The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

358 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 21, 2019Indexed Jun 30, 2026

Crossing the line? The CBSA’s examination of digital devices at the border

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Quick view

Privacy ActWell-founded

Crossing the line? The CBSA’s examination of digital devices at the border

Oct 21, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Key Issues
  • Whether CBSA's collection of personal information via digital device searches contravened section 4 of the Privacy Act.
  • Whether the definition of "goods" under the Customs Act extends to electronic documents on digital devices.
  • Whether CBSA's authority to search digital devices is limited to information stored on the device.
  • Whether Border Services Officers (BSOs) complied with CBSA's internal policy (Operational Bulletin PRG-2015-31) regarding digital device examinations (e.g., airplane mode, note-taking, search threshold).
  • Whether the copying of content from a digital device by a BSO was consistent with CBSA's legal authority and policy.
  • Whether the CBSA complied with its obligations under subsection 6(1) of the Privacy Act to retain personal information used for administrative purposes.
  • Whether the CBSA's practices regarding training, awareness, and accountability mechanisms for digital device searches were adequate.
  • Whether the Customs Act requires amendment to include a clear legal framework and a higher threshold for digital device examinations.
  • Whether the threshold for digital device examinations should be "reasonable grounds to suspect".
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Apr 25, 2019PIPEDA Findings #2019-002Indexed Jun 30, 2026

PIPEDA Findings #2019-002: Joint investigation of Facebook, Inc. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Facebook, Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) conducted a joint investigation into Facebook, Inc.'s compliance with PIPEDA and PIPA following revelations about the "thisisyourdigitallife" (TYDL) app and its data sharing with Cambridge Analytica. The investigation focused on Facebook's consent practices for both installing users and their friends, its data safeguards, and its overall accountability. The OPC found that Facebook failed to obtain meaningful consent from users for the disclosure of their personal information to third-party apps, including the TYDL app, and that its safeguards against unauthorized access and use were inadequate. Furthermore, Facebook was deemed to have abdicated its responsibility for user information, demonstrating a lack of accountability. Despite recommendations from the OPC, Facebook rejected or refused to implement them, leading to a finding that the complaint was well-founded and remains unresolved. The OPC stated it would pursue further action under its authorities.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2019-002: Joint investigation of Facebook, Inc. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Apr 25, 2019PIPEDA Findings #2019-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) conducted a joint investigation into Facebook, Inc.'s compliance with PIPEDA and PIPA following revelations about the "thisisyourdigitallife" (TYDL) app and its data sharing with Cambridge Analytica. The investigation focused on Facebook's consent practices for both installing users and their friends, its data safeguards, and its overall accountability. The OPC found that Facebook failed to obtain meaningful consent from users for the disclosure of their personal information to third-party apps, including the TYDL app, and that its safeguards against unauthorized access and use were inadequate. Furthermore, Facebook was deemed to have abdicated its responsibility for user information, demonstrating a lack of accountability. Despite recommendations from the OPC, Facebook rejected or refused to implement them, leading to a finding that the complaint was well-founded and remains unresolved. The OPC stated it would pursue further action under its authorities.

Key Issues
  • Whether the OPC and OIPC BC had jurisdiction to investigate the matter.
  • Whether Facebook's provision of access to personal information via its Graph API constitutes a "disclosure" under PIPEDA.
  • Whether Facebook obtained valid and meaningful consent from installing users for the disclosure of their personal information to third-party apps, including the TYDL App.
  • Whether Facebook made reasonable efforts to ensure third-party apps obtained meaningful consent from installing users.
  • Whether Facebook's reliance on overbroad and conflicting language in its privacy communications was sufficient for meaningful consent from installing users.
  • Whether Facebook obtained meaningful consent from friends of installing users (Affected Users) for the disclosure of their personal information to third-party apps.
  • Whether Facebook had adequate safeguards to protect user information against unauthorized access, use, and disclosure by apps.
  • Whether Facebook's monitoring and enforcement of its Platform Policy were adequate.
  • Whether Facebook's implementation of Graph v2 and App Review adequately addressed safeguard concerns for ongoing compliance.
  • Whether Facebook was accountable for the user information under its control.
  • Whether Facebook's policies and practices gave effect to the privacy principles under PIPEDA and PIPA.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 29, 2019Indexed Jun 30, 2026

