The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

172 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Oct 31, 2012Early resolved case summary #2Indexed Jun 30, 2026

Early resolved case summary #2: Telecommunications firm discloses individual’s personal information without consent when it merged two household accounts that shared an address

A telecommunications firm

A landlord complained that a telecommunications firm disclosed his personal account information, including debt details, to his tenant without consent. The firm had merged the landlord's existing account with the tenant's new account because they shared the same address. This led to the firm demanding payment from the tenant for services he had not ordered and disclosing the landlord's information during collection attempts. The tenant then confronted the landlord, accusing him of debt evasion and threatening to vacate. The landlord filed a complaint with the OPC, alleging unauthorized disclosure of his personal information.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2: Telecommunications firm discloses individual’s personal information without consent when it merged two household accounts that shared an address

Oct 31, 2012Early resolved case summary #2
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A landlord complained that a telecommunications firm disclosed his personal account information, including debt details, to his tenant without consent. The firm had merged the landlord's existing account with the tenant's new account because they shared the same address. This led to the firm demanding payment from the tenant for services he had not ordered and disclosing the landlord's information during collection attempts. The tenant then confronted the landlord, accusing him of debt evasion and threatening to vacate. The landlord filed a complaint with the OPC, alleging unauthorized disclosure of his personal information.

Key Issues
  • Whether the telecommunications firm disclosed the landlord's personal information without consent
  • Whether the firm was responsible for merging the accounts and the subsequent unauthorized disclosure
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 22, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-004Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account

A cellular-telephone service provider

An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account

Aug 22, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-004
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.

Key Issues
  • Whether the cellular service provider disclosed personal information without consent to an imposter, contravening Principle 4.3 PIPEDA
  • Whether the cellular service provider adequately responded to the complainant's access request for personal information under Principle 4.9 PIPEDA
  • Whether the cellular service provider responded to the access request within the 30-day timeframe as per s.8(3) PIPEDA
  • Whether the redaction of the CSR's name from the transcript was permissible under s.9(1) PIPEDA
  • Whether the company was required to provide an audio recording of the conversation in addition to a transcript under s.10 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 14, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-010Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings # 2012-010: Telecommunications firm adopts additional accountability measures to ensure a consistent approach in handling access requests

A telecommunications firm

A complainant alleged that a telecommunications firm failed to provide her with access to her personal information, specifically notes and transcripts of recorded conversations related to an account dispute. The firm acknowledged receiving the access request but mistakenly believed it was not necessary to provide the information due to ongoing settlement negotiations. The OPC found that the firm failed to respond to the access request within 30 days and did not issue an extension notice, thus contravening PIPEDA subsections 8(3), 8(4), and 8(5). Furthermore, the firm purged the requested audio records, violating subsection 8(8) and Principles 4.9 and 4.9.4. The firm's internal policies were found to be unclear and staff training inadequate, leading to the erroneous deletion of records. The OPC made several recommendations, which the firm accepted and implemented, including amending policies and providing staff training. As a result, the complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings # 2012-010: Telecommunications firm adopts additional accountability measures to ensure a consistent approach in handling access requests

Aug 14, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a telecommunications firm failed to provide her with access to her personal information, specifically notes and transcripts of recorded conversations related to an account dispute. The firm acknowledged receiving the access request but mistakenly believed it was not necessary to provide the information due to ongoing settlement negotiations. The OPC found that the firm failed to respond to the access request within 30 days and did not issue an extension notice, thus contravening PIPEDA subsections 8(3), 8(4), and 8(5). Furthermore, the firm purged the requested audio records, violating subsection 8(8) and Principles 4.9 and 4.9.4. The firm's internal policies were found to be unclear and staff training inadequate, leading to the erroneous deletion of records. The OPC made several recommendations, which the firm accepted and implemented, including amending policies and providing staff training. As a result, the complaint was deemed well-founded and resolved.

