The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

358 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Phoenix pay system compromised Public Servants’ privacy

Public Services and Procurement Canada

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Quick view

Privacy ActWell-founded

Phoenix pay system compromised Public Servants’ privacy

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Key Issues
  • Whether personal information was at issue in the reported incidents
  • Whether the personal information at issue was improperly disclosed
  • What was the scope of the improper disclosure
  • Whether the personal information that was improperly disclosed was misused
  • Whether PSPC was aware of potential privacy issues with Phoenix before the launch
  • What kind of harm could result from the unauthorized disclosure of the personal information at issue
  • Whether PSPC resolved all of the vulnerabilities within Phoenix
  • Whether PSPC provided individuals with timely information regarding the breaches and vulnerabilities
  • Whether PSPC developed and implemented controls to monitor and document access to personal information held in Phoenix (Recommendation 1)
  • Whether PSPC developed more robust testing and response procedures (Recommendation 2)
  • Whether PSPC conducted necessary assessments to identify potential risks and vulnerabilities in Phoenix (Recommendation 3)
  • Whether PSPC took measures to mitigate the increased vulnerability of information used by employees in call centres (Recommendation 4)
  • Whether PSPC reviewed its breach notification practices and provided notification of the extent of the Phoenix breaches (Recommendation 5)
  • Whether PSPC completed the review of pages with row-level security (Recommendation 6)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Health Canada

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Quick view

Privacy ActWell-founded

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Key Issues
  • Whether diagnostic information about individual patients constitutes 'personal information' under s.3 of the Privacy Act
  • Whether Health Canada contravened s.4 of the Privacy Act by collecting diagnostic information about patients seeking medical transportation and specialist services that was not directly related to an operating program or activity
  • Whether the collection of diagnostic information was demonstrably necessary to achieve a specific and legitimate purpose
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 19, 2017Indexed Jun 30, 2026

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Royal Canadian Mounted Police (RCMP)

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Quick view

Privacy ActWell-founded

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Apr 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Key Issues
  • Whether the RCMP inappropriately disclosed the complainant's personal information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(f) of the Privacy Act.
  • Whether CBP's use of the complainant's personal information for an admissibility assessment constituted "criminal justice purposes" or "law enforcement" as defined in the Memorandum of Cooperation (MOC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(a) of the Privacy Act as a "consistent use."
  • Whether the CPIC policies in effect at the time provided sufficient clarity to guard against unauthorized disclosure of sensitive personal information.
  • Whether the revised CPIC policies, including the "SHARE US A" feature and "SIP-OB" entries, adequately protect against unauthorized disclosure of attempted suicide information.
  • Whether the default setting of the "SHARE US A" feature in CPIC should suppress the sharing of SIP-OB entries relating to threatened or attempted suicides with US border officials.
  • Whether CPIC policies should be revised to provide clear guidance for sharing attempted suicide information with US border officials only where an individual presents an ongoing risk to others.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Dec 29, 2016PIPEDA findings #2016-013Indexed Jun 30, 2026

PIPEDA findings #2016-013: Company’s disclosure of information about a debt owed is not covered under exemption to consent

A sports facilities company

An individual complained that a sports facilities company disclosed his personal information, specifically details about an outstanding debt, to a related sports association on two occasions without his consent. The company did not deny the disclosures but argued they were made in response to direct questions and with an expectation of privacy. The OPC found that information about a debt owed by an identifiable individual is personal and sensitive, requiring consent for disclosure unless a specific exemption applies. The OPC determined that the disclosures were not for the purpose of collecting the debt, thus the exemption under paragraph 7(3)(b) of PIPEDA did not apply. The company's reliance on an 'expectation of privacy' or being asked directly was not a valid substitute for obtaining consent. The complaint was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA findings #2016-013: Company’s disclosure of information about a debt owed is not covered under exemption to consent

Dec 29, 2016PIPEDA findings #2016-013
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a sports facilities company disclosed his personal information, specifically details about an outstanding debt, to a related sports association on two occasions without his consent. The company did not deny the disclosures but argued they were made in response to direct questions and with an expectation of privacy. The OPC found that information about a debt owed by an identifiable individual is personal and sensitive, requiring consent for disclosure unless a specific exemption applies. The OPC determined that the disclosures were not for the purpose of collecting the debt, thus the exemption under paragraph 7(3)(b) of PIPEDA did not apply. The company's reliance on an 'expectation of privacy' or being asked directly was not a valid substitute for obtaining consent. The complaint was found to be well-founded.

