The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

6 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 10, 2021Indexed Jun 30, 2026

Police use of Facial Recognition Technology in Canada and the way forward

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP)'s use of facial recognition technology from Clearview AI. The OPC found that the RCMP contravened Section 4 of the Privacy Act by collecting personal information from Clearview AI, as Clearview AI itself had collected this information unlawfully under PIPEDA and provincial privacy laws. The investigation revealed serious and systemic gaps in the RCMP's policies and systems for tracking, identifying, assessing, and controlling novel collections of personal information. Although the RCMP disagreed with the finding of contravention, it committed to implementing the OPC's recommendations for systemic changes, improved training, and robust controls. The OPC concluded that the matter was well-founded and conditionally resolved, pending the full implementation of these recommendations.

Quick view

Privacy ActWell-founded & conditionally resolved

Police use of Facial Recognition Technology in Canada and the way forward

Jun 10, 2021
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP)'s use of facial recognition technology from Clearview AI. The OPC found that the RCMP contravened Section 4 of the Privacy Act by collecting personal information from Clearview AI, as Clearview AI itself had collected this information unlawfully under PIPEDA and provincial privacy laws. The investigation revealed serious and systemic gaps in the RCMP's policies and systems for tracking, identifying, assessing, and controlling novel collections of personal information. Although the RCMP disagreed with the finding of contravention, it committed to implementing the OPC's recommendations for systemic changes, improved training, and robust controls. The OPC concluded that the matter was well-founded and conditionally resolved, pending the full implementation of these recommendations.

Key Issues
  • Whether the RCMP's collection of personal information from Clearview AI was directly related to an operating program or activity under Section 4 of the Privacy Act.
  • Whether a government institution can collect personal information from a third party that collected the information unlawfully.
  • Whether the RCMP had adequate controls to prevent future similar contraventions when collecting novel personal information.
  • Whether the RCMP had sufficient knowledge of its obligations under the Privacy Act and common law regarding personal information collection.
  • Whether the RCMP had adequate awareness and tracking systems for novel personal information collections.
  • Whether the RCMP had processes to identify potential compliance issues before undertaking novel collections.
  • Whether the RCMP had processes to complete timely assessments (like PIAs) when warranted.
  • Whether the RCMP had effective controls on collection, including policies and monitoring for unauthorized collections.
  • Whether the RCMP's use of Clearview AI constituted a justifiable exercise of police powers under common law (Waterfield test).
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 3, 2021Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data ProjectIndexed Jun 30, 2026

Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data Project: Final Report

Statistics Canada

This report is a compliance monitoring review by the Office of the Privacy Commissioner (OPC) of Statistics Canada's (StatCan) redesigned Financial Transactions Project and Credit Agency Data Project. It follows an earlier OPC investigation that found no contraventions of the Privacy Act but identified significant privacy concerns, leading to recommendations for StatCan to incorporate necessity and proportionality principles. The OPC assessed StatCan's progress, noting reductions in data collection and the implementation of privacy-enhancing measures like a data ethics secretariat and an external ethics body. However, the OPC found that the redesigned project plans still lacked sufficient specificity in describing public goals, failed to demonstrate effectiveness, and did not adequately analyze privacy impacts in context. The OPC concluded that while progress was made, "more work needs to be done" to fully meet its assessment criteria for necessity and proportionality. Consequently, the OPC issued four new recommendations, including describing public goals with greater precision, revisiting effectiveness, analyzing privacy in context, and resubmitting the plans for further review before final implementation. The outcome is classified as well-founded-conditionally-resolved, reflecting partial implementation and the need for further action.

