The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

38 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 25, 2025PIPEDA Findings #2025-005Indexed Jun 30, 2026

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

A privately owned swimming pool

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

Nov 25, 2025PIPEDA Findings #2025-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Key Issues
  • Whether requiring consent for promotional photos and videos of children as a condition of service for swimming lessons contravenes Principle 4.3.3 of PIPEDA
  • Whether images of children in swim attire constitute sensitive personal information
  • Whether the collection, use, or disclosure of images for promotional or staff training purposes is strictly necessary for the provision of swimming lessons
  • Whether the organization offered individuals a choice regarding the collection, use, or disclosure of images for promotional or staff training purposes
  • Whether the organization should have sought express consent for the collection, use, or disclosure of images of children
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 20, 2025PIPEDA Findings #2025-001Indexed Jun 30, 2026

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

23andMe Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

Jun 20, 2025PIPEDA Findings #2025-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Key Issues
  • Whether 23andMe had appropriate safeguards to protect highly sensitive personal information under its control, specifically against credential stuffing attacks.
  • Whether 23andMe's prevention measures, including mandatory Multi-factor Authentication (MFA), compromised-password checks, and minimum password requirements, were adequate.
  • Whether 23andMe's detection measures, including detection systems, digital fingerprinting, and device history, were adequate to identify ongoing attacks.
  • Whether 23andMe adequately investigated anomalies and claims of breach prior to public disclosure.
  • Whether 23andMe's breach response, including the timeliness of disabling active user sessions, disabling raw DNA download features, and implementing mandatory MFA, was adequate.
  • Whether 23andMe adequately notified the OPC about the breach, including the completeness of information provided and timeliness.
  • Whether 23andMe adequately notified affected individuals about the breach, including the completeness of information provided and timeliness.
  • Whether the data breach created a real risk of significant harm to affected individuals, triggering notification obligations.
  • Whether 23andMe's methodology for identifying and notifying individuals whose raw DNA was downloaded by the Threat Actor was adequate.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 28, 2024PIPEDA Findings #2024-002Indexed Jun 30, 2026

PIPEDA Findings #2024-002: Investigation into Brinks Home

Brinks Home

A Brinks Home customer complained that he could view other customers' personal information through his online portal. The OPC investigated whether Brinks Home had adequate security safeguards and complied with breach notification requirements. Brinks Home acknowledged an employee error caused 3,340 customer records to be accessible to 102 other customers, with up to 20 potentially accessing the data. The OPC found that Brinks Home failed to adequately protect personal information, but this issue was resolved by the company's corrective actions and subsequent sale of its Canadian customer accounts. Regarding breach notification, the OPC determined that while the information was sensitive, the probability of misuse was low because the unauthorized access was by known customers, not malicious actors. Therefore, the incident did not pose a real risk of significant harm, and Brinks Home was not required to report it or notify affected individuals.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2024-002: Investigation into Brinks Home

Mar 28, 2024PIPEDA Findings #2024-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

A Brinks Home customer complained that he could view other customers' personal information through his online portal. The OPC investigated whether Brinks Home had adequate security safeguards and complied with breach notification requirements. Brinks Home acknowledged an employee error caused 3,340 customer records to be accessible to 102 other customers, with up to 20 potentially accessing the data. The OPC found that Brinks Home failed to adequately protect personal information, but this issue was resolved by the company's corrective actions and subsequent sale of its Canadian customer accounts. Regarding breach notification, the OPC determined that while the information was sensitive, the probability of misuse was low because the unauthorized access was by known customers, not malicious actors. Therefore, the incident did not pose a real risk of significant harm, and Brinks Home was not required to report it or notify affected individuals.

