The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

39 decisions matching
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Feb 26, 2026Indexed Jun 30, 2026

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Canada Border Services Agency (CBSA)

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Quick view

Privacy ActWell-founded & resolved

Canada Border Services Agency’s Unauthorized Disclosure of Employee Personal Information Extracted from the Corporate Administrative Software Portal

Feb 26, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) received complaints regarding the unauthorized disclosure of personal information of over 18,000 Canada Border Services Agency (CBSA) employees. These disclosures occurred when HR-generated spreadsheets, intended for specific operational purposes like shift scheduling, contained excessive personal data or were shared with unauthorized employees. The CBSA's internal investigation uncovered four additional similar breaches. The OPC found that these incidents contravened section 8 of the Privacy Act regarding disclosure limitations. However, the CBSA took appropriate steps to notify affected individuals, contain the impact of the breaches, and implement both short-term and long-term measures to prevent recurrence, including new data request procedures and a future information management system. Consequently, the complaints were deemed well-founded and resolved.

Key Issues
  • Whether the CBSA's disclosure of employee personal information via spreadsheets contravened section 8 of the Privacy Act
  • Whether the inclusion of excess information in spreadsheets constituted unauthorized disclosure
  • Whether the use of personal email addresses for work-related data sharing contravened the Privacy Act
  • Whether the CBSA took adequate steps to address the incidents, including notification to affected individuals
  • Whether the CBSA's measures to reduce the risk of recurrence were reasonable
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 25, 2025PIPEDA Findings #2025-005Indexed Jun 30, 2026

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

A privately owned swimming pool

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

Nov 25, 2025PIPEDA Findings #2025-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Key Issues
  • Whether requiring consent for promotional photos and videos of children as a condition of service for swimming lessons contravenes Principle 4.3.3 of PIPEDA
  • Whether images of children in swim attire constitute sensitive personal information
  • Whether the collection, use, or disclosure of images for promotional or staff training purposes is strictly necessary for the provision of swimming lessons
  • Whether the organization offered individuals a choice regarding the collection, use, or disclosure of images for promotional or staff training purposes
  • Whether the organization should have sought express consent for the collection, use, or disclosure of images of children
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 28, 2024PIPEDA Findings #2024-002Indexed Jun 30, 2026

PIPEDA Findings #2024-002: Investigation into Brinks Home

Brinks Home

A Brinks Home customer complained that he could view other customers' personal information through his online portal. The OPC investigated whether Brinks Home had adequate security safeguards and complied with breach notification requirements. Brinks Home acknowledged an employee error caused 3,340 customer records to be accessible to 102 other customers, with up to 20 potentially accessing the data. The OPC found that Brinks Home failed to adequately protect personal information, but this issue was resolved by the company's corrective actions and subsequent sale of its Canadian customer accounts. Regarding breach notification, the OPC determined that while the information was sensitive, the probability of misuse was low because the unauthorized access was by known customers, not malicious actors. Therefore, the incident did not pose a real risk of significant harm, and Brinks Home was not required to report it or notify affected individuals.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2024-002: Investigation into Brinks Home

Mar 28, 2024PIPEDA Findings #2024-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

A Brinks Home customer complained that he could view other customers' personal information through his online portal. The OPC investigated whether Brinks Home had adequate security safeguards and complied with breach notification requirements. Brinks Home acknowledged an employee error caused 3,340 customer records to be accessible to 102 other customers, with up to 20 potentially accessing the data. The OPC found that Brinks Home failed to adequately protect personal information, but this issue was resolved by the company's corrective actions and subsequent sale of its Canadian customer accounts. Regarding breach notification, the OPC determined that while the information was sensitive, the probability of misuse was low because the unauthorized access was by known customers, not malicious actors. Therefore, the incident did not pose a real risk of significant harm, and Brinks Home was not required to report it or notify affected individuals.

