The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

172 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jul 5, 2017Early resolved case summary #2017-003Indexed Jun 30, 2026

Early resolved case summary #2017-003: Bank agrees to cease performing credit checks on individuals who are no longer clients

A bank

An individual complained that a bank performed numerous credit checks on her without consent, despite her not being a client for many years. The bank initially claimed the inquiries were from its marketing group and not visible to other organizations, but its internal investigation revealed they were 'soft hits' related to inactive accounts from 2013. The bank's privacy policy stated it retained the ability to perform credit inquiries after a service ended, but the OPC expressed concern over the continued collection of sensitive credit information without a legal requirement. To resolve the complaint, the bank agreed to cease this practice and update its privacy policy. The complainant was satisfied, and the matter was early resolved.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2017-003: Bank agrees to cease performing credit checks on individuals who are no longer clients

Jul 5, 2017Early resolved case summary #2017-003
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a bank performed numerous credit checks on her without consent, despite her not being a client for many years. The bank initially claimed the inquiries were from its marketing group and not visible to other organizations, but its internal investigation revealed they were 'soft hits' related to inactive accounts from 2013. The bank's privacy policy stated it retained the ability to perform credit inquiries after a service ended, but the OPC expressed concern over the continued collection of sensitive credit information without a legal requirement. To resolve the complaint, the bank agreed to cease this practice and update its privacy policy. The complainant was satisfied, and the matter was early resolved.

Key Issues
  • Whether a bank can continue to perform credit checks on former clients without their consent
  • Whether the bank's privacy policy adequately justified continued credit inquiries after the termination of a business relationship
  • Whether the bank provided accurate information to the complainant regarding the source and nature of the credit inquiries
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 26, 2017Incident case summary #2017-001Indexed Jun 30, 2026

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Multiple organizations (Airline, Retailer, Digital media company)

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Apr 26, 2017Incident case summary #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Key Issues
  • Whether organizations adequately responded to breaches caused by password reuse
  • Whether organizations implemented appropriate safeguards to prevent recurrence of breaches due to password reuse
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2017PIPEDA findings #2017-011Indexed Jun 30, 2026

PIPEDA findings #2017-011: Financial institution originally misuses confidential commercial information exemption to withhold personal information

A financial institution

A complainant alleged that a financial institution refused to respond to his access to personal information request related to a disputed credit card transaction. Initially, the financial institution withheld documents, claiming they contained confidential commercial information under PIPEDA s.9(3)(b). The OPC found this exemption was inappropriately applied and that the financial institution failed to respond within the statutory 30-day timeframe. Following the OPC's preliminary report, the financial institution provided further clarification, leading the OPC to determine that the information in question was not the complainant's personal information and was correctly redacted under s.9(1) as third-party information. Although the complainant eventually received all personal information he was entitled to, the OPC criticized the financial institution's delay and initial misuse of the exemption. The complaint was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2017-011: Financial institution originally misuses confidential commercial information exemption to withhold personal information

Mar 31, 2017PIPEDA findings #2017-011
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a financial institution refused to respond to his access to personal information request related to a disputed credit card transaction. Initially, the financial institution withheld documents, claiming they contained confidential commercial information under PIPEDA s.9(3)(b). The OPC found this exemption was inappropriately applied and that the financial institution failed to respond within the statutory 30-day timeframe. Following the OPC's preliminary report, the financial institution provided further clarification, leading the OPC to determine that the information in question was not the complainant's personal information and was correctly redacted under s.9(1) as third-party information. Although the complainant eventually received all personal information he was entitled to, the OPC criticized the financial institution's delay and initial misuse of the exemption. The complaint was found to be well-founded and resolved.