Key Issues
  • Whether the telecommunications firm responded to the access request within the 30-day time limit under subsection 8(3) PIPEDA
  • Whether the telecommunications firm issued a notice of extension for the access request under subsection 8(4) PIPEDA
  • Whether the telecommunications firm was deemed to have refused the access request under subsection 8(5) PIPEDA
  • Whether the telecommunications firm provided access to personal information as required by Principle 4.9 PIPEDA
  • Whether the telecommunications firm responded to the access request within a reasonable time and at minimal or no cost under Principle 4.9.4 PIPEDA
  • Whether the telecommunications firm retained personal information that was the subject of an access request for as long as necessary to allow the individual to exhaust any recourse under subsection 8(8) PIPEDA
  • Whether the telecommunications firm implemented policies and practices to give effect to the principles, including training staff and communicating policies and practices under Principle 4.1.4(c) PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 30, 2011Commissioner’s Findings - PIPEDA Report of Findings #2011-011Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2011-011: Public opinion research firm must better inform survey respondents about their personal information use; refrain from collecting full birth dates

A public opinion research firm

A complainant alleged that a public opinion research firm unnecessarily collected her full date of birth and failed to adequately inform her about the purpose of a profiling survey. The firm collected full birth dates for demographic purposes and to verify identity, arguing that month and year alone were insufficient. The OPC found that collecting the full date of birth was not necessary for the firm's stated purposes and that the consent language for profiling surveys was not sufficiently clear. While the firm agreed to clarify its consent language, it refused to stop collecting or delete the day of birth from its records. Consequently, the OPC found the complaint well-founded but partially unresolved regarding the collection of full birth dates.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Commissioner’s Findings - PIPEDA Report of Findings #2011-011: Public opinion research firm must better inform survey respondents about their personal information use; refrain from collecting full birth dates

Jun 30, 2011Commissioner’s Findings - PIPEDA Report of Findings #2011-011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a public opinion research firm unnecessarily collected her full date of birth and failed to adequately inform her about the purpose of a profiling survey. The firm collected full birth dates for demographic purposes and to verify identity, arguing that month and year alone were insufficient. The OPC found that collecting the full date of birth was not necessary for the firm's stated purposes and that the consent language for profiling surveys was not sufficiently clear. While the firm agreed to clarify its consent language, it refused to stop collecting or delete the day of birth from its records. Consequently, the OPC found the complaint well-founded but partially unresolved regarding the collection of full birth dates.

Key Issues
  • Whether it is necessary for the Respondent to collect all three elements of the date of birth at registration
  • Whether it is necessary for the Respondent to confirm all three elements of the date of birth in profiling surveys
  • Whether the Respondent adequately informed the complainant of the purpose of the profiling survey
  • Whether consent under Principle 4.3 was meaningful
  • Whether the collection of personal information was limited to that which is necessary for the identified purposes under Principle 4.4
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jan 6, 2010Settled Case summary #2010-001Indexed Jun 30, 2026

Settled Case summary #2010-001: Dental benefit information available to parents with daughter’s consent (January 6, 2010)

A dental plan administrator

The parents of a 17-year-old dependent complained that they could not access their daughter's online dental benefit information from their group dental plan administrator. The administrator's policy required consent from individuals aged 16 or older before their information could be accessed by another plan member, even parents. The administrator defended its policy by citing PIPEDA's consent requirements, the lack of a national age of majority consensus, and the distinction between age of majority and age of consent. The policy was based on the Ontario Health Care Consent Act, which suggests 16 as an age for health care consent. The mother was satisfied with the explanation and understood that she could access her daughter's account if her daughter provided consent by sharing her password.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #2010-001: Dental benefit information available to parents with daughter’s consent (January 6, 2010)

Jan 6, 2010Settled Case summary #2010-001
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The parents of a 17-year-old dependent complained that they could not access their daughter's online dental benefit information from their group dental plan administrator. The administrator's policy required consent from individuals aged 16 or older before their information could be accessed by another plan member, even parents. The administrator defended its policy by citing PIPEDA's consent requirements, the lack of a national age of majority consensus, and the distinction between age of majority and age of consent. The policy was based on the Ontario Health Care Consent Act, which suggests 16 as an age for health care consent. The mother was satisfied with the explanation and understood that she could access her daughter's account if her daughter provided consent by sharing her password.

