The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

14 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 7, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Canada Revenue Agency

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

May 7, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Key Issues
  • Whether the CRA adequately protected personal information against unauthorized disclosure and modification
  • Whether the CRA contravened subsection 6(2) of the Privacy Act regarding accuracy of personal information
  • Whether the CRA contravened subsection 8(2) of the Privacy Act regarding disclosure of personal information
  • Whether the CRA's prevention measures were adequate
  • Whether the CRA implemented mandatory multi-factor authentication (MFA) in a timely manner and with sufficient strength
  • Whether the CRA's authentication processes by phone were strong enough
  • Whether the CRA considered and integrated a zero-trust approach into its security measures
  • Whether the CRA had sufficient visibility over its attack surface and managed it effectively
  • Whether the CRA's vetting, training, and awareness tools were effective for employees and third parties
  • Whether the CRA's monitoring and detection approach was tailored to the threats and risks leading to Unauthorized Use of Taxpayer Information by a Third Party (UUTP)
  • Whether the CRA's remediation efforts for individual UUTPs were adequate, including root cause analysis
  • Whether the CRA's governance processes for addressing UUTPs were coordinated, comprehensive, and efficient
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 3, 2026Indexed Jun 30, 2026

Correctional Service of Canada Deleted Video

Correctional Service of Canada (CSC)

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Correctional Service of Canada Deleted Video

Mar 3, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether CSC failed to retain personal information used for an administrative purpose as required by Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations
  • Whether the complainant was denied a reasonable opportunity to obtain access to their personal information due to non-retention
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 29, 2024Indexed Jun 30, 2026

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Department of National Defence

The complainant, as the executor of a deceased Canadian Armed Forces member's estate, requested personal information from the Department of National Defence (DND) for estate administration purposes. DND initially refused disclosure, citing that the request did not meet the criteria under paragraph 10(b) of the Privacy Regulations and withheld information under section 26 of the Privacy Act, also claiming some records were not under its control or had surpassed retention periods. The OPC found that the complainant was authorized under paragraph 10(b) to access certain information (items 4, 5, 9, and later 2, 6, 7, 8) as it was relevant to potential civil claims regarding the deceased's financial situation and alleged undue influence. The investigation concluded that DND failed to conduct an adequate search for records and improperly applied section 26 without reviewing the records. DND was also found to have improperly deferred the complainant to an informal avenue without formally processing the request. The OPC recommended DND conduct a reasonable search for the specified records and provide a new response, which DND agreed to do. The complaint was therefore found well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Apr 29, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant, as the executor of a deceased Canadian Armed Forces member's estate, requested personal information from the Department of National Defence (DND) for estate administration purposes. DND initially refused disclosure, citing that the request did not meet the criteria under paragraph 10(b) of the Privacy Regulations and withheld information under section 26 of the Privacy Act, also claiming some records were not under its control or had surpassed retention periods. The OPC found that the complainant was authorized under paragraph 10(b) to access certain information (items 4, 5, 9, and later 2, 6, 7, 8) as it was relevant to potential civil claims regarding the deceased's financial situation and alleged undue influence. The investigation concluded that DND failed to conduct an adequate search for records and improperly applied section 26 without reviewing the records. DND was also found to have improperly deferred the complainant to an informal avenue without formally processing the request. The OPC recommended DND conduct a reasonable search for the specified records and provide a new response, which DND agreed to do. The complaint was therefore found well-founded and conditionally resolved.

Key Issues
  • Whether the complainant, as executor, was entitled to make a request on behalf of the deceased member under paragraph 10(b) of the Privacy Regulations for the purpose of administering the estate.
  • Whether the complainant sufficiently articulated or substantiated the precise purposes of the information to administer the estate and how the records in question could further those purposes.
  • Whether DND properly applied section 26 of the Privacy Act in refusing to disclose the requested information.
  • Whether DND conducted an adequate search for the requested records.
  • Whether DND improperly deferred the complainant to another avenue without formally processing a portion of the access request.
  • Whether personal information of a deceased individual (less than 20 years deceased) retains the same privacy protection as a living individual.
  • Whether the 'only for the purpose of such administration' clause in paragraph 10(b) of the Regulations imposes stricter requirements than 'relates to the administration of the individual’s estate' in MFIPPA.
  • Whether records sought to assist in prosecuting a civil claim brought on behalf of the estate for damages recoverable by the estate relate to the administration of the estate.
  • Whether records relevant to the deceased’s financial situation and allegations of fraud or theft of the deceased’s property relate to the administration of the estate.
  • Whether DND's obligation to process a formal access request is relieved if other informal avenues exist.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2024Indexed Jun 30, 2026

