The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

46 decisions matching
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Feb 26, 2026Indexed Jun 30, 2026

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Canada Border Services Agency (CBSA)

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Quick view

Privacy ActWell-founded & resolved

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Feb 26, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Key Issues
  • Whether the CBSA's disclosure of employee personal information via spreadsheets contravened section 8 of the Privacy Act
  • Whether the inclusion of excess information in spreadsheets constituted unauthorized disclosure
  • Whether the use of personal email addresses for work-related data sharing contravened the Privacy Act
  • Whether the CBSA took adequate steps to address the incidents, including notification to affected individuals
  • Whether the CBSA's measures to reduce the risk of recurrence were reasonable
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 25, 2025PIPEDA Findings #2025-005Indexed Jun 30, 2026

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

A privately owned swimming pool

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

Nov 25, 2025PIPEDA Findings #2025-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Key Issues
  • Whether requiring consent for promotional photos and videos of children as a condition of service for swimming lessons contravenes Principle 4.3.3 of PIPEDA
  • Whether images of children in swim attire constitute sensitive personal information
  • Whether the collection, use, or disclosure of images for promotional or staff training purposes is strictly necessary for the provision of swimming lessons
  • Whether the organization offered individuals a choice regarding the collection, use, or disclosure of images for promotional or staff training purposes
  • Whether the organization should have sought express consent for the collection, use, or disclosure of images of children
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 20, 2025PIPEDA Findings #2025-001Indexed Jun 30, 2026

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

23andMe Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

Jun 20, 2025PIPEDA Findings #2025-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Key Issues
  • Whether 23andMe had appropriate safeguards to protect highly sensitive personal information under its control, specifically against credential stuffing attacks.
  • Whether 23andMe's prevention measures, including mandatory Multi-factor Authentication (MFA), compromised-password checks, and minimum password requirements, were adequate.
  • Whether 23andMe's detection measures, including detection systems, digital fingerprinting, and device history, were adequate to identify ongoing attacks.
  • Whether 23andMe adequately investigated anomalies and claims of breach prior to public disclosure.
  • Whether 23andMe's breach response, including the timeliness of disabling active user sessions, disabling raw DNA download features, and implementing mandatory MFA, was adequate.
  • Whether 23andMe adequately notified the OPC about the breach, including the completeness of information provided and timeliness.
  • Whether 23andMe adequately notified affected individuals about the breach, including the completeness of information provided and timeliness.
  • Whether the data breach created a real risk of significant harm to affected individuals, triggering notification obligations.
  • Whether 23andMe's methodology for identifying and notifying individuals whose raw DNA was downloaded by the Threat Actor was adequate.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 28, 2024PIPEDA Findings #2024-002Indexed Jun 30, 2026

PIPEDA Findings #2024-002: Investigation into Brinks Home

Brinks Home

A Brinks Home customer complained that he could view other customers' personal information through his online portal. The OPC investigated whether Brinks Home had adequate security safeguards and complied with breach notification requirements. Brinks Home acknowledged an employee error caused 3,340 customer records to be accessible to 102 other customers, with up to 20 potentially accessing the data. The OPC found that Brinks Home failed to adequately protect personal information, but this issue was resolved by the company's corrective actions and subsequent sale of its Canadian customer accounts. Regarding breach notification, the OPC determined that while the information was sensitive, the probability of misuse was low because the unauthorized access was by known customers, not malicious actors. Therefore, the incident did not pose a real risk of significant harm, and Brinks Home was not required to report it or notify affected individuals.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2024-002: Investigation into Brinks Home

Mar 28, 2024PIPEDA Findings #2024-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

A Brinks Home customer complained that he could view other customers' personal information through his online portal. The OPC investigated whether Brinks Home had adequate security safeguards and complied with breach notification requirements. Brinks Home acknowledged an employee error caused 3,340 customer records to be accessible to 102 other customers, with up to 20 potentially accessing the data. The OPC found that Brinks Home failed to adequately protect personal information, but this issue was resolved by the company's corrective actions and subsequent sale of its Canadian customer accounts. Regarding breach notification, the OPC determined that while the information was sensitive, the probability of misuse was low because the unauthorized access was by known customers, not malicious actors. Therefore, the incident did not pose a real risk of significant harm, and Brinks Home was not required to report it or notify affected individuals.