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Global Affairs Canada

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Quick view

Privacy ActWell-founded

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Mar 29, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Key Issues
  • Whether the information in the diplomatic passport constitutes personal information under s.3 of the Privacy Act
  • Whether Global Affairs Canada's request for the diplomatic passport constituted a collection of personal information
  • Whether Global Affairs Canada demonstrated its authority to collect the personal travel information under s.4 of the Privacy Act
  • Whether the collection of personal travel information related directly to an operating program or activity of Global Affairs Canada
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 28, 2019Indexed Jun 30, 2026

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Employment and Social Development Canada (ESDC)

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Quick view

Privacy ActWell-founded

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Mar 28, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Key Issues
  • Whether the complainant's name, telephone number, and email address constitute personal information under the Act
  • Whether ESDC was required to collect personal information directly from the complainant under section 5 of the Act
  • Whether ESDC complied with section 4 of the Act regarding the collection of personal information
  • Whether ESDC adequately ensured Grey House Publishing Canada complied with consent requirements as per their contract
  • Whether ESDC improperly collected the complainant's information after he requested removal from the distribution list
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 11, 2019Indexed Jun 30, 2026

The name of an individual is considered personal information if it is accompanied by information that is about the individual

Canadian Transportation Agency (CTA)

The complainant, an air passenger rights advocate, requested access to all records about himself held by the Canadian Transportation Agency (CTA). The CTA initially withheld 760 pages, arguing that most references to the complainant's name were not personal information because he was acting on behalf of an organization. The OPC found that the information was indeed personal information, as the organization was not a separate legal entity and the records contained views and information directly about the complainant. The OPC also found that the CTA incorrectly applied exemptions under section 26 (third-party personal information) and subsection 70(1) (cabinet confidences) in some instances, and over-redacted under section 27 (solicitor-client privilege). The complaint was found to be well-founded, and the CTA agreed to implement the OPC's recommendations to disclose the withheld information.

Quick view

Privacy ActWell-founded

The name of an individual is considered personal information if it is accompanied by information that is about the individual

Feb 11, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, an air passenger rights advocate, requested access to all records about himself held by the Canadian Transportation Agency (CTA). The CTA initially withheld 760 pages, arguing that most references to the complainant's name were not personal information because he was acting on behalf of an organization. The OPC found that the information was indeed personal information, as the organization was not a separate legal entity and the records contained views and information directly about the complainant. The OPC also found that the CTA incorrectly applied exemptions under section 26 (third-party personal information) and subsection 70(1) (cabinet confidences) in some instances, and over-redacted under section 27 (solicitor-client privilege). The complaint was found to be well-founded, and the CTA agreed to implement the OPC's recommendations to disclose the withheld information.

Key Issues
  • Whether information relating to the complainant's advocacy activities, where his name appears, constitutes personal information under section 3 of the Privacy Act
  • Whether the CTA correctly invoked paragraph 12(1)(b) to deny access to information it deemed not to be personal information
  • Whether the CTA correctly withheld third-party personal information under section 26 of the Privacy Act
  • Whether the CTA correctly withheld information under section 27 of the Privacy Act (solicitor-client privilege)
  • Whether the CTA correctly withheld information under subsection 70(1) of the Privacy Act (cabinet confidences)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 20, 2018Indexed Jun 30, 2026

Innovation, Science and Economic Development Canada fails to ensure that the information it used to staff a position was accurate

Innovation, Science and Economic Development Canada (ISED)

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) used inaccurate personal information about him when staffing a position. ISED acknowledged that its Human Resources officials mistakenly selected the complainant's profile in the MyGCHR system instead of another individual with the same name, leading to the complainant being 'hired' by ISED and 'terminated' from his position at Public Services and Procurement Canada (PSPC). This error caused the complainant to miss pay periods. The OPC found that ISED did not take all reasonable steps to ensure the accuracy of the personal information, as officials only used first and last names for the search and did not verify with additional identifiers like a Personal Record Identifier (PRI) or date of birth. The complaint was found to be well-founded, but ISED has since implemented a new policy requiring staff to validate identities using multiple data fields.