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Canada Revenue Agency (CRA)

An individual complained that the Canada Revenue Agency (CRA) failed to ensure the accuracy of their personal information, leading to an imposter fraudulently obtaining Canada Emergency Response Benefit (CERB) payments in their name. The imposter gained unauthorized access to the complainant's CRA My Account, changed direct deposit information, and applied for benefits. This resulted in the complainant receiving a tax reassessment for over $5,500. The OPC found that the CRA relied on inadequate safeguards against unauthorized access and modification, thus failing to take reasonable steps to ensure the accuracy of personal information used for administrative decisions under section 6(2) of the Privacy Act. The CRA has since implemented corrective measures, including enhanced authentication processes and security for high-impact modifications. The OPC found the complaint well-founded and conditionally resolved, noting the CRA's commitments to address the issues.

Quick view

Privacy ActWell-founded & conditionally resolved

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Mar 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that the Canada Revenue Agency (CRA) failed to ensure the accuracy of their personal information, leading to an imposter fraudulently obtaining Canada Emergency Response Benefit (CERB) payments in their name. The imposter gained unauthorized access to the complainant's CRA My Account, changed direct deposit information, and applied for benefits. This resulted in the complainant receiving a tax reassessment for over $5,500. The OPC found that the CRA relied on inadequate safeguards against unauthorized access and modification, thus failing to take reasonable steps to ensure the accuracy of personal information used for administrative decisions under section 6(2) of the Privacy Act. The CRA has since implemented corrective measures, including enhanced authentication processes and security for high-impact modifications. The OPC found the complaint well-founded and conditionally resolved, noting the CRA's commitments to address the issues.

Key Issues
  • Whether the CRA took all reasonable steps to ensure the accuracy of personal information used for administrative purposes under subsection 6(2) of the Privacy Act
  • Whether the safeguards in place at the time of the breach were adequate to prevent unauthorized access and modification of personal information
  • Whether the CRA's authentication processes were sufficient to prevent identity theft and fraudulent activity
  • Whether the CRA should have contacted Employment and Social Development Canada (ESDC) sooner regarding the complainant's identity theft
  • Whether the CRA provided timely notification of the privacy breach to the affected individual
  • Whether the CRA fulfilled its mandatory privacy breach reporting obligations to the OPC
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Canada Revenue Agency and Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Key Issues
  • Whether Canada Revenue Agency (CRA) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether Employment and Social Development Canada (ESDC) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether CRA contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether ESDC contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether CRA and ESDC adequately assessed the level of identity authentication warranted for their online services.
  • Whether CRA and ESDC's identity assurance practices adequately protected against identity theft.
  • Whether CRA and ESDC's credential assurance practices adequately protected against credential stuffing.
  • Whether CRA and ESDC had adequately informed and accountable security decision-making processes.
  • Whether interdepartmental information sharing and accountability systems were adequate to protect personal information.
  • Whether CRA and ESDC conducted comprehensive vulnerability assessments and penetration testing.
  • Whether CRA and ESDC had effective monitoring to detect and promptly contain the ongoing breach.
  • Whether other federal departments using the GC Key service experienced fraudulent access or modification of personal information.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Protecting privacy in a pandemic

