The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

172 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 26, 2023PIPEDA Findings #2023-001Indexed Jun 30, 2026

PIPEDA Findings #2023-001: Investigation into Home Depot of Canada Inc.’s compliance with PIPEDA

Home Depot of Canada Inc.

The complainant alleged that Home Depot disclosed his personal information to Meta (formerly Facebook) without his knowledge and consent. Home Depot was sending in-store customers' hashed email addresses and purchase details to Meta via an "Offline Conversions" tool when customers requested an e-receipt. This data allowed Meta to measure ad effectiveness and use the information for its own business purposes, including targeted advertising. The OPC found that Home Depot failed to obtain valid consent, as its privacy statement was not readily available or sufficiently clear, and customers would not reasonably expect such disclosure. Home Depot discontinued the use of the tool in October 2022 in response to OPC recommendations. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2023-001: Investigation into Home Depot of Canada Inc.’s compliance with PIPEDA

Jan 26, 2023PIPEDA Findings #2023-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Home Depot disclosed his personal information to Meta (formerly Facebook) without his knowledge and consent. Home Depot was sending in-store customers' hashed email addresses and purchase details to Meta via an "Offline Conversions" tool when customers requested an e-receipt. This data allowed Meta to measure ad effectiveness and use the information for its own business purposes, including targeted advertising. The OPC found that Home Depot failed to obtain valid consent, as its privacy statement was not readily available or sufficiently clear, and customers would not reasonably expect such disclosure. Home Depot discontinued the use of the tool in October 2022 in response to OPC recommendations. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether Home Depot obtained valid consent for disclosing customer personal information to Meta
  • Whether the disclosure of personal information to Meta constituted a processing activity not requiring additional consent
  • Whether Home Depot's Privacy Statement and Meta's Privacy Policy were sufficient to obtain meaningful implied consent
  • Whether express opt-in consent was required for the disclosure of customer information to Meta
  • Whether the information disclosed was sensitive
  • Whether the disclosure was within the reasonable expectations of the individual
  • Whether the ability to withdraw consent after the fact was sufficient
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 27, 2022PIPEDA Findings #2022-006Indexed Jun 30, 2026

PIPEDA Findings #2022-006: Investigation into Trimac’s use of an audio and video surveillance device in its truck cabins

Trimac Transportation Services Inc.

A truck driver complained that Trimac Transportation Services Inc. (Trimac) installed a dash camera in his vehicle that continuously recorded audio and video without his consent, particularly concerned with audio recording. The OPC investigated two main issues: the appropriateness of the audio recording functionality and whether employee consent was required. The OPC found that Trimac's continuous audio recording, even when drivers were off-duty, was disproportionately privacy-intrusive, despite legitimate business needs. Trimac also initially failed to be transparent about the disciplinary purposes of the system, meaning it could not rely on the employment relationship exception to consent. Trimac agreed to implement recommendations to limit audio recording to on-duty hours and restrict access to recorded clips, and has since clarified the system's disciplinary uses to employees. The OPC found the audio recording issue well-founded and conditionally resolved, and the consent issue well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-006: Investigation into Trimac’s use of an audio and video surveillance device in its truck cabins

Jul 27, 2022PIPEDA Findings #2022-006
Adjudicator: Philippe Dufresne
Plain-Language Summary

A truck driver complained that Trimac Transportation Services Inc. (Trimac) installed a dash camera in his vehicle that continuously recorded audio and video without his consent, particularly concerned with audio recording. The OPC investigated two main issues: the appropriateness of the audio recording functionality and whether employee consent was required. The OPC found that Trimac's continuous audio recording, even when drivers were off-duty, was disproportionately privacy-intrusive, despite legitimate business needs. Trimac also initially failed to be transparent about the disciplinary purposes of the system, meaning it could not rely on the employment relationship exception to consent. Trimac agreed to implement recommendations to limit audio recording to on-duty hours and restrict access to recorded clips, and has since clarified the system's disciplinary uses to employees. The OPC found the audio recording issue well-founded and conditionally resolved, and the consent issue well-founded and resolved.

