foreign laws. She also recommended that US authorities use existing information-sharing mechanisms with built-in privacy protections rather than subpoenas for Canadian-related financial information.

Key Issues
  • Whether SWIFT is subject to PIPEDA
  • Whether SWIFT contravened PIPEDA by disclosing personal information to the US Department of the Treasury
  • Whether the exception to consent for disclosures in response to a subpoena applies
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Nov 7, 2003PIPEDA Case Summary #2003-243Indexed Jun 30, 2026

PIPEDA Case Summary #2003-243 — telecommunications company "B"

telecommunications company "B"

An individual complained that a telecommunications company failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the company did not adequately inform customers about its practice of sharing data with affiliates for marketing, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The company maintained that its privacy policy, code, and activation process provided a sufficient basis for customer knowledge and consent, and that it complied with CRTC restrictions on disclosing personal information. The investigation found that the company's privacy documents and activation process constituted a reasonable effort to advise individuals of secondary purposes and that customers could refuse or withdraw consent. The Assistant Commissioner concluded that the company was in compliance with PIPEDA.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Case Summary #2003-243 — telecommunications company "B"

Nov 7, 2003PIPEDA Case Summary #2003-243
Adjudicator: Robert Marleau
Plain-Language Summary

An individual complained that a telecommunications company failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the company did not adequately inform customers about its practice of sharing data with affiliates for marketing, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The company maintained that its privacy policy, code, and activation process provided a sufficient basis for customer knowledge and consent, and that it complied with CRTC restrictions on disclosing personal information. The investigation found that the company's privacy documents and activation process constituted a reasonable effort to advise individuals of secondary purposes and that customers could refuse or withdraw consent. The Assistant Commissioner concluded that the company was in compliance with PIPEDA.

Key Issues
  • Whether the telecommunications company obtained adequate knowledge and consent for the collection, use, or disclosure of personal information for secondary marketing purposes under Principle 4.3
  • Whether the company specified identified purposes at or before the time of collection as per Principle 4.2.3
  • Whether the company made a reasonable effort to ensure individuals were advised of the purposes for which information would be used, as required by Principle 4.3.2
  • Whether the form of consent sought by the organization was appropriate given the circumstances and type of information, considering Principle 4.3.4
  • Whether the reasonable expectations of the individual were considered in obtaining consent, as per Principle 4.3.5
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Oct 16, 2002PIPEDA Case Summary #2002-82Indexed Jun 30, 2026

PIPEDA Case Summary #2002-82: Alleged disclosure of personal information without consent for secondary marketing purposes by a bank

A bank

An individual complained that a bank failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the bank did not adequately inform customers of its data sharing practices with affiliates, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The OPC investigated the bank's privacy materials and processes, finding that the bank provided two privacy documents to customers and had a detailed privacy code available online or in paper format. The bank also had a process where representatives drew attention to privacy policies and recorded customer preferences regarding disclosure to affiliates. The Commissioner found that the bank's materials and processes constituted a reasonable effort to inform individuals and allow them to refuse or withdraw consent. The complaint was therefore found to be not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Case Summary #2002-82: Alleged disclosure of personal information without consent for secondary marketing purposes by a bank

Oct 16, 2002PIPEDA Case Summary #2002-82
Adjudicator: George Radwanski
Plain-Language Summary

An individual complained that a bank failed to obtain proper consent for the collection, use, or disclosure of personal information for secondary marketing purposes. The complainant alleged that the bank did not adequately inform customers of its data sharing practices with affiliates, failed to provide clear information on potential secondary uses, and did not offer an easy opt-out mechanism. The OPC investigated the bank's privacy materials and processes, finding that the bank provided two privacy documents to customers and had a detailed privacy code available online or in paper format. The bank also had a process where representatives drew attention to privacy policies and recorded customer preferences regarding disclosure to affiliates. The Commissioner found that the bank's materials and processes constituted a reasonable effort to inform individuals and allow them to refuse or withdraw consent. The complaint was therefore found to be not well-founded.

Key Issues
  • Whether the bank obtained adequate knowledge and consent for secondary marketing purposes under Principle 4.3
  • Whether the bank made a reasonable effort to advise individuals of the purposes for which information would be used, as required by Principle 4.3.2
  • Whether the purposes were stated in a manner that individuals could reasonably understand, as per Principle 4.3.2
  • Whether the bank considered the reasonable expectations of the individual in obtaining consent, as per Principle 4.3.5