The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

172 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Aug 14, 2015Early resolved case summary #2015-07Indexed Jun 30, 2026

Early resolved case summary #2015-07: Employee training a key factor in effectively satisfying customers’ requests about an organization’s personal information handling practices

A car dealership

An individual complained that a car dealership could not provide details about its personal information handling practices. The complainant was asked for her driver's license and credit card for a loaner car, and when she inquired about the collection and safeguards, the employee could not provide satisfactory answers. Her subsequent email to the dealership's privacy officer also went unanswered. The OPC conducted a site visit and reviewed the dealership's policies and practices, finding them satisfactory. However, the OPC emphasized the need for employees to be knowledgeable about these practices. The dealership agreed to conduct a review session for its employees. The complainant was satisfied with the outcome, and the matter was early resolved.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-07: Employee training a key factor in effectively satisfying customers’ requests about an organization’s personal information handling practices

Aug 14, 2015Early resolved case summary #2015-07
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a car dealership could not provide details about its personal information handling practices. The complainant was asked for her driver's license and credit card for a loaner car, and when she inquired about the collection and safeguards, the employee could not provide satisfactory answers. Her subsequent email to the dealership's privacy officer also went unanswered. The OPC conducted a site visit and reviewed the dealership's policies and practices, finding them satisfactory. However, the OPC emphasized the need for employees to be knowledgeable about these practices. The dealership agreed to conduct a review session for its employees. The complainant was satisfied with the outcome, and the matter was early resolved.

Key Issues
  • Whether the car dealership provided sufficient details about its personal information handling practices upon request
  • Whether the car dealership's employees were adequately trained to answer questions about personal information collection, safeguards, and retention
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Aug 1, 2015Early resolved case summary #2015-04Indexed Jun 30, 2026

Early resolved case summary #2015-04: Misidentification and lack of access to personal information leads to mistaken four-year debt pursuit

A collection agency

An individual complained that a collection agency was pursuing him for a debt he did not owe, which was negatively impacting his credit report. The individual alleged that the agency had been calling him for years and disclosed his financial information to his household members. He also claimed he was denied access to documentation validating the debt. The OPC contacted the collection agency, which then investigated the matter after discrepancies were noted in the original credit application. The agency ceased debt collection, acknowledged possible fraud, and committed to correcting the individual's credit report. The individual was satisfied with this resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-04: Misidentification and lack of access to personal information leads to mistaken four-year debt pursuit

Aug 1, 2015Early resolved case summary #2015-04
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a collection agency was pursuing him for a debt he did not owe, which was negatively impacting his credit report. The individual alleged that the agency had been calling him for years and disclosed his financial information to his household members. He also claimed he was denied access to documentation validating the debt. The OPC contacted the collection agency, which then investigated the matter after discrepancies were noted in the original credit application. The agency ceased debt collection, acknowledged possible fraud, and committed to correcting the individual's credit report. The individual was satisfied with this resolution.

Key Issues
  • Whether the collection agency ensured the accuracy of personal information used for debt collection (Principle 4.5 PIPEDA)
  • Whether the collection agency provided the individual with access to his personal information (Principle 4.9 PIPEDA)
  • Whether the collection agency disclosed personal financial information to third parties without consent (Principle 4.3 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jul 28, 2015Discontinued Case Summary #2015-002Indexed Jun 30, 2026

Discontinued Case Summary #2015-002: OPC discontinues additional complaints against Globe24h.com following investigation into same privacy issues

Globe24h.com

Multiple complainants alleged that Globe24h.com collected, used, and disclosed their personal information without consent by republishing Canadian court and tribunal decisions and charging for removal. The OPC had previously investigated similar complaints against Globe24h.com and found them to be well-founded. Despite this, additional complaints continued to be received. The OPC decided to discontinue these new complaints under paragraph 12.2(1)(e) of PIPEDA, as the matter had already been the subject of a Commissioner's report. The OPC noted its continued interest in Globe24h.com's compliance and later participated in a Federal Court proceeding initiated by one of the original complainants. The Federal Court ultimately confirmed the OPC's findings and ordered Globe24h.com to remove the information and cease contravening PIPEDA, leading to the website's closure.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Discontinued Case Summary #2015-002: OPC discontinues additional complaints against Globe24h.com following investigation into same privacy issues

Jul 28, 2015Discontinued Case Summary #2015-002
Adjudicator: Daniel Therrien
Plain-Language Summary

Multiple complainants alleged that Globe24h.com collected, used, and disclosed their personal information without consent by republishing Canadian court and tribunal decisions and charging for removal. The OPC had previously investigated similar complaints against Globe24h.com and found them to be well-founded. Despite this, additional complaints continued to be received. The OPC decided to discontinue these new complaints under paragraph 12.2(1)(e) of PIPEDA, as the matter had already been the subject of a Commissioner's report. The OPC noted its continued interest in Globe24h.com's compliance and later participated in a Federal Court proceeding initiated by one of the original complainants. The Federal Court ultimately confirmed the OPC's findings and ordered Globe24h.com to remove the information and cease contravening PIPEDA, leading to the website's closure.

