The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

49 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 14, 2026Indexed Jul 15, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

WestJet

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

Jul 14, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Key Issues
  • Adequacy of security safeguards under PIPEDA
  • Adequacy of notifications to affected individuals under PIPEDA
  • Whether WestJet's post-breach remediation actions and future commitments provide a fair and reasonable response to the incident
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 7, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Canada Revenue Agency

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

May 7, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Key Issues
  • Whether the CRA adequately protected personal information against unauthorized disclosure and modification
  • Whether the CRA contravened subsection 6(2) of the Privacy Act regarding accuracy of personal information
  • Whether the CRA contravened subsection 8(2) of the Privacy Act regarding disclosure of personal information
  • Whether the CRA's prevention measures were adequate
  • Whether the CRA implemented mandatory multi-factor authentication (MFA) in a timely manner and with sufficient strength
  • Whether the CRA's authentication processes by phone were strong enough
  • Whether the CRA considered and integrated a zero-trust approach into its security measures
  • Whether the CRA had sufficient visibility over its attack surface and managed it effectively
  • Whether the CRA's vetting, training, and awareness tools were effective for employees and third parties
  • Whether the CRA's monitoring and detection approach was tailored to the threats and risks leading to Unauthorized Use of Taxpayer Information by a Third Party (UUTP)
  • Whether the CRA's remediation efforts for individual UUTPs were adequate, including root cause analysis
  • Whether the CRA's governance processes for addressing UUTPs were coordinated, comprehensive, and efficient
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 5, 2026PIPEDA Findings #2026-001Indexed Jun 30, 2026

PIPEDA Findings #2026-001: Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program

Loblaw Companies Ltd.

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Loblaw Companies Ltd. (Loblaw) regarding its PC Optimum Loyalty Program, focusing on the handling of privacy challenges and the retention of personal information. The investigation found that Loblaw contravened PIPEDA Principle 4.10 by failing to adequately address privacy challenges and respond to account deletion requests in a timely manner, though this issue was resolved during the investigation as Loblaw enhanced its procedures. The OPC also found that Loblaw contravened PIPEDA Principle 4.5.3 by not sufficiently anonymizing personal information retained from closed PC Optimum accounts, meaning there was a serious possibility of re-identification. Loblaw disagreed with this finding but agreed to engage an independent third party to assess its anonymization process and implement recommendations. A preliminary matter regarding requiring physical card holders to create an online account for deletion was found not well-founded. The overall outcome reflects a mix of resolved and conditionally resolved well-founded findings.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2026-001: Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program

Mar 5, 2026PIPEDA Findings #2026-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Loblaw Companies Ltd. (Loblaw) regarding its PC Optimum Loyalty Program, focusing on the handling of privacy challenges and the retention of personal information. The investigation found that Loblaw contravened PIPEDA Principle 4.10 by failing to adequately address privacy challenges and respond to account deletion requests in a timely manner, though this issue was resolved during the investigation as Loblaw enhanced its procedures. The OPC also found that Loblaw contravened PIPEDA Principle 4.5.3 by not sufficiently anonymizing personal information retained from closed PC Optimum accounts, meaning there was a serious possibility of re-identification. Loblaw disagreed with this finding but agreed to engage an independent third party to assess its anonymization process and implement recommendations. A preliminary matter regarding requiring physical card holders to create an online account for deletion was found not well-founded. The overall outcome reflects a mix of resolved and conditionally resolved well-founded findings.