Key Issues
  • Whether Brinks Home implemented adequate security safeguards to protect customers' personal information under Principle 4.7 of Schedule 1 of PIPEDA
  • Whether Brinks Home complied with breach notification requirements under section 10.1 of PIPEDA
  • Whether the breach presented a real risk of significant harm (RROSH)
  • Whether the personal information involved was sensitive
  • Whether the probability of misuse of the personal information was low
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 26, 2023PIPEDA Findings #2023-001Indexed Jun 30, 2026

PIPEDA Findings #2023-001: Investigation into Home Depot of Canada Inc.’s compliance with PIPEDA

Home Depot of Canada Inc.

The complainant alleged that Home Depot disclosed his personal information to Meta (formerly Facebook) without his knowledge and consent. Home Depot was sending in-store customers' hashed email addresses and purchase details to Meta via an "Offline Conversions" tool when customers requested an e-receipt. This data allowed Meta to measure ad effectiveness and use the information for its own business purposes, including targeted advertising. The OPC found that Home Depot failed to obtain valid consent, as its privacy statement was not readily available or sufficiently clear, and customers would not reasonably expect such disclosure. Home Depot discontinued the use of the tool in October 2022 in response to OPC recommendations. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2023-001: Investigation into Home Depot of Canada Inc.’s compliance with PIPEDA

Jan 26, 2023PIPEDA Findings #2023-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Home Depot disclosed his personal information to Meta (formerly Facebook) without his knowledge and consent. Home Depot was sending in-store customers' hashed email addresses and purchase details to Meta via an "Offline Conversions" tool when customers requested an e-receipt. This data allowed Meta to measure ad effectiveness and use the information for its own business purposes, including targeted advertising. The OPC found that Home Depot failed to obtain valid consent, as its privacy statement was not readily available or sufficiently clear, and customers would not reasonably expect such disclosure. Home Depot discontinued the use of the tool in October 2022 in response to OPC recommendations. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether Home Depot obtained valid consent for disclosing customer personal information to Meta
  • Whether the disclosure of personal information to Meta constituted a processing activity not requiring additional consent
  • Whether Home Depot's Privacy Statement and Meta's Privacy Policy were sufficient to obtain meaningful implied consent
  • Whether express opt-in consent was required for the disclosure of customer information to Meta
  • Whether the information disclosed was sensitive
  • Whether the disclosure was within the reasonable expectations of the individual
  • Whether the ability to withdraw consent after the fact was sufficient
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-003Indexed Jun 30, 2026

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Bank of Montreal

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Mar 30, 2021PIPEDA Findings #2021-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether BMO implemented appropriate security safeguards to adequately protect personal information under its control, as required by PIPEDA Principle 4.7
  • Adequacy of BMO's developer security testing and evaluation processes
  • Adequacy of BMO's vulnerability management program, including identification, assessment, and remediation of vulnerabilities
  • Adequacy of BMO's oversight and monitoring capabilities, specifically regarding bot management, cyberattack detection, and real-time alerts
  • Adequacy of BMO's organizational policies and procedures for handling cyberattacks and incident response
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 24, 2021PIPEDA Findings #2021-007Indexed Jun 30, 2026

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

A computer services company

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

Mar 24, 2021PIPEDA Findings #2021-007
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Key Issues
  • Whether the respondent obtained meaningful consent prior to remotely accessing laptops
  • Whether the respondent had adequate safeguards to prevent unauthorized access to customers’ personal information by its personnel
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 22, 2021PIPEDA Findings #2021-008Indexed Jun 30, 2026

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Oculus Transport Ltd.

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Mar 22, 2021PIPEDA Findings #2021-008
Adjudicator: Daniel Therrien
Plain-Language Summary

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Key Issues
  • Whether the collection and use of personal information via audio surveillance technology was for purposes that a reasonable person would consider appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the personal information collected was sensitive
  • Whether the organization's purpose represented a legitimate need / bona fide business interest
  • Whether the collection, use and disclosure would be effective in meeting the organization’s need
  • Whether there are less privacy invasive means of achieving the same ends at comparable cost and with comparable benefits
  • Whether the loss of privacy is proportional to the benefits
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 28, 2020PIPEDA Findings #2020-004Indexed Jun 30, 2026