Key Issues
  • Whether Brinks Home implemented adequate security safeguards to protect customers' personal information under Principle 4.7 of Schedule 1 of PIPEDA
  • Whether Brinks Home complied with breach notification requirements under section 10.1 of PIPEDA
  • Whether the breach presented a real risk of significant harm (RROSH)
  • Whether the personal information involved was sensitive
  • Whether the probability of misuse of the personal information was low
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

Treasury Board of Canada Secretariat

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

Quick view

Privacy ActWell-founded & resolved

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

Key Issues
  • Whether the information collected by institutions related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act.
  • Whether institutions properly met the transparency requirements of subsection 5(2) of the Privacy Act regarding informing individuals of the purpose of collection.
  • Whether the Treasury Board of Canada Secretariat (TBS) complied with subsection 11(1) of the Privacy Act by publishing an index of personal information banks.
  • Whether disclosures of personal information collected under the Policy were authorized under section 8 of the Privacy Act.
  • Whether the collection of personal information was necessary and proportional, applying the OPC's four-part test.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Apr 13, 2023Indexed Jun 30, 2026

Investigation of Correctional Service Canada’s collection and disclosure of an individual’s personal information from Facebook related to an employee’s 699-leave

Correctional Service Canada

A complaint was filed against Correctional Service Canada (CSC) by the spouse of an employee, alleging inappropriate collection and disclosure of personal information from their public Facebook page. The information was collected by an assistant warden to investigate the employee's use of 'other leave with pay (699)' during the COVID-19 pandemic. The OPC found that significant portions of the collected information were not directly related to an operating program or activity of CSC, thus contravening Section 4 of the Privacy Act. The OPC also noted that the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies only to use and disclosure, not collection. CSC subsequently deleted the collected screenshots and committed to developing guidance for managers on collecting information in a labour relations context. The complainant also raised concerns about CSC's internal complaint process, which CSC acknowledged was mishandled.

Quick view

Privacy ActWell-founded & resolved

Investigation of Correctional Service Canada’s collection and disclosure of an individual’s personal information from Facebook related to an employee’s 699-leave

Apr 13, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

A complaint was filed against Correctional Service Canada (CSC) by the spouse of an employee, alleging inappropriate collection and disclosure of personal information from their public Facebook page. The information was collected by an assistant warden to investigate the employee's use of 'other leave with pay (699)' during the COVID-19 pandemic. The OPC found that significant portions of the collected information were not directly related to an operating program or activity of CSC, thus contravening Section 4 of the Privacy Act. The OPC also noted that the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies only to use and disclosure, not collection. CSC subsequently deleted the collected screenshots and committed to developing guidance for managers on collecting information in a labour relations context. The complainant also raised concerns about CSC's internal complaint process, which CSC acknowledged was mishandled.

Key Issues
  • Whether the collection of personal information from a public Facebook page was directly related to an operating program or activity of CSC under Section 4 of the Privacy Act
  • Whether the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies to the collection of personal information
  • Whether the subsequent disclosure of the collected information was appropriate
  • Whether CSC's internal process for handling privacy complaints from the public was adequate
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Feb 23, 2023Indexed Jun 30, 2026

Failure to publish a personal information bank description on Zero-Emissions Program contravenes the Privacy Act

Transport Canada

An individual complained that Transport Canada collected his personal information for the "Incentives for Zero-Emission Vehicles Program" (iZEV) without a publicly available Personal Information Bank (PIB) description, as required by the Privacy Act. Transport Canada launched the iZEV program in May 2019 but did not submit a PIB description to the Treasury Board Secretariat (TBS) for approval until 19 months later. The OPC found that both Transport Canada and TBS contributed to the contravention, as TBS failed to approve and publish the PIB description in a timely manner. Although Transport Canada eventually published the PIB, TBS declined to implement the OPC's recommendations for service standards, citing complexity, but outlined internal process improvements. The OPC acknowledged TBS's efforts to address the backlog.

Quick view

Privacy ActWell-founded & resolved

Failure to publish a personal information bank description on Zero-Emissions Program contravenes the Privacy Act

Feb 23, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that Transport Canada collected his personal information for the "Incentives for Zero-Emission Vehicles Program" (iZEV) without a publicly available Personal Information Bank (PIB) description, as required by the Privacy Act. Transport Canada launched the iZEV program in May 2019 but did not submit a PIB description to the Treasury Board Secretariat (TBS) for approval until 19 months later. The OPC found that both Transport Canada and TBS contributed to the contravention, as TBS failed to approve and publish the PIB description in a timely manner. Although Transport Canada eventually published the PIB, TBS declined to implement the OPC's recommendations for service standards, citing complexity, but outlined internal process improvements. The OPC acknowledged TBS's efforts to address the backlog.

Key Issues
  • Whether Transport Canada failed to ensure personal information collected for the iZEV program was included in a publicly available PIB description as required by section 10 of the Privacy Act
  • Whether Transport Canada obtained TBS approval for a new PIB before implementing the iZEV program as required by subsection 71(4) of the Privacy Act and the TBS Directive on Privacy Impact Assessment
  • Whether TBS fulfilled its responsibility under section 11 of the Privacy Act to ensure timely publication of PIB descriptions
  • Whether the lack of a timely PIB approval process by TBS impacts the operability of the PIB regime under the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 26, 2023PIPEDA Findings #2023-001Indexed Jun 30, 2026

PIPEDA Findings #2023-001: Investigation into Home Depot of Canada Inc.’s compliance with PIPEDA

Home Depot of Canada Inc.