Key Issues
  • Whether Loblaw adequately addresses privacy challenges raised by individuals concerning account deletion (PIPEDA Principle 4.10)
  • Whether Loblaw retains personal information of PC Optimum members for longer than necessary after account closure (PIPEDA Principle 4.5.3)
  • Whether Loblaw collected unnecessary personal information by requiring physical card holders to create an online account to delete their PC Optimum account (PIPEDA Principle 4.4)
  • Whether Loblaw established retention schedules for customer support logs (PIPEDA Principle 4.5.2)
  • Whether Loblaw retains universal login credentials (PCids) for longer than necessary for members with no other associated accounts (PIPEDA Principle 4.5.3)
  • Whether Loblaw's anonymization process for retained Historical Transaction Data, Loyalty Data, and Usage Data ensures no serious possibility of re-identification
  • Whether Loblaw's retention of public IP address data after account closure is sufficiently anonymized
  • Whether Loblaw's practice of retaining email domain portions after account closure is sufficiently anonymized
  • Whether manual processing errors in Loblaw's de-identification process were adequately detected and addressed
  • Whether Loblaw ensured identifiers were removed from back-up systems as part of its anonymization process
  • Whether Loblaw considered the impact of other factors affecting re-identification risk, such as separately retained PCid data
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 3, 2026Indexed Jun 30, 2026

Correctional Service of Canada Deleted Video

Correctional Service of Canada (CSC)

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Correctional Service of Canada Deleted Video

Mar 3, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether CSC failed to retain personal information used for an administrative purpose as required by Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations
  • Whether the complainant was denied a reasonable opportunity to obtain access to their personal information due to non-retention
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 9, 2026PIPEDA Findings #2026-003Indexed Jun 30, 2026

PIPEDA Findings #2026-003: Investigation into Bell’s compliance with PIPEDA when responding to an access request for personal information

Bell Canada

The complainant alleged that Bell Canada contravened PIPEDA by failing to respond to an access request within 30 days and by denying access to his cellphone logs. The OPC found that Bell contravened subsection 8(3) of PIPEDA for the delayed response and Principle 4.9 for denying access, as the phone logs constituted the complainant's personal information. The OPC determined that the complainant's privacy interest in his phone logs outweighed the ex-spouse's interest, and there was a public interest in disclosure. Bell agreed to provide the requested logs to the complainant, resolving that aspect of the complaint. Bell also committed to implementing recommendations to improve its access request procedures and enhance openness regarding data access on shared accounts, leading to a conditionally resolved outcome for these issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2026-003: Investigation into Bell’s compliance with PIPEDA when responding to an access request for personal information

Jan 9, 2026PIPEDA Findings #2026-003
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Bell Canada contravened PIPEDA by failing to respond to an access request within 30 days and by denying access to his cellphone logs. The OPC found that Bell contravened subsection 8(3) of PIPEDA for the delayed response and Principle 4.9 for denying access, as the phone logs constituted the complainant's personal information. The OPC determined that the complainant's privacy interest in his phone logs outweighed the ex-spouse's interest, and there was a public interest in disclosure. Bell agreed to provide the requested logs to the complainant, resolving that aspect of the complaint. Bell also committed to implementing recommendations to improve its access request procedures and enhance openness regarding data access on shared accounts, leading to a conditionally resolved outcome for these issues.

Key Issues
  • Whether Bell responded to the Complainant’s access request within thirty days as per subsection 8(3) of PIPEDA
  • Whether Bell adequately responded to the Complainant’s request to access his personal information under Principle 4.9 of PIPEDA
  • Whether phone logs relating to a specific phoneline constitute the personal information of the phoneline's user, even if they are not the account holder
  • Whether the Complainant's interest in accessing the phone logs is greater than the ex-spouse's interest in non-disclosure of the phone logs
  • Whether Bell was sufficiently open with individuals about account holders' access to phone usage details on shared accounts, contrary to PIPEDA's Openness principle (Principle 4.8.1)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 1, 2025PIPEDA Findings #2025-004Indexed Jun 30, 2026

PIPEDA Findings #2025-004: Investigation into the privacy practices of Staples Canada ULC related to electronic devices to be resold as part of its Openbox program