Key Issues
  • Whether a dental plan administrator requires consent from a 17-year-old dependent to disclose her dental benefit information to her parents
  • Whether the age of majority or age of consent impacts the requirement for consent under PIPEDA for minors
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 21, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-024Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2009-024: Bank Disclosed Personal Information without Consent

A Canadian bank

A married couple applied for a joint mortgage. The husband alleged that a bank mortgage specialist disclosed his account information to his wife without his consent during the application process. The bank argued there was implicit consent given the joint mortgage application. The Assistant Commissioner found that the bank did not make a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed to each other. Therefore, the bank did not have meaningful consent for the disclosure. Although the incident was a one-time error by an employee, the complaint was found to be well-founded and resolved as the bank had adopted reasonable practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Case Summary #2009-024: Bank Disclosed Personal Information without Consent

Dec 21, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-024
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A married couple applied for a joint mortgage. The husband alleged that a bank mortgage specialist disclosed his account information to his wife without his consent during the application process. The bank argued there was implicit consent given the joint mortgage application. The Assistant Commissioner found that the bank did not make a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed to each other. Therefore, the bank did not have meaningful consent for the disclosure. Although the incident was a one-time error by an employee, the complaint was found to be well-founded and resolved as the bank had adopted reasonable practices.

Key Issues
  • Whether the bank had the husband's implicit or explicit consent to disclose his account information to his wife
  • Whether the bank made a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed
  • Whether the bank's mortgage specialist followed the bank's usual practice for informing joint mortgage applicants
  • Whether the presumption of implied consent remained reasonable after the wife's reaction to the initial disclosure
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jul 27, 2009Report of FindingsIndexed Jun 30, 2026

Report of Findings: Complaint under PIPEDA against Accusearch Inc., doing business as Abika.com

Accusearch Inc., doing business as Abika.com

CIPPIC complained that Abika.com, a U.S. company, collected, used, and disclosed Canadians' personal information without consent, compiled and disclosed inaccurate personal information through its "psychological profile" service, and used personal information for inappropriate purposes. The OPC initially declined jurisdiction, but the Federal Court ordered the investigation to proceed. The OPC found that Abika collected and disclosed personal information, including telephone records, of Canadians without their knowledge or consent, often for inappropriate purposes such as investigating partners. While the OPC found the accuracy complaint not well-founded due to lack of verifiable evidence, it concluded that Abika contravened PIPEDA Principles 4.3 and subsection 5(3). Abika failed to respond adequately to the OPC's recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Report of Findings: Complaint under PIPEDA against Accusearch Inc., doing business as Abika.com

Jul 27, 2009Report of Findings
Adjudicator: Jennifer Stoddart
Plain-Language Summary

CIPPIC complained that Abika.com, a U.S. company, collected, used, and disclosed Canadians' personal information without consent, compiled and disclosed inaccurate personal information through its "psychological profile" service, and used personal information for inappropriate purposes. The OPC initially declined jurisdiction, but the Federal Court ordered the investigation to proceed. The OPC found that Abika collected and disclosed personal information, including telephone records, of Canadians without their knowledge or consent, often for inappropriate purposes such as investigating partners. While the OPC found the accuracy complaint not well-founded due to lack of verifiable evidence, it concluded that Abika contravened PIPEDA Principles 4.3 and subsection 5(3). Abika failed to respond adequately to the OPC's recommendations.