Key Issues
  • Whether the financial institution responded to the access request within the 30-day time limit required by PIPEDA s.8(3)
  • Whether the financial institution sent a notice of extension within 30 days of the request as required by PIPEDA s.8(4)
  • Whether the financial institution appropriately applied the confidential commercial information exemption under PIPEDA s.9(3)(b) to withhold documents
  • Whether the withheld information constituted the complainant's personal information
  • Whether the information was properly redacted as third-party information under PIPEDA s.9(1)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 14, 2017PIPEDA Report of Findings #2017-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-003: Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process

An insurance company

An individual complained that an insurance company collected and used his credit score without meaningful consent during an auto insurance claims assessment, over-collected his credit file, and used the score for an inappropriate purpose. The OPC found that the insurance company failed to demonstrate that collecting and using credit scores for fraud detection in auto claims was an appropriate purpose under PIPEDA subsection 5(3) or a "direct business need" under Ontario's Consumer Reporting Act. The OPC also determined that the company did not obtain meaningful consent because it failed to clearly advise the complainant that providing his credit score was optional, contrary to Principle 4.3. Furthermore, the company was found not to be open about its practices regarding credit score collection and use, violating Principle 4.8.1, due to insufficient notifications and inaccurate employee scripts. The allegation of over-collection was not substantiated, as only the credit score was provided. In response to the OPC's preliminary report, the insurance company agreed to cease collecting credit scores for auto accident benefit claims and review its practices for other insurance types. The matter was concluded as well-founded and conditionally resolved, pending the full implementation of these agreed-upon changes.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2017-003: Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process

Mar 14, 2017PIPEDA Report of Findings #2017-003
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an insurance company collected and used his credit score without meaningful consent during an auto insurance claims assessment, over-collected his credit file, and used the score for an inappropriate purpose. The OPC found that the insurance company failed to demonstrate that collecting and using credit scores for fraud detection in auto claims was an appropriate purpose under PIPEDA subsection 5(3) or a "direct business need" under Ontario's Consumer Reporting Act. The OPC also determined that the company did not obtain meaningful consent because it failed to clearly advise the complainant that providing his credit score was optional, contrary to Principle 4.3. Furthermore, the company was found not to be open about its practices regarding credit score collection and use, violating Principle 4.8.1, due to insufficient notifications and inaccurate employee scripts. The allegation of over-collection was not substantiated, as only the credit score was provided. In response to the OPC's preliminary report, the insurance company agreed to cease collecting credit scores for auto accident benefit claims and review its practices for other insurance types. The matter was concluded as well-founded and conditionally resolved, pending the full implementation of these agreed-upon changes.

Key Issues
  • Whether collecting and using a credit score for fraud detection during auto insurance claims assessment is an appropriate purpose under subsection 5(3) of PIPEDA.
  • Whether the insurance company had a "direct business need" for credit scores under Ontario's Consumer Reporting Act (CRA) s.8(1)(d)(vi) for fraud detection in auto claims.
  • Whether the insurance company over-collected personal information by obtaining the complainant's entire credit file.
  • Whether the insurance company properly identified the purposes for collecting the complainant's credit score under Principle 4.2.
  • Whether the insurance company obtained meaningful consent for collecting the credit score, specifically if it advised the complainant that providing the information was optional, under Principle 4.3.
  • Whether the insurance company was open about its policies and practices regarding credit score collection and use under Principle 4.8.1.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 10, 2017PIPEDA Case Summary #2017-005Indexed Jun 30, 2026

PIPEDA Case Summary #2017-005: Insurance company required to delete individual’s personal information after individual withdraws consent

An insurance company

An individual complained that his former automobile insurance company refused to delete his personal information from its records and from third-party organizations. The company initially refused, citing the need to provide insurance history to other insurers. The OPC reframed the request as a withdrawal of consent, and the company subsequently agreed to delete the information from its own records, as there was no legal requirement to retain it. However, the OPC found that the company was not obligated to ensure deletion from third-party records if the information was lawfully disclosed. The investigation also revealed the company lacked clear documentation regarding its disclosure practices to third parties, contravening Principle 4.1.4(d). The company committed to developing a document to track disclosures, which it later provided to the OPC.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2017-005: Insurance company required to delete individual’s personal information after individual withdraws consent