Quick view

Privacy ActWell-founded & conditionally resolved

Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data Project: Final Report

May 3, 2021Office of the Privacy Commissioner Compliance Monitoring of Statistics Canada’s Financial Transactions Project and Credit Agency Data Project
Adjudicator: Daniel Therrien
Plain-Language Summary

This report is a compliance monitoring review by the Office of the Privacy Commissioner (OPC) of Statistics Canada's (StatCan) redesigned Financial Transactions Project and Credit Agency Data Project. It follows an earlier OPC investigation that found no contraventions of the Privacy Act but identified significant privacy concerns, leading to recommendations for StatCan to incorporate necessity and proportionality principles. The OPC assessed StatCan's progress, noting reductions in data collection and the implementation of privacy-enhancing measures like a data ethics secretariat and an external ethics body. However, the OPC found that the redesigned project plans still lacked sufficient specificity in describing public goals, failed to demonstrate effectiveness, and did not adequately analyze privacy impacts in context. The OPC concluded that while progress was made, "more work needs to be done" to fully meet its assessment criteria for necessity and proportionality. Consequently, the OPC issued four new recommendations, including describing public goals with greater precision, revisiting effectiveness, analyzing privacy in context, and resubmitting the plans for further review before final implementation. The outcome is classified as well-founded-conditionally-resolved, reflecting partial implementation and the need for further action.

Key Issues
  • Whether the redesigned Financial Transactions Project and Credit Agency Data Project met the principles of necessity and proportionality.
  • Whether the public goals of the projects were described with a level of specificity and precision commensurate with privacy impacts.
  • Whether the effectiveness of the projects was demonstrated.
  • Whether privacy impacts were given sufficient analysis in context, considering risk of harm to individuals and broad-based harms.
  • Whether StatCan's Necessity and Proportionality Framework aligned with OPC's assessment criteria.
  • Whether less privacy-intrusive alternatives were adequately considered and compared.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-009Indexed Jun 30, 2026

PIPEDA Findings #2021-009: Opt-in consent required for a donor list trading program

A charitable organization

A complainant alleged that a charitable organization (the Respondent) failed to obtain proper consent before sharing his personal information through a donor list trading program. The Respondent used an opt-out checkbox on its mail-in donation forms, which the complainant found inadequate after receiving solicitations from another charity. The OPC determined that sharing donor information with other charities for solicitation purposes was outside the reasonable expectations of donors, thus requiring express opt-in consent. Furthermore, the information provided by the Respondent on its donation forms, inserts, and privacy policy was deemed insufficient to enable meaningful consent. The OPC recommended that the Respondent obtain express opt-in consent and enhance its privacy communications to clearly explain the nature, purpose, and consequences of the data sharing. The Respondent agreed to implement these recommendations, leading to a conditionally resolved outcome.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-009: Opt-in consent required for a donor list trading program

Mar 30, 2021PIPEDA Findings #2021-009
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a charitable organization (the Respondent) failed to obtain proper consent before sharing his personal information through a donor list trading program. The Respondent used an opt-out checkbox on its mail-in donation forms, which the complainant found inadequate after receiving solicitations from another charity. The OPC determined that sharing donor information with other charities for solicitation purposes was outside the reasonable expectations of donors, thus requiring express opt-in consent. Furthermore, the information provided by the Respondent on its donation forms, inserts, and privacy policy was deemed insufficient to enable meaningful consent. The OPC recommended that the Respondent obtain express opt-in consent and enhance its privacy communications to clearly explain the nature, purpose, and consequences of the data sharing. The Respondent agreed to implement these recommendations, leading to a conditionally resolved outcome.

Key Issues
  • Whether the Respondent obtained meaningful consent for its donor list trading program under PIPEDA
  • Whether opt-out consent was appropriate for sharing donor information with third parties
  • Whether the information shared (donor name, address, donation status) was sensitive in this context
  • Whether sharing donor information with other charities for solicitation was within the reasonable expectations of donors
  • Whether the donor list trading program created a meaningful residual risk of significant harm
  • Whether the information provided to donors on the donation form, insert, and privacy policy was sufficient to support meaningful consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-004Indexed Jun 30, 2026

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Fido Solutions Inc. (a subsidiary of Rogers Communications Inc.)