Key Issues
  • Whether Abika collected, used, and disclosed personal information of individuals living in Canada without their knowledge and consent, in contravention of Principle 4.3
  • Whether Abika compiled and disclosed inaccurate personal information through its "psychological profile" service, in contravention of Principle 4.6
  • Whether Abika collected, used, and disclosed personal information about Canadians for inappropriate purposes, in contravention of subsection 5(3)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 16, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-008Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2009-008: Report of Findings: CIPPIC v. Facebook Inc.

Facebook Inc.

The Canadian Internet Policy and Public Interest Clinic (CIPPIC) filed a comprehensive complaint against Facebook Inc., alleging 24 contraventions of PIPEDA across 12 subjects, including default privacy settings, advertising practices, third-party applications, and the handling of personal information for deactivated, deceased, and non-users. The Office of the Privacy Commissioner (OPC) focused its investigation on meaningful consent, retention, and security safeguards. The Assistant Commissioner found several allegations to be 'not well-founded', such as those concerning new uses of information, collection from other sources, Facebook Mobile safeguards, and deception. Other allegations, including those related to date of birth collection, default privacy settings, advertising, and monitoring for anomalous activity, were found 'well-founded and resolved' due to Facebook's agreement to implement corrective measures. However, significant issues regarding third-party applications, indefinite retention of deactivated account data, inadequate notification for deceased users' accounts, and the collection/retention of non-users' personal information were found 'well-founded' but remained unresolved, as Facebook declined to implement key recommendations. The OPC indicated it would follow up on all recommendations and consider further action for unresolved issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Case Summary #2009-008: Report of Findings: CIPPIC v. Facebook Inc.

Jul 16, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-008
Adjudicator: Elizabeth Denham
Plain-Language Summary

The Canadian Internet Policy and Public Interest Clinic (CIPPIC) filed a comprehensive complaint against Facebook Inc., alleging 24 contraventions of PIPEDA across 12 subjects, including default privacy settings, advertising practices, third-party applications, and the handling of personal information for deactivated, deceased, and non-users. The Office of the Privacy Commissioner (OPC) focused its investigation on meaningful consent, retention, and security safeguards. The Assistant Commissioner found several allegations to be 'not well-founded', such as those concerning new uses of information, collection from other sources, Facebook Mobile safeguards, and deception. Other allegations, including those related to date of birth collection, default privacy settings, advertising, and monitoring for anomalous activity, were found 'well-founded and resolved' due to Facebook's agreement to implement corrective measures. However, significant issues regarding third-party applications, indefinite retention of deactivated account data, inadequate notification for deceased users' accounts, and the collection/retention of non-users' personal information were found 'well-founded' but remained unresolved, as Facebook declined to implement key recommendations. The OPC indicated it would follow up on all recommendations and consider further action for unresolved issues.