Feb 10, 2017PIPEDA Case Summary #2017-005
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that his former automobile insurance company refused to delete his personal information from its records and from third-party organizations. The company initially refused, citing the need to provide insurance history to other insurers. The OPC reframed the request as a withdrawal of consent, and the company subsequently agreed to delete the information from its own records, as there was no legal requirement to retain it. However, the OPC found that the company was not obligated to ensure deletion from third-party records if the information was lawfully disclosed. The investigation also revealed the company lacked clear documentation regarding its disclosure practices to third parties, contravening Principle 4.1.4(d). The company committed to developing a document to track disclosures, which it later provided to the OPC.

Key Issues
  • Whether the insurance company was required to delete the individual's personal information from its own records upon withdrawal of consent
  • Whether the insurance company was required to ensure deletion of the individual's personal information from third-party organizations' records after lawful disclosure
  • Whether the insurance company contravened Principle 4.1.4(d) by lacking a clear explanation of its disclosure practices to third parties
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Jan 11, 2017PIPEDA Case Summary #2017-004Indexed Jun 30, 2026

PIPEDA Case Summary #2017-004: Consent provided extends to third-party doctor hired to evaluate accident insurance claim

A doctor hired by an independent medical evaluation firm

An individual complained that a doctor collected, used, and disclosed his personal information without consent. The complainant had been in a car accident and his insurance company hired an independent medical evaluation (IME) firm to assess his claim for catastrophic impairment. The doctor in question was hired by the IME firm to compile a summary report based on assessments from other doctors. The complainant argued he had not consented to this specific doctor, though he had consented to other doctors involved in his claim. The doctor contended that the complainant had provided consent through signed accident benefit forms (OCF-1 and OCF-19). The OPC found that the signed forms included explicit consent for health professionals to collect, use, and disclose personal information for the purpose of investigating and processing the insurance claim. The OPC concluded that the doctor's actions were within the scope of the consent provided.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Case Summary #2017-004: Consent provided extends to third-party doctor hired to evaluate accident insurance claim

Jan 11, 2017PIPEDA Case Summary #2017-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a doctor collected, used, and disclosed his personal information without consent. The complainant had been in a car accident and his insurance company hired an independent medical evaluation (IME) firm to assess his claim for catastrophic impairment. The doctor in question was hired by the IME firm to compile a summary report based on assessments from other doctors. The complainant argued he had not consented to this specific doctor, though he had consented to other doctors involved in his claim. The doctor contended that the complainant had provided consent through signed accident benefit forms (OCF-1 and OCF-19). The OPC found that the signed forms included explicit consent for health professionals to collect, use, and disclose personal information for the purpose of investigating and processing the insurance claim. The OPC concluded that the doctor's actions were within the scope of the consent provided.

Key Issues
  • Whether the doctor collected, used, and disclosed the complainant's personal information without consent
  • Whether the consent provided in OCF-1 and OCF-19 forms extended to the doctor preparing the summary report
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Dec 29, 2016PIPEDA findings #2016-013Indexed Jun 30, 2026

PIPEDA findings #2016-013: Company’s disclosure of information about a debt owed is not covered under exemption to consent

A sports facilities company

An individual complained that a sports facilities company disclosed his personal information, specifically details about an outstanding debt, to a related sports association on two occasions without his consent. The company did not deny the disclosures but argued they were made in response to direct questions and with an expectation of privacy. The OPC found that information about a debt owed by an identifiable individual is personal and sensitive, requiring consent for disclosure unless a specific exemption applies. The OPC determined that the disclosures were not for the purpose of collecting the debt, thus the exemption under paragraph 7(3)(b) of PIPEDA did not apply. The company's reliance on an 'expectation of privacy' or being asked directly was not a valid substitute for obtaining consent. The complaint was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA findings #2016-013: Company’s disclosure of information about a debt owed is not covered under exemption to consent