Key Issues
  • Whether Brinks Home implemented adequate security safeguards to protect customers' personal information under Principle 4.7 of Schedule 1 of PIPEDA
  • Whether Brinks Home complied with breach notification requirements under section 10.1 of PIPEDA
  • Whether the breach presented a real risk of significant harm (RROSH)
  • Whether the personal information involved was sensitive
  • Whether the probability of misuse of the personal information was low
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Apr 13, 2023Indexed Jun 30, 2026

Investigation of Correctional Service Canada’s collection and disclosure of an individual’s personal information from Facebook related to an employee’s 699-leave

Correctional Service Canada

A complaint was filed against Correctional Service Canada (CSC) by the spouse of an employee, alleging inappropriate collection and disclosure of personal information from their public Facebook page. The information was collected by an assistant warden to investigate the employee's use of 'other leave with pay (699)' during the COVID-19 pandemic. The OPC found that significant portions of the collected information were not directly related to an operating program or activity of CSC, thus contravening Section 4 of the Privacy Act. The OPC also noted that the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies only to use and disclosure, not collection. CSC subsequently deleted the collected screenshots and committed to developing guidance for managers on collecting information in a labour relations context. The complainant also raised concerns about CSC's internal complaint process, which CSC acknowledged was mishandled.

Quick view

Privacy ActWell-founded & resolved

Investigation of Correctional Service Canada’s collection and disclosure of an individual’s personal information from Facebook related to an employee’s 699-leave

Apr 13, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

A complaint was filed against Correctional Service Canada (CSC) by the spouse of an employee, alleging inappropriate collection and disclosure of personal information from their public Facebook page. The information was collected by an assistant warden to investigate the employee's use of 'other leave with pay (699)' during the COVID-19 pandemic. The OPC found that significant portions of the collected information were not directly related to an operating program or activity of CSC, thus contravening Section 4 of the Privacy Act. The OPC also noted that the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies only to use and disclosure, not collection. CSC subsequently deleted the collected screenshots and committed to developing guidance for managers on collecting information in a labour relations context. The complainant also raised concerns about CSC's internal complaint process, which CSC acknowledged was mishandled.

Key Issues
  • Whether the collection of personal information from a public Facebook page was directly related to an operating program or activity of CSC under Section 4 of the Privacy Act
  • Whether the exclusion for publicly available information under subsection 69(2) of the Privacy Act applies to the collection of personal information
  • Whether the subsequent disclosure of the collected information was appropriate
  • Whether CSC's internal process for handling privacy complaints from the public was adequate
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Feb 23, 2023Indexed Jun 30, 2026

Failure to publish a personal information bank description on Zero-Emissions Program contravenes the Privacy Act

Transport Canada

An individual complained that Transport Canada collected his personal information for the "Incentives for Zero-Emission Vehicles Program" (iZEV) without a publicly available Personal Information Bank (PIB) description, as required by the Privacy Act. Transport Canada launched the iZEV program in May 2019 but did not submit a PIB description to the Treasury Board Secretariat (TBS) for approval until 19 months later. The OPC found that both Transport Canada and TBS contributed to the contravention, as TBS failed to approve and publish the PIB description in a timely manner. Although Transport Canada eventually published the PIB, TBS declined to implement the OPC's recommendations for service standards, citing complexity, but outlined internal process improvements. The OPC acknowledged TBS's efforts to address the backlog.

Quick view

Privacy ActWell-founded & resolved

Failure to publish a personal information bank description on Zero-Emissions Program contravenes the Privacy Act

Feb 23, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that Transport Canada collected his personal information for the "Incentives for Zero-Emission Vehicles Program" (iZEV) without a publicly available Personal Information Bank (PIB) description, as required by the Privacy Act. Transport Canada launched the iZEV program in May 2019 but did not submit a PIB description to the Treasury Board Secretariat (TBS) for approval until 19 months later. The OPC found that both Transport Canada and TBS contributed to the contravention, as TBS failed to approve and publish the PIB description in a timely manner. Although Transport Canada eventually published the PIB, TBS declined to implement the OPC's recommendations for service standards, citing complexity, but outlined internal process improvements. The OPC acknowledged TBS's efforts to address the backlog.