The complainant alleged that Home Depot disclosed his personal information to Meta (formerly Facebook) without his knowledge and consent. Home Depot was sending in-store customers' hashed email addresses and purchase details to Meta via an "Offline Conversions" tool when customers requested an e-receipt. This data allowed Meta to measure ad effectiveness and use the information for its own business purposes, including targeted advertising. The OPC found that Home Depot failed to obtain valid consent, as its privacy statement was not readily available or sufficiently clear, and customers would not reasonably expect such disclosure. Home Depot discontinued the use of the tool in October 2022 in response to OPC recommendations. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2023-001: Investigation into Home Depot of Canada Inc.’s compliance with PIPEDA

Jan 26, 2023PIPEDA Findings #2023-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Home Depot disclosed his personal information to Meta (formerly Facebook) without his knowledge and consent. Home Depot was sending in-store customers' hashed email addresses and purchase details to Meta via an "Offline Conversions" tool when customers requested an e-receipt. This data allowed Meta to measure ad effectiveness and use the information for its own business purposes, including targeted advertising. The OPC found that Home Depot failed to obtain valid consent, as its privacy statement was not readily available or sufficiently clear, and customers would not reasonably expect such disclosure. Home Depot discontinued the use of the tool in October 2022 in response to OPC recommendations. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether Home Depot obtained valid consent for disclosing customer personal information to Meta
  • Whether the disclosure of personal information to Meta constituted a processing activity not requiring additional consent
  • Whether Home Depot's Privacy Statement and Meta's Privacy Policy were sufficient to obtain meaningful implied consent
  • Whether express opt-in consent was required for the disclosure of customer information to Meta
  • Whether the information disclosed was sensitive
  • Whether the disclosure was within the reasonable expectations of the individual
  • Whether the ability to withdraw consent after the fact was sufficient
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 20, 2022Indexed Jun 30, 2026

Investigation into a privacy breach at a Canada Border Services Agency contractor

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at a Canada Border Services Agency contractor

May 20, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Key Issues
  • Whether licence plate image files, including associated metadata (jurisdiction, characters, date, time, border crossing site, lane number), constitute personal information under Section 3 of the Privacy Act.
  • Whether the unauthorized access and disclosure of these licence plate image files constituted an improper disclosure under Section 8 of the Privacy Act.
  • Whether the Canada Border Services Agency (CBSA) had adequate security safeguards in place, particularly in its contractual arrangements with a third-party contractor, to protect personal information.
  • Whether the data retention practices for licence plate image files by the CBSA and its contractor were appropriate and compliant with the Privacy Act.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-003Indexed Jun 30, 2026

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Bank of Montreal

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Mar 30, 2021PIPEDA Findings #2021-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether BMO implemented appropriate security safeguards to adequately protect personal information under its control, as required by PIPEDA Principle 4.7
  • Adequacy of BMO's developer security testing and evaluation processes
  • Adequacy of BMO's vulnerability management program, including identification, assessment, and remediation of vulnerabilities
  • Adequacy of BMO's oversight and monitoring capabilities, specifically regarding bot management, cyberattack detection, and real-time alerts
  • Adequacy of BMO's organizational policies and procedures for handling cyberattacks and incident response
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 24, 2021PIPEDA Findings #2021-007Indexed Jun 30, 2026

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

A computer services company

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

Mar 24, 2021PIPEDA Findings #2021-007
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Key Issues
  • Whether the respondent obtained meaningful consent prior to remotely accessing laptops
  • Whether the respondent had adequate safeguards to prevent unauthorized access to customers’ personal information by its personnel
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 22, 2021PIPEDA Findings #2021-008Indexed Jun 30, 2026

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Oculus Transport Ltd.

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Mar 22, 2021PIPEDA Findings #2021-008
Adjudicator: Daniel Therrien
Plain-Language Summary

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Key Issues
  • Whether the collection and use of personal information via audio surveillance technology was for purposes that a reasonable person would consider appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the personal information collected was sensitive
  • Whether the organization's purpose represented a legitimate need / bona fide business interest
  • Whether the collection, use and disclosure would be effective in meeting the organization’s need
  • Whether there are less privacy invasive means of achieving the same ends at comparable cost and with comparable benefits
  • Whether the loss of privacy is proportional to the benefits
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Nov 17, 2020Indexed Jun 30, 2026

Employer’s disclosure related to a transgender individual was contrary to the Privacy Act

A federal government institution

An employee complained that a federal government institution breached her privacy by disclosing her transgender identity and the reasons for her transfer to her new manager and colleagues without her consent. The complainant had explicitly requested confidentiality due to prior workplace harassment related to her gender identity, and the employer had assured her of discretion. The institution's internal review confirmed that managers disclosed this sensitive information, believing it necessary to support the employee and her new supervisor, but acknowledged this was an error and contrary to internal policies. The OPC found that the disclosure was made without consent, contravening section 8(1) of the Privacy Act. The institution recognized the breach and committed to improving policies and providing transgender awareness education. The OPC recommended updating policies to prevent similar incidents, and the institution created new guidance for its staff.