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Mar 30, 2021PIPEDA Findings #2021-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Key Issues
  • Whether Fido adequately safeguarded the Complainant’s personal information under Principle 4.7
  • Whether Fido responded to the Complainant’s access request in a generally understandable format under Principle 4.9 and 4.9.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 29, 2021PIPEDA Findings #2021-002Indexed Jun 30, 2026

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

CoreFour Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

Mar 29, 2021PIPEDA Findings #2021-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Key Issues
  • Whether CoreFour's security safeguards were appropriate to the sensitivity and volume of personal information under Principle 4.7 PIPEDA
  • Whether CoreFour's weak password requirements for certain Edsby parental accounts constituted an inadequate safeguard
  • Whether CoreFour's safeguards to protect against unauthorized access to thumbnail images of student profile pictures were adequate
  • Whether Edsby's failure to scan for malware when uploading content from third-party applications constituted a safeguard weakness
  • Whether CoreFour lacked a robust overarching information security framework, contravening Principle 4.1.4 and 4.7-4.7.3 PIPEDA
  • Whether CoreFour had an adequate mechanism for handling and reporting privacy breaches under PIPEDA
  • Whether CoreFour was required to report the password management vulnerability, given it occurred before mandatory breach reporting came into effect
  • Whether the student image vulnerability created a "real risk of significant harm" requiring mandatory reporting and notification under s.10.1 PIPEDA
  • Whether CoreFour maintained a breach register as required under s.10.3 PIPEDA
  • Whether CoreFour lacked a privacy management framework, including appropriate written internal policies and practices (e.g., complaint handling, data retention), contravening Principle 4.1.4 PIPEDA
  • Whether CoreFour provided adequate privacy training to its employees, consultants, contractors, and students
  • Whether CoreFour's Privacy Policy was unclear regarding the characterization of personal information, its responsibility for security, and the sharing of user information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 15, 2021PIPEDA Findings #2021-005Indexed Jun 30, 2026

PIPEDA Findings #2021-005: Staying signed in by default to email services poses serious privacy concerns for users accessing their email on a public or shared computer

Yahoo! Canada

The complainant alleged that Yahoo! Canada's default "Stay signed in" setting for Yahoo Mail, particularly for Rogers Yahoo Mail users, posed significant privacy concerns on public or shared computers. The OPC investigated whether Yahoo adequately safeguarded against unauthorized access and obtained valid consent for potential disclosures. The OPC found that Yahoo's safeguards were not appropriate for the sensitivity of email content and that its consent for the "Stay signed in" setting was not meaningful. Yahoo committed to changing the setting to opt-in and providing clearer information about privacy implications. Rogers, while not a respondent, also agreed to implement measures for Rogers Yahoo Mail users. The complaint was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-005: Staying signed in by default to email services poses serious privacy concerns for users accessing their email on a public or shared computer

Mar 15, 2021PIPEDA Findings #2021-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Yahoo! Canada's default "Stay signed in" setting for Yahoo Mail, particularly for Rogers Yahoo Mail users, posed significant privacy concerns on public or shared computers. The OPC investigated whether Yahoo adequately safeguarded against unauthorized access and obtained valid consent for potential disclosures. The OPC found that Yahoo's safeguards were not appropriate for the sensitivity of email content and that its consent for the "Stay signed in" setting was not meaningful. Yahoo committed to changing the setting to opt-in and providing clearer information about privacy implications. Rogers, while not a respondent, also agreed to implement measures for Rogers Yahoo Mail users. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether Yahoo's safeguards against unauthorized third-party access to email content on public or shared computers were adequate under Principle 4.7 PIPEDA
  • Whether Yahoo obtained valid and meaningful consent for the disclosure of personal information to others who subsequently access emails via the "Stay signed in" setting under Principle 4.3 PIPEDA
  • Whether the "Stay signed in" setting was clearly and prominently displayed
  • Whether a reasonable person would understand the "Stay signed in" setting to be "on" by default
  • Whether the "Stay signed in" setting is consistent with industry standards
  • Whether Yahoo's additional safeguards (algorithm, sign-out option, session expiration, password reset, security information) were effective
  • Whether express opt-in consent was required for the "Stay signed in" setting due to sensitivity of information, reasonable expectations, and risk of harm
  • Whether the language "stay signed in" provided users with key information for meaningful consent