Key Issues
  • Whether the disclosure of debt information without consent contravened Principle 4.3 of PIPEDA
  • Whether the disclosure was exempt from consent under paragraph 7(3)(b) of PIPEDA for debt collection purposes
  • Whether an 'expectation of privacy' or responding to a direct question constitutes a valid exception to consent requirements
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 20, 2016Indexed Jun 30, 2026

The PBC refuses to process requests for record suspension information

Parole Board of Canada

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Quick view

Privacy ActWell-founded

The PBC refuses to process requests for record suspension information

Dec 20, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Key Issues
  • Whether an individual can make a request under the Privacy Act to confirm that no personal information relating to record suspensions exists.
  • Whether the PBC properly applied the exemption under paragraph 22(1)(b) of the Privacy Act to refuse access requests for record suspension information.
  • Whether the disclosure of record suspension information under the Privacy Act would injure the enforcement of the Criminal Records Act.
  • Whether the PBC's requirement for additional identification (FPS number, PBC reference number, criminal record copy) is necessary to adequately identify a requester under the Privacy Act.
  • Whether the company's record suspension verification service circumvents the vulnerable sector verification process under the CRA.
  • Whether the consent obtained by the company for its service is valid.
  • Whether the proposed use of personal information by the company violates human rights legislation.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 6, 2016Indexed Jun 30, 2026

TV show raises numerous questions of consent

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Quick view

Privacy ActWell-founded

TV show raises numerous questions of consent

Jun 6, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Key Issues
  • Whether the CBSA, as a federal institution, could contract out of its obligations under the Privacy Act
  • Whether the CBSA's collection of personal information in connection with the TV Program related directly to an operating program or activity of the institution (s.4 Privacy Act)
  • Whether the CBSA was involved in the collection of personal information for the purposes of the TV Program
  • Whether there was a real-time disclosure of personal information by the CBSA to Force Four for the purpose of filming the TV Program
  • Whether the CBSA obtained valid, meaningful, and freely given consent from individuals, including the complainant, for the disclosure of their personal information to Force Four (s.8 Privacy Act)
  • Whether the "Voluntary Appearance Release Form" (Waiver) effectively waived individuals' rights under the Privacy Act
  • Whether the practice of "silent filming" by the production crew was consistent with obtaining valid consent
  • Whether the CBSA disclosed personal information of an intended subject to Force Four in advance of filming without authorization (s.8 Privacy Act)
  • Whether the personal information of the intended subject was publicly available at the time of disclosure
  • Whether the facial blurring and other identity concealment techniques used in the TV Program were sufficient to prevent the identification of individuals who had not provided written consent
  • Whether the CBSA demonstrated how the disclosure of personal information of individuals without written consent was consistent with section 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 30, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – RCMP

Royal Canadian Mounted Police (RCMP)

The complainant, an RCMP employee, alleged that the RCMP inappropriately used employees' personal information during a training course for Respectful Workplace Advisors on the National Administrative Records Management System (NARMS). During a data entry exercise, participants were given sheets containing real personal information of 91 employees, including names, ranks, and incident descriptions. The complainant raised concerns as participants were not advised real data would be used nor required to sign confidentiality agreements. The RCMP acknowledged that the use of this personal information for training purposes was not authorized under section 7 of the Privacy Act, as training was not a consistent use described in the applicable Personal Information Bank. The RCMP subsequently notified all 91 affected employees of the breach and took steps to prevent future occurrences. The OPC found the complaint to be well-founded.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – RCMP

Jul 30, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, an RCMP employee, alleged that the RCMP inappropriately used employees' personal information during a training course for Respectful Workplace Advisors on the National Administrative Records Management System (NARMS). During a data entry exercise, participants were given sheets containing real personal information of 91 employees, including names, ranks, and incident descriptions. The complainant raised concerns as participants were not advised real data would be used nor required to sign confidentiality agreements. The RCMP acknowledged that the use of this personal information for training purposes was not authorized under section 7 of the Privacy Act, as training was not a consistent use described in the applicable Personal Information Bank. The RCMP subsequently notified all 91 affected employees of the breach and took steps to prevent future occurrences. The OPC found the complaint to be well-founded.