Key Issues
  • Whether requiring date of birth as a condition of registration contravened Principle 4.3.3
  • Whether Facebook adequately explained the purposes for collecting and using date of birth under Principle 4.3.2
  • Whether default privacy settings constituted improper opt-out consent for sensitive information under Principle 4.3.6
  • Whether Facebook made reasonable efforts to advise users of purposes and extent of information use/disclosure via default settings under Principles 4.2.3 and 4.3.2
  • Whether default settings for photo albums met users' reasonable expectations under Principle 4.3.5
  • Whether default settings for public search listings met users' reasonable expectations under Principle 4.3.5
  • Whether Facebook made reasonable efforts to notify users of advertising purposes under Principle 4.3.2
  • Whether Social Ads improperly used opt-out consent for sensitive information under Principle 4.3.6
  • Whether users could opt out of Facebook Ads under Principle 4.3.8
  • Whether requiring consent to Facebook Ads as a condition of service violated Principle 4.3.3
  • Whether Facebook adequately informed users of the purpose for disclosing personal information to third-party application developers under Principles 4.2.2 and 4.2.5
  • Whether Facebook provided third-party application developers with access to personal information beyond what was necessary under Principle 4.4.1
  • Whether Facebook required consent to disclosure beyond what was necessary to run an application under Principle 4.3.3
  • Whether Facebook adequately safeguarded personal information transferred to third-party applications under Principle 4.7
  • Whether Facebook obtained meaningful consent for disclosure of personal information to application developers when users or their friends added applications under Principles 4.2, 4.2.3, 4.3.2, 4.3.4, 4.3.5, 4.3.6, and subsection 5(3)
  • Whether Facebook failed to notify users of new purposes for collecting, using, or disclosing personal information under Principle 4.2.4
  • Whether Facebook failed to provide specific information and obtain meaningful consent for collecting personal information from sources outside Facebook under Principle 4.3
  • Whether Facebook inappropriately deprived users of a means to delete all personal information from the site
  • Whether Facebook's indefinite retention of personal information in deactivated accounts contravened Principles 4.5 and 4.5.3
  • Whether Facebook obtained meaningful consent for memorializing deceased users' profiles under Principle 4.3.3
  • Whether memorializing profiles was an unnecessary condition of service under Principle 4.3.3
  • Whether Facebook adequately informed users of its practice of account memorialization under Principles 4.2.1, 4.2.3, 4.3.2, and 4.8
  • Whether Facebook obtained consent from non-users for uploading their personal information (e.g., tagging, invitations) under Principle 4.3
  • Whether Facebook's retention of non-users' email addresses beyond the initial purpose contravened Principle 4.5
  • Whether Facebook Mobile's use of a persistent cookie constituted inadequate safeguarding of personal information under Principles 4.7, 4.7.1, and 4.7.3
  • Whether Facebook adequately informed users of its practice of monitoring for anomalous activity under Principle 4.8
  • Whether Facebook misrepresented its purpose or users' control over personal information under Principles 4.3.2 and 4.4.2
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
May 29, 2008Executive SummaryIndexed Jun 30, 2026

Executive Summary: Law School Admission Council Investigation

Law School Admission Council (LSAC)

A complainant objected to the Law School Admission Council's (LSAC) requirement for Canadian students to provide fingerprints to write the Law School Admission Test (LSAT). LSAC, a US-based non-profit, argued it was outside PIPEDA's jurisdiction and its activities were educational. The Assistant Privacy Commissioner found sufficient links to Canada for PIPEDA to apply and determined LSAC's activities were administrative, not educational. Applying a four-part test, the Assistant Commissioner found fingerprinting was not demonstrably necessary, effective, or proportional, and less privacy-invasive alternatives existed. LSAC agreed to cease fingerprint collection but reserved the right to reinstate it, proposing photographic evidence instead. The Assistant Commissioner found the complaint well-founded due to the disproportionate nature of fingerprint collection and LSAC's reservation to reinstate the policy.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Executive Summary: Law School Admission Council Investigation

May 29, 2008Executive Summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant objected to the Law School Admission Council's (LSAC) requirement for Canadian students to provide fingerprints to write the Law School Admission Test (LSAT). LSAC, a US-based non-profit, argued it was outside PIPEDA's jurisdiction and its activities were educational. The Assistant Privacy Commissioner found sufficient links to Canada for PIPEDA to apply and determined LSAC's activities were administrative, not educational. Applying a four-part test, the Assistant Commissioner found fingerprinting was not demonstrably necessary, effective, or proportional, and less privacy-invasive alternatives existed. LSAC agreed to cease fingerprint collection but reserved the right to reinstate it, proposing photographic evidence instead. The Assistant Commissioner found the complaint well-founded due to the disproportionate nature of fingerprint collection and LSAC's reservation to reinstate the policy.

