The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

3 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 20, 2017PIPEDA Case Summary #2017-006Indexed Jun 30, 2026

PIPEDA Case Summary #2017-006: Using SIN for identity verification cannot be a condition of service

A financial institution

A complainant alleged that a financial institution required customers to provide their Social Insurance Number (SIN) to credit reporting agencies for identity verification when opening a savings account, even though the SIN was not needed for income reporting. The financial institution argued that using the SIN for identity verification was beneficial for maintaining data integrity and cited FINTRAC guidelines. The OPC reviewed FINTRAC and Employment and Social Development Canada (ESDC) guidelines and found no requirement or suggestion for using SINs for identity verification. The OPC concluded that requiring consent for this practice as a condition of service contravened Principle 4.3.3 of PIPEDA. The financial institution agreed to make the use of SIN for identity verification optional, and the complaint was deemed well-founded and conditionally resolved. A follow-up confirmed full compliance.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2017-006: Using SIN for identity verification cannot be a condition of service

Dec 20, 2017PIPEDA Case Summary #2017-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a financial institution required customers to provide their Social Insurance Number (SIN) to credit reporting agencies for identity verification when opening a savings account, even though the SIN was not needed for income reporting. The financial institution argued that using the SIN for identity verification was beneficial for maintaining data integrity and cited FINTRAC guidelines. The OPC reviewed FINTRAC and Employment and Social Development Canada (ESDC) guidelines and found no requirement or suggestion for using SINs for identity verification. The OPC concluded that requiring consent for this practice as a condition of service contravened Principle 4.3.3 of PIPEDA. The financial institution agreed to make the use of SIN for identity verification optional, and the complaint was deemed well-founded and conditionally resolved. A follow-up confirmed full compliance.

Key Issues
  • Whether requiring a SIN for identity verification as a condition of service contravenes Principle 4.3.3 of PIPEDA
  • Whether FINTRAC or ESDC guidelines require or suggest the use of SINs for identity verification
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 14, 2017PIPEDA Report of Findings #2017-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-003: Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process

An insurance company

An individual complained that an insurance company collected and used his credit score without meaningful consent during an auto insurance claims assessment, over-collected his credit file, and used the score for an inappropriate purpose. The OPC found that the insurance company failed to demonstrate that collecting and using credit scores for fraud detection in auto claims was an appropriate purpose under PIPEDA subsection 5(3) or a "direct business need" under Ontario's Consumer Reporting Act. The OPC also determined that the company did not obtain meaningful consent because it failed to clearly advise the complainant that providing his credit score was optional, contrary to Principle 4.3. Furthermore, the company was found not to be open about its practices regarding credit score collection and use, violating Principle 4.8.1, due to insufficient notifications and inaccurate employee scripts. The allegation of over-collection was not substantiated, as only the credit score was provided. In response to the OPC's preliminary report, the insurance company agreed to cease collecting credit scores for auto accident benefit claims and review its practices for other insurance types. The matter was concluded as well-founded and conditionally resolved, pending the full implementation of these agreed-upon changes.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2017-003: Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process

Mar 14, 2017PIPEDA Report of Findings #2017-003
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an insurance company collected and used his credit score without meaningful consent during an auto insurance claims assessment, over-collected his credit file, and used the score for an inappropriate purpose. The OPC found that the insurance company failed to demonstrate that collecting and using credit scores for fraud detection in auto claims was an appropriate purpose under PIPEDA subsection 5(3) or a "direct business need" under Ontario's Consumer Reporting Act. The OPC also determined that the company did not obtain meaningful consent because it failed to clearly advise the complainant that providing his credit score was optional, contrary to Principle 4.3. Furthermore, the company was found not to be open about its practices regarding credit score collection and use, violating Principle 4.8.1, due to insufficient notifications and inaccurate employee scripts. The allegation of over-collection was not substantiated, as only the credit score was provided. In response to the OPC's preliminary report, the insurance company agreed to cease collecting credit scores for auto accident benefit claims and review its practices for other insurance types. The matter was concluded as well-founded and conditionally resolved, pending the full implementation of these agreed-upon changes.

Key Issues
  • Whether collecting and using a credit score for fraud detection during auto insurance claims assessment is an appropriate purpose under subsection 5(3) of PIPEDA.
  • Whether the insurance company had a "direct business need" for credit scores under Ontario's Consumer Reporting Act (CRA) s.8(1)(d)(vi) for fraud detection in auto claims.
  • Whether the insurance company over-collected personal information by obtaining the complainant's entire credit file.
  • Whether the insurance company properly identified the purposes for collecting the complainant's credit score under Principle 4.2.
  • Whether the insurance company obtained meaningful consent for collecting the credit score, specifically if it advised the complainant that providing the information was optional, under Principle 4.3.
  • Whether the insurance company was open about its policies and practices regarding credit score collection and use under Principle 4.8.1.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 10, 2017PIPEDA Case Summary #2017-005Indexed Jun 30, 2026

PIPEDA Case Summary #2017-005: Insurance company required to delete individual’s personal information after individual withdraws consent

An insurance company

An individual complained that his former automobile insurance company refused to delete his personal information from its records and from third-party organizations. The company initially refused, citing the need to provide insurance history to other insurers. The OPC reframed the request as a withdrawal of consent, and the company subsequently agreed to delete the information from its own records, as there was no legal requirement to retain it. However, the OPC found that the company was not obligated to ensure deletion from third-party records if the information was lawfully disclosed. The investigation also revealed the company lacked clear documentation regarding its disclosure practices to third parties, contravening Principle 4.1.4(d). The company committed to developing a document to track disclosures, which it later provided to the OPC.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2017-005: Insurance company required to delete individual’s personal information after individual withdraws consent

Feb 10, 2017PIPEDA Case Summary #2017-005
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that his former automobile insurance company refused to delete his personal information from its records and from third-party organizations. The company initially refused, citing the need to provide insurance history to other insurers. The OPC reframed the request as a withdrawal of consent, and the company subsequently agreed to delete the information from its own records, as there was no legal requirement to retain it. However, the OPC found that the company was not obligated to ensure deletion from third-party records if the information was lawfully disclosed. The investigation also revealed the company lacked clear documentation regarding its disclosure practices to third parties, contravening Principle 4.1.4(d). The company committed to developing a document to track disclosures, which it later provided to the OPC.

Key Issues
  • Whether the insurance company was required to delete the individual's personal information from its own records upon withdrawal of consent
  • Whether the insurance company was required to ensure deletion of the individual's personal information from third-party organizations' records after lawful disclosure
  • Whether the insurance company contravened Principle 4.1.4(d) by lacking a clear explanation of its disclosure practices to third parties