Key Issues
  • Whether the use of employees' personal information for training purposes constituted an unauthorized use under section 7(a) of the Privacy Act
  • Whether training was a consistent use of personal information as described in the applicable Personal Information Bank (PIB PSU 915)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 28, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – Parole Board of Canada

Parole Board of Canada

The complaint alleged that the Parole Board of Canada (PBC) contravened the disclosure provisions of the Privacy Act when a human resources employee disclosed the complainant's medical information to individuals involved in a Public Service Staffing Tribunal (PSST) hearing. The PSST had specifically ordered the PBC to remove medical information from the material provided. The PBC acknowledged the disclosure, apologized to the complainant, and ensured the recipients disposed of the information. The OPC found that the complainant's medical information was disclosed without consent and not under any permitted disclosure provision of subsection 8(2) of the Act. Therefore, the OPC concluded that the complaint was well-founded.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – Parole Board of Canada

Jul 28, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint alleged that the Parole Board of Canada (PBC) contravened the disclosure provisions of the Privacy Act when a human resources employee disclosed the complainant's medical information to individuals involved in a Public Service Staffing Tribunal (PSST) hearing. The PSST had specifically ordered the PBC to remove medical information from the material provided. The PBC acknowledged the disclosure, apologized to the complainant, and ensured the recipients disposed of the information. The OPC found that the complainant's medical information was disclosed without consent and not under any permitted disclosure provision of subsection 8(2) of the Act. Therefore, the OPC concluded that the complaint was well-founded.

Key Issues
  • Whether the complainant's medical information constitutes personal information under s.3 of the Privacy Act
  • Whether the disclosure of the complainant's medical information by the PBC contravened s.8(1) of the Privacy Act
  • Whether the disclosure was in accordance with any of the permitted categories under s.8(2) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jul 28, 2015Discontinued Case Summary #2015-002Indexed Jun 30, 2026

Discontinued Case Summary #2015-002: OPC discontinues additional complaints against Globe24h.com following investigation into same privacy issues

Globe24h.com

Multiple complainants alleged that Globe24h.com collected, used, and disclosed their personal information without consent by republishing Canadian court and tribunal decisions and charging for removal. The OPC had previously investigated similar complaints against Globe24h.com and found them to be well-founded. Despite this, additional complaints continued to be received. The OPC decided to discontinue these new complaints under paragraph 12.2(1)(e) of PIPEDA, as the matter had already been the subject of a Commissioner's report. The OPC noted its continued interest in Globe24h.com's compliance and later participated in a Federal Court proceeding initiated by one of the original complainants. The Federal Court ultimately confirmed the OPC's findings and ordered Globe24h.com to remove the information and cease contravening PIPEDA, leading to the website's closure.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Discontinued Case Summary #2015-002: OPC discontinues additional complaints against Globe24h.com following investigation into same privacy issues

Jul 28, 2015Discontinued Case Summary #2015-002
Adjudicator: Daniel Therrien
Plain-Language Summary

Multiple complainants alleged that Globe24h.com collected, used, and disclosed their personal information without consent by republishing Canadian court and tribunal decisions and charging for removal. The OPC had previously investigated similar complaints against Globe24h.com and found them to be well-founded. Despite this, additional complaints continued to be received. The OPC decided to discontinue these new complaints under paragraph 12.2(1)(e) of PIPEDA, as the matter had already been the subject of a Commissioner's report. The OPC noted its continued interest in Globe24h.com's compliance and later participated in a Federal Court proceeding initiated by one of the original complainants. The Federal Court ultimately confirmed the OPC's findings and ordered Globe24h.com to remove the information and cease contravening PIPEDA, leading to the website's closure.