Key Issues
  • Whether Transport Canada failed to ensure personal information collected for the iZEV program was included in a publicly available PIB description as required by section 10 of the Privacy Act
  • Whether Transport Canada obtained TBS approval for a new PIB before implementing the iZEV program as required by subsection 71(4) of the Privacy Act and the TBS Directive on Privacy Impact Assessment
  • Whether TBS fulfilled its responsibility under section 11 of the Privacy Act to ensure timely publication of PIB descriptions
  • Whether the lack of a timely PIB approval process by TBS impacts the operability of the PIB regime under the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 26, 2023PIPEDA Findings #2023-001Indexed Jun 30, 2026

PIPEDA Findings #2023-001: Investigation into Home Depot of Canada Inc.’s compliance with PIPEDA

Home Depot of Canada Inc.

The complainant alleged that Home Depot disclosed his personal information to Meta (formerly Facebook) without his knowledge and consent. Home Depot was sending in-store customers' hashed email addresses and purchase details to Meta via an "Offline Conversions" tool when customers requested an e-receipt. This data allowed Meta to measure ad effectiveness and use the information for its own business purposes, including targeted advertising. The OPC found that Home Depot failed to obtain valid consent, as its privacy statement was not readily available or sufficiently clear, and customers would not reasonably expect such disclosure. Home Depot discontinued the use of the tool in October 2022 in response to OPC recommendations. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2023-001: Investigation into Home Depot of Canada Inc.’s compliance with PIPEDA

Jan 26, 2023PIPEDA Findings #2023-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Home Depot disclosed his personal information to Meta (formerly Facebook) without his knowledge and consent. Home Depot was sending in-store customers' hashed email addresses and purchase details to Meta via an "Offline Conversions" tool when customers requested an e-receipt. This data allowed Meta to measure ad effectiveness and use the information for its own business purposes, including targeted advertising. The OPC found that Home Depot failed to obtain valid consent, as its privacy statement was not readily available or sufficiently clear, and customers would not reasonably expect such disclosure. Home Depot discontinued the use of the tool in October 2022 in response to OPC recommendations. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether Home Depot obtained valid consent for disclosing customer personal information to Meta
  • Whether the disclosure of personal information to Meta constituted a processing activity not requiring additional consent
  • Whether Home Depot's Privacy Statement and Meta's Privacy Policy were sufficient to obtain meaningful implied consent
  • Whether express opt-in consent was required for the disclosure of customer information to Meta
  • Whether the information disclosed was sensitive
  • Whether the disclosure was within the reasonable expectations of the individual
  • Whether the ability to withdraw consent after the fact was sufficient
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-003Indexed Jun 30, 2026

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Bank of Montreal

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Mar 30, 2021PIPEDA Findings #2021-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether BMO implemented appropriate security safeguards to adequately protect personal information under its control, as required by PIPEDA Principle 4.7
  • Adequacy of BMO's developer security testing and evaluation processes
  • Adequacy of BMO's vulnerability management program, including identification, assessment, and remediation of vulnerabilities
  • Adequacy of BMO's oversight and monitoring capabilities, specifically regarding bot management, cyberattack detection, and real-time alerts
  • Adequacy of BMO's organizational policies and procedures for handling cyberattacks and incident response
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 24, 2021PIPEDA Findings #2021-007Indexed Jun 30, 2026

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

A computer services company

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

Mar 24, 2021PIPEDA Findings #2021-007
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Key Issues
  • Whether the respondent obtained meaningful consent prior to remotely accessing laptops
  • Whether the respondent had adequate safeguards to prevent unauthorized access to customers’ personal information by its personnel
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 22, 2021PIPEDA Findings #2021-008Indexed Jun 30, 2026

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Oculus Transport Ltd.