Key Issues
  • Whether road safety, asset protection, and employee performance management are appropriate purposes for the continuous collection of in-cabin audio via the System, including when drivers are off-duty and not driving, under subsection 5(3) of PIPEDA.
  • Whether the collection of sensitive personal information (in-cabin audio) was justified given the legitimate need, effectiveness, less privacy-invasive means, and proportionality.
  • Whether employee consent was required for the collection of personal information via the System, specifically whether Trimac could rely on the exception to consent under subsection 7.3 of PIPEDA.
  • Whether Trimac was sufficiently transparent about the disciplinary purposes of its dash camera system to rely on the subsection 7.3 exception to consent.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 15, 2022PIPEDA Findings #2022-005Indexed Jun 30, 2026

PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor

Marriott International, Inc.

On November 30, 2018, Marriott International, Inc. announced a data security breach involving unauthorized access to a Starwood Hotels database, which it had acquired in 2016. The breach, spanning over four years, affected up to 12.8 million Canadian records, including passport and payment card details. The OPC launched an investigation into Luxury Hotels Canada, Marriott's Canadian operating company, following eleven complaints. The investigation found Marriott's security safeguards, accountability measures, and information retention practices to be inadequate, contravening PIPEDA Principles 4.7, 4.1.4, and 4.5. Specifically, Marriott failed to detect the breach sooner due to insufficient logging, monitoring, and multi-factor authentication, and retained personal information longer than necessary. While Marriott's notification to affected individuals was deemed adequate, the OPC had outstanding concerns regarding remote access, unencrypted data storage, and retention periods. The findings are well-founded and conditionally resolved, as Marriott committed to implementing the OPC's recommendations, including engaging an external assessor and reviewing its privacy framework.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor

Jul 15, 2022PIPEDA Findings #2022-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

On November 30, 2018, Marriott International, Inc. announced a data security breach involving unauthorized access to a Starwood Hotels database, which it had acquired in 2016. The breach, spanning over four years, affected up to 12.8 million Canadian records, including passport and payment card details. The OPC launched an investigation into Luxury Hotels Canada, Marriott's Canadian operating company, following eleven complaints. The investigation found Marriott's security safeguards, accountability measures, and information retention practices to be inadequate, contravening PIPEDA Principles 4.7, 4.1.4, and 4.5. Specifically, Marriott failed to detect the breach sooner due to insufficient logging, monitoring, and multi-factor authentication, and retained personal information longer than necessary. While Marriott's notification to affected individuals was deemed adequate, the OPC had outstanding concerns regarding remote access, unencrypted data storage, and retention periods. The findings are well-founded and conditionally resolved, as Marriott committed to implementing the OPC's recommendations, including engaging an external assessor and reviewing its privacy framework.

Key Issues
  • Whether personal information held by Marriott was protected by security safeguards appropriate to the sensitivity of the information as required by Principle 4.7 (Safeguards).
  • Whether Marriott demonstrated due diligence and took steps to fulfil its responsibilities to implement policies and practices to protect personal information under Principle 4.1.4 (Accountability) when acquiring control of the Starwood network.
  • Whether Marriott retained personal information for longer than necessary, relevant to Principle 4.5 (Limiting use, disclosure and retention).
  • Whether the mitigation measures offered by Marriott to affected individuals were adequate to protect their personal information from unauthorized use, such as future identity theft, in accordance with Principle 4.7 (Safeguards).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 1, 2022PIPEDA Findings #2022-001Indexed Jun 30, 2026

PIPEDA Findings #2022-001: Joint investigation into location tracking by the Tim Hortons App

The TDL Group Corp. (Tim Hortons)

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-001: Joint investigation into location tracking by the Tim Hortons App

Jun 1, 2022PIPEDA Findings #2022-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

