The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

7 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 14, 2022Indexed Jun 30, 2026

IRCC email breach creates risk of harm to individuals seeking Afghan emergency assistance

Immigration, Refugees and Citizenship Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach involving 636 individuals seeking emergency assistance related to the situation in Afghanistan. IRCC inadvertently disclosed recipients' email addresses, and in some cases thumbnail photos, by using the "TO" field instead of "BCC" in four mass emails. This disclosure revealed that individuals had inquired about sensitive emergency measures, posing potential life-threatening risks. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose. While IRCC took immediate steps to mitigate the impact on affected individuals, the OPC determined that its preventative measures were initially insufficient. IRCC subsequently revised its internal procedures, implemented a "two pairs of eyes" rule, limited recipients, introduced a secure webform, and committed to exploring further technological solutions. The OPC was satisfied with IRCC's actions and considered the matter closed.

Quick view

Privacy ActWell-founded & conditionally resolved

IRCC email breach creates risk of harm to individuals seeking Afghan emergency assistance

Dec 14, 2022
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach involving 636 individuals seeking emergency assistance related to the situation in Afghanistan. IRCC inadvertently disclosed recipients' email addresses, and in some cases thumbnail photos, by using the "TO" field instead of "BCC" in four mass emails. This disclosure revealed that individuals had inquired about sensitive emergency measures, posing potential life-threatening risks. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose. While IRCC took immediate steps to mitigate the impact on affected individuals, the OPC determined that its preventative measures were initially insufficient. IRCC subsequently revised its internal procedures, implemented a "two pairs of eyes" rule, limited recipients, introduced a secure webform, and committed to exploring further technological solutions. The OPC was satisfied with IRCC's actions and considered the matter closed.

Key Issues
  • Whether IRCC's disclosure of personal information via mass email contravened section 8 of the Privacy Act
  • Whether IRCC had sufficient administrative and procedural controls in place to prevent accidental disclosures of sensitive personal information when communicating by mass email
  • Whether IRCC's measures to mitigate the impact of the incident on affected individuals were adequate
  • Whether IRCC's actions to reduce the risk of recurrence of similar incidents in the future were adequate
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 27, 2022PIPEDA Findings #2022-006Indexed Jun 30, 2026

PIPEDA Findings #2022-006: Investigation into Trimac’s use of an audio and video surveillance device in its truck cabins

Trimac Transportation Services Inc.

A truck driver complained that Trimac Transportation Services Inc. (Trimac) installed a dash camera in his vehicle that continuously recorded audio and video without his consent, particularly concerned with audio recording. The OPC investigated two main issues: the appropriateness of the audio recording functionality and whether employee consent was required. The OPC found that Trimac's continuous audio recording, even when drivers were off-duty, was disproportionately privacy-intrusive, despite legitimate business needs. Trimac also initially failed to be transparent about the disciplinary purposes of the system, meaning it could not rely on the employment relationship exception to consent. Trimac agreed to implement recommendations to limit audio recording to on-duty hours and restrict access to recorded clips, and has since clarified the system's disciplinary uses to employees. The OPC found the audio recording issue well-founded and conditionally resolved, and the consent issue well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-006: Investigation into Trimac’s use of an audio and video surveillance device in its truck cabins

Jul 27, 2022PIPEDA Findings #2022-006
Adjudicator: Philippe Dufresne
Plain-Language Summary

A truck driver complained that Trimac Transportation Services Inc. (Trimac) installed a dash camera in his vehicle that continuously recorded audio and video without his consent, particularly concerned with audio recording. The OPC investigated two main issues: the appropriateness of the audio recording functionality and whether employee consent was required. The OPC found that Trimac's continuous audio recording, even when drivers were off-duty, was disproportionately privacy-intrusive, despite legitimate business needs. Trimac also initially failed to be transparent about the disciplinary purposes of the system, meaning it could not rely on the employment relationship exception to consent. Trimac agreed to implement recommendations to limit audio recording to on-duty hours and restrict access to recorded clips, and has since clarified the system's disciplinary uses to employees. The OPC found the audio recording issue well-founded and conditionally resolved, and the consent issue well-founded and resolved.