Key Issues
  • Whether Globe24h.com collected, used, and disclosed personal information without consent
  • Whether the Commissioner should discontinue investigation of additional complaints when the matter has already been reported on
  • Whether the practices of Globe24h.com contravened PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 29, 2015Indexed Jun 30, 2026

Disclosure to Interpol raises concerns regarding electronic transmission of personal information

Canada Border Services Agency

The complainant alleged that the Canada Border Services Agency (CBSA) improperly disclosed his personal information, including a judgment from his country of origin, to the High Commission of Canada in Ghana and subsequently to Interpol, without his consent. This disclosure occurred during the verification of documents submitted for his refugee claim, which alleged persecution by the Nigerian government. The CBSA argued the disclosure was a consistent use under the Privacy Act for refugee determination and enforcement of the IRPA, necessary to verify the authenticity of the judgment after other documents were found fraudulent. The OPC found that the disclosure itself was permitted under paragraph 8(2)(a) of the Privacy Act as a consistent use for refugee determination purposes, thus concluding the primary complaint was "not well-founded." However, the OPC raised significant concerns regarding the CBSA's lack of established procedures for such verifications at the time, and the use of insecure commercial email (Yahoo!) for transmitting sensitive personal information of a refugee claimant. The OPC emphasized the inherent sensitivity of such information and the potential risk to claimants, recommending that CBSA review and strengthen its procedures, particularly concerning secure transmission methods and training. The OPC also noted it lacked jurisdiction over the actions of Interpol or Nigerian authorities.

Quick view

Privacy ActWell-founded

Disclosure to Interpol raises concerns regarding electronic transmission of personal information

Apr 29, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) improperly disclosed his personal information, including a judgment from his country of origin, to the High Commission of Canada in Ghana and subsequently to Interpol, without his consent. This disclosure occurred during the verification of documents submitted for his refugee claim, which alleged persecution by the Nigerian government. The CBSA argued the disclosure was a consistent use under the Privacy Act for refugee determination and enforcement of the IRPA, necessary to verify the authenticity of the judgment after other documents were found fraudulent. The OPC found that the disclosure itself was permitted under paragraph 8(2)(a) of the Privacy Act as a consistent use for refugee determination purposes, thus concluding the primary complaint was "not well-founded." However, the OPC raised significant concerns regarding the CBSA's lack of established procedures for such verifications at the time, and the use of insecure commercial email (Yahoo!) for transmitting sensitive personal information of a refugee claimant. The OPC emphasized the inherent sensitivity of such information and the potential risk to claimants, recommending that CBSA review and strengthen its procedures, particularly concerning secure transmission methods and training. The OPC also noted it lacked jurisdiction over the actions of Interpol or Nigerian authorities.

Key Issues
  • Whether the disclosure of the complainant's personal information (including the Judgment) by CBSA to the High Commission and Interpol without consent contravened section 8 of the Privacy Act.
  • Whether the disclosure was for a purpose consistent with the original collection under paragraph 8(2)(a) of the Privacy Act.
  • Whether CBSA's procedures for verifying documents with countries of origin and Interpol were sufficient at the time of disclosure.
  • Whether the electronic transmission of personal information via commercial email (Yahoo!) was secure and appropriate given the sensitivity.
  • Whether the OPC had jurisdiction over alleged secondary disclosures by Interpol or Nigerian authorities.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 16, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – Public Services and Procurement Canada

Public Services and Procurement Canada (PSPC)

An individual complained that Public Services and Procurement Canada (PSPC) mishandled her personal information by disclosing that she had filed a harassment complaint against her Director. The complainant alleged that the Director revealed this information during a management meeting. The investigation confirmed that the Director disclosed at a management meeting that the complainant had filed a complaint against her, as evidenced by meeting notes and confirmations from attendees. While the Director claimed the information was also her personal information, the OPC found no evidence that the employees present at the meeting needed to know the complainant's identity. The OPC concluded that PSPC did not reasonably consider the appropriateness of disclosing the complainant's identity without her consent, violating the Privacy Act.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – Public Services and Procurement Canada

Apr 16, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Public Services and Procurement Canada (PSPC) mishandled her personal information by disclosing that she had filed a harassment complaint against her Director. The complainant alleged that the Director revealed this information during a management meeting. The investigation confirmed that the Director disclosed at a management meeting that the complainant had filed a complaint against her, as evidenced by meeting notes and confirmations from attendees. While the Director claimed the information was also her personal information, the OPC found no evidence that the employees present at the meeting needed to know the complainant's identity. The OPC concluded that PSPC did not reasonably consider the appropriateness of disclosing the complainant's identity without her consent, violating the Privacy Act.