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

The Cadillac Fairview Corporation Limited

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

Oct 28, 2020PIPEDA Findings #2020-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Key Issues
  • Whether CFCL’s use of Anonymous Video Analytics (AVA) technology, via in-mall directories, resulted in the collection, use, and/or disclosure of personal information.
  • Whether images of individual faces captured by AVA technology constitute personal information.
  • Whether numerical representations of faces (biometric information) generated by AVA technology constitute personal information.
  • Whether age range and gender assessments, combined with other data, constitute personal information.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via AVA technology.
  • Whether CFCL retained personal information collected via AVA technology longer than necessary.
  • Whether CFCL’s use of mobile device geolocation technologies (Anonymous Shopper Journey) resulted in the collection, use, and/or disclosure of personal information.
  • Whether hashed and randomized MAC addresses, combined with non-granular zone geolocation, constitute personal information in the context of anonymous shopper tracking.
  • Whether CFCL’s use of mobile device geolocation technologies (Logged In Shopper Journey) resulted in the collection, use, and/or disclosure of personal information linked to identifiable individuals.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via mobile device geolocation technologies (Logged In Shopper Journey).
  • Whether CFCL's privacy policy and signage provided sufficient notice and obtained valid consent for its data collection practices.
  • Whether the "serious possibility" threshold for identifying individuals was met for anonymous shopper journey data.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 9, 2020PIPEDA Findings #2020-003Indexed Jun 30, 2026

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Dell Inc.

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Jul 9, 2020PIPEDA Findings #2020-003
Adjudicator: Daniel Therrien
Plain-Language Summary

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Key Issues
  • Whether Dell adequately safeguarded personal information under its control while using a service provider (PIPEDA Principle 4.1.3 and 4.7).
  • Whether the personal information transferred to the service provider was sensitive enough to require a high degree of protection.
  • Whether Dell's access controls were sufficient to protect customer information.
  • Whether Dell's logging and monitoring practices were adequate to detect anomalous employee requests for customer information.
  • Whether Dell's technical measures, such as USB drive restrictions, were sufficient.
  • Whether Dell adequately investigated the circumstances and scope of the June 2017 breach.
  • Whether Dell adequately responded to customer complaints about potential privacy breaches (PIPEDA Principle 4.10.4).
  • Whether Dell remained responsible for personal information transferred to a third party for processing.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 16, 2019PIPEDA Findings #2019-003Indexed Jun 30, 2026

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Loblaw Companies Ltd.

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Oct 16, 2019PIPEDA Findings #2019-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Key Issues
  • Whether Loblaw collected more personal information than necessary for the Loblaw Card Program (Principle 4.4)
  • Whether Loblaw ensured a comparable level of protection for personal information transferred to a third party for processing (Principle 4.1.3)
  • Whether Loblaw was required to obtain additional consent for the transfer of personal information for processing (Principle 4.3)
  • Whether Loblaw was sufficiently open and transparent about its cross-border data transfers (Principle 4.8)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 8, 2018PIPEDA Report of Findings #2018-001Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

VTech Holdings Limited

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

Jan 8, 2018PIPEDA Report of Findings #2018-001
Adjudicator: Daniel Therrien
Plain-Language Summary

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Key Issues
  • Whether VTech Holdings Limited failed to adequately safeguard personal information under Principle 4.7 PIPEDA
  • Whether VTech's security safeguards were appropriate to the sensitivity of the information (Principle 4.7 PIPEDA)
  • Whether VTech's safeguards protected against unauthorized access, disclosure, copying, use, or modification (Principle 4.7.1 PIPEDA)
  • Whether the nature of VTech's safeguards varied depending on the sensitivity, amount, distribution, format, and storage method of the information (Principle 4.7.2 PIPEDA)
  • Whether VTech's methods of protection included physical, organizational, and technological measures (Principle 4.7.3 PIPEDA)
  • Whether VTech had adequate testing and maintenance protocols to identify and mitigate vulnerabilities
  • Whether VTech had adequate administrative access controls
  • Whether VTech had adequate cryptographic protection for personal information
  • Whether VTech had sufficient security monitoring and logging to detect threats
  • Whether VTech had a comprehensive security management program
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 29, 2017PIPEDA findings #2017-012Indexed Jun 30, 2026

