The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

8 decisions matching
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Feb 26, 2026Indexed Jun 30, 2026

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Canada Border Services Agency (CBSA)

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Quick view

Privacy ActWell-founded & resolved

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Feb 26, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Key Issues
  • Whether the CBSA's disclosure of employee personal information via spreadsheets contravened section 8 of the Privacy Act
  • Whether the inclusion of excess information in spreadsheets constituted unauthorized disclosure
  • Whether the use of personal email addresses for work-related data sharing contravened the Privacy Act
  • Whether the CBSA took adequate steps to address the incidents, including notification to affected individuals
  • Whether the CBSA's measures to reduce the risk of recurrence were reasonable
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

Treasury Board of Canada Secretariat

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

Quick view

Privacy ActWell-founded & resolved

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

Key Issues
  • Whether the information collected by institutions related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act.
  • Whether institutions properly met the transparency requirements of subsection 5(2) of the Privacy Act regarding informing individuals of the purpose of collection.
  • Whether the Treasury Board of Canada Secretariat (TBS) complied with subsection 11(1) of the Privacy Act by publishing an index of personal information banks.
  • Whether disclosures of personal information collected under the Policy were authorized under section 8 of the Privacy Act.
  • Whether the collection of personal information was necessary and proportional, applying the OPC's four-part test.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Apr 13, 2023Indexed Jun 30, 2026

Investigation of Correctional Service Canada’s collection and disclosure of an individual’s personal information from Facebook related to an employee’s 699-leave

Correctional Service Canada

A complaint was filed against Correctional Service Canada (CSC) by the spouse of an employee, alleging inappropriate collection and disclosure of personal information from their public Facebook page. The information was collected by an assistant warden to investigate the employee's use of 'other leave with pay (699)' during the COVID-19 pandemic. The OPC found that significant portions of the collected information were not directly related to an operating program or activity of CSC, thus contravening Section 4 of the Privacy Act. The OPC also noted that the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies only to use and disclosure, not collection. CSC subsequently deleted the collected screenshots and committed to developing guidance for managers on collecting information in a labour relations context. The complainant also raised concerns about CSC's internal complaint process, which CSC acknowledged was mishandled.

Quick view

Privacy ActWell-founded & resolved

Investigation of Correctional Service Canada’s collection and disclosure of an individual’s personal information from Facebook related to an employee’s 699-leave

Apr 13, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

A complaint was filed against Correctional Service Canada (CSC) by the spouse of an employee, alleging inappropriate collection and disclosure of personal information from their public Facebook page. The information was collected by an assistant warden to investigate the employee's use of 'other leave with pay (699)' during the COVID-19 pandemic. The OPC found that significant portions of the collected information were not directly related to an operating program or activity of CSC, thus contravening Section 4 of the Privacy Act. The OPC also noted that the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies only to use and disclosure, not collection. CSC subsequently deleted the collected screenshots and committed to developing guidance for managers on collecting information in a labour relations context. The complainant also raised concerns about CSC's internal complaint process, which CSC acknowledged was mishandled.

Key Issues
  • Whether the collection of personal information from a public Facebook page was directly related to an operating program or activity of CSC under Section 4 of the Privacy Act
  • Whether the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies to the collection of personal information
  • Whether the subsequent disclosure of the collected information was appropriate
  • Whether CSC's internal process for handling privacy complaints from the public was adequate
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Feb 23, 2023Indexed Jun 30, 2026

Failure to publish a personal information bank description on Zero-Emissions Program contravenes the Privacy Act

Transport Canada

An individual complained that Transport Canada collected his personal information for the "Incentives for Zero-Emission Vehicles Program" (iZEV) without a publicly available Personal Information Bank (PIB) description, as required by the Privacy Act. Transport Canada launched the iZEV program in May 2019 but did not submit a PIB description to the Treasury Board Secretariat (TBS) for approval until 19 months later. The OPC found that both Transport Canada and TBS contributed to the contravention, as TBS failed to approve and publish the PIB description in a timely manner. Although Transport Canada eventually published the PIB, TBS declined to implement the OPC's recommendations for service standards, citing complexity, but outlined internal process improvements. The OPC acknowledged TBS's efforts to address the backlog.

Quick view

Privacy ActWell-founded & resolved

Failure to publish a personal information bank description on Zero-Emissions Program contravenes the Privacy Act

Feb 23, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that Transport Canada collected his personal information for the "Incentives for Zero-Emission Vehicles Program" (iZEV) without a publicly available Personal Information Bank (PIB) description, as required by the Privacy Act. Transport Canada launched the iZEV program in May 2019 but did not submit a PIB description to the Treasury Board Secretariat (TBS) for approval until 19 months later. The OPC found that both Transport Canada and TBS contributed to the contravention, as TBS failed to approve and publish the PIB description in a timely manner. Although Transport Canada eventually published the PIB, TBS declined to implement the OPC's recommendations for service standards, citing complexity, but outlined internal process improvements. The OPC acknowledged TBS's efforts to address the backlog.