Key Issues
  • Whether road safety, asset protection, and employee performance management are appropriate purposes for the continuous collection of in-cabin audio via the System, including when drivers are off-duty and not driving, under subsection 5(3) of PIPEDA.
  • Whether the collection of sensitive personal information (in-cabin audio) was justified given the legitimate need, effectiveness, less privacy-invasive means, and proportionality.
  • Whether employee consent was required for the collection of personal information via the System, specifically whether Trimac could rely on the exception to consent under subsection 7.3 of PIPEDA.
  • Whether Trimac was sufficiently transparent about the disciplinary purposes of its dash camera system to rely on the subsection 7.3 exception to consent.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 15, 2022PIPEDA Findings #2022-005Indexed Jun 30, 2026

PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor

Marriott International, Inc.

On November 30, 2018, Marriott International, Inc. announced a data security breach involving unauthorized access to a Starwood Hotels database, which it had acquired in 2016. The breach, spanning over four years, affected up to 12.8 million Canadian records, including passport and payment card details. The OPC launched an investigation into Luxury Hotels Canada, Marriott's Canadian operating company, following eleven complaints. The investigation found Marriott's security safeguards, accountability measures, and information retention practices to be inadequate, contravening PIPEDA Principles 4.7, 4.1.4, and 4.5. Specifically, Marriott failed to detect the breach sooner due to insufficient logging, monitoring, and multi-factor authentication, and retained personal information longer than necessary. While Marriott's notification to affected individuals was deemed adequate, the OPC had outstanding concerns regarding remote access, unencrypted data storage, and retention periods. The findings are well-founded and conditionally resolved, as Marriott committed to implementing the OPC's recommendations, including engaging an external assessor and reviewing its privacy framework.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor

Jul 15, 2022PIPEDA Findings #2022-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

On November 30, 2018, Marriott International, Inc. announced a data security breach involving unauthorized access to a Starwood Hotels database, which it had acquired in 2016. The breach, spanning over four years, affected up to 12.8 million Canadian records, including passport and payment card details. The OPC launched an investigation into Luxury Hotels Canada, Marriott's Canadian operating company, following eleven complaints. The investigation found Marriott's security safeguards, accountability measures, and information retention practices to be inadequate, contravening PIPEDA Principles 4.7, 4.1.4, and 4.5. Specifically, Marriott failed to detect the breach sooner due to insufficient logging, monitoring, and multi-factor authentication, and retained personal information longer than necessary. While Marriott's notification to affected individuals was deemed adequate, the OPC had outstanding concerns regarding remote access, unencrypted data storage, and retention periods. The findings are well-founded and conditionally resolved, as Marriott committed to implementing the OPC's recommendations, including engaging an external assessor and reviewing its privacy framework.

Key Issues
  • Whether personal information held by Marriott was protected by security safeguards appropriate to the sensitivity of the information as required by Principle 4.7 (Safeguards).
  • Whether Marriott demonstrated due diligence and took steps to fulfil its responsibilities to implement policies and practices to protect personal information under Principle 4.1.4 (Accountability) when acquiring control of the Starwood network.
  • Whether Marriott retained personal information for longer than necessary, relevant to Principle 4.5 (Limiting use, disclosure and retention).
  • Whether the mitigation measures offered by Marriott to affected individuals were adequate to protect their personal information from unauthorized use, such as future identity theft, in accordance with Principle 4.7 (Safeguards).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 1, 2022PIPEDA Findings #2022-001Indexed Jun 30, 2026

PIPEDA Findings #2022-001: Joint investigation into location tracking by the Tim Hortons App

The TDL Group Corp. (Tim Hortons)

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-001: Joint investigation into location tracking by the Tim Hortons App

Jun 1, 2022PIPEDA Findings #2022-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

Key Issues
  • Whether Tim Hortons collected or used personal information for an appropriate purpose under the Acts.
  • Whether Tim Hortons obtained valid consent for the collection and use of granular location data.
  • Adequacy of contractual protections for personal information transferred to third-party service providers.
  • Tim Hortons' accountability and implementation of a privacy management program.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2022PIPEDA Findings #2022-004Indexed Jun 30, 2026

