The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

5 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 14, 2026Indexed Jul 15, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

WestJet

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

Jul 14, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Key Issues
  • Adequacy of security safeguards under PIPEDA
  • Adequacy of notifications to affected individuals under PIPEDA
  • Whether WestJet's post-breach remediation actions and future commitments provide a fair and reasonable response to the incident
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 7, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Canada Revenue Agency

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

May 7, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a systemic investigation into the Canada Revenue Agency (CRA) following media reports and a complaint regarding widespread unauthorized disclosures and modifications of taxpayer personal information. The investigation, a Special Report to Parliament, examined whether the CRA had adequate safeguards to protect taxpayer data from identity theft and fraudulent activities. The OPC found that the CRA contravened subsections 6(2) and 8(2) of the Privacy Act due to shortcomings in its prevention, monitoring, detection, remediation, and governance practices. While acknowledging the CRA's efforts to improve its security posture, the OPC identified specific weaknesses, such as delayed implementation of mandatory multi-factor authentication (MFA) and insufficient tracking of individual breaches. The OPC issued nine recommendations to the CRA, covering areas like strengthening MFA, enhancing phone authentication, adopting zero-trust principles, improving attack surface management, and refining breach tracking and governance. The CRA accepted eight recommendations in full and one in part, leading to a "well-founded and conditionally resolved" outcome.

Key Issues
  • Whether the CRA adequately protected personal information against unauthorized disclosure and modification
  • Whether the CRA contravened subsection 6(2) of the Privacy Act regarding accuracy of personal information
  • Whether the CRA contravened subsection 8(2) of the Privacy Act regarding disclosure of personal information
  • Whether the CRA's prevention measures were adequate
  • Whether the CRA implemented mandatory multi-factor authentication (MFA) in a timely manner and with sufficient strength
  • Whether the CRA's authentication processes by phone were strong enough
  • Whether the CRA considered and integrated a zero-trust approach into its security measures
  • Whether the CRA had sufficient visibility over its attack surface and managed it effectively
  • Whether the CRA's vetting, training, and awareness tools were effective for employees and third parties
  • Whether the CRA's monitoring and detection approach was tailored to the threats and risks leading to Unauthorized Use of Taxpayer Information by a Third Party (UUTP)
  • Whether the CRA's remediation efforts for individual UUTPs were adequate, including root cause analysis
  • Whether the CRA's governance processes for addressing UUTPs were coordinated, comprehensive, and efficient
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 5, 2026PIPEDA Findings #2026-001Indexed Jun 30, 2026

PIPEDA Findings #2026-001: Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program

Loblaw Companies Ltd.

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Loblaw Companies Ltd. (Loblaw) regarding its PC Optimum Loyalty Program, focusing on the handling of privacy challenges and the retention of personal information. The investigation found that Loblaw contravened PIPEDA Principle 4.10 by failing to adequately address privacy challenges and respond to account deletion requests in a timely manner, though this issue was resolved during the investigation as Loblaw enhanced its procedures. The OPC also found that Loblaw contravened PIPEDA Principle 4.5.3 by not sufficiently anonymizing personal information retained from closed PC Optimum accounts, meaning there was a serious possibility of re-identification. Loblaw disagreed with this finding but agreed to engage an independent third party to assess its anonymization process and implement recommendations. A preliminary matter regarding requiring physical card holders to create an online account for deletion was found not well-founded. The overall outcome reflects a mix of resolved and conditionally resolved well-founded findings.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2026-001: Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program

Mar 5, 2026PIPEDA Findings #2026-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Loblaw Companies Ltd. (Loblaw) regarding its PC Optimum Loyalty Program, focusing on the handling of privacy challenges and the retention of personal information. The investigation found that Loblaw contravened PIPEDA Principle 4.10 by failing to adequately address privacy challenges and respond to account deletion requests in a timely manner, though this issue was resolved during the investigation as Loblaw enhanced its procedures. The OPC also found that Loblaw contravened PIPEDA Principle 4.5.3 by not sufficiently anonymizing personal information retained from closed PC Optimum accounts, meaning there was a serious possibility of re-identification. Loblaw disagreed with this finding but agreed to engage an independent third party to assess its anonymization process and implement recommendations. A preliminary matter regarding requiring physical card holders to create an online account for deletion was found not well-founded. The overall outcome reflects a mix of resolved and conditionally resolved well-founded findings.