Dec 29, 2016PIPEDA findings #2016-013
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a sports facilities company disclosed his personal information, specifically details about an outstanding debt, to a related sports association on two occasions without his consent. The company did not deny the disclosures but argued they were made in response to direct questions and with an expectation of privacy. The OPC found that information about a debt owed by an identifiable individual is personal and sensitive, requiring consent for disclosure unless a specific exemption applies. The OPC determined that the disclosures were not for the purpose of collecting the debt, thus the exemption under paragraph 7(3)(b) of PIPEDA did not apply. The company's reliance on an 'expectation of privacy' or being asked directly was not a valid substitute for obtaining consent. The complaint was found to be well-founded.

Key Issues
  • Whether the disclosure of debt information without consent contravened Principle 4.3 of PIPEDA
  • Whether the disclosure was exempt from consent under paragraph 7(3)(b) of PIPEDA for debt collection purposes
  • Whether an 'expectation of privacy' or responding to a direct question constitutes a valid exception to consent requirements
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Sep 23, 2016Early resolved case summary #2016-01Indexed Jun 30, 2026

Early resolved case summary #2016-01: Access to personal information request revised to accommodate both requestor and organization

A condominium developer

A condominium owner filed a complaint after his request for access to his personal information was met with a demand for payment for photocopies or an offer to view documents at the organization's lawyer's office. The individual argued that this was not access at "minimal or no cost" as required by PIPEDA Principle 4.9.4. The OPC's early resolution unit intervened, and the organization initially offered free viewing with the option to select pages for free copies. The complainant, citing a disability, found viewing 1000 pages unreasonable. The OPC proposed that the individual narrow his request, which he accepted. Consequently, the organization agreed to provide free copies of the specific documents containing his personal information, leading to the complainant's satisfaction.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2016-01: Access to personal information request revised to accommodate both requestor and organization

Sep 23, 2016Early resolved case summary #2016-01
Adjudicator: Daniel Therrien
Plain-Language Summary

A condominium owner filed a complaint after his request for access to his personal information was met with a demand for payment for photocopies or an offer to view documents at the organization's lawyer's office. The individual argued that this was not access at "minimal or no cost" as required by PIPEDA Principle 4.9.4. The OPC's early resolution unit intervened, and the organization initially offered free viewing with the option to select pages for free copies. The complainant, citing a disability, found viewing 1000 pages unreasonable. The OPC proposed that the individual narrow his request, which he accepted. Consequently, the organization agreed to provide free copies of the specific documents containing his personal information, leading to the complainant's satisfaction.

Key Issues
  • Whether the organization's initial response to an access request met the "minimal or no cost" requirement under Principle 4.9.4 of PIPEDA
  • Whether an offer to view documents without free copies constitutes adequate access under PIPEDA
  • Whether the organization's proposed solution of viewing documents at a lawyer's office was reasonable given the complainant's disability
  • Whether narrowing the scope of an access request can facilitate resolution and compliance with PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 22, 2016PIPEDA Report of Findings #2016-005Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Avid Life Media Inc. (ALM)

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Aug 22, 2016PIPEDA Report of Findings #2016-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Key Issues
  • Whether ALM's security safeguards were appropriate to the sensitivity of the information under PIPEDA Principle 4.7.
  • Whether ALM implemented policies and practices to give effect to the Principles, including procedures to protect personal information, under PIPEDA Principle 4.1.4.
  • Whether ALM's indefinite retention of personal information for deactivated or inactive accounts contravened PIPEDA Principle 4.5.
  • Whether ALM's failure to establish maximum retention periods for personal information contravened PIPEDA Principle 4.5.2.
  • Whether ALM's practice of charging a fee for the complete deletion of personal information contravened an individual's right to withdraw consent under PIPEDA Principle 4.3.8.
  • Whether ALM took reasonable steps to ensure personal information (email addresses) was accurate, complete, and up-to-date as necessary for its purposes, taking into account the interests of the individual, under PIPEDA Principle 4.6 and 4.6.1.
  • Whether ALM's consent for the collection, use, or disclosure of personal information was valid, given the nature, purpose, and consequences, under PIPEDA s.6.1 and Principle 4.3.
  • Whether ALM made information about its personal information handling policies and practices readily available and understandable, and did not obtain consent through deception, under PIPEDA Principle 4.8, 4.8.1, and 4.3.5.
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Aug 10, 2016Early resolved case summary #2016-02Indexed Jun 30, 2026