Key Issues
  • Whether Tim Hortons collected or used personal information for an appropriate purpose under the Acts.
  • Whether Tim Hortons obtained valid consent for the collection and use of granular location data.
  • Adequacy of contractual protections for personal information transferred to third-party service providers.
  • Tim Hortons' accountability and implementation of a privacy management program.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2022PIPEDA Findings #2022-004Indexed Jun 30, 2026

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

MGM Resorts International

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

May 19, 2022PIPEDA Findings #2022-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Key Issues
  • Whether MGM had the obligation to report the breach to the OPC and notify affected Canadians
  • Whether the MGM breach met the RROSH reporting and notification threshold
  • Whether the personal information involved was sensitive
  • Whether there was a high probability of misuse of the personal information
  • Whether MGM notified the OPC and affected Canadians as soon as feasible
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
May 10, 2022PIPEDA Findings #2022-002Indexed Jun 30, 2026

PIPEDA Findings #2022-002: Biron Health Group has ceased sending promotional emails to travellers arriving in Canada who undergo COVID-19 testing

Biron Health Group

The complainant alleged that Biron Health Group (Biron) sent him promotional emails without his consent after he underwent mandatory COVID-19 testing upon arrival at Montreal Trudeau Airport. He provided his email solely for test results. Biron initially believed it had implicit consent due to an established business relationship. The OPC found that Biron could not reasonably assume implicit consent, as travellers had no choice but to use Biron for mandatory testing and would not expect their health information to be used for marketing. Biron ceased the practice and deleted affected email addresses from its marketing database. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

PIPEDA Findings #2022-002: Biron Health Group has ceased sending promotional emails to travellers arriving in Canada who undergo COVID-19 testing

May 10, 2022PIPEDA Findings #2022-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Biron Health Group (Biron) sent him promotional emails without his consent after he underwent mandatory COVID-19 testing upon arrival at Montreal Trudeau Airport. He provided his email solely for test results. Biron initially believed it had implicit consent due to an established business relationship. The OPC found that Biron could not reasonably assume implicit consent, as travellers had no choice but to use Biron for mandatory testing and would not expect their health information to be used for marketing. Biron ceased the practice and deleted affected email addresses from its marketing database. The complaint was settled during the investigation.

Key Issues
  • Whether Biron Health Group had implicit consent to send promotional emails to individuals undergoing mandatory COVID-19 testing
  • Whether the collection of personal information for mandatory health testing could be used for secondary marketing purposes
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2022PIPEDA Findings #2022-003Indexed Jun 30, 2026

PIPEDA Findings #2022-003: Telecommunications firm failed to obtain appropriate consent for voiceprint authentication program

Rogers Communications Inc.

The complainant alleged that Rogers Communications Inc. improperly enrolled her in its Voice ID voiceprint authentication program without her consent and failed to allow her to opt out or delete her voiceprint. Rogers utilized a passive voiceprinting technology, "tuning," to create algorithmic voiceprints for customer authentication and fraud prevention. The Office of the Privacy Commissioner (OPC) found Rogers' purpose for collecting voiceprints to be appropriate, concluding this aspect of the complaint was not well-founded. However, the OPC determined that Rogers failed to obtain valid and meaningful express consent for the collection of sensitive biometric voiceprints, both during the "tuning" process and enrolment, as customers would not reasonably expect this. Furthermore, Rogers did not provide a clearly explained and easily accessible option for individuals to opt out and improperly retained voiceprints of opted-out individuals without any actual purpose. The OPC also identified deficiencies in Rogers' training materials and monitoring protocols for ensuring staff obtained valid consent. In response to OPC recommendations, Rogers committed to significant changes, including obtaining express consent before tuning, clearly informing customers of opt-out/deletion, deleting retained voiceprints, and improving training and monitoring. Consequently, the consent and retention aspects of the complaint were found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-003: Telecommunications firm failed to obtain appropriate consent for voiceprint authentication program