Federal Government Institutions and Biron Health Group

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

Quick view

Privacy ActWell-founded & conditionally resolved

Protecting privacy in a pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

Key Issues
  • Whether the collection of COVID-19 vaccination status for domestic travel was lawful under the Privacy Act
  • Whether the collection of COVID-19 vaccination status for domestic travel was necessary and proportional
  • Whether the handling of personal information collected for domestic travel vaccine mandates was reasonable
  • Whether the collection of COVID-19 vaccination status for entry into Canada was lawful under the Privacy Act
  • Whether the collection of COVID-19 vaccination status for entry into Canada was necessary and proportional
  • Whether the collection of federal employees' vaccination status and related medical/religious information was lawful under the Privacy Act
  • Whether the collection of federal employees' vaccination status and related medical/religious information was necessary and proportional
  • Whether the Monitor-MASS system used by DND/CAF had adequate oversight to prevent unauthorized access to personal information
  • Whether there were inappropriate disclosures of personal information related to federal employee vaccination status
  • Whether the Treasury Board of Canada contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description
  • Whether the Canada Border Services Agency (CBSA) took all reasonable steps to ensure the accuracy of information in the ArriveCAN app under section 6 of the Privacy Act
  • Whether the collection and use of de-identified mobility data by PHAC constituted the collection of personal information under the Privacy Act
  • Whether Biron Health Group obtained valid consent under PIPEDA for using personal information collected for COVID-19 testing for marketing purposes
  • Whether information sharing by RCMP, FINTRAC, and CSIS under the Emergencies Act complied with the Privacy Act
  • Whether information sharing under the Emergencies Act was necessary and proportionate
  • Whether there was clear direction and guidance for information sharing under the Emergencies Act
  • Whether appropriate safeguards were in place for personal information shared under the Emergencies Act
  • The need for modernized privacy laws to address necessity, proportionality, and de-identified information
  • The importance of transparency and accountability in government initiatives involving personal information during crises
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2023Indexed Jun 30, 2026

TBS email breach illustrates the importance of considering context when assessing impact of a breach

Treasury Board of Canada Secretariat (TBS)

Twenty complainants, current or former federal government employees, alleged that the Treasury Board of Canada Secretariat (TBS) improperly disclosed their personal information. TBS mistakenly sent two emails to 400 applicants for the Severe Phoenix Impacts program using the 'cc' field instead of 'bcc', revealing email addresses (some with names) and the fact they had filed a claim for Phoenix-related damages. The OPC found that the disclosure was not authorized under the Privacy Act, making the complaints well-founded. While TBS acknowledged the error, it initially deemed the breach non-material, a conclusion the OPC disagreed with, emphasizing the importance of contextual factors in assessing harm. TBS agreed to implement two of the OPC's three recommendations, but not the one concerning incorporating the findings on materiality into its policy instruments. The OPC concluded the complaints were well-founded and conditionally resolved in part, expressing ongoing concern about TBS's assessment of breach materiality.

Quick view

Privacy ActWell-founded & conditionally resolved

TBS email breach illustrates the importance of considering context when assessing impact of a breach

Feb 15, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

Twenty complainants, current or former federal government employees, alleged that the Treasury Board of Canada Secretariat (TBS) improperly disclosed their personal information. TBS mistakenly sent two emails to 400 applicants for the Severe Phoenix Impacts program using the 'cc' field instead of 'bcc', revealing email addresses (some with names) and the fact they had filed a claim for Phoenix-related damages. The OPC found that the disclosure was not authorized under the Privacy Act, making the complaints well-founded. While TBS acknowledged the error, it initially deemed the breach non-material, a conclusion the OPC disagreed with, emphasizing the importance of contextual factors in assessing harm. TBS agreed to implement two of the OPC's three recommendations, but not the one concerning incorporating the findings on materiality into its policy instruments. The OPC concluded the complaints were well-founded and conditionally resolved in part, expressing ongoing concern about TBS's assessment of breach materiality.

Key Issues
  • Whether the disclosure of personal information via email was authorized under the Privacy Act
  • Whether the privacy breach was 'material' in nature according to TBS's guidelines
  • Whether TBS's assessment of the breach's materiality was appropriate
  • Whether the context of the personal information disclosed should be considered when assessing the risk of injury or harm
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 14, 2022Indexed Jun 30, 2026

IRCC email breach creates risk of harm to individuals seeking Afghan emergency assistance

Immigration, Refugees and Citizenship Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach involving 636 individuals seeking emergency assistance related to the situation in Afghanistan. IRCC inadvertently disclosed recipients' email addresses, and in some cases thumbnail photos, by using the "TO" field instead of "BCC" in four mass emails. This disclosure revealed that individuals had inquired about sensitive emergency measures, posing potential life-threatening risks. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose. While IRCC took immediate steps to mitigate the impact on affected individuals, the OPC determined that its preventative measures were initially insufficient. IRCC subsequently revised its internal procedures, implemented a "two pairs of eyes" rule, limited recipients, introduced a secure webform, and committed to exploring further technological solutions. The OPC was satisfied with IRCC's actions and considered the matter closed.