Key Issues
  • Whether LSAC's activities fall within the scope of PIPEDA despite its non-profit status and US location
  • Whether LSAC's activities are educational in nature or serve administrative needs
  • Whether the collection of thumbprints is demonstrably necessary to meet a specific need
  • Whether the collection of thumbprints is likely to be effective in meeting that need
  • Whether the loss of privacy from thumbprint collection is proportional to the benefit gained
  • Whether there is a less privacy-invasive way of achieving the same end as thumbprint collection
  • Whether the collection of photographs as an alternative is acceptable under PIPEDA
  • Whether LSAC's reservation of the right to reinstate its fingerprint policy is compliant with PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Feb 12, 2008BackgrounderIndexed Jun 30, 2026

Backgrounder: Ticketmaster Investigation

Ticketmaster Canada Limited

The OPC investigated Ticketmaster Canada Limited (TM) following a complaint that its practices for collecting, disclosing, and using customer personal information for marketing purposes did not comply with PIPEDA. The complainant alleged that customers were not properly informed or given a viable alternative to sharing their information for marketing. The Assistant Privacy Commissioner found that TM failed to uphold the principles of openness and consent. TM subsequently revised its privacy policy and online notifications to explicitly communicate information sharing practices and provide clear opt-in options for marketing. The investigation concluded that the issues were resolved satisfactorily, but the Assistant Commissioner expressed concern about the well-founded violations several years after PIPEDA's enactment.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Backgrounder: Ticketmaster Investigation

Feb 12, 2008Backgrounder
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated Ticketmaster Canada Limited (TM) following a complaint that its practices for collecting, disclosing, and using customer personal information for marketing purposes did not comply with PIPEDA. The complainant alleged that customers were not properly informed or given a viable alternative to sharing their information for marketing. The Assistant Privacy Commissioner found that TM failed to uphold the principles of openness and consent. TM subsequently revised its privacy policy and online notifications to explicitly communicate information sharing practices and provide clear opt-in options for marketing. The investigation concluded that the issues were resolved satisfactorily, but the Assistant Commissioner expressed concern about the well-founded violations several years after PIPEDA's enactment.

Key Issues
  • Whether Ticketmaster's privacy policy met the openness principle of PIPEDA
  • Whether Ticketmaster obtained valid consent for the use of personal information for marketing purposes
  • Whether customers were properly informed about the use of their personal information for marketing
  • Whether customers were provided a viable opt-in/opt-out option for marketing without penalty
  • Whether Ticketmaster's agreements with event providers ensured compliance with customer preferences
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 15, 2007Settled Case summary #30Indexed Jun 30, 2026

Settled Case summary #30: Solicitor’s lien insufficient grounds to deny access to personal information (November 15, 2007)

A law firm

A client sought access to her personal information from her former lawyer. The lawyer refused access, citing outstanding fees and asserting a solicitor's lien on the client's file, believing that providing access could jeopardize payment. The OPC noted that PIPEDA's subsection 9(3) provides an exhaustive list of reasons for refusing access, which does not include a solicitor's lien. Therefore, lawyers must grant access to personal information even if a valid lien exists. The OPC suggested that allowing the individual to view, but not copy, the information could balance the right to access with the lien. The lawyer subsequently provided a complete copy of the file, and the complaint was settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #30: Solicitor’s lien insufficient grounds to deny access to personal information (November 15, 2007)

Nov 15, 2007Settled Case summary #30
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A client sought access to her personal information from her former lawyer. The lawyer refused access, citing outstanding fees and asserting a solicitor's lien on the client's file, believing that providing access could jeopardize payment. The OPC noted that PIPEDA's subsection 9(3) provides an exhaustive list of reasons for refusing access, which does not include a solicitor's lien. Therefore, lawyers must grant access to personal information even if a valid lien exists. The OPC suggested that allowing the individual to view, but not copy, the information could balance the right to access with the lien. The lawyer subsequently provided a complete copy of the file, and the complaint was settled.