Mar 30, 2022PIPEDA Findings #2022-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Rogers Communications Inc. improperly enrolled her in its Voice ID voiceprint authentication program without her consent and failed to allow her to opt out or delete her voiceprint. Rogers utilized a passive voiceprinting technology, "tuning," to create algorithmic voiceprints for customer authentication and fraud prevention. The Office of the Privacy Commissioner (OPC) found Rogers' purpose for collecting voiceprints to be appropriate, concluding this aspect of the complaint was not well-founded. However, the OPC determined that Rogers failed to obtain valid and meaningful express consent for the collection of sensitive biometric voiceprints, both during the "tuning" process and enrolment, as customers would not reasonably expect this. Furthermore, Rogers did not provide a clearly explained and easily accessible option for individuals to opt out and improperly retained voiceprints of opted-out individuals without any actual purpose. The OPC also identified deficiencies in Rogers' training materials and monitoring protocols for ensuring staff obtained valid consent. In response to OPC recommendations, Rogers committed to significant changes, including obtaining express consent before tuning, clearly informing customers of opt-out/deletion, deleting retained voiceprints, and improving training and monitoring. Consequently, the consent and retention aspects of the complaint were found to be well-founded and conditionally resolved.

Key Issues
  • Whether the collection and use of voiceprints for authentication and fraud prevention constituted an appropriate purpose under PIPEDA s. 5(3)
  • Whether Rogers obtained valid and meaningful consent for the collection of voiceprints (tuning and enrolment) under PIPEDA Principle 4.3 and s. 6.1
  • Whether Rogers provided an adequate mechanism for the withdrawal of consent under PIPEDA Principle 4.3.8
  • Whether Rogers' retention of voiceprints after opt-out was compliant with PIPEDA Principle 4.5.3
  • Whether Rogers' training materials and protocols for obtaining consent were adequate
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-009Indexed Jun 30, 2026

PIPEDA Findings #2021-009: Opt-in consent required for a donor list trading program

A charitable organization

A complainant alleged that a charitable organization (the Respondent) failed to obtain proper consent before sharing his personal information through a donor list trading program. The Respondent used an opt-out checkbox on its mail-in donation forms, which the complainant found inadequate after receiving solicitations from another charity. The OPC determined that sharing donor information with other charities for solicitation purposes was outside the reasonable expectations of donors, thus requiring express opt-in consent. Furthermore, the information provided by the Respondent on its donation forms, inserts, and privacy policy was deemed insufficient to enable meaningful consent. The OPC recommended that the Respondent obtain express opt-in consent and enhance its privacy communications to clearly explain the nature, purpose, and consequences of the data sharing. The Respondent agreed to implement these recommendations, leading to a conditionally resolved outcome.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-009: Opt-in consent required for a donor list trading program

Mar 30, 2021PIPEDA Findings #2021-009
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a charitable organization (the Respondent) failed to obtain proper consent before sharing his personal information through a donor list trading program. The Respondent used an opt-out checkbox on its mail-in donation forms, which the complainant found inadequate after receiving solicitations from another charity. The OPC determined that sharing donor information with other charities for solicitation purposes was outside the reasonable expectations of donors, thus requiring express opt-in consent. Furthermore, the information provided by the Respondent on its donation forms, inserts, and privacy policy was deemed insufficient to enable meaningful consent. The OPC recommended that the Respondent obtain express opt-in consent and enhance its privacy communications to clearly explain the nature, purpose, and consequences of the data sharing. The Respondent agreed to implement these recommendations, leading to a conditionally resolved outcome.

Key Issues
  • Whether the Respondent obtained meaningful consent for its donor list trading program under PIPEDA
  • Whether opt-out consent was appropriate for sharing donor information with third parties
  • Whether the information shared (donor name, address, donation status) was sensitive in this context
  • Whether sharing donor information with other charities for solicitation was within the reasonable expectations of donors
  • Whether the donor list trading program created a meaningful residual risk of significant harm
  • Whether the information provided to donors on the donation form, insert, and privacy policy was sufficient to support meaningful consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-004Indexed Jun 30, 2026

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Fido Solutions Inc. (a subsidiary of Rogers Communications Inc.)