Key Issues
  • Whether Globe24h.com collected, used, and disclosed personal information without consent
  • Whether the Commissioner should discontinue investigation of additional complaints when the matter has already been reported on
  • Whether the practices of Globe24h.com contravened PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Jul 22, 2015PIPEDA findings #2015-019Indexed Jun 30, 2026

PIPEDA findings #2015-019: OPC complaint prompts telecom’s fraud investigation

A telecommunications company

A complainant reported a fraudulent telecommunications account causing a false debt statement on their credit report. The complainant alleged they never lived at the address associated with the debt, and the telecommunications company initially refused to correct the debt or provide proof of account opening. The credit-reporting agency had validated the debt with the telecom company. Upon the OPC's intervention, the telecommunications company's fraud team reviewed the file and determined the account was fraudulent. The company then cancelled the fraudulent account and updated the credit-reporting agency with accurate information. The complainant was satisfied with these actions, leading to an early resolution.

Quick view

Personal Information Protection and Electronic Documents ActResolved

PIPEDA findings #2015-019: OPC complaint prompts telecom’s fraud investigation

Jul 22, 2015PIPEDA findings #2015-019
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant reported a fraudulent telecommunications account causing a false debt statement on their credit report. The complainant alleged they never lived at the address associated with the debt, and the telecommunications company initially refused to correct the debt or provide proof of account opening. The credit-reporting agency had validated the debt with the telecom company. Upon the OPC's intervention, the telecommunications company's fraud team reviewed the file and determined the account was fraudulent. The company then cancelled the fraudulent account and updated the credit-reporting agency with accurate information. The complainant was satisfied with these actions, leading to an early resolution.

Key Issues
  • Whether the telecommunications company failed to ensure the accuracy of personal information
  • Whether the telecommunications company failed to correct inaccurate personal information
  • Whether the credit-reporting agency failed to ensure the accuracy of personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jul 9, 2015Early resolved case summary #2015-01Indexed Jun 30, 2026

Early resolved case summary #2015-01: Store stops practice of posting pictures of suspected shoplifters - July 2015

A department store

A customer complained to the OPC after noticing a department store publicly displaying photographs of individuals, asking for information about them. The store claimed police and legal counsel advised this practice was permissible for alleged shoplifters. The OPC disagreed, explaining that publicly disclosing personal information (photographs) without consent is not allowed under PIPEDA. The store agreed to remove the pictures and discontinue the practice, opting to deal with police directly for such matters. The complainant was satisfied with this resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-01: Store stops practice of posting pictures of suspected shoplifters - July 2015

Jul 9, 2015Early resolved case summary #2015-01
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained to the OPC after noticing a department store publicly displaying photographs of individuals, asking for information about them. The store claimed police and legal counsel advised this practice was permissible for alleged shoplifters. The OPC disagreed, explaining that publicly disclosing personal information (photographs) without consent is not allowed under PIPEDA. The store agreed to remove the pictures and discontinue the practice, opting to deal with police directly for such matters. The complainant was satisfied with this resolution.

Key Issues
  • Whether publicly displaying photographs of suspected shoplifters without consent constitutes an unauthorized disclosure of personal information under PIPEDA
  • Whether photographs of individuals recorded on video surveillance are considered personal information under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 6, 2015PIPEDA Case Summary #2015-010Indexed Jun 30, 2026

PIPEDA Case Summary #2015-010: Customer’s emails sent to her acquaintance following a telecom employee’s attempt to fix a problem with the customer’s email service

A telecommunications provider

An individual complained that her telecommunications provider disclosed her personal information without consent. A technical support representative, while attempting to fix her email service, inadvertently configured her email application to automatically forward her emails, including one containing a temporary password, to an acquaintance. The OPC found that this constituted a disclosure of personal information without consent, contravening Principle 4.3. The telecom provider initially provided inaccurate information to the OPC regarding corrective measures taken, but later clarified its existing measures. The complaint was found to be well-founded and resolved, as the provider had some measures in place to prevent recurrence, despite the initial misrepresentations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2015-010: Customer’s emails sent to her acquaintance following a telecom employee’s attempt to fix a problem with the customer’s email service

