The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

3 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 31, 2023PIPEDA Findings #2023-002Indexed Jun 30, 2026

PIPEDA Findings #2023-002: Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information

Agronomy Company of Canada Ltd.

The Office of the Privacy Commissioner of Canada (OPC) investigated Agronomy Company of Canada Ltd. following a complaint alleging inadequate safeguards, lack of accountability, and invalid consent for personal information collection and use, stemming from a data breach. A malicious actor gained access to Agronomy's systems, exfiltrating sensitive personal information of 845 individuals, including SINs, financial details, and identification documents, before deploying ransomware. The OPC found Agronomy failed to implement appropriate safeguards, citing a lack of multifactor authentication, network segregation, data encryption, and detection tools, which contributed to the breach. Furthermore, Agronomy lacked a comprehensive privacy policy, a designated privacy officer, and adequate staff training, indicating a failure in accountability. While these two aspects were found well-founded, Agronomy committed to significant improvements, leading to a conditionally resolved outcome. However, the OPC found the complaint regarding invalid consent for credit services not well-founded, as the complainant had signed a clearly labelled credit application and utilized the extended credit.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2023-002: Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information

Jul 31, 2023PIPEDA Findings #2023-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated Agronomy Company of Canada Ltd. following a complaint alleging inadequate safeguards, lack of accountability, and invalid consent for personal information collection and use, stemming from a data breach. A malicious actor gained access to Agronomy's systems, exfiltrating sensitive personal information of 845 individuals, including SINs, financial details, and identification documents, before deploying ransomware. The OPC found Agronomy failed to implement appropriate safeguards, citing a lack of multifactor authentication, network segregation, data encryption, and detection tools, which contributed to the breach. Furthermore, Agronomy lacked a comprehensive privacy policy, a designated privacy officer, and adequate staff training, indicating a failure in accountability. While these two aspects were found well-founded, Agronomy committed to significant improvements, leading to a conditionally resolved outcome. However, the OPC found the complaint regarding invalid consent for credit services not well-founded, as the complainant had signed a clearly labelled credit application and utilized the extended credit.

Key Issues
  • Whether Agronomy implemented appropriate safeguards to adequately protect personal information under its control, as per PIPEDA Principle 4.7.
  • Whether Agronomy's technical safeguards (multifactor authentication, network segregation, data encryption, detection and response tools) were appropriate for the sensitivity of the information.
  • Whether Agronomy's organizational safeguards (incident response protocols, information management, security documentation, staff training) were adequate.
  • Whether Agronomy was accountable for personal information under its control, including designating an individual for PIPEDA compliance and implementing policies and practices, as per PIPEDA Principle 4.1.
  • Whether Agronomy obtained valid and meaningful consent for the collection and use of personal information for credit services, particularly sensitive information, as per PIPEDA Principle 4.3.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Protecting privacy in a pandemic

Federal Government Institutions and Biron Health Group

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

Quick view

Privacy ActWell-founded & conditionally resolved

Protecting privacy in a pandemic

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

Key Issues
  • Whether the collection of COVID-19 vaccination status for domestic travel was lawful under the Privacy Act
  • Whether the collection of COVID-19 vaccination status for domestic travel was necessary and proportional
  • Whether the handling of personal information collected for domestic travel vaccine mandates was reasonable
  • Whether the collection of COVID-19 vaccination status for entry into Canada was lawful under the Privacy Act
  • Whether the collection of COVID-19 vaccination status for entry into Canada was necessary and proportional
  • Whether the collection of federal employees' vaccination status and related medical/religious information was lawful under the Privacy Act
  • Whether the collection of federal employees' vaccination status and related medical/religious information was necessary and proportional
  • Whether the Monitor-MASS system used by DND/CAF had adequate oversight to prevent unauthorized access to personal information
  • Whether there were inappropriate disclosures of personal information related to federal employee vaccination status
  • Whether the Treasury Board of Canada contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description
  • Whether the Canada Border Services Agency (CBSA) took all reasonable steps to ensure the accuracy of information in the ArriveCAN app under section 6 of the Privacy Act
  • Whether the collection and use of de-identified mobility data by PHAC constituted the collection of personal information under the Privacy Act
  • Whether Biron Health Group obtained valid consent under PIPEDA for using personal information collected for COVID-19 testing for marketing purposes
  • Whether information sharing by RCMP, FINTRAC, and CSIS under the Emergencies Act complied with the Privacy Act
  • Whether information sharing under the Emergencies Act was necessary and proportionate
  • Whether there was clear direction and guidance for information sharing under the Emergencies Act
  • Whether appropriate safeguards were in place for personal information shared under the Emergencies Act
  • The need for modernized privacy laws to address necessity, proportionality, and de-identified information
  • The importance of transparency and accountability in government initiatives involving personal information during crises
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2023Indexed Jun 30, 2026

TBS email breach illustrates the importance of considering context when assessing impact of a breach

Treasury Board of Canada Secretariat (TBS)

Twenty complainants, current or former federal government employees, alleged that the Treasury Board of Canada Secretariat (TBS) improperly disclosed their personal information. TBS mistakenly sent two emails to 400 applicants for the Severe Phoenix Impacts program using the 'cc' field instead of 'bcc', revealing email addresses (some with names) and the fact they had filed a claim for Phoenix-related damages. The OPC found that the disclosure was not authorized under the Privacy Act, making the complaints well-founded. While TBS acknowledged the error, it initially deemed the breach non-material, a conclusion the OPC disagreed with, emphasizing the importance of contextual factors in assessing harm. TBS agreed to implement two of the OPC's three recommendations, but not the one concerning incorporating the findings on materiality into its policy instruments. The OPC concluded the complaints were well-founded and conditionally resolved in part, expressing ongoing concern about TBS's assessment of breach materiality.

Quick view

Privacy ActWell-founded & conditionally resolved

TBS email breach illustrates the importance of considering context when assessing impact of a breach

Feb 15, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

Twenty complainants, current or former federal government employees, alleged that the Treasury Board of Canada Secretariat (TBS) improperly disclosed their personal information. TBS mistakenly sent two emails to 400 applicants for the Severe Phoenix Impacts program using the 'cc' field instead of 'bcc', revealing email addresses (some with names) and the fact they had filed a claim for Phoenix-related damages. The OPC found that the disclosure was not authorized under the Privacy Act, making the complaints well-founded. While TBS acknowledged the error, it initially deemed the breach non-material, a conclusion the OPC disagreed with, emphasizing the importance of contextual factors in assessing harm. TBS agreed to implement two of the OPC's three recommendations, but not the one concerning incorporating the findings on materiality into its policy instruments. The OPC concluded the complaints were well-founded and conditionally resolved in part, expressing ongoing concern about TBS's assessment of breach materiality.

Key Issues
  • Whether the disclosure of personal information via email was authorized under the Privacy Act
  • Whether the privacy breach was 'material' in nature according to TBS's guidelines
  • Whether TBS's assessment of the breach's materiality was appropriate
  • Whether the context of the personal information disclosed should be considered when assessing the risk of injury or harm