Staples Canada ULC

A former employee complained that Staples Canada ULC (Staples) failed to adequately protect and remove personal information from returned laptops before reselling them through its Openbox program. The complainant alleged that Staples lacked adequate internal policies, processes, and training for staff to wipe data from these devices. The OPC's investigation found deficiencies in Staples' policies, procedures, and training, and that employees did not consistently follow manufacturer guidelines for data wiping, leading to residual personal information on 23% of sampled devices. Staples agreed to implement recommendations to improve its data wiping procedures, training, and to arrange for independent third-party spot checks. The OPC concluded that Staples contravened PIPEDA Principles 4.7.1 and 4.7.3.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2025-004: Investigation into the privacy practices of Staples Canada ULC related to electronic devices to be resold as part of its Openbox program

Dec 1, 2025PIPEDA Findings #2025-004
Adjudicator: Philippe Dufresne
Plain-Language Summary

A former employee complained that Staples Canada ULC (Staples) failed to adequately protect and remove personal information from returned laptops before reselling them through its Openbox program. The complainant alleged that Staples lacked adequate internal policies, processes, and training for staff to wipe data from these devices. The OPC's investigation found deficiencies in Staples' policies, procedures, and training, and that employees did not consistently follow manufacturer guidelines for data wiping, leading to residual personal information on 23% of sampled devices. Staples agreed to implement recommendations to improve its data wiping procedures, training, and to arrange for independent third-party spot checks. The OPC concluded that Staples contravened PIPEDA Principles 4.7.1 and 4.7.3.

Key Issues
  • Whether Staples had adequate security safeguards to protect personal information on returned laptops under Principle 4.7.1 PIPEDA
  • Whether Staples' methods of protection included adequate physical, organizational, and technological measures under Principle 4.7.3 PIPEDA
  • Whether Staples' internal policies and procedures for data wiping were clear and consistent
  • Whether Staples provided adequate training to employees responsible for wiping data from returned devices
  • Whether Staples consistently performed full data wipes according to manufacturer instructions on returned laptops
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Sep 23, 2025PIPEDA Findings #2025-003Indexed Jun 30, 2026

PIPEDA Findings #2025-003: Joint investigation of TikTok Pte. Ltd. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, and the Office of the Information and Privacy Commissioner of Alberta

TikTok Pte. Ltd.

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and provincial privacy regulators (CAI, OIPC BC, OIPC AB) examined TikTok Pte. Ltd.'s compliance with federal and provincial private sector privacy laws. The investigation focused on TikTok's collection, use, and disclosure of personal information for ad targeting and content personalization, with a particular emphasis on practices affecting children. The Offices found that TikTok's age assurance measures were inadequate, leading to the collection and use of sensitive personal information from a large number of underage users for purposes deemed inappropriate. Furthermore, TikTok failed to obtain valid and meaningful consent from both adult and youth users due to unclear, inaccessible, and incomplete privacy communications, including regarding biometric information and cross-border data transfers. The CAI specifically identified contraventions related to Quebec's transparency and privacy-by-default obligations. While TikTok disagreed with the findings, it committed to implementing enhanced age assurance mechanisms, improving privacy communications, and limiting ad targeting for under-18 users. The Offices concluded the matter as well-founded and conditionally resolved, contingent on TikTok's satisfactory implementation of these significant commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2025-003: Joint investigation of TikTok Pte. Ltd. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, and the Office of the Information and Privacy Commissioner of Alberta

Sep 23, 2025PIPEDA Findings #2025-003
Adjudicator: Philippe Dufresne
Plain-Language Summary

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and provincial privacy regulators (CAI, OIPC BC, OIPC AB) examined TikTok Pte. Ltd.'s compliance with federal and provincial private sector privacy laws. The investigation focused on TikTok's collection, use, and disclosure of personal information for ad targeting and content personalization, with a particular emphasis on practices affecting children. The Offices found that TikTok's age assurance measures were inadequate, leading to the collection and use of sensitive personal information from a large number of underage users for purposes deemed inappropriate. Furthermore, TikTok failed to obtain valid and meaningful consent from both adult and youth users due to unclear, inaccessible, and incomplete privacy communications, including regarding biometric information and cross-border data transfers. The CAI specifically identified contraventions related to Quebec's transparency and privacy-by-default obligations. While TikTok disagreed with the findings, it committed to implementing enhanced age assurance mechanisms, improving privacy communications, and limiting ad targeting for under-18 users. The Offices concluded the matter as well-founded and conditionally resolved, contingent on TikTok's satisfactory implementation of these significant commitments.