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Mar 30, 2021PIPEDA Findings #2021-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Key Issues
  • Whether Fido adequately safeguarded the Complainant’s personal information under Principle 4.7
  • Whether Fido responded to the Complainant’s access request in a generally understandable format under Principle 4.9 and 4.9.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-003Indexed Jun 30, 2026

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Bank of Montreal

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Mar 30, 2021PIPEDA Findings #2021-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether BMO implemented appropriate security safeguards to adequately protect personal information under its control, as required by PIPEDA Principle 4.7
  • Adequacy of BMO's developer security testing and evaluation processes
  • Adequacy of BMO's vulnerability management program, including identification, assessment, and remediation of vulnerabilities
  • Adequacy of BMO's oversight and monitoring capabilities, specifically regarding bot management, cyberattack detection, and real-time alerts
  • Adequacy of BMO's organizational policies and procedures for handling cyberattacks and incident response
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 29, 2021PIPEDA Findings #2021-002Indexed Jun 30, 2026

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

CoreFour Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

Mar 29, 2021PIPEDA Findings #2021-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Key Issues
  • Whether CoreFour's security safeguards were appropriate to the sensitivity and volume of personal information under Principle 4.7 PIPEDA
  • Whether CoreFour's weak password requirements for certain Edsby parental accounts constituted an inadequate safeguard
  • Whether CoreFour's safeguards to protect against unauthorized access to thumbnail images of student profile pictures were adequate
  • Whether Edsby's failure to scan for malware when uploading content from third-party applications constituted a safeguard weakness
  • Whether CoreFour lacked a robust overarching information security framework, contravening Principle 4.1.4 and 4.7-4.7.3 PIPEDA
  • Whether CoreFour had an adequate mechanism for handling and reporting privacy breaches under PIPEDA
  • Whether CoreFour was required to report the password management vulnerability, given it occurred before mandatory breach reporting came into effect
  • Whether the student image vulnerability created a "real risk of significant harm" requiring mandatory reporting and notification under s.10.1 PIPEDA
  • Whether CoreFour maintained a breach register as required under s.10.3 PIPEDA
  • Whether CoreFour lacked a privacy management framework, including appropriate written internal policies and practices (e.g., complaint handling, data retention), contravening Principle 4.1.4 PIPEDA
  • Whether CoreFour provided adequate privacy training to its employees, consultants, contractors, and students
  • Whether CoreFour's Privacy Policy was unclear regarding the characterization of personal information, its responsibility for security, and the sharing of user information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 24, 2021PIPEDA Findings #2021-007Indexed Jun 30, 2026

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

A computer services company

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

Mar 24, 2021PIPEDA Findings #2021-007
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Key Issues
  • Whether the respondent obtained meaningful consent prior to remotely accessing laptops
  • Whether the respondent had adequate safeguards to prevent unauthorized access to customers’ personal information by its personnel
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 22, 2021PIPEDA Findings #2021-008Indexed Jun 30, 2026

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Oculus Transport Ltd.

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Mar 22, 2021PIPEDA Findings #2021-008
Adjudicator: Daniel Therrien
Plain-Language Summary

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Key Issues
  • Whether the collection and use of personal information via audio surveillance technology was for purposes that a reasonable person would consider appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the personal information collected was sensitive
  • Whether the organization's purpose represented a legitimate need / bona fide business interest
  • Whether the collection, use and disclosure would be effective in meeting the organization’s need
  • Whether there are less privacy invasive means of achieving the same ends at comparable cost and with comparable benefits
  • Whether the loss of privacy is proportional to the benefits
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 15, 2021PIPEDA Findings #2021-005Indexed Jun 30, 2026

PIPEDA Findings #2021-005: Staying signed in by default to email services poses serious privacy concerns for users accessing their email on a public or shared computer