Key Issues
  • Whether Transport Canada failed to ensure personal information collected for the iZEV program was included in a publicly available PIB description as required by section 10 of the Privacy Act
  • Whether Transport Canada obtained TBS approval for a new PIB before implementing the iZEV program as required by subsection 71(4) of the Privacy Act and the TBS Directive on Privacy Impact Assessment
  • Whether TBS fulfilled its responsibility under section 11 of the Privacy Act to ensure timely publication of PIB descriptions
  • Whether the lack of a timely PIB approval process by TBS impacts the operability of the PIB regime under the Privacy Act
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 20, 2022Indexed Jun 30, 2026

Investigation into a privacy breach at a Canada Border Services Agency contractor

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at a Canada Border Services Agency contractor

May 20, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Key Issues
  • Whether licence plate image files, including associated metadata (jurisdiction, characters, date, time, border crossing site, lane number), constitute personal information under Section 3 of the Privacy Act.
  • Whether the unauthorized access and disclosure of these licence plate image files constituted an improper disclosure under Section 8 of the Privacy Act.
  • Whether the Canada Border Services Agency (CBSA) had adequate security safeguards in place, particularly in its contractual arrangements with a third-party contractor, to protect personal information.
  • Whether the data retention practices for licence plate image files by the CBSA and its contractor were appropriate and compliant with the Privacy Act.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Nov 17, 2020Indexed Jun 30, 2026

Employer’s disclosure related to a transgender individual was contrary to the Privacy Act

A federal government institution

An employee complained that a federal government institution breached her privacy by disclosing her transgender identity and the reasons for her transfer to her new manager and colleagues without her consent. The complainant had explicitly requested confidentiality due to prior workplace harassment related to her gender identity, and the employer had assured her of discretion. The institution's internal review confirmed that managers disclosed this sensitive information, believing it necessary to support the employee and her new supervisor, but acknowledged this was an error and contrary to internal policies. The OPC found that the disclosure was made without consent, contravening section 8(1) of the Privacy Act. The institution recognized the breach and committed to improving policies and providing transgender awareness education. The OPC recommended updating policies to prevent similar incidents, and the institution created new guidance for its staff.

Quick view

Privacy ActWell-founded & resolved

Employer’s disclosure related to a transgender individual was contrary to the Privacy Act

Nov 17, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that a federal government institution breached her privacy by disclosing her transgender identity and the reasons for her transfer to her new manager and colleagues without her consent. The complainant had explicitly requested confidentiality due to prior workplace harassment related to her gender identity, and the employer had assured her of discretion. The institution's internal review confirmed that managers disclosed this sensitive information, believing it necessary to support the employee and her new supervisor, but acknowledged this was an error and contrary to internal policies. The OPC found that the disclosure was made without consent, contravening section 8(1) of the Privacy Act. The institution recognized the breach and committed to improving policies and providing transgender awareness education. The OPC recommended updating policies to prevent similar incidents, and the institution created new guidance for its staff.

Key Issues
  • Whether information about an individual's transgender identity is personal information requiring protection under the Privacy Act
  • Whether the institution disclosed the complainant's personal information without consent
  • Whether the disclosure was contrary to section 8(1) of the Privacy Act
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Investigation into a privacy breach at Public Services and Procurement Canada

Public Services and Procurement Canada (PSPC)

The Office of the Privacy Commissioner (OPC) investigated complaints from federal public servants regarding an improper disclosure of their pay-related information by Public Services and Procurement Canada (PSPC). PSPC inadvertently sent personnel overpayment reports containing personal information of 69,087 public servants to the wrong government institutions. The OPC found that PSPC contravened section 8 of the Privacy Act by disclosing personal information without authorization. However, the complaints were deemed resolved due to PSPC's corrective actions, which included implementing new procedures with quality controls for report generation, requesting deletion of the flawed reports, and notifying affected individuals. The OPC noted that while notification was timely, some departments modified the notification letters, leading to inconsistencies in the information received by individuals.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at Public Services and Procurement Canada

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated complaints from federal public servants regarding an improper disclosure of their pay-related information by Public Services and Procurement Canada (PSPC). PSPC inadvertently sent personnel overpayment reports containing personal information of 69,087 public servants to the wrong government institutions. The OPC found that PSPC contravened section 8 of the Privacy Act by disclosing personal information without authorization. However, the complaints were deemed resolved due to PSPC's corrective actions, which included implementing new procedures with quality controls for report generation, requesting deletion of the flawed reports, and notifying affected individuals. The OPC noted that while notification was timely, some departments modified the notification letters, leading to inconsistencies in the information received by individuals.

Key Issues
  • Whether PSPC improperly disclosed personal information in contravention of section 8 of the Privacy Act
  • Whether the information disclosed constituted 'personal information' under section 3 of the Privacy Act
  • Whether PSPC's response to the breach, including mitigation and notification, was adequate
  • Whether PSPC implemented sufficient measures to prevent recurrence of the breach
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Employment and Social Development Canada (ESDC)

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Quick view

Privacy ActWell-founded & resolved

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Key Issues
  • Whether Employment and Social Development Canada (ESDC) adequately protected personal information on a lost USB key
  • Whether Justice Canada adequately protected personal information on a lost USB key while in its custody
  • Whether physical controls for personal information were adequate
  • Whether technological controls (encryption, password protection) for personal information were adequate
  • Whether administrative controls for personal information were adequate
  • Whether personnel controls for personal information were adequate
  • Whether ESDC translated its privacy and security policies into meaningful business practices
  • Whether Justice Canada translated its privacy and security policies into meaningful business practices