Key Issues
  • Whether TikTok was collecting, using, and disclosing personal information, particularly with respect to children, for an appropriate, reasonable, and legitimate purpose.
  • Whether TikTok's age assurance mechanisms were effective in preventing underage users from accessing the platform.
  • Whether TikTok obtained valid and meaningful consent from its users for tracking, profiling, targeting, and content personalization.
  • Whether TikTok's privacy communications provided sufficient upfront, clear, and comprehensive information to adult users to ensure meaningful consent.
  • Whether TikTok adequately explained its collection and use of users' biometric information to ensure meaningful consent.
  • Whether TikTok's privacy communications were adequate to obtain meaningful consent from youth (13-17), considering their cognitive development and potential harms from targeted ads.
  • Whether TikTok met its obligations under Quebec's Private Sector Act to inform persons concerned about the collection and use of personal information for user profiles, ad targeting, and content personalization.
  • Whether TikTok ensured that privacy settings provided the highest level of privacy by default under Quebec's Private Sector Act.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 29, 2024Indexed Jun 30, 2026

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Department of National Defence

The complainant, as the executor of a deceased Canadian Armed Forces member's estate, requested personal information from the Department of National Defence (DND) for estate administration purposes. DND initially refused disclosure, citing that the request did not meet the criteria under paragraph 10(b) of the Privacy Regulations and withheld information under section 26 of the Privacy Act, also claiming some records were not under its control or had surpassed retention periods. The OPC found that the complainant was authorized under paragraph 10(b) to access certain information (items 4, 5, 9, and later 2, 6, 7, 8) as it was relevant to potential civil claims regarding the deceased's financial situation and alleged undue influence. The investigation concluded that DND failed to conduct an adequate search for records and improperly applied section 26 without reviewing the records. DND was also found to have improperly deferred the complainant to an informal avenue without formally processing the request. The OPC recommended DND conduct a reasonable search for the specified records and provide a new response, which DND agreed to do. The complaint was therefore found well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Apr 29, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant, as the executor of a deceased Canadian Armed Forces member's estate, requested personal information from the Department of National Defence (DND) for estate administration purposes. DND initially refused disclosure, citing that the request did not meet the criteria under paragraph 10(b) of the Privacy Regulations and withheld information under section 26 of the Privacy Act, also claiming some records were not under its control or had surpassed retention periods. The OPC found that the complainant was authorized under paragraph 10(b) to access certain information (items 4, 5, 9, and later 2, 6, 7, 8) as it was relevant to potential civil claims regarding the deceased's financial situation and alleged undue influence. The investigation concluded that DND failed to conduct an adequate search for records and improperly applied section 26 without reviewing the records. DND was also found to have improperly deferred the complainant to an informal avenue without formally processing the request. The OPC recommended DND conduct a reasonable search for the specified records and provide a new response, which DND agreed to do. The complaint was therefore found well-founded and conditionally resolved.