Yahoo! Canada

The complainant alleged that Yahoo! Canada's default "Stay signed in" setting for Yahoo Mail, particularly for Rogers Yahoo Mail users, posed significant privacy concerns on public or shared computers. The OPC investigated whether Yahoo adequately safeguarded against unauthorized access and obtained valid consent for potential disclosures. The OPC found that Yahoo's safeguards were not appropriate for the sensitivity of email content and that its consent for the "Stay signed in" setting was not meaningful. Yahoo committed to changing the setting to opt-in and providing clearer information about privacy implications. Rogers, while not a respondent, also agreed to implement measures for Rogers Yahoo Mail users. The complaint was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-005: Staying signed in by default to email services poses serious privacy concerns for users accessing their email on a public or shared computer

Mar 15, 2021PIPEDA Findings #2021-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Yahoo! Canada's default "Stay signed in" setting for Yahoo Mail, particularly for Rogers Yahoo Mail users, posed significant privacy concerns on public or shared computers. The OPC investigated whether Yahoo adequately safeguarded against unauthorized access and obtained valid consent for potential disclosures. The OPC found that Yahoo's safeguards were not appropriate for the sensitivity of email content and that its consent for the "Stay signed in" setting was not meaningful. Yahoo committed to changing the setting to opt-in and providing clearer information about privacy implications. Rogers, while not a respondent, also agreed to implement measures for Rogers Yahoo Mail users. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether Yahoo's safeguards against unauthorized third-party access to email content on public or shared computers were adequate under Principle 4.7 PIPEDA
  • Whether Yahoo obtained valid and meaningful consent for the disclosure of personal information to others who subsequently access emails via the "Stay signed in" setting under Principle 4.3 PIPEDA
  • Whether the "Stay signed in" setting was clearly and prominently displayed
  • Whether a reasonable person would understand the "Stay signed in" setting to be "on" by default
  • Whether the "Stay signed in" setting is consistent with industry standards
  • Whether Yahoo's additional safeguards (algorithm, sign-out option, session expiration, password reset, security information) were effective
  • Whether express opt-in consent was required for the "Stay signed in" setting due to sensitivity of information, reasonable expectations, and risk of harm
  • Whether the language "stay signed in" provided users with key information for meaningful consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Mar 12, 2021PIPEDA Findings #2021-006Indexed Jun 30, 2026

PIPEDA Findings #2021-006: A short-term lender collects online banking credentials in the course of payday loan applications

CashHere (2124478 Ontario Corporation)

The OPC initiated an investigation into CashHere, a short-term lender, after being alerted by the Ontario Ministry of Government and Consumer Services that it was collecting online banking credentials (passwords, usernames, security questions/answers) from loan applicants. The OPC found that while CashHere had a legitimate need to validate identity and income, collecting banking credentials was not an appropriate purpose under PIPEDA s. 5(3) due to less privacy-invasive alternatives and disproportionate privacy risks. The investigation also noted that a related entity, MoneyHome, appeared to be continuing the same practices. CashHere ceased responding to the OPC, and the matter was found to be well-founded and unresolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2021-006: A short-term lender collects online banking credentials in the course of payday loan applications

Mar 12, 2021PIPEDA Findings #2021-006
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated an investigation into CashHere, a short-term lender, after being alerted by the Ontario Ministry of Government and Consumer Services that it was collecting online banking credentials (passwords, usernames, security questions/answers) from loan applicants. The OPC found that while CashHere had a legitimate need to validate identity and income, collecting banking credentials was not an appropriate purpose under PIPEDA s. 5(3) due to less privacy-invasive alternatives and disproportionate privacy risks. The investigation also noted that a related entity, MoneyHome, appeared to be continuing the same practices. CashHere ceased responding to the OPC, and the matter was found to be well-founded and unresolved.

Key Issues
  • Whether CashHere's collection of online banking login credentials was for a purpose that a reasonable person would consider appropriate under s. 5(3) of PIPEDA
  • Whether the collection of banking credentials was effective in meeting CashHere's legitimate need
  • Whether there were less privacy-invasive means of achieving the same ends
  • Whether the loss of privacy was proportional to the benefits for CashHere