Quick view

Privacy ActWell-founded & resolved

Employer’s disclosure related to a transgender individual was contrary to the Privacy Act

Nov 17, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that a federal government institution breached her privacy by disclosing her transgender identity and the reasons for her transfer to her new manager and colleagues without her consent. The complainant had explicitly requested confidentiality due to prior workplace harassment related to her gender identity, and the employer had assured her of discretion. The institution's internal review confirmed that managers disclosed this sensitive information, believing it necessary to support the employee and her new supervisor, but acknowledged this was an error and contrary to internal policies. The OPC found that the disclosure was made without consent, contravening section 8(1) of the Privacy Act. The institution recognized the breach and committed to improving policies and providing transgender awareness education. The OPC recommended updating policies to prevent similar incidents, and the institution created new guidance for its staff.

Key Issues
  • Whether information about an individual's transgender identity is personal information requiring protection under the Privacy Act
  • Whether the institution disclosed the complainant's personal information without consent
  • Whether the disclosure was contrary to section 8(1) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 28, 2020PIPEDA Findings #2020-004Indexed Jun 30, 2026

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

The Cadillac Fairview Corporation Limited

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

Oct 28, 2020PIPEDA Findings #2020-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Key Issues
  • Whether CFCL’s use of Anonymous Video Analytics (AVA) technology, via in-mall directories, resulted in the collection, use, and/or disclosure of personal information.
  • Whether images of individual faces captured by AVA technology constitute personal information.
  • Whether numerical representations of faces (biometric information) generated by AVA technology constitute personal information.
  • Whether age range and gender assessments, combined with other data, constitute personal information.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via AVA technology.
  • Whether CFCL retained personal information collected via AVA technology longer than necessary.
  • Whether CFCL’s use of mobile device geolocation technologies (Anonymous Shopper Journey) resulted in the collection, use, and/or disclosure of personal information.
  • Whether hashed and randomized MAC addresses, combined with non-granular zone geolocation, constitute personal information in the context of anonymous shopper tracking.
  • Whether CFCL’s use of mobile device geolocation technologies (Logged In Shopper Journey) resulted in the collection, use, and/or disclosure of personal information linked to identifiable individuals.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via mobile device geolocation technologies (Logged In Shopper Journey).
  • Whether CFCL's privacy policy and signage provided sufficient notice and obtained valid consent for its data collection practices.
  • Whether the "serious possibility" threshold for identifying individuals was met for anonymous shopper journey data.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Investigation into a privacy breach at Public Services and Procurement Canada

Public Services and Procurement Canada (PSPC)

The Office of the Privacy Commissioner (OPC) investigated complaints from federal public servants regarding an improper disclosure of their pay-related information by Public Services and Procurement Canada (PSPC). PSPC inadvertently sent personnel overpayment reports containing personal information of 69,087 public servants to the wrong government institutions. The OPC found that PSPC contravened section 8 of the Privacy Act by disclosing personal information without authorization. However, the complaints were deemed resolved due to PSPC's corrective actions, which included implementing new procedures with quality controls for report generation, requesting deletion of the flawed reports, and notifying affected individuals. The OPC noted that while notification was timely, some departments modified the notification letters, leading to inconsistencies in the information received by individuals.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at Public Services and Procurement Canada

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated complaints from federal public servants regarding an improper disclosure of their pay-related information by Public Services and Procurement Canada (PSPC). PSPC inadvertently sent personnel overpayment reports containing personal information of 69,087 public servants to the wrong government institutions. The OPC found that PSPC contravened section 8 of the Privacy Act by disclosing personal information without authorization. However, the complaints were deemed resolved due to PSPC's corrective actions, which included implementing new procedures with quality controls for report generation, requesting deletion of the flawed reports, and notifying affected individuals. The OPC noted that while notification was timely, some departments modified the notification letters, leading to inconsistencies in the information received by individuals.

Key Issues
  • Whether PSPC improperly disclosed personal information in contravention of section 8 of the Privacy Act
  • Whether the information disclosed constituted 'personal information' under section 3 of the Privacy Act
  • Whether PSPC's response to the breach, including mitigation and notification, was adequate
  • Whether PSPC implemented sufficient measures to prevent recurrence of the breach