The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

358 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 30, 2011Commissioner’s Findings - PIPEDA Report of Findings #2011-011Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2011-011: Public opinion research firm must better inform survey respondents about their personal information use; refrain from collecting full birth dates

A public opinion research firm

A complainant alleged that a public opinion research firm unnecessarily collected her full date of birth and failed to adequately inform her about the purpose of a profiling survey. The firm collected full birth dates for demographic purposes and to verify identity, arguing that month and year alone were insufficient. The OPC found that collecting the full date of birth was not necessary for the firm's stated purposes and that the consent language for profiling surveys was not sufficiently clear. While the firm agreed to clarify its consent language, it refused to stop collecting or delete the day of birth from its records. Consequently, the OPC found the complaint well-founded but partially unresolved regarding the collection of full birth dates.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Commissioner’s Findings - PIPEDA Report of Findings #2011-011: Public opinion research firm must better inform survey respondents about their personal information use; refrain from collecting full birth dates

Jun 30, 2011Commissioner’s Findings - PIPEDA Report of Findings #2011-011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a public opinion research firm unnecessarily collected her full date of birth and failed to adequately inform her about the purpose of a profiling survey. The firm collected full birth dates for demographic purposes and to verify identity, arguing that month and year alone were insufficient. The OPC found that collecting the full date of birth was not necessary for the firm's stated purposes and that the consent language for profiling surveys was not sufficiently clear. While the firm agreed to clarify its consent language, it refused to stop collecting or delete the day of birth from its records. Consequently, the OPC found the complaint well-founded but partially unresolved regarding the collection of full birth dates.

Key Issues
  • Whether it is necessary for the Respondent to collect all three elements of the date of birth at registration
  • Whether it is necessary for the Respondent to confirm all three elements of the date of birth in profiling surveys
  • Whether the Respondent adequately informed the complainant of the purpose of the profiling survey
  • Whether consent under Principle 4.3 was meaningful
  • Whether the collection of personal information was limited to that which is necessary for the identified purposes under Principle 4.4
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 6, 2010Indexed Jun 30, 2026

Veteran’s complaint highlights significant privacy issues - October 6, 2010

Veterans Affairs Canada

A veteran complained that Veterans Affairs Canada (VAC) inappropriately used his personal information by including excessive medical details in briefing notes for the Minister and by transferring his medical file to a hospital without consent. The OPC investigation found that briefing notes contained sensitive medical information far beyond what was necessary for their stated purpose and that this information was widely shared within VAC on a non-need-to-know basis. It also found that VAC transferred the complainant's medical file to a hospital it administered without obtaining his consent, despite departmental guidelines requiring it. The OPC concluded that VAC's actions violated section 7 of the Privacy Act, which governs the use of personal information. The complaint was found to be well-founded, and the OPC issued several recommendations to VAC, including developing an enhanced privacy policy framework, revising information-management practices, providing employee training, and reviewing consent procedures for information transfers.

Quick view

Privacy ActWell-founded

Veteran’s complaint highlights significant privacy issues - October 6, 2010

Oct 6, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A veteran complained that Veterans Affairs Canada (VAC) inappropriately used his personal information by including excessive medical details in briefing notes for the Minister and by transferring his medical file to a hospital without consent. The OPC investigation found that briefing notes contained sensitive medical information far beyond what was necessary for their stated purpose and that this information was widely shared within VAC on a non-need-to-know basis. It also found that VAC transferred the complainant's medical file to a hospital it administered without obtaining his consent, despite departmental guidelines requiring it. The OPC concluded that VAC's actions violated section 7 of the Privacy Act, which governs the use of personal information. The complaint was found to be well-founded, and the OPC issued several recommendations to VAC, including developing an enhanced privacy policy framework, revising information-management practices, providing employee training, and reviewing consent procedures for information transfers.