Quick view

Privacy ActWell-founded

Innovation, Science and Economic Development Canada fails to ensure that the information it used to staff a position was accurate

Aug 20, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) used inaccurate personal information about him when staffing a position. ISED acknowledged that its Human Resources officials mistakenly selected the complainant's profile in the MyGCHR system instead of another individual with the same name, leading to the complainant being 'hired' by ISED and 'terminated' from his position at Public Services and Procurement Canada (PSPC). This error caused the complainant to miss pay periods. The OPC found that ISED did not take all reasonable steps to ensure the accuracy of the personal information, as officials only used first and last names for the search and did not verify with additional identifiers like a Personal Record Identifier (PRI) or date of birth. The complaint was found to be well-founded, but ISED has since implemented a new policy requiring staff to validate identities using multiple data fields.

Key Issues
  • Whether the information at issue constituted personal information under section 3 of the Privacy Act
  • Whether ISED took all reasonable steps to ensure that the personal information it used for an administrative purpose was as accurate, up-to-date and complete as possible, as required by subsection 6(2) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 12, 2018PIPEDA Report of Findings #2018-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-002: Company’s re-use of millions of Canadian Facebook user profiles violated privacy law

Profile Technology Ltd.

Multiple complainants alleged that Profile Technology Ltd. copied their personal information from Facebook profiles and groups without consent and posted it on its social networking website, making removal difficult, and indefinitely retaining helpdesk information. The OPC asserted jurisdiction over the New Zealand-based company due to a real and substantial connection to Canada. The OPC found that the information was not "publicly available" under PIPEDA's Regulations, and Profile Technology failed to obtain valid consent for its new purpose of operating a social networking site. Furthermore, the OPC determined that using this information for such a purpose was not appropriate in the circumstances and that the indefinite retention of helpdesk ticket information violated retention principles. Profile Technology refused to implement recommendations for deletion and a retention policy. Although the company later removed profiles from its website, it uploaded much of the data to the Internet Archive, which the OPC found did not resolve the contraventions and created new privacy risks. The matter was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2018-002: Company’s re-use of millions of Canadian Facebook user profiles violated privacy law

Jun 12, 2018PIPEDA Report of Findings #2018-002
Adjudicator: Daniel Therrien
Plain-Language Summary

Multiple complainants alleged that Profile Technology Ltd. copied their personal information from Facebook profiles and groups without consent and posted it on its social networking website, making removal difficult, and indefinitely retaining helpdesk information. The OPC asserted jurisdiction over the New Zealand-based company due to a real and substantial connection to Canada. The OPC found that the information was not "publicly available" under PIPEDA's Regulations, and Profile Technology failed to obtain valid consent for its new purpose of operating a social networking site. Furthermore, the OPC determined that using this information for such a purpose was not appropriate in the circumstances and that the indefinite retention of helpdesk ticket information violated retention principles. Profile Technology refused to implement recommendations for deletion and a retention policy. Although the company later removed profiles from its website, it uploaded much of the data to the Internet Archive, which the OPC found did not resolve the contraventions and created new privacy risks. The matter was found to be well-founded.

Key Issues
  • Whether the OPC had jurisdiction to investigate a New Zealand-based company's activities affecting Canadians.
  • Whether the investigation was time-barred under subsection 13(1) of PIPEDA.
  • Whether PIPEDA's application to commercial activity is constitutionally valid under the federal Trade and Commerce power.
  • Whether personal information copied from Facebook profiles was "publicly available" under PIPEDA's Regulations Specifying Publicly Available Information.
  • Whether Facebook profiles constitute a "publication" for the purposes of the Regulations.
  • Whether Profile Technology obtained valid knowledge and consent (Principle 4.3 PIPEDA) for the collection, use, and disclosure of personal information for its social networking website.
  • Whether consent obtained by Facebook was sufficient for Profile Technology's subsequent use of the data.
  • Whether opt-out consent would be an appropriate form of consent in this context (Principle 4.3.4 PIPEDA).
  • Whether Profile Technology's use of Facebook profile information for its social networking site was for purposes a reasonable person would consider "appropriate in the circumstances" (subsection 5(3) PIPEDA).
  • Whether Profile Technology retained personal information (helpdesk tickets) longer than necessary (Principle 4.5 PIPEDA).
  • Whether Profile Technology was responsible for personal information held by its third-party helpdesk service provider.
  • Whether Profile Technology's actions of removing profiles from its website and uploading data to the Internet Archive resolved the identified contraventions.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 12, 2018Repeat offenderIndexed Jun 30, 2026