Jul 6, 2015PIPEDA Case Summary #2015-010
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that her telecommunications provider disclosed her personal information without consent. A technical support representative, while attempting to fix her email service, inadvertently configured her email application to automatically forward her emails, including one containing a temporary password, to an acquaintance. The OPC found that this constituted a disclosure of personal information without consent, contravening Principle 4.3. The telecom provider initially provided inaccurate information to the OPC regarding corrective measures taken, but later clarified its existing measures. The complaint was found to be well-founded and resolved, as the provider had some measures in place to prevent recurrence, despite the initial misrepresentations.

Key Issues
  • Whether the telecommunications provider disclosed the individual's personal information without consent
  • Whether the disclosure contravened Principle 4.3 of PIPEDA
  • Whether the telecommunications provider provided accurate information to the OPC during the investigation
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jun 28, 2015Early resolved case summary #2015-05Indexed Jun 30, 2026

Early resolved case summary #2015-05: Anti-virus service provider steps up safeguards after customer personal information fraudulently used by someone posing as an employee

Anti-virus service provider

A couple received fraudulent calls from someone posing as an anti-virus service provider technician, who gained remote access to their computer and processed a fraudulent credit card payment. The fraudster used the couple's private account number, which they believed was obtained from the legitimate service provider. The couple struggled to get the service provider to investigate the matter, leading them to file a complaint with the OPC. The OPC requested the service provider conduct an investigation, which revealed an employee had improperly accessed the complainant's account. The employee was dismissed, and the service provider reimbursed the couple and implemented new safeguards, including an auditing system for employee access and a streamlined procedure for escalating privacy concerns. The complainants were satisfied with these outcomes.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-05: Anti-virus service provider steps up safeguards after customer personal information fraudulently used by someone posing as an employee

Jun 28, 2015Early resolved case summary #2015-05
Adjudicator: Daniel Therrien
Plain-Language Summary

A couple received fraudulent calls from someone posing as an anti-virus service provider technician, who gained remote access to their computer and processed a fraudulent credit card payment. The fraudster used the couple's private account number, which they believed was obtained from the legitimate service provider. The couple struggled to get the service provider to investigate the matter, leading them to file a complaint with the OPC. The OPC requested the service provider conduct an investigation, which revealed an employee had improperly accessed the complainant's account. The employee was dismissed, and the service provider reimbursed the couple and implemented new safeguards, including an auditing system for employee access and a streamlined procedure for escalating privacy concerns. The complainants were satisfied with these outcomes.

Key Issues
  • Whether the anti-virus service provider adequately protected personal information against unauthorized access by employees (Principle 4.7 PIPEDA)
  • Whether the anti-virus service provider had adequate procedures to receive and respond to complaints about personal information handling (Principle 4.10 PIPEDA)
  • Whether the anti-virus service provider adequately investigated the complaint (Principle 4.10.4 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
May 22, 2015Early resolved case summary #2015-06Indexed Jun 30, 2026

Early resolved case summary #2015-06: Manager snoops on employee’s personal bank account after employee calls in sick

A credit union

An employee of a credit union complained that her manager accessed her personal financial information without consent. The manager suspected the employee had falsely called in sick and checked her bank account transactions to see if she had used her debit card out of province. The employee discovered this when her employment was terminated and the manager referenced the incident. After receiving an inconclusive response from the credit union, she filed a complaint with the OPC. The OPC initiated its early resolution process, and the credit union acknowledged the manager's actions were without a valid business purpose and constituted an unauthorized use of personal information. The credit union committed to addressing the issue with the manager and sent a letter of apology to the employee. The employee was satisfied with this resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-06: Manager snoops on employee’s personal bank account after employee calls in sick

May 22, 2015Early resolved case summary #2015-06
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee of a credit union complained that her manager accessed her personal financial information without consent. The manager suspected the employee had falsely called in sick and checked her bank account transactions to see if she had used her debit card out of province. The employee discovered this when her employment was terminated and the manager referenced the incident. After receiving an inconclusive response from the credit union, she filed a complaint with the OPC. The OPC initiated its early resolution process, and the credit union acknowledged the manager's actions were without a valid business purpose and constituted an unauthorized use of personal information. The credit union committed to addressing the issue with the manager and sent a letter of apology to the employee. The employee was satisfied with this resolution.