PIPEDA findings #2017-012: Financial institution discloses too much information in response to production order

A financial institution

A complainant alleged that his financial institution improperly disclosed his personal information, specifically RESP account details from 1999, to a municipal police service. The financial institution claimed the disclosure was made under a production order or, alternatively, with the complainant's consent via its privacy policy. The OPC found that the disclosed 1999 RESP information fell outside the scope of the production order, which specified a different date range and nature of information. The OPC also rejected the financial institution's argument of consent, stating that the privacy policy's general language was insufficient for informed consent, especially for sensitive financial information. The financial institution agreed to review its procedures and provide training to ensure compliance with production orders. The complaint was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2017-012: Financial institution discloses too much information in response to production order

Aug 29, 2017PIPEDA findings #2017-012
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that his financial institution improperly disclosed his personal information, specifically RESP account details from 1999, to a municipal police service. The financial institution claimed the disclosure was made under a production order or, alternatively, with the complainant's consent via its privacy policy. The OPC found that the disclosed 1999 RESP information fell outside the scope of the production order, which specified a different date range and nature of information. The OPC also rejected the financial institution's argument of consent, stating that the privacy policy's general language was insufficient for informed consent, especially for sensitive financial information. The financial institution agreed to review its procedures and provide training to ensure compliance with production orders. The complaint was found to be well-founded and resolved.

Key Issues
  • Whether the disclosure of RESP account information from 1999 was justified under paragraph 7(3)(c) of PIPEDA as being required by a production order
  • Whether the financial institution could rely on the complainant's consent, as stipulated in its privacy policy, for the disclosure of personal information to law enforcement
  • Whether the RESP account information constituted sensitive personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 28, 2017PIPEDA Report of Findings #2017-001Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-001: Drug activity history in property reports deemed not publicly available

A property report provider

A complainant alleged that a company selling "home history reports" collected, used, and disclosed personal information without consent, specifically sales history, drug activity, and insurance claims. The OPC found that sales history was no longer included in reports and insurance claims information, as clarified by the respondent, related to property damage paid to third parties, not individuals, thus not constituting personal information. However, information about drug activity was deemed personal information because it could be linked to identifiable individuals and suggested their involvement in drug activity. The OPC concluded that this drug activity information was not "publicly available" under PIPEDA Regulations, requiring consent for its use. The respondent agreed to cease including drug activity details in its reports, leading to a well-founded and resolved outcome.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2017-001: Drug activity history in property reports deemed not publicly available

Aug 28, 2017PIPEDA Report of Findings #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a company selling "home history reports" collected, used, and disclosed personal information without consent, specifically sales history, drug activity, and insurance claims. The OPC found that sales history was no longer included in reports and insurance claims information, as clarified by the respondent, related to property damage paid to third parties, not individuals, thus not constituting personal information. However, information about drug activity was deemed personal information because it could be linked to identifiable individuals and suggested their involvement in drug activity. The OPC concluded that this drug activity information was not "publicly available" under PIPEDA Regulations, requiring consent for its use. The respondent agreed to cease including drug activity details in its reports, leading to a well-founded and resolved outcome.