Quick view

Privacy ActWell-founded & conditionally resolved

IRCC email breach creates risk of harm to individuals seeking Afghan emergency assistance

Dec 14, 2022
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach involving 636 individuals seeking emergency assistance related to the situation in Afghanistan. IRCC inadvertently disclosed recipients' email addresses, and in some cases thumbnail photos, by using the "TO" field instead of "BCC" in four mass emails. This disclosure revealed that individuals had inquired about sensitive emergency measures, posing potential life-threatening risks. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose. While IRCC took immediate steps to mitigate the impact on affected individuals, the OPC determined that its preventative measures were initially insufficient. IRCC subsequently revised its internal procedures, implemented a "two pairs of eyes" rule, limited recipients, introduced a secure webform, and committed to exploring further technological solutions. The OPC was satisfied with IRCC's actions and considered the matter closed.

Key Issues
  • Whether IRCC's disclosure of personal information via mass email contravened section 8 of the Privacy Act
  • Whether IRCC had sufficient administrative and procedural controls in place to prevent accidental disclosures of sensitive personal information when communicating by mass email
  • Whether IRCC's measures to mitigate the impact of the incident on affected individuals were adequate
  • Whether IRCC's actions to reduce the risk of recurrence of similar incidents in the future were adequate
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 13, 2022Indexed Jun 30, 2026

DND breached the Privacy Act in disclosing the identity of a workplace violence complainant who had an expectation of confidentiality

Department of National Defence (DND)

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

Quick view

Privacy ActWell-founded & conditionally resolved

DND breached the Privacy Act in disclosing the identity of a workplace violence complainant who had an expectation of confidentiality

May 13, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

Key Issues
  • Whether the disclosure of the WPV complainant's identity to labour relations was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the disclosure of the WPV complainant's identity to an investigator for a separate administrative investigation was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the consent form provided by DND created a reasonable expectation of confidentiality regarding the complainant's identity
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 10, 2021Indexed Jun 30, 2026

Police use of Facial Recognition Technology in Canada and the way forward

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP)'s use of facial recognition technology from Clearview AI. The OPC found that the RCMP contravened Section 4 of the Privacy Act by collecting personal information from Clearview AI, as Clearview AI itself had collected this information unlawfully under PIPEDA and provincial privacy laws. The investigation revealed serious and systemic gaps in the RCMP's policies and systems for tracking, identifying, assessing, and controlling novel collections of personal information. Although the RCMP disagreed with the finding of contravention, it committed to implementing the OPC's recommendations for systemic changes, improved training, and robust controls. The OPC concluded that the matter was well-founded and conditionally resolved, pending the full implementation of these recommendations.

Quick view

Privacy ActWell-founded & conditionally resolved

Police use of Facial Recognition Technology in Canada and the way forward

Jun 10, 2021
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP)'s use of facial recognition technology from Clearview AI. The OPC found that the RCMP contravened Section 4 of the Privacy Act by collecting personal information from Clearview AI, as Clearview AI itself had collected this information unlawfully under PIPEDA and provincial privacy laws. The investigation revealed serious and systemic gaps in the RCMP's policies and systems for tracking, identifying, assessing, and controlling novel collections of personal information. Although the RCMP disagreed with the finding of contravention, it committed to implementing the OPC's recommendations for systemic changes, improved training, and robust controls. The OPC concluded that the matter was well-founded and conditionally resolved, pending the full implementation of these recommendations.

Key Issues
  • Whether the RCMP's collection of personal information from Clearview AI was directly related to an operating program or activity under Section 4 of the Privacy Act.
  • Whether a government institution can collect personal information from a third party that collected the information unlawfully.
  • Whether the RCMP had adequate controls to prevent future similar contraventions when collecting novel personal information.
  • Whether the RCMP had sufficient knowledge of its obligations under the Privacy Act and common law regarding personal information collection.
  • Whether the RCMP had adequate awareness and tracking systems for novel personal information collections.
  • Whether the RCMP had processes to identify potential compliance issues before undertaking novel collections.
  • Whether the RCMP had processes to complete timely assessments (like PIAs) when warranted.
  • Whether the RCMP had effective controls on collection, including policies and monitoring for unauthorized collections.
  • Whether the RCMP's use of Clearview AI constituted a justifiable exercise of police powers under common law (Waterfield test).
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 3, 2021Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data ProjectIndexed Jun 30, 2026

Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data Project: Final Report

Statistics Canada

This report is a compliance monitoring review by the Office of the Privacy Commissioner (OPC) of Statistics Canada's (StatCan) redesigned Financial Transactions Project and Credit Agency Data Project. It follows an earlier OPC investigation that found no contraventions of the Privacy Act but identified significant privacy concerns, leading to recommendations for StatCan to incorporate necessity and proportionality principles. The OPC assessed StatCan's progress, noting reductions in data collection and the implementation of privacy-enhancing measures like a data ethics secretariat and an external ethics body. However, the OPC found that the redesigned project plans still lacked sufficient specificity in describing public goals, failed to demonstrate effectiveness, and did not adequately analyze privacy impacts in context. The OPC concluded that while progress was made, "more work needs to be done" to fully meet its assessment criteria for necessity and proportionality. Consequently, the OPC issued four new recommendations, including describing public goals with greater precision, revisiting effectiveness, analyzing privacy in context, and resubmitting the plans for further review before final implementation. The outcome is classified as well-founded-conditionally-resolved, reflecting partial implementation and the need for further action.

Quick view

Privacy ActWell-founded & conditionally resolved

Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data Project: Final Report

May 3, 2021Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data Project
Adjudicator: Daniel Therrien
Plain-Language Summary

This report is a compliance monitoring review by the Office of the Privacy Commissioner (OPC) of Statistics Canada's (StatCan) redesigned Financial Transactions Project and Credit Agency Data Project. It follows an earlier OPC investigation that found no contraventions of the Privacy Act but identified significant privacy concerns, leading to recommendations for StatCan to incorporate necessity and proportionality principles. The OPC assessed StatCan's progress, noting reductions in data collection and the implementation of privacy-enhancing measures like a data ethics secretariat and an external ethics body. However, the OPC found that the redesigned project plans still lacked sufficient specificity in describing public goals, failed to demonstrate effectiveness, and did not adequately analyze privacy impacts in context. The OPC concluded that while progress was made, "more work needs to be done" to fully meet its assessment criteria for necessity and proportionality. Consequently, the OPC issued four new recommendations, including describing public goals with greater precision, revisiting effectiveness, analyzing privacy in context, and resubmitting the plans for further review before final implementation. The outcome is classified as well-founded-conditionally-resolved, reflecting partial implementation and the need for further action.

Key Issues
  • Whether the redesigned Financial Transactions Project and Credit Agency Data Project met the principles of necessity and proportionality.
  • Whether the public goals of the projects were described with a level of specificity and precision commensurate with privacy impacts.
  • Whether the effectiveness of the projects was demonstrated.
  • Whether privacy impacts were given sufficient analysis in context, considering risk of harm to individuals and broad-based harms.
  • Whether StatCan's Necessity and Proportionality Framework aligned with OPC's assessment criteria.
  • Whether less privacy-intrusive alternatives were adequately considered and compared.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

PA-048557, PA-048561 — Canadian Air Transport Security Authority (CATSA)

Canadian Air Transport Security Authority (CATSA)

An individual complained that the Canadian Air Transport Security Authority (CATSA) contravened the Privacy Act by collecting and disclosing his personal information to police after finding legal medical cannabis during a security screening. The complainant argued that CATSA's mandate is aviation security, not general law enforcement, and that cannabis is not a prohibited item. CATSA maintained that its actions were incidental to its mandate and in the public interest, consistent with its regulator's direction. The OPC found that CATSA lacked the legal authority under section 4 of the Privacy Act to collect personal information for general law enforcement purposes related to cannabis, as cannabis is not on the Prohibited Items List and does not pose an aviation security threat. Similarly, the OPC concluded that the disclosure of this personal information to police was not consistent with section 8 of the Privacy Act. However, the OPC found CATSA's practice of destroying records related to such searches to be consistent with section 6 of the Act. The OPC recommended that CATSA cease unauthorized collection and disclosure of personal information related to cannabis and destroy any existing records, which CATSA agreed to implement.

Quick view

Privacy ActWell-founded & conditionally resolved

PA-048557, PA-048561 — Canadian Air Transport Security Authority (CATSA)

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that the Canadian Air Transport Security Authority (CATSA) contravened the Privacy Act by collecting and disclosing his personal information to police after finding legal medical cannabis during a security screening. The complainant argued that CATSA's mandate is aviation security, not general law enforcement, and that cannabis is not a prohibited item. CATSA maintained that its actions were incidental to its mandate and in the public interest, consistent with its regulator's direction. The OPC found that CATSA lacked the legal authority under section 4 of the Privacy Act to collect personal information for general law enforcement purposes related to cannabis, as cannabis is not on the Prohibited Items List and does not pose an aviation security threat. Similarly, the OPC concluded that the disclosure of this personal information to police was not consistent with section 8 of the Privacy Act. However, the OPC found CATSA's practice of destroying records related to such searches to be consistent with section 6 of the Act. The OPC recommended that CATSA cease unauthorized collection and disclosure of personal information related to cannabis and destroy any existing records, which CATSA agreed to implement.