Key Issues
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by including excessive medical details in briefing notes for the Minister.
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by widely sharing sensitive personal information within the department on a non-need-to-know basis.
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by transferring his medical file to a hospital without obtaining his consent.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Toronto Port Authority worker misuses personal data for political fundraiser

Toronto Port Authority

A Member of Parliament complained that an employee of the Toronto Port Authority (TPA) misused the organization's email database to invite people to a political fundraising event. The investigation found that a TPA employee sent an email to approximately 60 people, soliciting donations and inviting participation in a fundraiser for another MP. The employee obtained these email addresses from business cards collected by the TPA, including both business and personal addresses. The OPC determined that the employee used this personal information without the TPA's knowledge or authorization and for reasons unrelated to the organization's business activities. The complaint was found to be well-founded, but the TPA took corrective measures, including reminding employees of their responsibilities and pledging Privacy Act training.

Quick view

Privacy ActWell-founded

Toronto Port Authority worker misuses personal data for political fundraiser

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A Member of Parliament complained that an employee of the Toronto Port Authority (TPA) misused the organization's email database to invite people to a political fundraising event. The investigation found that a TPA employee sent an email to approximately 60 people, soliciting donations and inviting participation in a fundraiser for another MP. The employee obtained these email addresses from business cards collected by the TPA, including both business and personal addresses. The OPC determined that the employee used this personal information without the TPA's knowledge or authorization and for reasons unrelated to the organization's business activities. The complaint was found to be well-founded, but the TPA took corrective measures, including reminding employees of their responsibilities and pledging Privacy Act training.

Key Issues
  • Whether a Toronto Port Authority employee misused personal information for a political fundraiser
  • Whether email addresses obtained from business cards constitute personal information
  • Whether the use of personal information was without the knowledge or authorization of the institution
  • Whether the use of personal information was for reasons unrelated to the organization's business activities
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Mechanical malfunction, compounded by human error, leads to data spill

Human Resources and Skills Development Canada

In March 2009, Human Resources and Skills Development Canada (HRSDC) mailed 11,900 forms for the Guaranteed Income Supplement. Due to a mechanical malfunction and human error, some individuals received forms intended for others, containing names, addresses, and Social Insurance Numbers (SINs). The OPC initiated a complaint after HRSDC notified them of 44 reported cases of mix-ups. The investigation found that a technician failed to stop the mailing despite noticing errors and did not report the issue to management. The OPC determined the complaint was well-founded, highlighting both mechanical failure and human error. HRSDC conducted its own investigation, improved equipment, and strengthened quality control procedures. The OPC recommended better employee sensitization to privacy obligations, which HRSDC committed to implementing.

Quick view

Privacy ActWell-founded

Mechanical malfunction, compounded by human error, leads to data spill

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

In March 2009, Human Resources and Skills Development Canada (HRSDC) mailed 11,900 forms for the Guaranteed Income Supplement. Due to a mechanical malfunction and human error, some individuals received forms intended for others, containing names, addresses, and Social Insurance Numbers (SINs). The OPC initiated a complaint after HRSDC notified them of 44 reported cases of mix-ups. The investigation found that a technician failed to stop the mailing despite noticing errors and did not report the issue to management. The OPC determined the complaint was well-founded, highlighting both mechanical failure and human error. HRSDC conducted its own investigation, improved equipment, and strengthened quality control procedures. The OPC recommended better employee sensitization to privacy obligations, which HRSDC committed to implementing.

Key Issues
  • Whether personal information was inappropriately disclosed due to mechanical malfunction
  • Whether personal information was inappropriately disclosed due to human error
  • Whether the institution adequately safeguarded personal information during mass mailings
  • Whether employees were sufficiently sensitized to their obligations to safeguard personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Personal data of 191 EI claimants disclosed

Human Resources and Skills Development Canada

The Office of the Privacy Commissioner of Canada (OPC) received 82 complaints after Human Resources and Skills Development Canada (HRSDC) inadvertently disclosed the personal information of 191 Employment Insurance (EI) claimants to another individual. The disclosure occurred when an individual appealing an EI claim denial received an appeal docket that included names, dates of birth, employee identification numbers, and Social Insurance Numbers of 191 fellow employees, along with a second list of employment and leave statuses. The OPC's investigation confirmed that in 79 instances, the information was indeed released, leading to well-founded findings. HRSDC took immediate steps to retrieve the data, notify affected parties, and advise on identity theft prevention. They also implemented measures to prevent future recurrences, including reminding officials of proper procedures for protecting personal information during appeals.