Key Issues
  • Whether the disclosure of the complainant's identity as having filed a harassment complaint constituted personal information under s.3 of the Privacy Act
  • Whether the disclosure of the complainant's identity was made without her consent
  • Whether the disclosure was for a purpose consistent with the purpose for which the information was obtained or compiled, as per s.8(2)(a) of the Privacy Act
  • Whether the employees present at the meeting needed to know the complainant's identity
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 3, 2015Indexed Jun 30, 2026

Accidental disclosure by Health Canada - March 3, 2015

Health Canada

The Office of the Privacy Commissioner (OPC) initiated a complaint against Health Canada (HC) after HC sent 41,514 letters to "Marihuana Medical Access Program" (MMAP) clients in windowed envelopes that allowed the program name to be openly visible. The OPC also received 339 individual complaints regarding this incident. Complainants were concerned that the visible program name revealed their association with MMAP to Canada Post employees and the public, potentially impacting their careers, reputation, and safety due to the stigma associated with marihuana. HC argued that the disclosure was implicitly consented to, was a consistent use of information, or was not an unlawful disclosure by HC. The OPC found that the combination of the MMAP name and the individual's name and address constituted sensitive personal information. HC failed to demonstrate appropriate consent or that any permissible disclosures under section 8(2) of the Privacy Act applied. The OPC concluded that HC contravened the Privacy Act.

Quick view

Privacy ActWell-founded

Accidental disclosure by Health Canada - March 3, 2015

Mar 3, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) initiated a complaint against Health Canada (HC) after HC sent 41,514 letters to "Marihuana Medical Access Program" (MMAP) clients in windowed envelopes that allowed the program name to be openly visible. The OPC also received 339 individual complaints regarding this incident. Complainants were concerned that the visible program name revealed their association with MMAP to Canada Post employees and the public, potentially impacting their careers, reputation, and safety due to the stigma associated with marihuana. HC argued that the disclosure was implicitly consented to, was a consistent use of information, or was not an unlawful disclosure by HC. The OPC found that the combination of the MMAP name and the individual's name and address constituted sensitive personal information. HC failed to demonstrate appropriate consent or that any permissible disclosures under section 8(2) of the Privacy Act applied. The OPC concluded that HC contravened the Privacy Act.

Key Issues
  • Whether the phrase "Marihuana Medical Access Program" combined with an individual's name and address constitutes personal information under section 3 of the Privacy Act
  • Whether subsequent actions by individuals (e.g., media communication) alter Health Canada's obligations under the Privacy Act
  • Whether mail recipients implicitly consented to the disclosure of their personal information under section 8(1) of the Privacy Act
  • Whether the disclosure was a "consistent use" under section 8(2)(a) of the Privacy Act
  • Whether limiting information on return address blocks would have broad implications for government communication
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 10, 2015Indexed Jun 30, 2026

Records deemed 'transitory' prematurely destroyed - February 10, 2015

Department of National Defence (DND)

A former Canadian Forces member complained that the Department of National Defence (DND) prematurely destroyed an audio recording of his Progress Review Board (PRB) hearing, thereby contravening the retention and disposal provisions of the Privacy Act. The complainant argued that the recording was personal information used for an administrative purpose and should have been retained for a reasonable period to allow him access. DND contended the recording was a "transitory" record, destroyed after minutes were drafted, and that the complainant had implicitly consented to its disposal by signing the minutes. The OPC found that the audio recording contained personal information used for an administrative purpose and that the complainant had not consented to its disposal. Therefore, DND was obligated to retain the recording for at least two years.

Quick view

Privacy ActWell-founded

Records deemed 'transitory' prematurely destroyed - February 10, 2015

Feb 10, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

A former Canadian Forces member complained that the Department of National Defence (DND) prematurely destroyed an audio recording of his Progress Review Board (PRB) hearing, thereby contravening the retention and disposal provisions of the Privacy Act. The complainant argued that the recording was personal information used for an administrative purpose and should have been retained for a reasonable period to allow him access. DND contended the recording was a "transitory" record, destroyed after minutes were drafted, and that the complainant had implicitly consented to its disposal by signing the minutes. The OPC found that the audio recording contained personal information used for an administrative purpose and that the complainant had not consented to its disposal. Therefore, DND was obligated to retain the recording for at least two years.