Key Issues
  • Whether the collection of personal information from travellers found to be in possession of cannabis is consistent with section 4 of the Privacy Act
  • Whether the disclosure of the personal information of travellers found to be in possession of cannabis is consistent with section 8 of the Privacy Act
  • Whether CATSA’s record retention practices in terms of the personal information collected from travellers found to be in possession of cannabis are consistent with section 6 of the Privacy Act
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Review of passport protection practices of four federal institutions

Immigration, Refugees and Citizenship Canada (IRCC)

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Quick view

Privacy ActWell-founded & conditionally resolved

Review of passport protection practices of four federal institutions

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Key Issues
  • Whether the institutions had adequate controls to prevent unauthorized disclosures of passports under s.8 of the Privacy Act
  • Whether the institutions had adequate measures to detect potential unauthorized disclosures of passports
  • Whether the institutions had adequate measures to remediate risks to individuals from unauthorized disclosures of passports
  • Whether the institutions consistently and appropriately assessed the "materiality" of passport-related breaches
  • Whether notifications to affected individuals regarding lost or stolen passports were timely
  • Whether concrete assistance, such as credit monitoring, was offered to individuals affected by lost or stolen passports
  • Whether incident assessment and investigation processes were robust enough to identify suspicious patterns and share lessons learned among relevant stakeholders
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

RCMP contravened the Act by using certain types of non-conviction information for vulnerable sector checks without consent

Royal Canadian Mounted Police (RCMP)

Three individuals complained about the Royal Canadian Mounted Police's (RCMP) use of non-conviction information in vulnerable sector (VS) checks, which they required for employment or volunteer positions. The complainants alleged that the RCMP inappropriately used non-criminal information, including mental health incidents, without proper consent. The OPC found that for two of the complaints, the RCMP contravened section 7 of the Privacy Act because the consent forms did not clearly inform applicants about the types of non-conviction information that would be used. While the RCMP argued consent was obtained, the OPC determined it was not informed consent in these cases. The OPC also concluded that the RCMP's broad policy of reporting non-conviction information, including mental health incidents, was not proportional or minimally intrusive compared to more restrictive provincial models. However, the complaint regarding the RCMP's retention period for personal information was found not well-founded, as it complied with the minimum requirements of the Privacy Regulations. The RCMP agreed to revise its consent forms and policy to address the OPC's concerns, leading to a well-founded and conditionally resolved outcome for the two complaints.

Quick view

Privacy ActWell-founded & conditionally resolved

RCMP contravened the Act by using certain types of non-conviction information for vulnerable sector checks without consent

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

Three individuals complained about the Royal Canadian Mounted Police's (RCMP) use of non-conviction information in vulnerable sector (VS) checks, which they required for employment or volunteer positions. The complainants alleged that the RCMP inappropriately used non-criminal information, including mental health incidents, without proper consent. The OPC found that for two of the complaints, the RCMP contravened section 7 of the Privacy Act because the consent forms did not clearly inform applicants about the types of non-conviction information that would be used. While the RCMP argued consent was obtained, the OPC determined it was not informed consent in these cases. The OPC also concluded that the RCMP's broad policy of reporting non-conviction information, including mental health incidents, was not proportional or minimally intrusive compared to more restrictive provincial models. However, the complaint regarding the RCMP's retention period for personal information was found not well-founded, as it complied with the minimum requirements of the Privacy Regulations. The RCMP agreed to revise its consent forms and policy to address the OPC's concerns, leading to a well-founded and conditionally resolved outcome for the two complaints.

Key Issues
  • Whether the use of non-conviction information by the RCMP for VS checks was done with informed consent consistent with section 7 of the Privacy Act.
  • Whether the RCMP's policy of reporting non-conviction information broadly, including mental health incidents, in VS checks was proportional or minimally intrusive.
  • Whether the RCMP should amend its policies with respect to the use of non-conviction information in VS checks.
  • Whether the RCMP contravened the Act by retaining Complainant 2’s personal information for too long.