Quick view

Privacy ActWell-founded

Personal data of 191 EI claimants disclosed

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) received 82 complaints after Human Resources and Skills Development Canada (HRSDC) inadvertently disclosed the personal information of 191 Employment Insurance (EI) claimants to another individual. The disclosure occurred when an individual appealing an EI claim denial received an appeal docket that included names, dates of birth, employee identification numbers, and Social Insurance Numbers of 191 fellow employees, along with a second list of employment and leave statuses. The OPC's investigation confirmed that in 79 instances, the information was indeed released, leading to well-founded findings. HRSDC took immediate steps to retrieve the data, notify affected parties, and advise on identity theft prevention. They also implemented measures to prevent future recurrences, including reminding officials of proper procedures for protecting personal information during appeals.

Key Issues
  • Whether Human Resources and Skills Development Canada inadvertently disclosed personal information of EI claimants
  • Whether the disclosure of names, dates of birth, employee identification numbers, and Social Insurance Numbers constituted a contravention of the Privacy Act
  • Whether the disclosure of employment and leave status constituted a contravention of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Internet posting highlights inappropriate access to tax records by CRA workers

Canada Revenue Agency (CRA)

The Commissioner initiated an investigation following media allegations that a Canada Revenue Agency (CRA) employee posted personal tax information of high-profile sports figures to an Internet chat group. The investigation confirmed that a former CRA employee had posted such information, and that other CRA employees had inappropriately accessed the tax information of these athletes, likely out of curiosity. While there was no evidence that these employees disclosed the information to outside sources, accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act. Consequently, the portion of the complaint concerning the improper use of personal information by CRA employees was found to be well-founded. The CRA took corrective measures, including suspending one employee, firing two others, and modernizing its audit trail system to monitor access to taxpayer information.

Quick view

Privacy ActWell-founded

Internet posting highlights inappropriate access to tax records by CRA workers

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Commissioner initiated an investigation following media allegations that a Canada Revenue Agency (CRA) employee posted personal tax information of high-profile sports figures to an Internet chat group. The investigation confirmed that a former CRA employee had posted such information, and that other CRA employees had inappropriately accessed the tax information of these athletes, likely out of curiosity. While there was no evidence that these employees disclosed the information to outside sources, accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act. Consequently, the portion of the complaint concerning the improper use of personal information by CRA employees was found to be well-founded. The CRA took corrective measures, including suspending one employee, firing two others, and modernizing its audit trail system to monitor access to taxpayer information.

Key Issues
  • Whether CRA employees inappropriately accessed personal tax information
  • Whether CRA employees disclosed personal tax information to outside sources
  • Whether accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 6, 2009Indexed Jun 30, 2026

Personal information leaked from DFAIT database

Department of Foreign Affairs and International Trade (DFAIT)

The OPC investigated a complaint regarding the leak of a Canadian citizen's personal information from a DFAIT database, which was reported in the media in spring 2008. The investigation confirmed the information was held in an official consular record within DFAIT's computer system. A significant concern was that 1,231 DFAIT employees had access to these files, and the system lacked audit trail capabilities or mechanisms to restrict access to specific records. Consequently, the OPC could not identify the source of the leak. The complaint was found to be well-founded, and DFAIT agreed to implement corrective measures.

Quick view

Privacy ActWell-founded

Personal information leaked from DFAIT database

Oct 6, 2009
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated a complaint regarding the leak of a Canadian citizen's personal information from a DFAIT database, which was reported in the media in spring 2008. The investigation confirmed the information was held in an official consular record within DFAIT's computer system. A significant concern was that 1,231 DFAIT employees had access to these files, and the system lacked audit trail capabilities or mechanisms to restrict access to specific records. Consequently, the OPC could not identify the source of the leak. The complaint was found to be well-founded, and DFAIT agreed to implement corrective measures.