Early resolved case summary #2016-02: Organization’s technical glitch results in the disclosure of a client’s personal information to another client

An online service company

An individual complained to the OPC after an online service company failed to resolve a technical glitch that caused another person's personal information to appear in his account. Despite months of attempts, the company's customer service and IT specialists could not fix the issue, nor could the individual escalate his concerns to a privacy officer. The OPC intervened, prompting the company to investigate and discover the glitch originated from another organization's software interface. The online company, in collaboration with the other organization, corrected the technical glitch for all users. The online company also revised its internal policies to include an escalation process for privacy concerns and established a new contractual agreement with the other organization to prevent future issues and enhance PIPEDA compliance. The complainant confirmed the issue was resolved to his satisfaction.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2016-02: Organization’s technical glitch results in the disclosure of a client’s personal information to another client

Aug 10, 2016Early resolved case summary #2016-02
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after an online service company failed to resolve a technical glitch that caused another person's personal information to appear in his account. Despite months of attempts, the company's customer service and IT specialists could not fix the issue, nor could the individual escalate his concerns to a privacy officer. The OPC intervened, prompting the company to investigate and discover the glitch originated from another organization's software interface. The online company, in collaboration with the other organization, corrected the technical glitch for all users. The online company also revised its internal policies to include an escalation process for privacy concerns and established a new contractual agreement with the other organization to prevent future issues and enhance PIPEDA compliance. The complainant confirmed the issue was resolved to his satisfaction.

Key Issues
  • Whether an online service company adequately addressed a technical glitch leading to unauthorized disclosure of personal information
  • Whether the online service company had appropriate internal policies for escalating privacy concerns
  • Whether the online service company had adequate contractual agreements with third-party service providers regarding privacy and data breaches
Federal (Canada)Personal Information Protection and Electronic Documents ActNo jurisdiction
Federal (Canada) flag
Jul 18, 2016PIPEDA Case Summary #2016-011Indexed Jun 30, 2026

PIPEDA Case Summary #2016-011: Defending against a civil lawsuit not considered a commercial activity

A psychiatrist retained by an independent medical evaluation provider

An individual (the plaintiff) filed a complaint after a psychiatrist, retained by an insurance company to assess the plaintiff's well-being for a civil lawsuit, did not provide full access to his personal information. The plaintiff had requested access to his personal information held by the psychiatrist and received only a redacted report, leading to concerns about the completeness and accuracy of the information. The OPC investigated whether the psychiatrist's collection and use of the plaintiff's personal information constituted a "commercial activity" under PIPEDA. The OPC determined that defending against a civil lawsuit is not a commercial activity, and therefore, PIPEDA did not apply. The complaint was ultimately dismissed due to lack of jurisdiction.

Quick view

Personal Information Protection and Electronic Documents ActNo jurisdiction

PIPEDA Case Summary #2016-011: Defending against a civil lawsuit not considered a commercial activity

Jul 18, 2016PIPEDA Case Summary #2016-011
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual (the plaintiff) filed a complaint after a psychiatrist, retained by an insurance company to assess the plaintiff's well-being for a civil lawsuit, did not provide full access to his personal information. The plaintiff had requested access to his personal information held by the psychiatrist and received only a redacted report, leading to concerns about the completeness and accuracy of the information. The OPC investigated whether the psychiatrist's collection and use of the plaintiff's personal information constituted a "commercial activity" under PIPEDA. The OPC determined that defending against a civil lawsuit is not a commercial activity, and therefore, PIPEDA did not apply. The complaint was ultimately dismissed due to lack of jurisdiction.

