The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

6 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 20, 2025PIPEDA Findings #2025-001Indexed Jun 30, 2026

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

23andMe Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

Jun 20, 2025PIPEDA Findings #2025-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Key Issues
  • Whether 23andMe had appropriate safeguards to protect highly sensitive personal information under its control, specifically against credential stuffing attacks.
  • Whether 23andMe's prevention measures, including mandatory Multi-factor Authentication (MFA), compromised-password checks, and minimum password requirements, were adequate.
  • Whether 23andMe's detection measures, including detection systems, digital fingerprinting, and device history, were adequate to identify ongoing attacks.
  • Whether 23andMe adequately investigated anomalies and claims of breach prior to public disclosure.
  • Whether 23andMe's breach response, including the timeliness of disabling active user sessions, disabling raw DNA download features, and implementing mandatory MFA, was adequate.
  • Whether 23andMe adequately notified the OPC about the breach, including the completeness of information provided and timeliness.
  • Whether 23andMe adequately notified affected individuals about the breach, including the completeness of information provided and timeliness.
  • Whether the data breach created a real risk of significant harm to affected individuals, triggering notification obligations.
  • Whether 23andMe's methodology for identifying and notifying individuals whose raw DNA was downloaded by the Threat Actor was adequate.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 30, 2023Indexed Jun 30, 2026

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

Treasury Board of Canada Secretariat

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

Quick view

Privacy ActWell-founded & resolved

Investigation into COVID-19 vaccination attestation requirements established by the Treasury Board of Canada for employees of the core public administration

May 30, 2023
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

Key Issues
  • Whether the information collected by institutions related directly to an operating program or activity of the institution as required by section 4 of the Privacy Act.
  • Whether institutions properly met the transparency requirements of subsection 5(2) of the Privacy Act regarding informing individuals of the purpose of collection.
  • Whether the Treasury Board of Canada Secretariat (TBS) complied with subsection 11(1) of the Privacy Act by publishing an index of personal information banks.
  • Whether disclosures of personal information collected under the Policy were authorized under section 8 of the Privacy Act.
  • Whether the collection of personal information was necessary and proportional, applying the OPC's four-part test.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 20, 2022Indexed Jun 30, 2026

Investigation into a privacy breach at a Canada Border Services Agency contractor

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at a Canada Border Services Agency contractor

May 20, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Key Issues
  • Whether licence plate image files, including associated metadata (jurisdiction, characters, date, time, border crossing site, lane number), constitute personal information under Section 3 of the Privacy Act.
  • Whether the unauthorized access and disclosure of these licence plate image files constituted an improper disclosure under Section 8 of the Privacy Act.
  • Whether the Canada Border Services Agency (CBSA) had adequate security safeguards in place, particularly in its contractual arrangements with a third-party contractor, to protect personal information.
  • Whether the data retention practices for licence plate image files by the CBSA and its contractor were appropriate and compliant with the Privacy Act.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Employment and Social Development Canada (ESDC)

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Quick view

Privacy ActWell-founded & resolved

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Key Issues
  • Whether Employment and Social Development Canada (ESDC) adequately protected personal information on a lost USB key
  • Whether Justice Canada adequately protected personal information on a lost USB key while in its custody
  • Whether physical controls for personal information were adequate
  • Whether technological controls (encryption, password protection) for personal information were adequate
  • Whether administrative controls for personal information were adequate
  • Whether personnel controls for personal information were adequate
  • Whether ESDC translated its privacy and security policies into meaningful business practices
  • Whether Justice Canada translated its privacy and security policies into meaningful business practices
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 4, 2006Incident Summary #3Indexed Jun 30, 2026

Incident Summary #3: Misdirected faxes - December 4, 2006

Two Canadian banks

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #3: Misdirected faxes - December 4, 2006

Dec 4, 2006Incident Summary #3
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Key Issues
  • Whether organizations adequately safeguard personal information to prevent inappropriate disclosure (Principle 4.7 PIPEDA)
  • Whether organizations implement effective policies and procedures to give effect to fair information practices (Principle 4.1 PIPEDA)
  • Whether employees are attuned to privacy issues and can respond to problems when they arise
  • Whether organizations notify affected customers of privacy breaches
  • Whether organizations have processes for confirming correct fax transmission
  • Whether organizations have measures to recover erroneously transmitted customer information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 18, 2005Incident Summary #2Indexed Jun 30, 2026

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

CIBC

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

Apr 18, 2005Incident Summary #2
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Key Issues
  • Whether CIBC's privacy practices adequately protected personal information from misdirected faxes
  • Whether CIBC effectively responded to notifications of misdirected faxes
  • Whether CIBC appropriately recovered misdirected personal information
  • Whether CIBC adequately notified affected customers of privacy breaches
  • Whether CIBC employees recognized misdirected faxes as privacy issues
  • Whether CIBC's internal privacy management structure was sufficient to address breaches