Repeat offender: CSC unlawfully denies complainant access to his personal information a second time

Correctional Service Canada (CSC)

A federal inmate complained that Correctional Service Canada (CSC) repeatedly denied him access to his personal information, specifically video and audio recordings, in contravention of the Privacy Act. This complaint followed a similar investigation in 2012 where the OPC found serious deficiencies in CSC's handling of the complainant's requests, including failure to retain video recordings before destruction. In the current investigation, the OPC found that CSC again failed to retrieve and retain requested video recordings within their short retention period in two cases, and failed to respond to four other requests for grievance-related records. The OPC concluded that CSC contravened subsection 12(1) of the Privacy Act by denying the complainant access to his personal information. CSC accepted the OPC's recommendations to improve its processes for handling access requests for records with short retention periods and to respond to outstanding requests.

Quick view

Privacy ActWell-founded

Repeat offender: CSC unlawfully denies complainant access to his personal information a second time

Jun 12, 2018Repeat offender
Adjudicator: Daniel Therrien
Plain-Language Summary

A federal inmate complained that Correctional Service Canada (CSC) repeatedly denied him access to his personal information, specifically video and audio recordings, in contravention of the Privacy Act. This complaint followed a similar investigation in 2012 where the OPC found serious deficiencies in CSC's handling of the complainant's requests, including failure to retain video recordings before destruction. In the current investigation, the OPC found that CSC again failed to retrieve and retain requested video recordings within their short retention period in two cases, and failed to respond to four other requests for grievance-related records. The OPC concluded that CSC contravened subsection 12(1) of the Privacy Act by denying the complainant access to his personal information. CSC accepted the OPC's recommendations to improve its processes for handling access requests for records with short retention periods and to respond to outstanding requests.

Key Issues
  • Whether CSC contravened subsection 6(1) of the Privacy Act by failing to retain personal information for a prescribed period
  • Whether CSC contravened subsection 12(1) of the Privacy Act by failing to provide access to personal information
  • Whether CSC contravened subsection 16(3) of the Privacy Act by failing to respond to access requests within statutory time limits
  • Whether CSC appropriately applied paragraph 22(1)(c) of the Privacy Act to withhold video recordings
  • Whether CSC appropriately applied section 26 of the Privacy Act to withhold video recordings
  • Whether CSC made reasonable efforts to secure video recordings before destruction as per previous OPC recommendations
  • Whether CSC's processes for handling access requests for records with short retention periods are adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 4, 2018Indexed Jun 30, 2026

Employee text messages intercepted without authorization at the Warkworth Institution

Correctional Service Canada (CSC)

The OPC received complaints alleging that Correctional Service Canada (CSC) contravened the Privacy Act by intercepting cell phone conversations and text messages near Warkworth Institution. CSC confirmed intercepting six text messages but denied recording conversations, stating it did not intend to collect text messages. The investigation found that CSC used a cell-site simulator, operated by a contractor, to detect unauthorized cell phone use by inmates. While the collection of metadata was deemed consistent with the Act due to security concerns, the interception of text message content was not authorized. The OPC concluded that CSC was responsible for the contractor's actions and that the collection of text messages contravened the Privacy Act. The complaints were found to be well-founded.