Key Issues
  • Whether sales history information constituted personal information and was collected, used, or disclosed without consent
  • Whether insurance claims information constituted personal information
  • Whether drug activity information constituted personal information
  • Whether drug activity information was "publicly available" under the Regulations Specifying Publicly Available Information
  • Whether the respondent obtained adequate consent for the collection, use, and disclosure of personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2017PIPEDA findings #2017-011Indexed Jun 30, 2026

PIPEDA findings #2017-011: Financial institution originally misuses confidential commercial information exemption to withhold personal information

A financial institution

A complainant alleged that a financial institution refused to respond to his access to personal information request related to a disputed credit card transaction. Initially, the financial institution withheld documents, claiming they contained confidential commercial information under PIPEDA s.9(3)(b). The OPC found this exemption was inappropriately applied and that the financial institution failed to respond within the statutory 30-day timeframe. Following the OPC's preliminary report, the financial institution provided further clarification, leading the OPC to determine that the information in question was not the complainant's personal information and was correctly redacted under s.9(1) as third-party information. Although the complainant eventually received all personal information he was entitled to, the OPC criticized the financial institution's delay and initial misuse of the exemption. The complaint was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2017-011: Financial institution originally misuses confidential commercial information exemption to withhold personal information

Mar 31, 2017PIPEDA findings #2017-011
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a financial institution refused to respond to his access to personal information request related to a disputed credit card transaction. Initially, the financial institution withheld documents, claiming they contained confidential commercial information under PIPEDA s.9(3)(b). The OPC found this exemption was inappropriately applied and that the financial institution failed to respond within the statutory 30-day timeframe. Following the OPC's preliminary report, the financial institution provided further clarification, leading the OPC to determine that the information in question was not the complainant's personal information and was correctly redacted under s.9(1) as third-party information. Although the complainant eventually received all personal information he was entitled to, the OPC criticized the financial institution's delay and initial misuse of the exemption. The complaint was found to be well-founded and resolved.

Key Issues
  • Whether the financial institution responded to the access request within the 30-day time limit required by PIPEDA s.8(3)
  • Whether the financial institution sent a notice of extension within 30 days of the request as required by PIPEDA s.8(4)
  • Whether the financial institution appropriately applied the confidential commercial information exemption under PIPEDA s.9(3)(b) to withhold documents
  • Whether the withheld information constituted the complainant's personal information
  • Whether the information was properly redacted as third-party information under PIPEDA s.9(1)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 14, 2016PIPEDA Case Summary #2016-008Indexed Jun 30, 2026

PIPEDA Case Summary #2016-008: Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties

A telecommunications company

An individual complained that a telecommunications company (telco) provided an incomplete response to her access request for information about disclosures of her personal information to other parties, including law enforcement. The telco initially responded by stating it was in compliance with specific PIPEDA subsections, without confirming or denying disclosures. The OPC found that the telco's response did not meet its obligation under Principle 4.9 of PIPEDA, which requires organizations to inform individuals of the existence, use, and disclosure of their personal information. The OPC clarified that an organization must provide a clear 'yes' or 'no' answer regarding disclosures, unless a government institution objects to such disclosure under PIPEDA s.9(2.4). Following the OPC's recommendation, the telco provided a complete response to the complainant and updated its policy for handling future access requests. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-008: Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties

Jul 14, 2016PIPEDA Case Summary #2016-008
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a telecommunications company (telco) provided an incomplete response to her access request for information about disclosures of her personal information to other parties, including law enforcement. The telco initially responded by stating it was in compliance with specific PIPEDA subsections, without confirming or denying disclosures. The OPC found that the telco's response did not meet its obligation under Principle 4.9 of PIPEDA, which requires organizations to inform individuals of the existence, use, and disclosure of their personal information. The OPC clarified that an organization must provide a clear 'yes' or 'no' answer regarding disclosures, unless a government institution objects to such disclosure under PIPEDA s.9(2.4). Following the OPC's recommendation, the telco provided a complete response to the complainant and updated its policy for handling future access requests. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the telco's initial response to an access request for disclosure information met its obligations under Principle 4.9 of PIPEDA
  • Whether the telco's practice of stating compliance with PIPEDA s.9(2.1)-(2.4) was sufficient for access requests
  • Whether the telco had an obligation to provide a 'yes' or 'no' answer regarding disclosures to all third parties, including those not covered by PIPEDA s.9(2.1)-(2.4)
  • How an organization should respond to an access request for disclosure information when a government institution objects under PIPEDA s.9(2.4)