Key Issues
  • Whether personal information was leaked from a DFAIT database
  • Whether DFAIT's security safeguards were adequate to protect personal information
  • Whether DFAIT's computer system had sufficient audit trail capabilities
  • Whether DFAIT's computer system had mechanisms to restrict access to particular files
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jul 27, 2009Report of FindingsIndexed Jun 30, 2026

Report of Findings: Complaint under PIPEDA against Accusearch Inc., doing business as Abika.com

Accusearch Inc., doing business as Abika.com

CIPPIC complained that Abika.com, a U.S. company, collected, used, and disclosed Canadians' personal information without consent, compiled and disclosed inaccurate personal information through its "psychological profile" service, and used personal information for inappropriate purposes. The OPC initially declined jurisdiction, but the Federal Court ordered the investigation to proceed. The OPC found that Abika collected and disclosed personal information, including telephone records, of Canadians without their knowledge or consent, often for inappropriate purposes such as investigating partners. While the OPC found the accuracy complaint not well-founded due to lack of verifiable evidence, it concluded that Abika contravened PIPEDA Principles 4.3 and subsection 5(3). Abika failed to respond adequately to the OPC's recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Report of Findings: Complaint under PIPEDA against Accusearch Inc., doing business as Abika.com

Jul 27, 2009Report of Findings
Adjudicator: Jennifer Stoddart
Plain-Language Summary

CIPPIC complained that Abika.com, a U.S. company, collected, used, and disclosed Canadians' personal information without consent, compiled and disclosed inaccurate personal information through its "psychological profile" service, and used personal information for inappropriate purposes. The OPC initially declined jurisdiction, but the Federal Court ordered the investigation to proceed. The OPC found that Abika collected and disclosed personal information, including telephone records, of Canadians without their knowledge or consent, often for inappropriate purposes such as investigating partners. While the OPC found the accuracy complaint not well-founded due to lack of verifiable evidence, it concluded that Abika contravened PIPEDA Principles 4.3 and subsection 5(3). Abika failed to respond adequately to the OPC's recommendations.

Key Issues
  • Whether Abika collected, used, and disclosed personal information of individuals living in Canada without their knowledge and consent, in contravention of Principle 4.3
  • Whether Abika compiled and disclosed inaccurate personal information through its "psychological profile" service, in contravention of Principle 4.6
  • Whether Abika collected, used, and disclosed personal information about Canadians for inappropriate purposes, in contravention of subsection 5(3)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
May 29, 2008Executive SummaryIndexed Jun 30, 2026

Executive Summary: Law School Admission Council Investigation

Law School Admission Council (LSAC)

A complainant objected to the Law School Admission Council's (LSAC) requirement for Canadian students to provide fingerprints to write the Law School Admission Test (LSAT). LSAC, a US-based non-profit, argued it was outside PIPEDA's jurisdiction and its activities were educational. The Assistant Privacy Commissioner found sufficient links to Canada for PIPEDA to apply and determined LSAC's activities were administrative, not educational. Applying a four-part test, the Assistant Commissioner found fingerprinting was not demonstrably necessary, effective, or proportional, and less privacy-invasive alternatives existed. LSAC agreed to cease fingerprint collection but reserved the right to reinstate it, proposing photographic evidence instead. The Assistant Commissioner found the complaint well-founded due to the disproportionate nature of fingerprint collection and LSAC's reservation to reinstate the policy.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Executive Summary: Law School Admission Council Investigation

May 29, 2008Executive Summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant objected to the Law School Admission Council's (LSAC) requirement for Canadian students to provide fingerprints to write the Law School Admission Test (LSAT). LSAC, a US-based non-profit, argued it was outside PIPEDA's jurisdiction and its activities were educational. The Assistant Privacy Commissioner found sufficient links to Canada for PIPEDA to apply and determined LSAC's activities were administrative, not educational. Applying a four-part test, the Assistant Commissioner found fingerprinting was not demonstrably necessary, effective, or proportional, and less privacy-invasive alternatives existed. LSAC agreed to cease fingerprint collection but reserved the right to reinstate it, proposing photographic evidence instead. The Assistant Commissioner found the complaint well-founded due to the disproportionate nature of fingerprint collection and LSAC's reservation to reinstate the policy.

