The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

6 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 11, 2026PIPEDA Findings #2026-004Indexed Jun 30, 2026

PIPEDA Findings #2026-004: Commissioner-initiated complaints concerning X Corp.’s and X.AI LLC’s compliance with PIPEDA

X Corp. and X.AI LLC

The Office of the Privacy Commissioner of Canada (OPC) initiated complaints against X Corp. and X.AI LLC following reports that their AI chatbot, Grok, generated millions of sexualized deepfakes of identifiable individuals. The investigation focused on whether valid consent was obtained for the collection, use, and disclosure of personal information for this purpose, and if such practices were appropriate under PIPEDA. The OPC found that neither company obtained valid consent, noting the sensitive nature of the information, the unreasonableness of individuals' expectations, and the significant risk of harm. Furthermore, the OPC concluded that the generation of sexualized deepfakes was inappropriate, as the loss of privacy and harm far outweighed any benefits, and less privacy-invasive means were available. While the companies implemented some safeguards, the OPC deemed their initial response insufficient and their current measures unproven. Consequently, the matter was found well-founded, with the OPC making several recommendations for improved safeguards, proactive monitoring, and annual third-party audits, while committing to ongoing monitoring.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2026-004: Commissioner-initiated complaints concerning X Corp.’s and X.AI LLC’s compliance with PIPEDA

Jun 11, 2026PIPEDA Findings #2026-004
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated complaints against X Corp. and X.AI LLC following reports that their AI chatbot, Grok, generated millions of sexualized deepfakes of identifiable individuals. The investigation focused on whether valid consent was obtained for the collection, use, and disclosure of personal information for this purpose, and if such practices were appropriate under PIPEDA. The OPC found that neither company obtained valid consent, noting the sensitive nature of the information, the unreasonableness of individuals' expectations, and the significant risk of harm. Furthermore, the OPC concluded that the generation of sexualized deepfakes was inappropriate, as the loss of privacy and harm far outweighed any benefits, and less privacy-invasive means were available. While the companies implemented some safeguards, the OPC deemed their initial response insufficient and their current measures unproven. Consequently, the matter was found well-founded, with the OPC making several recommendations for improved safeguards, proactive monitoring, and annual third-party audits, while committing to ongoing monitoring.

Key Issues
  • Whether PIPEDA applies to X Corp. and X.AI LLC, specifically regarding the existence of a "real and substantial connection" to Canada.
  • Whether deepfakes of identifiable individuals, including sexualized deepfakes, constitute "personal information" under PIPEDA.
  • Whether X Corp. and X.AI LLC obtained valid consent for the collection, use, and disclosure of personal information to generate sexualized deepfakes, as required by Principle 4.3 of PIPEDA.
  • Whether express consent was required for the generation of sexualized deepfakes, considering the sensitivity of the information, individuals' reasonable expectations, and the risk of significant harm (Principle 4.3.4, 4.3.5, and s.6.1 of PIPEDA).
  • Whether X Corp. and X.AI LLC are accountable for ensuring valid consent for content generated by their tools in the course of commercial activity.
  • Whether a reasonable person would consider the collection, use, and disclosure of personal information for the purpose of an image generation service capable of producing sexualized deepfakes to be appropriate in the circumstances, as per subsection 5(3) of PIPEDA.
  • Whether the organizations had a legitimate need or bona fide business interest that extended to providing an image generation tool capable of producing non-consensual sexualized deepfakes.
  • Whether less privacy-invasive means were available to achieve the organizations' purposes at comparable cost and benefits.
  • Whether the loss of privacy and risk of harm associated with sexualized deepfakes were proportionate to the benefits of the practice.
  • Whether X Corp. and X.AI LLC's initial response and implemented safeguards were sufficient and effective in preventing the generation of sexualized deepfakes.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP's collection of personal information via Social Studio complied with Section 4 of the Privacy Act.
  • Whether the RCMP's collection of personal information via Babel X complied with Section 4 of the Privacy Act.
  • Whether the RCMP conducted adequate due diligence on the lawfulness of collection practices of Babel X and its data providers.
  • Whether Section 4 of the Privacy Act permits the collection of personal information from a third-party agent that collected, used, or disclosed the information in contravention of a law that third party is subject to.
  • Whether the RCMP's publicly available descriptions of its open-source information gathering are granular enough to meet transparency obligations under Section 11 of the Privacy Act.
  • Whether the RCMP's published descriptions clarify limits on purposes for collection under Section 11 of the Privacy Act.
  • Whether the RCMP's descriptions of open-source information collection and related purposes are adequate under Section 11 of the Privacy Act.
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 26, 2022Indexed Jun 30, 2026

Access at issue: The challenge of accessing our collective memory

Library and Archives Canada

The Information Commissioner initiated a systemic investigation into Library and Archives Canada's (LAC) delayed responses to access requests. This investigation was prompted by a long-standing trend of LAC failing to meet legislative deadlines for responding to access requests, which worsened during the COVID-19 pandemic. The investigation found that during the period under review, nearly 80% of requests completed by LAC did not comply with the timeframes set out in the Access to Information Act. The Commissioner informed the Minister of Canadian Heritage, as the head of LAC, of these findings and made ten recommendations. A special report was subsequently tabled in Parliament, highlighting issues within LAC and broader challenges in Canada's access to information system, specifically regarding inter-institutional consultations and the absence of a government-wide declassification framework.