Key Issues
  • Whether the complainant, as executor, was entitled to make a request on behalf of the deceased member under paragraph 10(b) of the Privacy Regulations for the purpose of administering the estate.
  • Whether the complainant sufficiently articulated or substantiated the precise purposes of the information to administer the estate and how the records in question could further those purposes.
  • Whether DND properly applied section 26 of the Privacy Act in refusing to disclose the requested information.
  • Whether DND conducted an adequate search for the requested records.
  • Whether DND improperly deferred the complainant to another avenue without formally processing a portion of the access request.
  • Whether personal information of a deceased individual (less than 20 years deceased) retains the same privacy protection as a living individual.
  • Whether the 'only for the purpose of such administration' clause in paragraph 10(b) of the Regulations imposes stricter requirements than 'relates to the administration of the individual’s estate' in MFIPPA.
  • Whether records sought to assist in prosecuting a civil claim brought on behalf of the estate for damages recoverable by the estate relate to the administration of the estate.
  • Whether records relevant to the deceased’s financial situation and allegations of fraud or theft of the deceased’s property relate to the administration of the estate.
  • Whether DND's obligation to process a formal access request is relieved if other informal avenues exist.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2024Indexed Jun 30, 2026

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Canada Revenue Agency (CRA)

An individual complained that the Canada Revenue Agency (CRA) failed to ensure the accuracy of their personal information, leading to an imposter fraudulently obtaining Canada Emergency Response Benefit (CERB) payments in their name. The imposter gained unauthorized access to the complainant's CRA My Account, changed direct deposit information, and applied for benefits. This resulted in the complainant receiving a tax reassessment for over $5,500. The OPC found that the CRA relied on inadequate safeguards against unauthorized access and modification, thus failing to take reasonable steps to ensure the accuracy of personal information used for administrative decisions under section 6(2) of the Privacy Act. The CRA has since implemented corrective measures, including enhanced authentication processes and security for high-impact modifications. The OPC found the complaint well-founded and conditionally resolved, noting the CRA's commitments to address the issues.

Quick view

Privacy ActWell-founded & conditionally resolved

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Mar 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that the Canada Revenue Agency (CRA) failed to ensure the accuracy of their personal information, leading to an imposter fraudulently obtaining Canada Emergency Response Benefit (CERB) payments in their name. The imposter gained unauthorized access to the complainant's CRA My Account, changed direct deposit information, and applied for benefits. This resulted in the complainant receiving a tax reassessment for over $5,500. The OPC found that the CRA relied on inadequate safeguards against unauthorized access and modification, thus failing to take reasonable steps to ensure the accuracy of personal information used for administrative decisions under section 6(2) of the Privacy Act. The CRA has since implemented corrective measures, including enhanced authentication processes and security for high-impact modifications. The OPC found the complaint well-founded and conditionally resolved, noting the CRA's commitments to address the issues.

Key Issues
  • Whether the CRA took all reasonable steps to ensure the accuracy of personal information used for administrative purposes under subsection 6(2) of the Privacy Act
  • Whether the safeguards in place at the time of the breach were adequate to prevent unauthorized access and modification of personal information
  • Whether the CRA's authentication processes were sufficient to prevent identity theft and fraudulent activity
  • Whether the CRA should have contacted Employment and Social Development Canada (ESDC) sooner regarding the complainant's identity theft
  • Whether the CRA provided timely notification of the privacy breach to the affected individual
  • Whether the CRA fulfilled its mandatory privacy breach reporting obligations to the OPC
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Canada Revenue Agency and Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Key Issues
  • Whether Canada Revenue Agency (CRA) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether Employment and Social Development Canada (ESDC) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether CRA contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether ESDC contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether CRA and ESDC adequately assessed the level of identity authentication warranted for their online services.
  • Whether CRA and ESDC's identity assurance practices adequately protected against identity theft.
  • Whether CRA and ESDC's credential assurance practices adequately protected against credential stuffing.
  • Whether CRA and ESDC had adequately informed and accountable security decision-making processes.
  • Whether interdepartmental information sharing and accountability systems were adequate to protect personal information.
  • Whether CRA and ESDC conducted comprehensive vulnerability assessments and penetration testing.
  • Whether CRA and ESDC had effective monitoring to detect and promptly contain the ongoing breach.
  • Whether other federal departments using the GC Key service experienced fraudulent access or modification of personal information.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 31, 2023PIPEDA Findings #2023-002Indexed Jun 30, 2026

PIPEDA Findings #2023-002: Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information

Agronomy Company of Canada Ltd.