Key Issues
  • Whether LSAC's activities fall within the scope of PIPEDA despite its non-profit status and US location
  • Whether LSAC's activities are educational in nature or serve administrative needs
  • Whether the collection of thumbprints is demonstrably necessary to meet a specific need
  • Whether the collection of thumbprints is likely to be effective in meeting that need
  • Whether the loss of privacy from thumbprint collection is proportional to the benefit gained
  • Whether there is a less privacy-invasive way of achieving the same end as thumbprint collection
  • Whether the collection of photographs as an alternative is acceptable under PIPEDA
  • Whether LSAC's reservation of the right to reinstate its fingerprint policy is compliant with PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Feb 12, 2008BackgrounderIndexed Jun 30, 2026

Backgrounder: Ticketmaster Investigation

Ticketmaster Canada Limited

The OPC investigated Ticketmaster Canada Limited (TM) following a complaint that its practices for collecting, disclosing, and using customer personal information for marketing purposes did not comply with PIPEDA. The complainant alleged that customers were not properly informed or given a viable alternative to sharing their information for marketing. The Assistant Privacy Commissioner found that TM failed to uphold the principles of openness and consent. TM subsequently revised its privacy policy and online notifications to explicitly communicate information sharing practices and provide clear opt-in options for marketing. The investigation concluded that the issues were resolved satisfactorily, but the Assistant Commissioner expressed concern about the well-founded violations several years after PIPEDA's enactment.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Backgrounder: Ticketmaster Investigation

Feb 12, 2008Backgrounder
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated Ticketmaster Canada Limited (TM) following a complaint that its practices for collecting, disclosing, and using customer personal information for marketing purposes did not comply with PIPEDA. The complainant alleged that customers were not properly informed or given a viable alternative to sharing their information for marketing. The Assistant Privacy Commissioner found that TM failed to uphold the principles of openness and consent. TM subsequently revised its privacy policy and online notifications to explicitly communicate information sharing practices and provide clear opt-in options for marketing. The investigation concluded that the issues were resolved satisfactorily, but the Assistant Commissioner expressed concern about the well-founded violations several years after PIPEDA's enactment.

Key Issues
  • Whether Ticketmaster's privacy policy met the openness principle of PIPEDA
  • Whether Ticketmaster obtained valid consent for the use of personal information for marketing purposes
  • Whether customers were properly informed about the use of their personal information for marketing
  • Whether customers were provided a viable opt-in/opt-out option for marketing without penalty
  • Whether Ticketmaster's agreements with event providers ensured compliance with customer preferences
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Nov 7, 2003PIPEDA Case Summary #2003-244Indexed Jun 30, 2026

PIPEDA Case Summary #2003-244 — Telecommunications company "A"

Telecommunications company "A"

An individual complained that a telecommunications company failed to obtain proper consent for the collection, use, and disclosure of personal information for secondary marketing purposes. The complainant alleged that the company did not adequately inform customers of these practices or provide an easy opt-out mechanism. The investigation found that while the company had a privacy policy available online and in booklets, it did not actively bring these practices to the attention of new customers during the service application process. The Assistant Commissioner determined that the company's practices did not meet the reasonable expectations of its customers and thus contravened several PIPEDA principles. The complaint was found to be well-founded, and the Assistant Commissioner recommended that the company draw customers' attention to its privacy policy and options at the time of collection.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Case Summary #2003-244 — Telecommunications company "A"

Nov 7, 2003PIPEDA Case Summary #2003-244
Adjudicator: Robert Marleau
Plain-Language Summary

An individual complained that a telecommunications company failed to obtain proper consent for the collection, use, and disclosure of personal information for secondary marketing purposes. The complainant alleged that the company did not adequately inform customers of these practices or provide an easy opt-out mechanism. The investigation found that while the company had a privacy policy available online and in booklets, it did not actively bring these practices to the attention of new customers during the service application process. The Assistant Commissioner determined that the company's practices did not meet the reasonable expectations of its customers and thus contravened several PIPEDA principles. The complaint was found to be well-founded, and the Assistant Commissioner recommended that the company draw customers' attention to its privacy policy and options at the time of collection.