Key Issues
  • Whether the collection and use of a plaintiff’s personal information for the purpose of defending against a civil lawsuit constitutes a "commercial activity" under PIPEDA
  • Whether PIPEDA applies to the activities of a third-party retained to carry out an activity exempt from PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 14, 2016PIPEDA Case Summary #2016-008Indexed Jun 30, 2026

PIPEDA Case Summary #2016-008: Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties

A telecommunications company

An individual complained that a telecommunications company (telco) provided an incomplete response to her access request for information about disclosures of her personal information to other parties, including law enforcement. The telco initially responded by stating it was in compliance with specific PIPEDA subsections, without confirming or denying disclosures. The OPC found that the telco's response did not meet its obligation under Principle 4.9 of PIPEDA, which requires organizations to inform individuals of the existence, use, and disclosure of their personal information. The OPC clarified that an organization must provide a clear 'yes' or 'no' answer regarding disclosures, unless a government institution objects to such disclosure under PIPEDA s.9(2.4). Following the OPC's recommendation, the telco provided a complete response to the complainant and updated its policy for handling future access requests. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-008: Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties

Jul 14, 2016PIPEDA Case Summary #2016-008
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a telecommunications company (telco) provided an incomplete response to her access request for information about disclosures of her personal information to other parties, including law enforcement. The telco initially responded by stating it was in compliance with specific PIPEDA subsections, without confirming or denying disclosures. The OPC found that the telco's response did not meet its obligation under Principle 4.9 of PIPEDA, which requires organizations to inform individuals of the existence, use, and disclosure of their personal information. The OPC clarified that an organization must provide a clear 'yes' or 'no' answer regarding disclosures, unless a government institution objects to such disclosure under PIPEDA s.9(2.4). Following the OPC's recommendation, the telco provided a complete response to the complainant and updated its policy for handling future access requests. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the telco's initial response to an access request for disclosure information met its obligations under Principle 4.9 of PIPEDA
  • Whether the telco's practice of stating compliance with PIPEDA s.9(2.1)-(2.4) was sufficient for access requests
  • Whether the telco had an obligation to provide a 'yes' or 'no' answer regarding disclosures to all third parties, including those not covered by PIPEDA s.9(2.1)-(2.4)
  • How an organization should respond to an access request for disclosure information when a government institution objects under PIPEDA s.9(2.4)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 7, 2016PIPEDA Case Summary #2016-010Indexed Jun 30, 2026

PIPEDA Case Summary #2016-010: Credit reporting agency takes remedial action after failing to maintain accurate records

A credit reporting agency

An individual complained to the OPC after discovering inaccuracies in his credit file, including two unrecognized credit inquiries and a notation that his account had been automatically combined with others. The credit reporting agency acknowledged that his file had been manually combined with another individual's due to similar names and addresses. The OPC investigated two main issues: unauthorized use/disclosure and accuracy of personal information. The OPC found no unauthorized use or disclosure, as the inquiries occurred before the files were combined and only the other individual's information was used. However, the OPC determined that the agency failed to maintain accurate personal information, as combining files compromised accuracy and led to incorrect information being attributed to the complainant. The agency rectified the error by separating the files, notifying creditors of corrections, and committing to enhanced employee training. Consequently, the accuracy issue was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-010: Credit reporting agency takes remedial action after failing to maintain accurate records

Jul 7, 2016PIPEDA Case Summary #2016-010
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after discovering inaccuracies in his credit file, including two unrecognized credit inquiries and a notation that his account had been automatically combined with others. The credit reporting agency acknowledged that his file had been manually combined with another individual's due to similar names and addresses. The OPC investigated two main issues: unauthorized use/disclosure and accuracy of personal information. The OPC found no unauthorized use or disclosure, as the inquiries occurred before the files were combined and only the other individual's information was used. However, the OPC determined that the agency failed to maintain accurate personal information, as combining files compromised accuracy and led to incorrect information being attributed to the complainant. The agency rectified the error by separating the files, notifying creditors of corrections, and committing to enhanced employee training. Consequently, the accuracy issue was found to be well-founded and resolved.