Key Issues
  • Whether the audio recording contained the complainant's "personal information" as defined by the Act
  • Whether the personal information in the audio recording was used for an "administrative purpose"
  • Whether the complainant consented to the disposal of the information
  • Whether DND's classification of the recording as "transitory" exempted it from Privacy Act retention requirements
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 3, 2014Indexed Jun 30, 2026

Canada Revenue Agency and the Canadian Broadcasting Corporation (CRA) - 2015

Canada Revenue Agency

The Canada Revenue Agency (CRA) inadvertently mailed the personal information of approximately 1,000 individuals to a Canadian Broadcasting Corporation (CBC) journalist. This occurred due to an ATIP clerk mistakenly switching cover letters for two different response packages. The disclosed information included names, addresses, and details of donations. The CBC refused the CRA's requests to return the information, leading the CRA to initiate legal action. The OPC found that the CRA disclosed personal information without consent, contravening the Privacy Act. While the OPC noted the CRA's immediate remedial actions and action plan, it concluded that the disclosure did not meet the requirements of the Act.

Quick view

Privacy ActWell-founded

Canada Revenue Agency and the Canadian Broadcasting Corporation (CRA) - 2015

Dec 3, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

The Canada Revenue Agency (CRA) inadvertently mailed the personal information of approximately 1,000 individuals to a Canadian Broadcasting Corporation (CBC) journalist. This occurred due to an ATIP clerk mistakenly switching cover letters for two different response packages. The disclosed information included names, addresses, and details of donations. The CBC refused the CRA's requests to return the information, leading the CRA to initiate legal action. The OPC found that the CRA disclosed personal information without consent, contravening the Privacy Act. While the OPC noted the CRA's immediate remedial actions and action plan, it concluded that the disclosure did not meet the requirements of the Act.

Key Issues
  • Whether the inadvertent mailing of personal information to a journalist constituted a disclosure without consent under the Privacy Act
  • Whether the information disclosed was 'personal information' as defined by section 3 of the Privacy Act
  • Whether the disclosure met the requirements of section 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2014Indexed Jun 30, 2026

Collection of RCMP member's health information unnecessary (RCMP) - November 17, 2014

Royal Canadian Mounted Police (RCMP)

A former RCMP member complained that the RCMP inappropriately collected her personal medical and financial information from Veterans Affairs Canada (VAC) after she was awarded a disability pension. The complainant alleged that the RCMP's National Compensation Policy Centre had no need for this sensitive information. The OPC found that the 2002 Memorandum of Understanding (MOU) between the RCMP and VAC transferred responsibility for pension administration to VAC, meaning the RCMP's National Compensation Policy Centre did not require the detailed medical diagnosis or financial information. The OPC concluded that the collection of this information by the RCMP was not for a purpose consistent with section 4 of the Privacy Act. The complaint was found to be well-founded, and the OPC recommended updating the MOU and reviewing RCMP's internal policies on access to medical records.

Quick view

Privacy ActWell-founded

Collection of RCMP member's health information unnecessary (RCMP) - November 17, 2014

Nov 17, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A former RCMP member complained that the RCMP inappropriately collected her personal medical and financial information from Veterans Affairs Canada (VAC) after she was awarded a disability pension. The complainant alleged that the RCMP's National Compensation Policy Centre had no need for this sensitive information. The OPC found that the 2002 Memorandum of Understanding (MOU) between the RCMP and VAC transferred responsibility for pension administration to VAC, meaning the RCMP's National Compensation Policy Centre did not require the detailed medical diagnosis or financial information. The OPC concluded that the collection of this information by the RCMP was not for a purpose consistent with section 4 of the Privacy Act. The complaint was found to be well-founded, and the OPC recommended updating the MOU and reviewing RCMP's internal policies on access to medical records.

Key Issues
  • Whether the collection of the complainant's financial information by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of the complainant's medical diagnosis/pensioned disability by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of the complainant's disability percentage by the RCMP was necessary and related directly to an operating program or activity under section 4 of the Privacy Act
  • Whether the collection of personal information by the RCMP's National Compensation Policy Centre was consistent with the RCMP's own internal policies restricting access to sensitive medical information
  • Whether the MOU between VAC and the RCMP adequately addressed information sharing practices for sensitive personal information
Decisions | Condita Research