Key Issues
  • Whether a manager accessing an employee's personal bank account without a valid business purpose constitutes unauthorized use of personal information under PIPEDA
  • Whether the credit union's actions to address the manager's conduct and apologize to the employee were satisfactory for early resolution
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

An organization

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Key Issues
  • Whether the disclosed leave information constituted personal information under PIPEDA
  • Whether the organization's purposes for disclosing employee leave information to other employees were appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the disclosure of leave type was necessary for the organization to meet its employee schedule management needs
  • Whether the benefits of the leave exchange system were proportional to the loss of privacy experienced by employees
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 23, 2015PIPEDA Report of Findings #2015-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

An investment brokerage

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 23, 2015PIPEDA Report of Findings #2015-006
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Key Issues
  • Whether the collection of net worth, marital status, and spouse's occupation was necessary for opening a self-directed investment account under Principle 4.4 PIPEDA
  • Whether the purposes for collecting the personal information were explicitly specified under Principle 4.2 PIPEDA
  • Whether the purposes for collecting the personal information were legitimate and appropriate under subsection 5(3) PIPEDA
  • Whether the organization required consent to the collection of information beyond that required for explicitly specified and legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 13, 2015PIPEDA Report of Findings #2015-007Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-007: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Peoples Trust

The OPC initiated an investigation into Peoples Trust following a data breach that compromised sensitive personal information of approximately 12,000 customers. The investigation found that Peoples Trust failed to implement adequate technological and organizational safeguards, including using an outdated and vulnerable web editor and lacking ongoing monitoring. Additionally, the organization unnecessarily stored duplicate, unencrypted customer information on a web server for longer than required, contravening its retention policies. Following the OPC's intervention, Peoples Trust implemented comprehensive remedial measures, such as redesigning its web portal, enhancing monitoring, and developing a new Information Security Policy. As a result, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2015-007: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 13, 2015PIPEDA Report of Findings #2015-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated an investigation into Peoples Trust following a data breach that compromised sensitive personal information of approximately 12,000 customers. The investigation found that Peoples Trust failed to implement adequate technological and organizational safeguards, including using an outdated and vulnerable web editor and lacking ongoing monitoring. Additionally, the organization unnecessarily stored duplicate, unencrypted customer information on a web server for longer than required, contravening its retention policies. Following the OPC's intervention, Peoples Trust implemented comprehensive remedial measures, such as redesigning its web portal, enhancing monitoring, and developing a new Information Security Policy. As a result, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether Peoples Trust implemented adequate technological and organizational safeguards appropriate to the sensitivity of the information, as per Principle 4.7 and 4.1.4(a) PIPEDA
  • Whether Peoples Trust retained personal information for longer than necessary to fulfill its purposes, as per Principle 4.5 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Mar 12, 2015PIPEDA findings #2015-020Indexed Jun 30, 2026

PIPEDA findings #2015-020: Hotel chain alerts its clients about “special offer” telephone scam

A major hotel chain

An individual complained after receiving a promotional phone call from a hotel chain shortly after visiting its website, suspecting the hotel linked her IP address to her phone number. The hotel chain denied making such calls or collecting her personal information, stating the call was part of a telemarketing scam by an unrelated party. The OPC's investigation confirmed the calls were indeed a scam. The complainant suggested the hotel warn its customers, which the hotel did. The matter was resolved through the OPC's early resolution process.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

PIPEDA findings #2015-020: Hotel chain alerts its clients about “special offer” telephone scam

Mar 12, 2015PIPEDA findings #2015-020
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained after receiving a promotional phone call from a hotel chain shortly after visiting its website, suspecting the hotel linked her IP address to her phone number. The hotel chain denied making such calls or collecting her personal information, stating the call was part of a telemarketing scam by an unrelated party. The OPC's investigation confirmed the calls were indeed a scam. The complainant suggested the hotel warn its customers, which the hotel did. The matter was resolved through the OPC's early resolution process.