Key Issues
  • Whether the credit reporting agency improperly disclosed the complainant's personal information without consent
  • Whether the credit reporting agency failed to maintain accurate personal information as required by PIPEDA Principle 4.6
  • Whether the credit reporting agency failed to maintain accurate personal information as required by PIPEDA Principle 4.6.3
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
May 6, 2016Early resolution case summary #2016-03Indexed Jun 30, 2026

Early resolution case summary #2016-03: First Nation develops a privacy policy following allegations of lost doctor’s notes

First Nation band council

An employee of a First Nation band council complained that two doctor's notes he submitted for leave requests were lost by the band office, leading to non-payment for his leave. The complainant also filed a complaint under the Canada Labour Code. The OPC's Early Resolution Unit engaged with the band council, which, while not confirming the loss of the notes, agreed to develop a privacy policy and adopt best privacy practices. The OPC provided resources to assist in this development. The complainant was satisfied with the band council's commitment to a privacy policy, leading to an early resolution of the privacy complaint, with the issue of lost notes to be addressed via the Canada Labour Code complaint. The band council subsequently adopted a privacy policy with the OPC's guidance.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolution case summary #2016-03: First Nation develops a privacy policy following allegations of lost doctor’s notes

May 6, 2016Early resolution case summary #2016-03
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee of a First Nation band council complained that two doctor's notes he submitted for leave requests were lost by the band office, leading to non-payment for his leave. The complainant also filed a complaint under the Canada Labour Code. The OPC's Early Resolution Unit engaged with the band council, which, while not confirming the loss of the notes, agreed to develop a privacy policy and adopt best privacy practices. The OPC provided resources to assist in this development. The complainant was satisfied with the band council's commitment to a privacy policy, leading to an early resolution of the privacy complaint, with the issue of lost notes to be addressed via the Canada Labour Code complaint. The band council subsequently adopted a privacy policy with the OPC's guidance.

Key Issues
  • Whether a First Nation band council is a federal work, undertaking or business (FWUB) under PIPEDA
  • Whether the personal information of employees of a FWUB is protected under PIPEDA
  • Whether the First Nation band council adequately protected the complainant's medical information
  • Whether the First Nation band council had appropriate privacy policies and practices in place
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 21, 2016PIPEDA Report of Findings #2016-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Compu-Finder (3510395 Canada Inc.)

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Apr 21, 2016PIPEDA Report of Findings #2016-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Key Issues
  • Whether Compu-Finder's collection and use of email addresses constituted "personal information" under PIPEDA.
  • Whether the business contact information carve-out under s. 4.01 PIPEDA applied to Compu-Finder's activities.
  • Whether Compu-Finder obtained meaningful express consent for collecting email addresses via telemarketing (Principles 4.2, 4.3, 4.3.2).
  • Whether Compu-Finder collected personal information by fair and lawful means (Principle 4.4).
  • Whether Compu-Finder obtained meaningful implied consent for collecting email addresses from publicly available sources (Principle 4.3.6).
  • Whether the "publicly available information" exemption (s. 7(1)(d), 7(2)(c.1) PIPEDA and s. 1 of the Regulations) applied to Compu-Finder's collection and use of email addresses.
  • Whether the address harvesting provisions (s. 7.1(2) PIPEDA) prohibited the use of email addresses collected via software before the provision came into force.
  • Whether Compu-Finder had a designated individual accountable for PIPEDA compliance (Principle 4.1).
  • Whether Compu-Finder implemented policies and practices to give effect to PIPEDA principles (Principle 4.1.4).
  • Whether Compu-Finder was open about its personal information management policies and practices (Principles 4.8.1, 4.8.2).