BreachOfPrivacy

Canadian Privacy Decisions

The comprehensive archive of Canadian privacy decisions from federal, provincial, and territorial commissioners — with AI-summarized plain-language summaries for every decision.

5 decisions matching
Federal (Canada)Privacy ActWell-founded
Oct 6, 2010· Indexed Apr 12, 2026

Veteran’s complaint highlights significant privacy issues - October 6, 2010

Veterans Affairs Canada

A veteran complained that Veterans Affairs Canada (VAC) had inappropriately used and shared his sensitive medical information in briefing notes to the Minister, and had transferred his medical file to a VAC-administered hospital without his consent. The investigation found that the briefing notes contained excessive medical details and that sensitive information was shared widely within VAC without a need-to-know. The transfer of the medical file also occurred without the required consent. The complaint was found to be well-founded.

Quick View

Privacy ActWell-founded

Veteran’s complaint highlights significant privacy issues - October 6, 2010

Oct 6, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A veteran complained that Veterans Affairs Canada (VAC) had inappropriately used and shared his sensitive medical information in briefing notes to the Minister, and had transferred his medical file to a VAC-administered hospital without his consent. The investigation found that the briefing notes contained excessive medical details and that sensitive information was shared widely within VAC without a need-to-know. The transfer of the medical file also occurred without the required consent. The complaint was found to be well-founded.

Key Issues
  • Inappropriate use and disclosure of sensitive medical information in briefing notes.
  • Transfer of personal medical information to a hospital without consent.
  • Failure to limit access to personal information on a need-to-know basis.
  • Compliance with section 7 of the Privacy Act regarding use of personal information.
Federal (Canada)Privacy ActWell-founded
Oct 5, 2010· Indexed Apr 12, 2026

Mechanical malfunction, compounded by human error, leads to data spill

Human Resources and Skills Development Canada

This investigation concerned a data spill involving 11,900 forms mailed to applicants for the Guaranteed Income Supplement. A mechanical malfunction caused some applicants to receive forms destined for other individuals, including names, addresses, and Social Insurance Numbers. Human error by the overseeing technician, who failed to use detection mechanisms and notify management, compounded the issue. The Office found the complaint well-founded and recommended that the department enhance employee awareness of their obligations to protect personal information.

Quick View

Privacy ActWell-founded

Mechanical malfunction, compounded by human error, leads to data spill

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

This investigation concerned a data spill involving 11,900 forms mailed to applicants for the Guaranteed Income Supplement. A mechanical malfunction caused some applicants to receive forms destined for other individuals, including names, addresses, and Social Insurance Numbers. Human error by the overseeing technician, who failed to use detection mechanisms and notify management, compounded the issue. The Office found the complaint well-founded and recommended that the department enhance employee awareness of their obligations to protect personal information.

Key Issues
  • Adequacy of security safeguards for personal information
  • Role of human error in compounding a mechanical defect
  • Reporting obligations of employees regarding privacy breaches
Federal (Canada)Privacy ActWell-founded
Oct 5, 2010· Indexed Apr 12, 2026

Toronto Port Authority worker misuses personal data for political fundraiser

Toronto Port Authority

A Member of Parliament complained that an employee of the Toronto Port Authority used the organization's e-mail database to invite individuals to a political fundraising event. The investigation found that an employee sent an email using personal and business addresses obtained from business cards, soliciting donations. Although recipient addresses were in the BCC field, the employee's signature block indicated they worked for the Authority, implying institutional sanction.

Quick View

Privacy ActWell-founded

Toronto Port Authority worker misuses personal data for political fundraiser

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A Member of Parliament complained that an employee of the Toronto Port Authority used the organization's e-mail database to invite individuals to a political fundraising event. The investigation found that an employee sent an email using personal and business addresses obtained from business cards, soliciting donations. Although recipient addresses were in the BCC field, the employee's signature block indicated they worked for the Authority, implying institutional sanction.

Key Issues
  • Use of institutional database for personal fundraising activities
  • Collection and use of personal information for non-business purposes
  • Impression of institutional sanction for personal activities
Federal (Canada)Privacy ActWell-founded
Oct 5, 2010· Indexed Apr 12, 2026

Internet posting highlights inappropriate access to tax records by CRA workers

Canada Revenue Agency

This investigation was initiated following media reports that a Canada Revenue Agency (CRA) employee posted personal tax information of athletes to an Internet chat group. The OPC found that a former employee did post information, and other CRA employees inappropriately accessed the athletes' tax information out of curiosity, which constituted a breach of the Privacy Act. The CRA took corrective measures, including disciplinary action against employees and modernization of its audit trail system.

Quick View

Privacy ActWell-founded

Internet posting highlights inappropriate access to tax records by CRA workers

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

This investigation was initiated following media reports that a Canada Revenue Agency (CRA) employee posted personal tax information of athletes to an Internet chat group. The OPC found that a former employee did post information, and other CRA employees inappropriately accessed the athletes' tax information out of curiosity, which constituted a breach of the Privacy Act. The CRA took corrective measures, including disciplinary action against employees and modernization of its audit trail system.

Key Issues
  • Unauthorized access to taxpayer information by CRA employees
  • Disclosure of taxpayer information to an external party
  • Adequacy of CRA's corrective measures and audit systems
Federal (Canada)Privacy ActWell-founded
Oct 5, 2010· Indexed Apr 12, 2026

Personal data of 191 EI claimants disclosed

Human Resources and Skills Development Canada

The Office of the Privacy Commissioner of Canada (OPC) received 82 complaints after Human Resources and Skills Development Canada (HRSDC) inadvertently disclosed the personal information of 191 Employment Insurance (EI) claimants. The disclosed information included names, dates of birth, employee identification numbers, and Social Insurance Numbers. HRSDC took immediate steps to retrieve the data, notify affected individuals, and implement preventative measures. The OPC found 79 of the 82 complaints to be well-founded.

Quick View

Privacy ActWell-founded

Personal data of 191 EI claimants disclosed

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) received 82 complaints after Human Resources and Skills Development Canada (HRSDC) inadvertently disclosed the personal information of 191 Employment Insurance (EI) claimants. The disclosed information included names, dates of birth, employee identification numbers, and Social Insurance Numbers. HRSDC took immediate steps to retrieve the data, notify affected individuals, and implement preventative measures. The OPC found 79 of the 82 complaints to be well-founded.

Key Issues
  • Inadvertent disclosure of personal information
  • Adequacy of breach response measures
  • Preventing recurrence of similar breaches
Decisions | BreachOfPrivacy