Key Issues
  • Whether the hotel chain collected the complainant's personal information (phone number) from her website visit
  • Whether the promotional phone call originated from the hotel chain or an unrelated third party
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jan 21, 2015Early resolved case summary #2015-03Indexed Jun 30, 2026

Early resolved case summary #2015-03: Office building tenant reconsiders placement of video surveillance cameras

An office building tenant (call centre company)

An office building tenant complained about five video surveillance cameras installed in a shared common area by another tenant, a call centre company. The complainant found it disturbing that the cameras recorded his and his clients' movements, particularly two cameras positioned between his office, the washrooms, and the elevators. The installing tenant claimed the cameras were for safety following a security incident and that building management had authorized their installation. After the OPC became involved, the building management facilitated the relocation of the two most concerning cameras from the shared hallway into the installing tenant's offices. The complainant expressed satisfaction that his and his clients' privacy rights were now respected. The case was resolved early.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-03: Office building tenant reconsiders placement of video surveillance cameras

Jan 21, 2015Early resolved case summary #2015-03
Adjudicator: Daniel Therrien
Plain-Language Summary

An office building tenant complained about five video surveillance cameras installed in a shared common area by another tenant, a call centre company. The complainant found it disturbing that the cameras recorded his and his clients' movements, particularly two cameras positioned between his office, the washrooms, and the elevators. The installing tenant claimed the cameras were for safety following a security incident and that building management had authorized their installation. After the OPC became involved, the building management facilitated the relocation of the two most concerning cameras from the shared hallway into the installing tenant's offices. The complainant expressed satisfaction that his and his clients' privacy rights were now respected. The case was resolved early.

Key Issues
  • Whether the installation of video surveillance cameras in a shared common area by one tenant infringed on the privacy of another tenant and their clients
  • Whether the collection of personal information via video surveillance was appropriate and proportionate to the stated safety purpose
  • Whether consent was obtained for the video surveillance
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Oct 31, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-013Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-013: Organization could reasonably assume customer's implied consent for disclosure in dispute resolution situation

An Internet service provider (ISP)

A complainant alleged that his Internet service provider (ISP) disclosed his personal information without consent to a newspaper columnist. The complainant had contacted the columnist for assistance in resolving a service dispute with the ISP. The ISP argued it had implied consent to disclose information relevant to the dispute. The OPC found that the personal information disclosed was not sensitive and that, given the complainant's actions and familiarity with the columnist's work, it was reasonable for the ISP to infer implied consent. The ISP also limited its disclosure to information relevant to the complaint. Therefore, the OPC concluded that the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Commissioner’s Findings - PIPEDA Report of Findings #2014-013: Organization could reasonably assume customer's implied consent for disclosure in dispute resolution situation

Oct 31, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-013
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that his Internet service provider (ISP) disclosed his personal information without consent to a newspaper columnist. The complainant had contacted the columnist for assistance in resolving a service dispute with the ISP. The ISP argued it had implied consent to disclose information relevant to the dispute. The OPC found that the personal information disclosed was not sensitive and that, given the complainant's actions and familiarity with the columnist's work, it was reasonable for the ISP to infer implied consent. The ISP also limited its disclosure to information relevant to the complaint. Therefore, the OPC concluded that the complaint was not well-founded.

Key Issues
  • Whether the ISP had the complainant's consent to disclose information to the newspaper columnist
  • Whether the personal information disclosed was sensitive
  • Whether implied consent was appropriate in the circumstances
  • Whether the ISP limited its disclosure to relevant information
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Oct 30, 2014Early resolved case summary #9Indexed Jun 30, 2026

Early resolved case summary #9: Equipment store ends practice of photocopying driver’s licences as a condition of renting equipment - October 30, 2014

An equipment store

An individual complained that an equipment store required a scanned copy of his driver's license and a photograph as a condition for renting equipment. The store justified this practice by citing past losses of expensive rental equipment. The OPC informed the store that collecting driver's license information in this manner was generally inappropriate due to the excessive personal information contained on the license and its limited value in theft investigations. The OPC provided guidance on appropriate collection practices. As a result of the OPC's intervention, the store implemented a less privacy-invasive solution and trained its staff. The complainant was satisfied with the outcome.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #9: Equipment store ends practice of photocopying driver’s licences as a condition of renting equipment - October 30, 2014

Oct 30, 2014Early resolved case summary #9
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an equipment store required a scanned copy of his driver's license and a photograph as a condition for renting equipment. The store justified this practice by citing past losses of expensive rental equipment. The OPC informed the store that collecting driver's license information in this manner was generally inappropriate due to the excessive personal information contained on the license and its limited value in theft investigations. The OPC provided guidance on appropriate collection practices. As a result of the OPC's intervention, the store implemented a less privacy-invasive solution and trained its staff. The complainant was satisfied with the outcome.

Key Issues
  • Whether requiring a scanned copy of a driver's license and a photograph for equipment rental constitutes appropriate collection of personal information under PIPEDA
  • Whether the collection of driver's license information is justified for addressing customer theft