BreachOfPrivacy

Canadian Privacy Decisions

The comprehensive archive of Canadian privacy decisions from federal, provincial, and territorial commissioners — with AI-summarized plain-language summaries for every decision.

1 decision matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Dec 15, 2015PIPEDA Case Summary #2015-014· Indexed Apr 12, 2026

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

A pension and benefit provider

An employee complained that her pension and benefit provider improperly disclosed her unique identifier, failed to keep her address accurate, and did not implement adequate safeguards. An individual with the same name was mistakenly given the complainant's ID number, leading to her address being changed. Consequently, five mailings containing sensitive information were sent to the wrong address, and the complainant lost her life insurance coverage due to missed forms. The provider corrected the error and reinstated coverage.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2015-014: Pension and benefit provider agrees to revamp authentication and address-change procedures after misdirected mailings

Dec 15, 2015PIPEDA Case Summary #2015-014
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that her pension and benefit provider improperly disclosed her unique identifier, failed to keep her address accurate, and did not implement adequate safeguards. An individual with the same name was mistakenly given the complainant's ID number, leading to her address being changed. Consequently, five mailings containing sensitive information were sent to the wrong address, and the complainant lost her life insurance coverage due to missed forms. The provider corrected the error and reinstated coverage.

Key Issues
  • Disclosure of unique identifier to a third party without consent.
  • Failure to maintain accurate client address information.
  • Inadequate safeguards against unauthorized disclosure and modification of personal information.
  • Improper authentication of caller identity.