The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

3 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 29, 2024Indexed Jun 30, 2026

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Department of National Defence

The complainant, as the executor of a deceased Canadian Armed Forces member's estate, requested personal information from the Department of National Defence (DND) for estate administration purposes. DND initially refused disclosure, citing that the request did not meet the criteria under paragraph 10(b) of the Privacy Regulations and withheld information under section 26 of the Privacy Act, also claiming some records were not under its control or had surpassed retention periods. The OPC found that the complainant was authorized under paragraph 10(b) to access certain information (items 4, 5, 9, and later 2, 6, 7, 8) as it was relevant to potential civil claims regarding the deceased's financial situation and alleged undue influence. The investigation concluded that DND failed to conduct an adequate search for records and improperly applied section 26 without reviewing the records. DND was also found to have improperly deferred the complainant to an informal avenue without formally processing the request. The OPC recommended DND conduct a reasonable search for the specified records and provide a new response, which DND agreed to do. The complaint was therefore found well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Investigation of the Department of National Defence’s refusal to disclose personal information of a deceased individual

Apr 29, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant, as the executor of a deceased Canadian Armed Forces member's estate, requested personal information from the Department of National Defence (DND) for estate administration purposes. DND initially refused disclosure, citing that the request did not meet the criteria under paragraph 10(b) of the Privacy Regulations and withheld information under section 26 of the Privacy Act, also claiming some records were not under its control or had surpassed retention periods. The OPC found that the complainant was authorized under paragraph 10(b) to access certain information (items 4, 5, 9, and later 2, 6, 7, 8) as it was relevant to potential civil claims regarding the deceased's financial situation and alleged undue influence. The investigation concluded that DND failed to conduct an adequate search for records and improperly applied section 26 without reviewing the records. DND was also found to have improperly deferred the complainant to an informal avenue without formally processing the request. The OPC recommended DND conduct a reasonable search for the specified records and provide a new response, which DND agreed to do. The complaint was therefore found well-founded and conditionally resolved.

Key Issues
  • Whether the complainant, as executor, was entitled to make a request on behalf of the deceased member under paragraph 10(b) of the Privacy Regulations for the purpose of administering the estate.
  • Whether the complainant sufficiently articulated or substantiated the precise purposes of the information to administer the estate and how the records in question could further those purposes.
  • Whether DND properly applied section 26 of the Privacy Act in refusing to disclose the requested information.
  • Whether DND conducted an adequate search for the requested records.
  • Whether DND improperly deferred the complainant to another avenue without formally processing a portion of the access request.
  • Whether personal information of a deceased individual (less than 20 years deceased) retains the same privacy protection as a living individual.
  • Whether the 'only for the purpose of such administration' clause in paragraph 10(b) of the Regulations imposes stricter requirements than 'relates to the administration of the individual’s estate' in MFIPPA.
  • Whether records sought to assist in prosecuting a civil claim brought on behalf of the estate for damages recoverable by the estate relate to the administration of the estate.
  • Whether records relevant to the deceased’s financial situation and allegations of fraud or theft of the deceased’s property relate to the administration of the estate.
  • Whether DND's obligation to process a formal access request is relieved if other informal avenues exist.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2024Indexed Jun 30, 2026

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Canada Revenue Agency (CRA)

An individual complained that the Canada Revenue Agency (CRA) failed to ensure the accuracy of their personal information, leading to an imposter fraudulently obtaining Canada Emergency Response Benefit (CERB) payments in their name. The imposter gained unauthorized access to the complainant's CRA My Account, changed direct deposit information, and applied for benefits. This resulted in the complainant receiving a tax reassessment for over $5,500. The OPC found that the CRA relied on inadequate safeguards against unauthorized access and modification, thus failing to take reasonable steps to ensure the accuracy of personal information used for administrative decisions under section 6(2) of the Privacy Act. The CRA has since implemented corrective measures, including enhanced authentication processes and security for high-impact modifications. The OPC found the complaint well-founded and conditionally resolved, noting the CRA's commitments to address the issues.

Quick view

Privacy ActWell-founded & conditionally resolved

Investigation into the steps the Canada Revenue Agency took to ensure the accuracy of a taxpayer’s personal information that it used to make an administrative decision about them

Mar 28, 2024
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that the Canada Revenue Agency (CRA) failed to ensure the accuracy of their personal information, leading to an imposter fraudulently obtaining Canada Emergency Response Benefit (CERB) payments in their name. The imposter gained unauthorized access to the complainant's CRA My Account, changed direct deposit information, and applied for benefits. This resulted in the complainant receiving a tax reassessment for over $5,500. The OPC found that the CRA relied on inadequate safeguards against unauthorized access and modification, thus failing to take reasonable steps to ensure the accuracy of personal information used for administrative decisions under section 6(2) of the Privacy Act. The CRA has since implemented corrective measures, including enhanced authentication processes and security for high-impact modifications. The OPC found the complaint well-founded and conditionally resolved, noting the CRA's commitments to address the issues.

Key Issues
  • Whether the CRA took all reasonable steps to ensure the accuracy of personal information used for administrative purposes under subsection 6(2) of the Privacy Act
  • Whether the safeguards in place at the time of the breach were adequate to prevent unauthorized access and modification of personal information
  • Whether the CRA's authentication processes were sufficient to prevent identity theft and fraudulent activity
  • Whether the CRA should have contacted Employment and Social Development Canada (ESDC) sooner regarding the complainant's identity theft
  • Whether the CRA provided timely notification of the privacy breach to the affected individual
  • Whether the CRA fulfilled its mandatory privacy breach reporting obligations to the OPC
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Canada Revenue Agency and Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Key Issues
  • Whether Canada Revenue Agency (CRA) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether Employment and Social Development Canada (ESDC) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether CRA contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether ESDC contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether CRA and ESDC adequately assessed the level of identity authentication warranted for their online services.
  • Whether CRA and ESDC's identity assurance practices adequately protected against identity theft.
  • Whether CRA and ESDC's credential assurance practices adequately protected against credential stuffing.
  • Whether CRA and ESDC had adequately informed and accountable security decision-making processes.
  • Whether interdepartmental information sharing and accountability systems were adequate to protect personal information.
  • Whether CRA and ESDC conducted comprehensive vulnerability assessments and penetration testing.
  • Whether CRA and ESDC had effective monitoring to detect and promptly contain the ongoing breach.
  • Whether other federal departments using the GC Key service experienced fraudulent access or modification of personal information.