The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

4 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Nov 26, 2019PIPEDA Findings #2019-004Indexed Jun 30, 2026

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

AggregateIQ Data Services Ltd.

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Nov 26, 2019PIPEDA Findings #2019-004
Adjudicator: Daniel Therrien
Plain-Language Summary

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Key Issues
  • Whether AIQ was compliant with consent requirements for the collection, use, or disclosure of personal information under PIPEDA and PIPA.
  • Whether AIQ could rely on consent obtained by its clients for its own collection, use, and disclosure of personal information.
  • Whether consent was adequate for specific uses, such as disclosing personal information to Facebook for "custom audiences" and "lookalike audiences."
  • Whether consent was adequate for sensitive personal information, such as political opinions or psychographic profiles.
  • Whether AIQ took reasonable security measures to protect the personal information in its custody or control under PIPEDA and PIPA.
  • Whether the security breach involving the GitLab repository constituted a failure of reasonable security measures.
  • Whether personal information collected from public telephone directories required consent.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 9, 2019PIPEDA Findings #2019-001Indexed Jun 30, 2026

PIPEDA Findings #2019-001: Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information

Equifax Canada Co.

The Office of the Privacy Commissioner of Canada (OPC) investigated a 2017 data breach that compromised the personal information of approximately 19,000 Canadians held by Equifax Inc., the US parent company of Equifax Canada Co. The investigation examined the adequacy of security safeguards by both entities, Equifax Canada's accountability for data processed by Equifax Inc., the validity of consent obtained for data transfers, retention practices, and the sufficiency of post-breach mitigation measures. The OPC concluded that both Equifax Inc. and Equifax Canada contravened PIPEDA in all these areas, citing inadequate vulnerability management, network segregation, basic information security practices, and oversight. Equifax Canada signed a compliance agreement, committing to corrective measures for most findings, which were deemed well-founded and conditionally resolved. However, the finding regarding post-breach safeguards was only partially resolved, as Equifax Canada committed to extended credit monitoring but not a free credit freeze product.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-001: Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information

Apr 9, 2019PIPEDA Findings #2019-001
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a 2017 data breach that compromised the personal information of approximately 19,000 Canadians held by Equifax Inc., the US parent company of Equifax Canada Co. The investigation examined the adequacy of security safeguards by both entities, Equifax Canada's accountability for data processed by Equifax Inc., the validity of consent obtained for data transfers, retention practices, and the sufficiency of post-breach mitigation measures. The OPC concluded that both Equifax Inc. and Equifax Canada contravened PIPEDA in all these areas, citing inadequate vulnerability management, network segregation, basic information security practices, and oversight. Equifax Canada signed a compliance agreement, committing to corrective measures for most findings, which were deemed well-founded and conditionally resolved. However, the finding regarding post-breach safeguards was only partially resolved, as Equifax Canada committed to extended credit monitoring but not a free credit freeze product.

Key Issues
  • Whether Equifax Inc.'s security safeguards were appropriate to the sensitivity of the information as required by PIPEDA Safeguards Principle 4.7.
  • Whether Equifax Inc.'s retention and destruction practices for Canadian personal information complied with PIPEDA Principle 4.5.
  • Whether Equifax Canada demonstrated adequate accountability for protecting Canadian personal information handled by Equifax Inc. as required under PIPEDA Principle 4.1.
  • Whether there was adequate consent from Canadians for the collection of their personal information by Equifax Inc. and disclosure to Equifax Inc. by Equifax Canada, as required under PIPEDA Principle 4.3 and s.6.1.
  • Whether Equifax Canada's security safeguards for personal information it held directly were appropriate as required by PIPEDA Safeguards Principle 4.7.
  • Whether the post-breach mitigation measures offered by Equifax Canada were adequate to protect against unauthorized use of compromised personal information as required by PIPEDA Safeguards Principle 4.7.1.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2019PIPEDA Case Summary #2019-006Indexed Jun 30, 2026

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Grey House Publishing Canada

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Mar 28, 2019PIPEDA Case Summary #2019-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Key Issues
  • Whether the complainant's contact information constituted 'personal information' under PIPEDA
  • Whether Grey House Publishing Canada was engaged in 'commercial activity' under PIPEDA
  • Whether Grey House obtained adequate consent for the collection, use, and disclosure of the complainant's personal information
  • Whether the 'publicly available information' exceptions to consent applied
  • Whether Grey House's privacy statement met the 'openness' principle under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 25, 2019PIPEDA Findings #2019-005Indexed Jun 30, 2026

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

411Numbers

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

Mar 25, 2019PIPEDA Findings #2019-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Key Issues
  • Whether the OPC had jurisdiction over 411Numbers, a Hong Kong-incorporated company with servers outside Canada, due to a 'real and substantial connection' to Canada.
  • Whether 411Numbers collected, used, and disclosed the complainant's personal information (unlisted phone number, name, address) without knowledge and consent, contravening Principle 4.3.
  • Whether information associated with unlisted telephone numbers constitutes 'publicly available' information under paragraph 1(a) of the Regulations Specifying Publicly Available Information.
  • Whether 411Numbers exercised due diligence to ensure its databases did not include unlisted numbers.
  • Whether publishing personal information for the purpose of encouraging individuals to pay to have it removed constitutes an inappropriate purpose under s. 5(3) of PIPEDA.
  • Whether 411Numbers required individuals to provide more information than necessary for removal services, contravening Principle 4.3.3.
  • Whether 411Numbers met its obligations regarding accountability under Principles 4.1, 4.1.2, and 4.1.4.
  • Whether 411Numbers met its obligations regarding openness under Principle 4.8 and 4.8.3.
  • Whether 411Numbers met its obligations regarding challenging compliance under Principle 4.10.