BreachOfPrivacy

Canadian Privacy Decisions

The comprehensive archive of Canadian privacy decisions from federal, provincial, and territorial commissioners — with AI-summarized plain-language summaries for every decision.

3 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Jul 31, 2023PIPEDA Findings #2023-002· Indexed Apr 12, 2026

PIPEDA Findings #2023-002: Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information

Agronomy Company of Canada Ltd.

The Office of the Privacy Commissioner of Canada investigated a complaint against Agronomy Company of Canada Ltd. (Agronomy) following a significant data breach. The investigation found that Agronomy lacked appropriate safeguards, including multi-factor authentication, network segregation, and encryption, which contributed to the breach affecting 845 individuals. The OPC also found Agronomy lacked accountability structures. However, the complaint regarding valid consent for credit services was found not well-founded. Agronomy has since made significant improvements to its security measures and accountability practices.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2023-002: Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information

Jul 31, 2023PIPEDA Findings #2023-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada investigated a complaint against Agronomy Company of Canada Ltd. (Agronomy) following a significant data breach. The investigation found that Agronomy lacked appropriate safeguards, including multi-factor authentication, network segregation, and encryption, which contributed to the breach affecting 845 individuals. The OPC also found Agronomy lacked accountability structures. However, the complaint regarding valid consent for credit services was found not well-founded. Agronomy has since made significant improvements to its security measures and accountability practices.

Key Issues
  • Adequacy of security safeguards
  • Accountability for personal information
  • Validity of consent for collection and use of personal information
Federal (Canada)Privacy ActWell-founded & conditionally resolved
May 30, 2023· Indexed Apr 12, 2026

Protecting privacy in a pandemic

Office of the Privacy Commissioner of Canada

This Special Report to Parliament details the OPC's investigations into federal government privacy practices during the COVID-19 pandemic. It examined vaccine mandates for travel and employment, the ArriveCAN app, and the use of mobility data. While most government measures complied with the Privacy Act, the OPC identified areas for improvement, including the need for clearer objectives in mandates and better documentation of less privacy-intrusive alternatives. An error in the ArriveCAN app led to incorrect quarantine notifications, and a PIPEDA investigation found a private company misused a traveller's contact information for marketing.

Quick View

Privacy ActWell-founded & conditionally resolved

Protecting privacy in a pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

This Special Report to Parliament details the OPC's investigations into federal government privacy practices during the COVID-19 pandemic. It examined vaccine mandates for travel and employment, the ArriveCAN app, and the use of mobility data. While most government measures complied with the Privacy Act, the OPC identified areas for improvement, including the need for clearer objectives in mandates and better documentation of less privacy-intrusive alternatives. An error in the ArriveCAN app led to incorrect quarantine notifications, and a PIPEDA investigation found a private company misused a traveller's contact information for marketing.

Key Issues
  • Compliance of COVID-19 measures with the Privacy Act
  • Necessity and proportionality of personal information collection
  • Accuracy of personal information used in administrative decisions (ArriveCAN)
  • Use of de-identified mobility data and PIPEDA compliance
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Feb 15, 2023· Indexed Apr 12, 2026

TBS email breach illustrates the importance of considering context when assessing impact of a breach

Treasury Board of Canada Secretariat (TBS)

Twenty federal employees complained after the Treasury Board of Canada Secretariat (TBS) mistakenly disclosed their email addresses and the fact they had filed claims for damages related to the Severe Phoenix Impacts program. The OPC found that TBS contravened the Privacy Act by improperly disclosing personal information. While TBS argued the breach was not material, the OPC disagreed, emphasizing the importance of contextual factors and the potential for harm, even if not all individuals experienced severe injury.

Quick View

Privacy ActWell-founded & conditionally resolved

TBS email breach illustrates the importance of considering context when assessing impact of a breach

Feb 15, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

Twenty federal employees complained after the Treasury Board of Canada Secretariat (TBS) mistakenly disclosed their email addresses and the fact they had filed claims for damages related to the Severe Phoenix Impacts program. The OPC found that TBS contravened the Privacy Act by improperly disclosing personal information. While TBS argued the breach was not material, the OPC disagreed, emphasizing the importance of contextual factors and the potential for harm, even if not all individuals experienced severe injury.

Key Issues
  • Was the disclosure of personal information authorized under the Privacy Act?
  • Was the privacy breach considered "material" by TBS?
  • Did TBS conduct a holistic and context-informed assessment of the breach's materiality and potential harm?