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

MGM Resorts International

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

May 19, 2022PIPEDA Findings #2022-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Key Issues
  • Whether MGM had the obligation to report the breach to the OPC and notify affected Canadians
  • Whether the MGM breach met the RROSH reporting and notification threshold
  • Whether the personal information involved was sensitive
  • Whether there was a high probability of misuse of the personal information
  • Whether MGM notified the OPC and affected Canadians as soon as feasible
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 13, 2022Indexed Jun 30, 2026

DND breached the Privacy Act in disclosing the identity of a workplace violence complainant who had an expectation of confidentiality

Department of National Defence (DND)

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

Quick view

Privacy ActWell-founded & conditionally resolved

DND breached the Privacy Act in disclosing the identity of a workplace violence complainant who had an expectation of confidentiality

May 13, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

Key Issues
  • Whether the disclosure of the WPV complainant's identity to labour relations was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the disclosure of the WPV complainant's identity to an investigator for a separate administrative investigation was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the consent form provided by DND created a reasonable expectation of confidentiality regarding the complainant's identity
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2022PIPEDA Findings #2022-003Indexed Jun 30, 2026

PIPEDA Findings #2022-003: Telecommunications firm failed to obtain appropriate consent for voiceprint authentication program

Rogers Communications Inc.

The complainant alleged that Rogers Communications Inc. improperly enrolled her in its Voice ID voiceprint authentication program without her consent and failed to allow her to opt out or delete her voiceprint. Rogers utilized a passive voiceprinting technology, "tuning," to create algorithmic voiceprints for customer authentication and fraud prevention. The Office of the Privacy Commissioner (OPC) found Rogers' purpose for collecting voiceprints to be appropriate, concluding this aspect of the complaint was not well-founded. However, the OPC determined that Rogers failed to obtain valid and meaningful express consent for the collection of sensitive biometric voiceprints, both during the "tuning" process and enrolment, as customers would not reasonably expect this. Furthermore, Rogers did not provide a clearly explained and easily accessible option for individuals to opt out and improperly retained voiceprints of opted-out individuals without any actual purpose. The OPC also identified deficiencies in Rogers' training materials and monitoring protocols for ensuring staff obtained valid consent. In response to OPC recommendations, Rogers committed to significant changes, including obtaining express consent before tuning, clearly informing customers of opt-out/deletion, deleting retained voiceprints, and improving training and monitoring. Consequently, the consent and retention aspects of the complaint were found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-003: Telecommunications firm failed to obtain appropriate consent for voiceprint authentication program

Mar 30, 2022PIPEDA Findings #2022-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Rogers Communications Inc. improperly enrolled her in its Voice ID voiceprint authentication program without her consent and failed to allow her to opt out or delete her voiceprint. Rogers utilized a passive voiceprinting technology, "tuning," to create algorithmic voiceprints for customer authentication and fraud prevention. The Office of the Privacy Commissioner (OPC) found Rogers' purpose for collecting voiceprints to be appropriate, concluding this aspect of the complaint was not well-founded. However, the OPC determined that Rogers failed to obtain valid and meaningful express consent for the collection of sensitive biometric voiceprints, both during the "tuning" process and enrolment, as customers would not reasonably expect this. Furthermore, Rogers did not provide a clearly explained and easily accessible option for individuals to opt out and improperly retained voiceprints of opted-out individuals without any actual purpose. The OPC also identified deficiencies in Rogers' training materials and monitoring protocols for ensuring staff obtained valid consent. In response to OPC recommendations, Rogers committed to significant changes, including obtaining express consent before tuning, clearly informing customers of opt-out/deletion, deleting retained voiceprints, and improving training and monitoring. Consequently, the consent and retention aspects of the complaint were found to be well-founded and conditionally resolved.

Key Issues
  • Whether the collection and use of voiceprints for authentication and fraud prevention constituted an appropriate purpose under PIPEDA s. 5(3)
  • Whether Rogers obtained valid and meaningful consent for the collection of voiceprints (tuning and enrolment) under PIPEDA Principle 4.3 and s. 6.1
  • Whether Rogers provided an adequate mechanism for the withdrawal of consent under PIPEDA Principle 4.3.8
  • Whether Rogers' retention of voiceprints after opt-out was compliant with PIPEDA Principle 4.5.3
  • Whether Rogers' training materials and protocols for obtaining consent were adequate