The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

49 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 15, 2015PIPEDA Case Summary #2015-014Indexed Jun 30, 2026

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

A pension and benefit provider

An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

Dec 15, 2015PIPEDA Case Summary #2015-014
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that her pension and benefit provider disclosed her unique identifier to a third party, failed to keep her address accurate, and failed to safeguard her personal information. The investigation found that another plan member with the same name called the provider, and was mistakenly given the complainant's ID number. This led to the complainant's address being changed to the other member's address, resulting in five misdirected mailings containing sensitive information. Although the mailings were returned unopened, the complainant's insurance coverage was cancelled due to unreturned forms. The provider admitted to disclosing the ID number without consent and failing to follow authentication procedures. The provider agreed to reinstate the insurance, revamp authentication and address-change procedures, develop a privacy plan, improve incident response, and undergo a third-party privacy audit. The OPC found the matter well-founded and conditionally resolved.

Key Issues
  • Whether the provider disclosed the complainant's unique identifier to a third party without consent (Principle 4.3 PIPEDA)
  • Whether the provider failed to keep the complainant's address information accurate (Principle 4.6 PIPEDA)
  • Whether the provider failed to implement appropriate safeguards to protect personal information from unauthorized disclosure and modification (Principle 4.7 PIPEDA)
  • Whether proper authentication of the caller took place before the complainant's ID number was given out (Principle 4.7.1 PIPEDA)
  • Whether the provider's failure to detect and correct the erroneous address sooner constituted a contravention of Principle 4.6.1 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

An organization

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Key Issues
  • Whether the disclosed leave information constituted personal information under PIPEDA
  • Whether the organization's purposes for disclosing employee leave information to other employees were appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the disclosure of leave type was necessary for the organization to meet its employee schedule management needs
  • Whether the benefits of the leave exchange system were proportional to the loss of privacy experienced by employees
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apple Canada Inc.

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Key Issues
  • Whether Apple's privacy policy adequately identified the purposes for collecting date of birth information for authentication (Principle 4.2 PIPEDA)
  • Whether Apple's collection of date of birth was limited to what was necessary for identified purposes (Principle 4.4 PIPEDA)
  • Whether Apple made information about its policies and practices concerning the collection of credit card information readily available to individuals (Principle 4.8 PIPEDA)
  • Whether Apple's practices resulted in the over-collection of sensitive payment information (Principle 4.4 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 14, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-001Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-001: Use of sensitive health information for targeting of Google ads raises privacy concerns

Google Inc.

A complainant alleged that Google's AdSense service displayed targeted advertisements for sleep apnea devices on unrelated websites after he searched for medical devices online. He viewed his online activities related to sleep apnea as sensitive information requiring express consent for targeted advertising. The OPC's technical analysis confirmed that Google was delivering these ads through online behavioural advertising (OBA) and that they persisted over time. Google initially attributed this to a technical issue but later confirmed it was due to 'remarketed ads,' a form of interest-based advertising. The OPC found that Google's practice of delivering tailored ads based on sensitive health information without express consent contravened PIPEDA Principles 4.3 and 4.3.6. Google committed to several remedial measures, including rejecting relevant remarketing campaigns, revising its policies, developing new internal training, and increasing monitoring.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Report of Findings #2014-001: Use of sensitive health information for targeting of Google ads raises privacy concerns

Jan 14, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-001
Adjudicator: Chantal Bernier
Plain-Language Summary

A complainant alleged that Google's AdSense service displayed targeted advertisements for sleep apnea devices on unrelated websites after he searched for medical devices online. He viewed his online activities related to sleep apnea as sensitive information requiring express consent for targeted advertising. The OPC's technical analysis confirmed that Google was delivering these ads through online behavioural advertising (OBA) and that they persisted over time. Google initially attributed this to a technical issue but later confirmed it was due to 'remarketed ads,' a form of interest-based advertising. The OPC found that Google's practice of delivering tailored ads based on sensitive health information without express consent contravened PIPEDA Principles 4.3 and 4.3.6. Google committed to several remedial measures, including rejecting relevant remarketing campaigns, revising its policies, developing new internal training, and increasing monitoring.

Key Issues
  • Whether the delivery of targeted advertisements based on online searches for medical devices constitutes online behavioural advertising (OBA)
  • Whether information related to online searches for medical devices is sensitive personal information
  • Whether express consent is required for the collection and use of sensitive personal health information for OBA purposes
  • Whether Google obtained appropriate consent under Principle 4.3 and 4.3.6 for the use of sensitive health information for targeted advertising
  • Whether Google's privacy policy accurately reflected its practices regarding sensitive categories in tailored ads
  • Whether Google's monitoring tools for preventing policy abuses were scalable and effective