Key Issues
  • Whether the telecommunications company obtained adequate knowledge and consent for secondary marketing purposes under Principle 4.3
  • Whether the company specified identified purposes at or before the time of collection under Principle 4.2.3
  • Whether the company made reasonable efforts to ensure individuals were advised of the purposes for which information would be used, as required by Principle 4.3.2
  • Whether the company's consent practices met the reasonable expectations of the individual under Principle 4.3.5
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 25, 2002Indexed Jun 30, 2026

Privacy Commissioner's finding on Canada Post's National Change of Address service - February 25, 2002

Canada Post

The Privacy Commissioner investigated a complaint regarding Canada Post's National Change of Address (NCOA) service. The service allowed individuals to redirect mail and, with an opt-out clause in fine print, permitted Canada Post to supply new addresses to "mailers" for a fee. The Commissioner found that Canada Post failed to clearly inform customers that their personal information was being sold to organizations like list brokers and direct marketers, and that the consent obtained was not meaningful. Canada Post refused to implement a recommendation for an opt-in checkbox for this disclosure. The Commissioner concluded that Canada Post was in contravention of sections 5(2) and 8 of the Privacy Act for failing to plainly identify the purpose of collection and for disclosing personal information without proper consent.

Quick view

Privacy ActWell-founded

Privacy Commissioner's finding on Canada Post's National Change of Address service - February 25, 2002

Feb 25, 2002
Adjudicator: George Radwanski
Plain-Language Summary

The Privacy Commissioner investigated a complaint regarding Canada Post's National Change of Address (NCOA) service. The service allowed individuals to redirect mail and, with an opt-out clause in fine print, permitted Canada Post to supply new addresses to "mailers" for a fee. The Commissioner found that Canada Post failed to clearly inform customers that their personal information was being sold to organizations like list brokers and direct marketers, and that the consent obtained was not meaningful. Canada Post refused to implement a recommendation for an opt-in checkbox for this disclosure. The Commissioner concluded that Canada Post was in contravention of sections 5(2) and 8 of the Privacy Act for failing to plainly identify the purpose of collection and for disclosing personal information without proper consent.

Key Issues
  • Whether Canada Post adequately informed individuals about the purpose of collecting their new address information for the NCOA service, specifically regarding disclosure to "mailers" for commercial purposes under s.5(2) of the Privacy Act
  • Whether Canada Post obtained valid consent for the disclosure of new addresses to mass mailers and direct marketers under s.8 of the Privacy Act
  • Whether the "opt-out" mechanism used by Canada Post constituted meaningful consent
  • Whether the safeguard of only providing new addresses to mailers who already had the customer's name and old address adequately addressed consent concerns
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 15, 2001Indexed Jun 30, 2026

Letter of finding regarding the video surveillance issue

Centurion Security Services Co. Ltd.

The federal Privacy Commissioner investigated a complaint regarding Centurion Security Services' installation of surveillance cameras at a downtown Yellowknife intersection. The Commissioner found that both live and recorded video images of individuals constitute "personal information" under PIPEDA. Centurion Security Services, a private company, was monitoring public spaces for commercial purposes without the consent of individuals, which contravened Principle 4.3 of Schedule 1 and section 5(1) of the Act. Although the cameras were removed before the complaint was received, the Commissioner concluded that Centurion's intended future public video surveillance for commercial purposes would also be unlawful. The complaint was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Letter of finding regarding the video surveillance issue

Jun 15, 2001
Adjudicator: George Radwanski
Plain-Language Summary

The federal Privacy Commissioner investigated a complaint regarding Centurion Security Services' installation of surveillance cameras at a downtown Yellowknife intersection. The Commissioner found that both live and recorded video images of individuals constitute "personal information" under PIPEDA. Centurion Security Services, a private company, was monitoring public spaces for commercial purposes without the consent of individuals, which contravened Principle 4.3 of Schedule 1 and section 5(1) of the Act. Although the cameras were removed before the complaint was received, the Commissioner concluded that Centurion's intended future public video surveillance for commercial purposes would also be unlawful. The complaint was found to be well-founded.

Key Issues
  • Whether the subject matter falls within the Commissioner's jurisdiction under PIPEDA
  • Whether live video pictures of individuals constitute "personal information" under section 2 of PIPEDA
  • Whether the collection of personal information was in the course of a commercial activity under section 4 of PIPEDA
  • Whether Centurion Security Services collected personal information without consent in contravention of Principle 4.3 of Schedule 1 of PIPEDA
  • Whether the absence of recording (live feed only) affects the classification of information as personal information or the requirement for consent