The Office of the Privacy Commissioner of Canada (OPC) investigated Agronomy Company of Canada Ltd. following a complaint alleging inadequate safeguards, lack of accountability, and invalid consent for personal information collection and use, stemming from a data breach. A malicious actor gained access to Agronomy's systems, exfiltrating sensitive personal information of 845 individuals, including SINs, financial details, and identification documents, before deploying ransomware. The OPC found Agronomy failed to implement appropriate safeguards, citing a lack of multifactor authentication, network segregation, data encryption, and detection tools, which contributed to the breach. Furthermore, Agronomy lacked a comprehensive privacy policy, a designated privacy officer, and adequate staff training, indicating a failure in accountability. While these two aspects were found well-founded, Agronomy committed to significant improvements, leading to a conditionally resolved outcome. However, the OPC found the complaint regarding invalid consent for credit services not well-founded, as the complainant had signed a clearly labelled credit application and utilized the extended credit.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2023-002: Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information

Jul 31, 2023PIPEDA Findings #2023-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated Agronomy Company of Canada Ltd. following a complaint alleging inadequate safeguards, lack of accountability, and invalid consent for personal information collection and use, stemming from a data breach. A malicious actor gained access to Agronomy's systems, exfiltrating sensitive personal information of 845 individuals, including SINs, financial details, and identification documents, before deploying ransomware. The OPC found Agronomy failed to implement appropriate safeguards, citing a lack of multifactor authentication, network segregation, data encryption, and detection tools, which contributed to the breach. Furthermore, Agronomy lacked a comprehensive privacy policy, a designated privacy officer, and adequate staff training, indicating a failure in accountability. While these two aspects were found well-founded, Agronomy committed to significant improvements, leading to a conditionally resolved outcome. However, the OPC found the complaint regarding invalid consent for credit services not well-founded, as the complainant had signed a clearly labelled credit application and utilized the extended credit.

Key Issues
  • Whether Agronomy implemented appropriate safeguards to adequately protect personal information under its control, as per PIPEDA Principle 4.7.
  • Whether Agronomy's technical safeguards (multifactor authentication, network segregation, data encryption, detection and response tools) were appropriate for the sensitivity of the information.
  • Whether Agronomy's organizational safeguards (incident response protocols, information management, security documentation, staff training) were adequate.
  • Whether Agronomy was accountable for personal information under its control, including designating an individual for PIPEDA compliance and implementing policies and practices, as per PIPEDA Principle 4.1.
  • Whether Agronomy obtained valid and meaningful consent for the collection and use of personal information for credit services, particularly sensitive information, as per PIPEDA Principle 4.3.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Protecting privacy in a pandemic

Federal Government Institutions and Biron Health Group

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

Quick view

Privacy ActWell-founded & conditionally resolved

Protecting privacy in a pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

Key Issues
  • Whether the collection of COVID-19 vaccination status for domestic travel was lawful under the Privacy Act
  • Whether the collection of COVID-19 vaccination status for domestic travel was necessary and proportional
  • Whether the handling of personal information collected for domestic travel vaccine mandates was reasonable
  • Whether the collection of COVID-19 vaccination status for entry into Canada was lawful under the Privacy Act
  • Whether the collection of COVID-19 vaccination status for entry into Canada was necessary and proportional
  • Whether the collection of federal employees' vaccination status and related medical/religious information was lawful under the Privacy Act
  • Whether the collection of federal employees' vaccination status and related medical/religious information was necessary and proportional
  • Whether the Monitor-MASS system used by DND/CAF had adequate oversight to prevent unauthorized access to personal information
  • Whether there were inappropriate disclosures of personal information related to federal employee vaccination status
  • Whether the Treasury Board of Canada contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description
  • Whether the Canada Border Services Agency (CBSA) took all reasonable steps to ensure the accuracy of information in the ArriveCAN app under section 6 of the Privacy Act
  • Whether the collection and use of de-identified mobility data by PHAC constituted the collection of personal information under the Privacy Act
  • Whether Biron Health Group obtained valid consent under PIPEDA for using personal information collected for COVID-19 testing for marketing purposes
  • Whether information sharing by RCMP, FINTRAC, and CSIS under the Emergencies Act complied with the Privacy Act
  • Whether information sharing under the Emergencies Act was necessary and proportionate
  • Whether there was clear direction and guidance for information sharing under the Emergencies Act
  • Whether appropriate safeguards were in place for personal information shared under the Emergencies Act
  • The need for modernized privacy laws to address necessity, proportionality, and de-identified information
  • The importance of transparency and accountability in government initiatives involving personal information during crises
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2023Indexed Jun 30, 2026