Quick view

Access to Information ActWell-founded

Access at issue: The challenge of accessing our collective memory

Apr 26, 2022
Adjudicator: Caroline Maynard
Plain-Language Summary

The Information Commissioner initiated a systemic investigation into Library and Archives Canada's (LAC) delayed responses to access requests. This investigation was prompted by a long-standing trend of LAC failing to meet legislative deadlines for responding to access requests, which worsened during the COVID-19 pandemic. The investigation found that during the period under review, nearly 80% of requests completed by LAC did not comply with the timeframes set out in the Access to Information Act. The Commissioner informed the Minister of Canadian Heritage, as the head of LAC, of these findings and made ten recommendations. A special report was subsequently tabled in Parliament, highlighting issues within LAC and broader challenges in Canada's access to information system, specifically regarding inter-institutional consultations and the absence of a government-wide declassification framework.

Key Issues
  • Whether Library and Archives Canada was responding to access requests within the legislative deadlines
  • Whether the delays in responding to access requests constituted a systemic issue
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Feb 2, 2021PIPEDA Findings #2021-001Indexed Jun 30, 2026

PIPEDA Findings #2021-001: Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta

Clearview AI, Inc.

A joint investigation by Canadian privacy commissioners examined Clearview AI's facial recognition tool, which scraped billions of images from public websites to create a database for law enforcement and other users. Clearview argued that Canadian privacy laws did not apply due to a lack of jurisdiction and that the information was "publicly available," thus exempt from consent requirements. The Offices asserted jurisdiction, finding a real and substantial connection to Canada through Clearview's marketing and use by Canadian entities. They determined Clearview failed to obtain requisite consent, as the "publicly available" exception did not apply to sensitive biometric data scraped from social media for unrelated purposes. Furthermore, Clearview's mass collection and use of sensitive facial biometric information for commercial purposes were deemed inappropriate. In Quebec, Clearview also failed to report its biometric database and obtain express consent as required by law. The matter was found to be well-founded, with recommendations for Clearview to cease operations in Canada and delete Canadian data, which Clearview did not commit to implementing.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2021-001: Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta

Feb 2, 2021PIPEDA Findings #2021-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A joint investigation by Canadian privacy commissioners examined Clearview AI's facial recognition tool, which scraped billions of images from public websites to create a database for law enforcement and other users. Clearview argued that Canadian privacy laws did not apply due to a lack of jurisdiction and that the information was "publicly available," thus exempt from consent requirements. The Offices asserted jurisdiction, finding a real and substantial connection to Canada through Clearview's marketing and use by Canadian entities. They determined Clearview failed to obtain requisite consent, as the "publicly available" exception did not apply to sensitive biometric data scraped from social media for unrelated purposes. Furthermore, Clearview's mass collection and use of sensitive facial biometric information for commercial purposes were deemed inappropriate. In Quebec, Clearview also failed to report its biometric database and obtain express consent as required by law. The matter was found to be well-founded, with recommendations for Clearview to cease operations in Canada and delete Canadian data, which Clearview did not commit to implementing.

Key Issues
  • Whether the Canadian privacy commissioners had jurisdiction over Clearview AI's activities.
  • Whether Clearview AI obtained requisite consent for its collection, use, and disclosure of personal information under PIPEDA, PIPA AB, PIPA BC, and Quebec's Private Sector Act.
  • Whether the "publicly available" information exception applied to Clearview AI's collection of images from public websites.
  • Whether Clearview AI's collection, use, and disclosure of personal information was for an appropriate purpose under PIPEDA, PIPA AB, PIPA BC, and Quebec's Private Sector Act.
  • Whether Clearview AI satisfied its biometric obligations in Quebec, specifically regarding reporting the creation of a biometric database and obtaining express consent under the LCCJTI.
  • Whether Clearview AI's activities were protected by freedom of expression under the Canadian Charter of Rights and Freedoms.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Woman fails in attempt to return personal information to Canada Revenue Agency

Canada Revenue Agency (CRA)

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Quick view

Privacy ActWell-founded

Woman fails in attempt to return personal information to Canada Revenue Agency

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Key Issues
  • Whether the Canada Revenue Agency breached the privacy rights of taxpayers by mistakenly sending confidential personal information to an unauthorized individual
  • Whether the Canada Revenue Agency's procedures for handling misdirected mail and breach reporting were adequate
  • Whether the Canada Revenue Agency's client service channels were accessible for reporting privacy breaches
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2014Indexed Jun 30, 2026

IP54-56/2014 — Employment and Social Development Canada

Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Quick view

Privacy ActWell-founded

IP54-56/2014 — Employment and Social Development Canada

Mar 24, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Key Issues
  • Whether ESDC failed to implement adequate physical security controls for personal information stored on portable media.
  • Whether ESDC failed to implement adequate technical security controls, such as encryption and risk assessments, for personal information on portable media.
  • Whether ESDC failed to implement adequate administrative controls, including asset inventory, information classification, and lifecycle management, for personal information.
  • Whether ESDC failed to implement adequate personnel security controls, such as employee training, awareness, and accountability, regarding personal information.
  • Whether ESDC contravened subsection 6(3) of the Privacy Act by failing to properly dispose of personal information.
  • Whether ESDC contravened section 7 of the Privacy Act regarding the use of personal information.
  • Whether ESDC contravened section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether the delay in notifying affected individuals of the breach was reasonable.
  • Whether the scope of personal information reported to affected individuals in the notification letters was complete.