Quick view

Privacy ActWell-founded

Employee text messages intercepted without authorization at the Warkworth Institution

Jun 4, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC received complaints alleging that Correctional Service Canada (CSC) contravened the Privacy Act by intercepting cell phone conversations and text messages near Warkworth Institution. CSC confirmed intercepting six text messages but denied recording conversations, stating it did not intend to collect text messages. The investigation found that CSC used a cell-site simulator, operated by a contractor, to detect unauthorized cell phone use by inmates. While the collection of metadata was deemed consistent with the Act due to security concerns, the interception of text message content was not authorized. The OPC concluded that CSC was responsible for the contractor's actions and that the collection of text messages contravened the Privacy Act. The complaints were found to be well-founded.

Key Issues
  • Whether cell phone metadata constitutes personal information under the Privacy Act
  • Whether text messages constitute personal information under the Privacy Act
  • Whether the collection of cell phone metadata by CSC was consistent with section 4 of the Privacy Act
  • Whether the interception and collection of text message content by CSC was consistent with section 4 of the Privacy Act
  • Whether CSC is responsible for the actions of its contractor in collecting personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 12, 2018Indexed Jun 30, 2026

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Health Canada

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Quick view

Privacy ActWell-founded

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Mar 12, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Key Issues
  • Whether the information collected by Health Canada on Limited Use forms for drug benefits constitutes personal information under the Privacy Act
  • Whether Health Canada's collection of personal information on Limited Use forms relates directly to an operating program or activity of the institution as required by section 4 of the Privacy Act
  • Whether the specific data fields requesting detailed diagnostic information (e.g., exact number of swollen joints) are necessary for the adjudication of drug benefit claims under the NIHB Program
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 28, 2017PIPEDA Report of Findings #2017-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-002: Canadian adware developer Wajam Internet Technologies Inc. breaches multiple provisions of PIPEDA

Wajam Internet Technologies Inc.

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Wajam Internet Technologies Inc., an adware developer, regarding its software's installation, consent, uninstallation, and data handling practices. The software, Wajam or Social2Search, tracked online search queries, overlaid social media results, and displayed contextual ads. The OPC investigated whether Wajam obtained meaningful consent for installation, allowed users to withdraw consent, and adequately safeguarded personal information. The investigation found that Wajam lacked a privacy accountability framework, failed to obtain meaningful consent due to problematic third-party distribution methods and misleading information, indefinitely retained unencrypted raw user data, and had insufficient safeguards. All examined matters related to accountability, consent, limiting retention, safeguards, and openness were found to be well-founded. Wajam, having sold its assets to a Hong Kong-based company, IMTL, claimed it was unable to implement the OPC's recommendations, though it agreed to securely destroy Canadian user data. The OPC requested Wajam provide the report to IMTL and stated it would monitor the situation and engage international counterparts.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2017-002: Canadian adware developer Wajam Internet Technologies Inc. breaches multiple provisions of PIPEDA

Aug 28, 2017PIPEDA Report of Findings #2017-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Wajam Internet Technologies Inc., an adware developer, regarding its software's installation, consent, uninstallation, and data handling practices. The software, Wajam or Social2Search, tracked online search queries, overlaid social media results, and displayed contextual ads. The OPC investigated whether Wajam obtained meaningful consent for installation, allowed users to withdraw consent, and adequately safeguarded personal information. The investigation found that Wajam lacked a privacy accountability framework, failed to obtain meaningful consent due to problematic third-party distribution methods and misleading information, indefinitely retained unencrypted raw user data, and had insufficient safeguards. All examined matters related to accountability, consent, limiting retention, safeguards, and openness were found to be well-founded. Wajam, having sold its assets to a Hong Kong-based company, IMTL, claimed it was unable to implement the OPC's recommendations, though it agreed to securely destroy Canadian user data. The OPC requested Wajam provide the report to IMTL and stated it would monitor the situation and engage international counterparts.