TBS email breach illustrates the importance of considering context when assessing impact of a breach

Treasury Board of Canada Secretariat (TBS)

Twenty complainants, current or former federal government employees, alleged that the Treasury Board of Canada Secretariat (TBS) improperly disclosed their personal information. TBS mistakenly sent two emails to 400 applicants for the Severe Phoenix Impacts program using the 'cc' field instead of 'bcc', revealing email addresses (some with names) and the fact they had filed a claim for Phoenix-related damages. The OPC found that the disclosure was not authorized under the Privacy Act, making the complaints well-founded. While TBS acknowledged the error, it initially deemed the breach non-material, a conclusion the OPC disagreed with, emphasizing the importance of contextual factors in assessing harm. TBS agreed to implement two of the OPC's three recommendations, but not the one concerning incorporating the findings on materiality into its policy instruments. The OPC concluded the complaints were well-founded and conditionally resolved in part, expressing ongoing concern about TBS's assessment of breach materiality.

Quick view

Privacy ActWell-founded & conditionally resolved

TBS email breach illustrates the importance of considering context when assessing impact of a breach

Feb 15, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

Twenty complainants, current or former federal government employees, alleged that the Treasury Board of Canada Secretariat (TBS) improperly disclosed their personal information. TBS mistakenly sent two emails to 400 applicants for the Severe Phoenix Impacts program using the 'cc' field instead of 'bcc', revealing email addresses (some with names) and the fact they had filed a claim for Phoenix-related damages. The OPC found that the disclosure was not authorized under the Privacy Act, making the complaints well-founded. While TBS acknowledged the error, it initially deemed the breach non-material, a conclusion the OPC disagreed with, emphasizing the importance of contextual factors in assessing harm. TBS agreed to implement two of the OPC's three recommendations, but not the one concerning incorporating the findings on materiality into its policy instruments. The OPC concluded the complaints were well-founded and conditionally resolved in part, expressing ongoing concern about TBS's assessment of breach materiality.

Key Issues
  • Whether the disclosure of personal information via email was authorized under the Privacy Act
  • Whether the privacy breach was 'material' in nature according to TBS's guidelines
  • Whether TBS's assessment of the breach's materiality was appropriate
  • Whether the context of the personal information disclosed should be considered when assessing the risk of injury or harm
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 14, 2022Indexed Jun 30, 2026

IRCC email breach creates risk of harm to individuals seeking Afghan emergency assistance

Immigration, Refugees and Citizenship Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach involving 636 individuals seeking emergency assistance related to the situation in Afghanistan. IRCC inadvertently disclosed recipients' email addresses, and in some cases thumbnail photos, by using the "TO" field instead of "BCC" in four mass emails. This disclosure revealed that individuals had inquired about sensitive emergency measures, posing potential life-threatening risks. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose. While IRCC took immediate steps to mitigate the impact on affected individuals, the OPC determined that its preventative measures were initially insufficient. IRCC subsequently revised its internal procedures, implemented a "two pairs of eyes" rule, limited recipients, introduced a secure webform, and committed to exploring further technological solutions. The OPC was satisfied with IRCC's actions and considered the matter closed.