Key Issues
  • Whether Loblaw adequately addresses privacy challenges raised by individuals concerning account deletion (PIPEDA Principle 4.10)
  • Whether Loblaw retains personal information of PC Optimum members for longer than necessary after account closure (PIPEDA Principle 4.5.3)
  • Whether Loblaw collected unnecessary personal information by requiring physical card holders to create an online account to delete their PC Optimum account (PIPEDA Principle 4.4)
  • Whether Loblaw established retention schedules for customer support logs (PIPEDA Principle 4.5.2)
  • Whether Loblaw retains universal login credentials (PCids) for longer than necessary for members with no other associated accounts (PIPEDA Principle 4.5.3)
  • Whether Loblaw's anonymization process for retained Historical Transaction Data, Loyalty Data, and Usage Data ensures no serious possibility of re-identification
  • Whether Loblaw's retention of public IP address data after account closure is sufficiently anonymized
  • Whether Loblaw's practice of retaining email domain portions after account closure is sufficiently anonymized
  • Whether manual processing errors in Loblaw's de-identification process were adequately detected and addressed
  • Whether Loblaw ensured identifiers were removed from back-up systems as part of its anonymization process
  • Whether Loblaw considered the impact of other factors affecting re-identification risk, such as separately retained PCid data
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 3, 2026Indexed Jun 30, 2026

Correctional Service of Canada Deleted Video

Correctional Service of Canada (CSC)

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Quick view

Privacy ActWell-founded & conditionally resolved

Correctional Service of Canada Deleted Video

Mar 3, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An inmate complained that Correctional Service Canada (CSC) failed to retain video footage of use of force incidents involving them, which they requested access to under the Privacy Act. CSC's policy was to retain relevant footage for two years, but otherwise, it was automatically deleted after six days. The OPC's investigation found that CSC had disposed of footage that it was obligated to retain under Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations. This failure meant the complainant could not access the sensitive recordings. The OPC recommended that CSC ensure all relevant footage is retained for the prescribed two-year period. CSC agreed to monthly attestations from the institution and quarterly random audits across its Pacific Region, with findings reported to the OPC. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether CSC failed to retain personal information used for an administrative purpose as required by Subsection 6(1) of the Privacy Act and Paragraph 4(1)(a) of the Privacy Regulations
  • Whether the complainant was denied a reasonable opportunity to obtain access to their personal information due to non-retention
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 9, 2026PIPEDA Findings #2026-003Indexed Jun 30, 2026

PIPEDA Findings #2026-003: Investigation into Bell’s compliance with PIPEDA when responding to an access request for personal information

Bell Canada

The complainant alleged that Bell Canada contravened PIPEDA by failing to respond to an access request within 30 days and by denying access to his cellphone logs. The OPC found that Bell contravened subsection 8(3) of PIPEDA for the delayed response and Principle 4.9 for denying access, as the phone logs constituted the complainant's personal information. The OPC determined that the complainant's privacy interest in his phone logs outweighed the ex-spouse's interest, and there was a public interest in disclosure. Bell agreed to provide the requested logs to the complainant, resolving that aspect of the complaint. Bell also committed to implementing recommendations to improve its access request procedures and enhance openness regarding data access on shared accounts, leading to a conditionally resolved outcome for these issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2026-003: Investigation into Bell’s compliance with PIPEDA when responding to an access request for personal information

Jan 9, 2026PIPEDA Findings #2026-003
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Bell Canada contravened PIPEDA by failing to respond to an access request within 30 days and by denying access to his cellphone logs. The OPC found that Bell contravened subsection 8(3) of PIPEDA for the delayed response and Principle 4.9 for denying access, as the phone logs constituted the complainant's personal information. The OPC determined that the complainant's privacy interest in his phone logs outweighed the ex-spouse's interest, and there was a public interest in disclosure. Bell agreed to provide the requested logs to the complainant, resolving that aspect of the complaint. Bell also committed to implementing recommendations to improve its access request procedures and enhance openness regarding data access on shared accounts, leading to a conditionally resolved outcome for these issues.

Key Issues
  • Whether Bell responded to the Complainant’s access request within thirty days as per subsection 8(3) of PIPEDA
  • Whether Bell adequately responded to the Complainant’s request to access his personal information under Principle 4.9 of PIPEDA
  • Whether phone logs relating to a specific phoneline constitute the personal information of the phoneline's user, even if they are not the account holder
  • Whether the Complainant's interest in accessing the phone logs is greater than the ex-spouse's interest in non-disclosure of the phone logs
  • Whether Bell was sufficiently open with individuals about account holders' access to phone usage details on shared accounts, contrary to PIPEDA's Openness principle (Principle 4.8.1)