Key Issues
  • Whether Wajam Internet Technologies Inc. had an adequate privacy accountability framework in place (Principle 4.1.4 PIPEDA)
  • Whether Wajam obtained meaningful consent from individuals for the installation and operation of its software (Principle 4.3, 4.3.2, 4.3.5 PIPEDA, s.6.1 PIPEDA)
  • Whether Wajam's third-party distribution model ensured meaningful consent for software installation
  • Whether Wajam's multiple-offer consent screens provided sufficient information for meaningful consent
  • Whether the information provided by Wajam about its software's functionality and privacy practices was accurate and complete (Principle 4.2, 4.3.2, 4.3.5 PIPEDA)
  • Whether Wajam permitted users to withdraw consent by making it difficult to uninstall its software (Principle 4.3.8 PIPEDA)
  • Whether Wajam was responsible for unsolicited ads and fake offers presented during the uninstallation process (Principle 4.3 PIPEDA)
  • Whether Wajam limited the retention of personal information to only as long as necessary for identified purposes (Principle 4.5, 4.5.2 PIPEDA)
  • Whether Wajam was open about its policies and practices relating to the management of personal information (Principle 4.8 PIPEDA)
  • Whether Wajam adequately safeguarded users' personal information against loss, theft, or unauthorized access, including during transmission and storage (Principle 4.7.1, 4.7.2, 4.7.3 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 17, 2017PIPEDA Report of Findings #2017-008Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-008: Jet Airways says possibility of litigation allows it to refuse access to personal information

Jet Airways

The complainant alleged that Jet Airways failed to provide complete access to her personal information related to an incident where she and her companion were removed from a flight. Jet Airways initially failed to respond to the access request within the 30-day timeframe, citing potential litigation and staff medical leave. While Jet Airways eventually provided the Passenger Name Record, it withheld other documents, claiming solicitor-client privilege (including litigation privilege) and that the information was generated during a formal dispute resolution process. The OPC found that Jet Airways contravened its obligations regarding timely response and proper policies for handling access requests and applying exemptions. However, due to binding court decisions, the OPC could not make a finding on the specific application of solicitor-client/litigation privilege to the withheld documents, leading to an impasse on that issue. The OPC recommended that Jet Airways implement proper access request procedures and review its policies for applying exemptions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2017-008: Jet Airways says possibility of litigation allows it to refuse access to personal information

Aug 17, 2017PIPEDA Report of Findings #2017-008
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Jet Airways failed to provide complete access to her personal information related to an incident where she and her companion were removed from a flight. Jet Airways initially failed to respond to the access request within the 30-day timeframe, citing potential litigation and staff medical leave. While Jet Airways eventually provided the Passenger Name Record, it withheld other documents, claiming solicitor-client privilege (including litigation privilege) and that the information was generated during a formal dispute resolution process. The OPC found that Jet Airways contravened its obligations regarding timely response and proper policies for handling access requests and applying exemptions. However, due to binding court decisions, the OPC could not make a finding on the specific application of solicitor-client/litigation privilege to the withheld documents, leading to an impasse on that issue. The OPC recommended that Jet Airways implement proper access request procedures and review its policies for applying exemptions.

Key Issues
  • Whether Jet Airways responded to the access request within the prescribed 30-day time period under subsection 8(3) of PIPEDA
  • Whether Jet Airways had appropriate policies and practices to give effect to Principle 4.1.4 of Schedule 1 of PIPEDA
  • Whether the withheld information was protected by solicitor-client privilege or litigation privilege under paragraph 9(3)(a) of PIPEDA
  • Whether the withheld information was generated in the course of a formal dispute resolution process under paragraph 9(3)(d) of PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 16, 2017Indexed Jun 30, 2026

Cell site simulators used by RCMP not capable of intercepting private communication

Royal Canadian Mounted Police (RCMP)

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Quick view

Privacy ActWell-founded

Cell site simulators used by RCMP not capable of intercepting private communication

Aug 16, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Key Issues
  • Whether RCMP uses cell site simulators (MDIs)
  • Whether RCMP's MDIs are capable of intercepting private communications (voice, text, email, encryption keys)
  • Whether RCMP's collection of personal information using MDIs relates directly to an operating program or activity (s.4 Privacy Act)
  • Whether RCMP's collection of personal information using MDIs was lawful and Charter-compliant, specifically regarding prior judicial authorization
  • Whether exigent circumstances justified warrantless MDI deployments in certain cases
  • Whether RCMP's collection of personal information using MDIs complied with direct collection and notification requirements (s.5 Privacy Act)
  • Whether the RCMP adequately handles, retains, and disposes of third-party personal information (IMSI/IMEI numbers) collected by MDIs
  • Whether the wording in warrants and policies provides adequate protection for collected personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 8, 2017PIPEDA Report of Findings #2017-007Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-007: Operator of website that shamed debtors for profit takes down website after OPC takes the matter to Federal Court