Quick view

Privacy ActWell-founded & conditionally resolved

IRCC email breach creates risk of harm to individuals seeking Afghan emergency assistance

Dec 14, 2022
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach involving 636 individuals seeking emergency assistance related to the situation in Afghanistan. IRCC inadvertently disclosed recipients' email addresses, and in some cases thumbnail photos, by using the "TO" field instead of "BCC" in four mass emails. This disclosure revealed that individuals had inquired about sensitive emergency measures, posing potential life-threatening risks. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose. While IRCC took immediate steps to mitigate the impact on affected individuals, the OPC determined that its preventative measures were initially insufficient. IRCC subsequently revised its internal procedures, implemented a "two pairs of eyes" rule, limited recipients, introduced a secure webform, and committed to exploring further technological solutions. The OPC was satisfied with IRCC's actions and considered the matter closed.

Key Issues
  • Whether IRCC's disclosure of personal information via mass email contravened section 8 of the Privacy Act
  • Whether IRCC had sufficient administrative and procedural controls in place to prevent accidental disclosures of sensitive personal information when communicating by mass email
  • Whether IRCC's measures to mitigate the impact of the incident on affected individuals were adequate
  • Whether IRCC's actions to reduce the risk of recurrence of similar incidents in the future were adequate
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 27, 2022PIPEDA Findings #2022-006Indexed Jun 30, 2026

PIPEDA Findings #2022-006: Investigation into Trimac’s use of an audio and video surveillance device in its truck cabins

Trimac Transportation Services Inc.

A truck driver complained that Trimac Transportation Services Inc. (Trimac) installed a dash camera in his vehicle that continuously recorded audio and video without his consent, particularly concerned with audio recording. The OPC investigated two main issues: the appropriateness of the audio recording functionality and whether employee consent was required. The OPC found that Trimac's continuous audio recording, even when drivers were off-duty, was disproportionately privacy-intrusive, despite legitimate business needs. Trimac also initially failed to be transparent about the disciplinary purposes of the system, meaning it could not rely on the employment relationship exception to consent. Trimac agreed to implement recommendations to limit audio recording to on-duty hours and restrict access to recorded clips, and has since clarified the system's disciplinary uses to employees. The OPC found the audio recording issue well-founded and conditionally resolved, and the consent issue well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-006: Investigation into Trimac’s use of an audio and video surveillance device in its truck cabins

Jul 27, 2022PIPEDA Findings #2022-006
Adjudicator: Philippe Dufresne
Plain-Language Summary

A truck driver complained that Trimac Transportation Services Inc. (Trimac) installed a dash camera in his vehicle that continuously recorded audio and video without his consent, particularly concerned with audio recording. The OPC investigated two main issues: the appropriateness of the audio recording functionality and whether employee consent was required. The OPC found that Trimac's continuous audio recording, even when drivers were off-duty, was disproportionately privacy-intrusive, despite legitimate business needs. Trimac also initially failed to be transparent about the disciplinary purposes of the system, meaning it could not rely on the employment relationship exception to consent. Trimac agreed to implement recommendations to limit audio recording to on-duty hours and restrict access to recorded clips, and has since clarified the system's disciplinary uses to employees. The OPC found the audio recording issue well-founded and conditionally resolved, and the consent issue well-founded and resolved.

Key Issues
  • Whether road safety, asset protection, and employee performance management are appropriate purposes for the continuous collection of in-cabin audio via the System, including when drivers are off-duty and not driving, under subsection 5(3) of PIPEDA.
  • Whether the collection of sensitive personal information (in-cabin audio) was justified given the legitimate need, effectiveness, less privacy-invasive means, and proportionality.
  • Whether employee consent was required for the collection of personal information via the System, specifically whether Trimac could rely on the exception to consent under subsection 7.3 of PIPEDA.
  • Whether Trimac was sufficiently transparent about the disciplinary purposes of its dash camera system to rely on the subsection 7.3 exception to consent.