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Mar 22, 2021PIPEDA Findings #2021-008
Adjudicator: Daniel Therrien
Plain-Language Summary

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Key Issues
  • Whether the collection and use of personal information via audio surveillance technology was for purposes that a reasonable person would consider appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the personal information collected was sensitive
  • Whether the organization's purpose represented a legitimate need / bona fide business interest
  • Whether the collection, use and disclosure would be effective in meeting the organization’s need
  • Whether there are less privacy invasive means of achieving the same ends at comparable cost and with comparable benefits
  • Whether the loss of privacy is proportional to the benefits
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Nov 17, 2020Indexed Jun 30, 2026

Employer’s disclosure related to a transgender individual was contrary to the Privacy Act

A federal government institution

An employee complained that a federal government institution breached her privacy by disclosing her transgender identity and the reasons for her transfer to her new manager and colleagues without her consent. The complainant had explicitly requested confidentiality due to prior workplace harassment related to her gender identity, and the employer had assured her of discretion. The institution's internal review confirmed that managers disclosed this sensitive information, believing it necessary to support the employee and her new supervisor, but acknowledged this was an error and contrary to internal policies. The OPC found that the disclosure was made without consent, contravening section 8(1) of the Privacy Act. The institution recognized the breach and committed to improving policies and providing transgender awareness education. The OPC recommended updating policies to prevent similar incidents, and the institution created new guidance for its staff.

Quick view

Privacy ActWell-founded & resolved

Employer’s disclosure related to a transgender individual was contrary to the Privacy Act

Nov 17, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that a federal government institution breached her privacy by disclosing her transgender identity and the reasons for her transfer to her new manager and colleagues without her consent. The complainant had explicitly requested confidentiality due to prior workplace harassment related to her gender identity, and the employer had assured her of discretion. The institution's internal review confirmed that managers disclosed this sensitive information, believing it necessary to support the employee and her new supervisor, but acknowledged this was an error and contrary to internal policies. The OPC found that the disclosure was made without consent, contravening section 8(1) of the Privacy Act. The institution recognized the breach and committed to improving policies and providing transgender awareness education. The OPC recommended updating policies to prevent similar incidents, and the institution created new guidance for its staff.

Key Issues
  • Whether information about an individual's transgender identity is personal information requiring protection under the Privacy Act
  • Whether the institution disclosed the complainant's personal information without consent
  • Whether the disclosure was contrary to section 8(1) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 28, 2020PIPEDA Findings #2020-004Indexed Jun 30, 2026

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

The Cadillac Fairview Corporation Limited

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

Oct 28, 2020PIPEDA Findings #2020-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Key Issues
  • Whether CFCL’s use of Anonymous Video Analytics (AVA) technology, via in-mall directories, resulted in the collection, use, and/or disclosure of personal information.
  • Whether images of individual faces captured by AVA technology constitute personal information.
  • Whether numerical representations of faces (biometric information) generated by AVA technology constitute personal information.
  • Whether age range and gender assessments, combined with other data, constitute personal information.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via AVA technology.
  • Whether CFCL retained personal information collected via AVA technology longer than necessary.
  • Whether CFCL’s use of mobile device geolocation technologies (Anonymous Shopper Journey) resulted in the collection, use, and/or disclosure of personal information.
  • Whether hashed and randomized MAC addresses, combined with non-granular zone geolocation, constitute personal information in the context of anonymous shopper tracking.
  • Whether CFCL’s use of mobile device geolocation technologies (Logged In Shopper Journey) resulted in the collection, use, and/or disclosure of personal information linked to identifiable individuals.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via mobile device geolocation technologies (Logged In Shopper Journey).
  • Whether CFCL's privacy policy and signage provided sufficient notice and obtained valid consent for its data collection practices.
  • Whether the "serious possibility" threshold for identifying individuals was met for anonymous shopper journey data.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Investigation into a privacy breach at Public Services and Procurement Canada

Public Services and Procurement Canada (PSPC)

The Office of the Privacy Commissioner (OPC) investigated complaints from federal public servants regarding an improper disclosure of their pay-related information by Public Services and Procurement Canada (PSPC). PSPC inadvertently sent personnel overpayment reports containing personal information of 69,087 public servants to the wrong government institutions. The OPC found that PSPC contravened section 8 of the Privacy Act by disclosing personal information without authorization. However, the complaints were deemed resolved due to PSPC's corrective actions, which included implementing new procedures with quality controls for report generation, requesting deletion of the flawed reports, and notifying affected individuals. The OPC noted that while notification was timely, some departments modified the notification letters, leading to inconsistencies in the information received by individuals.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at Public Services and Procurement Canada