Public Executions Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Public Executions Inc., operator of publicexecutions.ca, a website that published personal information of judgment debtors for a fee. Complainants alleged their privacy rights under PIPEDA were breached by the website's practice of "naming and shaming" them into paying debts. The website owner argued PIPEDA did not apply, claiming it was not a commercial activity, was exempt as journalism, and that disclosures were permitted for debt collection. The OPC found that the website's fee-based service constituted a commercial activity under PIPEDA. It rejected the journalistic exemption, noting the lack of original production and journalistic discipline. The OPC concluded that broadly publicizing debtor information for financial gain and coercion was not an appropriate purpose under subsection 5(3) of PIPEDA, especially given existing legal mechanisms and regulations for debt collection. Furthermore, the OPC clarified that paragraph 7(3)(b) of PIPEDA, which allows disclosure for debt collection, does not permit indiscriminate disclosure to the public. Initially, the complaint was found well-founded and unresolved, as the website owner refused to comply with recommendations. However, after the OPC initiated Federal Court proceedings, the website was taken down, leading the OPC to discontinue its application.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2017-007: Operator of website that shamed debtors for profit takes down website after OPC takes the matter to Federal Court

Aug 8, 2017PIPEDA Report of Findings #2017-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Public Executions Inc., operator of publicexecutions.ca, a website that published personal information of judgment debtors for a fee. Complainants alleged their privacy rights under PIPEDA were breached by the website's practice of "naming and shaming" them into paying debts. The website owner argued PIPEDA did not apply, claiming it was not a commercial activity, was exempt as journalism, and that disclosures were permitted for debt collection. The OPC found that the website's fee-based service constituted a commercial activity under PIPEDA. It rejected the journalistic exemption, noting the lack of original production and journalistic discipline. The OPC concluded that broadly publicizing debtor information for financial gain and coercion was not an appropriate purpose under subsection 5(3) of PIPEDA, especially given existing legal mechanisms and regulations for debt collection. Furthermore, the OPC clarified that paragraph 7(3)(b) of PIPEDA, which allows disclosure for debt collection, does not permit indiscriminate disclosure to the public. Initially, the complaint was found well-founded and unresolved, as the website owner refused to comply with recommendations. However, after the OPC initiated Federal Court proceedings, the website was taken down, leading the OPC to discontinue its application.

Key Issues
  • Whether the website's activities constituted "commercial activity" under paragraph 4(1)(a) of PIPEDA.
  • Whether the website qualified for the "journalistic purposes" exemption under paragraph 4(2)(c) of PIPEDA.
  • Whether the collection, use, and disclosure of personal information by the website was for purposes that a reasonable person would consider "appropriate in the circumstances" under subsection 5(3) of PIPEDA.
  • Whether the disclosure of personal information was permitted without consent for the purpose of collecting a debt under paragraph 7(3)(b) of PIPEDA.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 19, 2017Indexed Jun 30, 2026

MyDemocracy website not designed in a privacy sensitive way

Privy Council Office

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Quick view

Privacy ActWell-founded

MyDemocracy website not designed in a privacy sensitive way

Jul 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Key Issues
  • Whether the MyDemocracy.ca website's design led to the disclosure of personal information to third parties (Facebook, Google Analytics) without consent.
  • Whether IP addresses, browser characteristics, and unique URLs constitute "personal information" under section 3 of the Privacy Act.
  • Whether the Privy Council Office (PCO) met its obligations under section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether PCO's amendments to the website and privacy policy were sufficient to obtain meaningful consent for data disclosure.
  • Whether PCO should have conducted a Privacy Impact Assessment (PIA) for the MyDemocracy.ca initiative.
  • Whether the collection of demographic information was justified and compliant with relevant standards.
  • Whether the use of Google Analytics complied with the Treasury Board of Canada Secretariat's (TBS) Standard on Privacy and Web Analytics.