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated complaints from federal public servants regarding an improper disclosure of their pay-related information by Public Services and Procurement Canada (PSPC). PSPC inadvertently sent personnel overpayment reports containing personal information of 69,087 public servants to the wrong government institutions. The OPC found that PSPC contravened section 8 of the Privacy Act by disclosing personal information without authorization. However, the complaints were deemed resolved due to PSPC's corrective actions, which included implementing new procedures with quality controls for report generation, requesting deletion of the flawed reports, and notifying affected individuals. The OPC noted that while notification was timely, some departments modified the notification letters, leading to inconsistencies in the information received by individuals.

Key Issues
  • Whether PSPC improperly disclosed personal information in contravention of section 8 of the Privacy Act
  • Whether the information disclosed constituted 'personal information' under section 3 of the Privacy Act
  • Whether PSPC's response to the breach, including mitigation and notification, was adequate
  • Whether PSPC implemented sufficient measures to prevent recurrence of the breach
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 9, 2020PIPEDA Findings #2020-003Indexed Jun 30, 2026

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Dell Inc.

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Jul 9, 2020PIPEDA Findings #2020-003
Adjudicator: Daniel Therrien
Plain-Language Summary

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Key Issues
  • Whether Dell adequately safeguarded personal information under its control while using a service provider (PIPEDA Principle 4.1.3 and 4.7).
  • Whether the personal information transferred to the service provider was sensitive enough to require a high degree of protection.
  • Whether Dell's access controls were sufficient to protect customer information.
  • Whether Dell's logging and monitoring practices were adequate to detect anomalous employee requests for customer information.
  • Whether Dell's technical measures, such as USB drive restrictions, were sufficient.
  • Whether Dell adequately investigated the circumstances and scope of the June 2017 breach.
  • Whether Dell adequately responded to customer complaints about potential privacy breaches (PIPEDA Principle 4.10.4).
  • Whether Dell remained responsible for personal information transferred to a third party for processing.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 16, 2019PIPEDA Findings #2019-003Indexed Jun 30, 2026

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Loblaw Companies Ltd.

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Oct 16, 2019PIPEDA Findings #2019-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Key Issues
  • Whether Loblaw collected more personal information than necessary for the Loblaw Card Program (Principle 4.4)
  • Whether Loblaw ensured a comparable level of protection for personal information transferred to a third party for processing (Principle 4.1.3)
  • Whether Loblaw was required to obtain additional consent for the transfer of personal information for processing (Principle 4.3)
  • Whether Loblaw was sufficiently open and transparent about its cross-border data transfers (Principle 4.8)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 8, 2018PIPEDA Report of Findings #2018-001Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

VTech Holdings Limited

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

Jan 8, 2018PIPEDA Report of Findings #2018-001
Adjudicator: Daniel Therrien
Plain-Language Summary

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Key Issues
  • Whether VTech Holdings Limited failed to adequately safeguard personal information under Principle 4.7 PIPEDA
  • Whether VTech's security safeguards were appropriate to the sensitivity of the information (Principle 4.7 PIPEDA)
  • Whether VTech's safeguards protected against unauthorized access, disclosure, copying, use, or modification (Principle 4.7.1 PIPEDA)
  • Whether the nature of VTech's safeguards varied depending on the sensitivity, amount, distribution, format, and storage method of the information (Principle 4.7.2 PIPEDA)
  • Whether VTech's methods of protection included physical, organizational, and technological measures (Principle 4.7.3 PIPEDA)
  • Whether VTech had adequate testing and maintenance protocols to identify and mitigate vulnerabilities
  • Whether VTech had adequate administrative access controls
  • Whether VTech had adequate cryptographic protection for personal information
  • Whether VTech had sufficient security monitoring and logging to detect threats
  • Whether VTech had a comprehensive security management program