Key Issues
  • Whether a solicitor's lien is a valid ground to refuse access to personal information under PIPEDA
  • Whether subsection 9(3) of PIPEDA provides an exhaustive list of circumstances for refusing access
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 2, 2007Executive SummaryIndexed Jun 30, 2026

Executive Summary: Privacy Commissioner of Canada v. SWIFT

SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication)

The Privacy Commissioner of Canada launched an investigation into SWIFT SCRL following allegations that it disclosed personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) via administrative subpoenas. SWIFT provides messaging services to financial institutions globally, and some messages contain personal information. The Commissioner determined that SWIFT was subject to PIPEDA due to its operations and significant presence in Canada. While acknowledging SWIFT's compliance with US laws, the Commissioner found that SWIFT had not contravened PIPEDA, as the Act allows for disclosure without consent in response to a subpoena from a body with jurisdiction to compel information. The Commissioner emphasized that organizations operating in Canada must still abide by PIPEDA, even when subject to foreign laws. She also recommended that US authorities use existing information-sharing mechanisms with built-in privacy protections rather than subpoenas for Canadian-related financial information.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Executive Summary: Privacy Commissioner of Canada v. SWIFT

Apr 2, 2007Executive Summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Privacy Commissioner of Canada launched an investigation into SWIFT SCRL following allegations that it disclosed personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) via administrative subpoenas. SWIFT provides messaging services to financial institutions globally, and some messages contain personal information. The Commissioner determined that SWIFT was subject to PIPEDA due to its operations and significant presence in Canada. While acknowledging SWIFT's compliance with US laws, the Commissioner found that SWIFT had not contravened PIPEDA, as the Act allows for disclosure without consent in response to a subpoena from a body with jurisdiction to compel information. The Commissioner emphasized that organizations operating in Canada must still abide by PIPEDA, even when subject to foreign laws. She also recommended that US authorities use existing information-sharing mechanisms with built-in privacy protections rather than subpoenas for Canadian-related financial information.

Key Issues
  • Whether SWIFT is subject to PIPEDA
  • Whether SWIFT contravened PIPEDA by disclosing personal information to the US Department of the Treasury
  • Whether the exception to consent for disclosures in response to a subpoena applies
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 2, 2007Report of FindingsIndexed Jun 30, 2026

Report of Findings: Privacy Commissioner of Canada v. SWIFT

SWIFT SCRL

The Privacy Commissioner of Canada initiated a complaint against SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication) for allegedly disclosing personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) in response to administrative subpoenas. SWIFT, a global financial messaging service, argued it was legally compelled to comply with valid US subpoenas and had negotiated privacy protections with the UST. The OPC first determined that the Personal Information Protection and Electronic Documents Act (PIPEDA) applied to SWIFT due to its significant presence and commercial activities in Canada. The key issue was whether SWIFT's disclosure without consent complied with PIPEDA, specifically the exception for subpoenas under paragraph 7(3)(c) and the appropriateness of the disclosure under subsection 5(3). The Commissioner concluded that paragraph 7(3)(c) allows for compliance with valid foreign subpoenas when an organization operates in multiple jurisdictions and legitimately stores data abroad, and that the disclosure was appropriate given the legal compulsion and privacy safeguards SWIFT negotiated. Consequently, the complaint was found not well-founded, as SWIFT's actions did not contravene PIPEDA. The Commissioner, however, recommended that the Canadian government engage with US counterparts to encourage the use of existing information-sharing mechanisms with built-in privacy protections, and noted SWIFT's efforts to explore enhanced privacy solutions.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Report of Findings: Privacy Commissioner of Canada v. SWIFT

Apr 2, 2007Report of Findings
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Privacy Commissioner of Canada initiated a complaint against SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication) for allegedly disclosing personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) in response to administrative subpoenas. SWIFT, a global financial messaging service, argued it was legally compelled to comply with valid US subpoenas and had negotiated privacy protections with the UST. The OPC first determined that the Personal Information Protection and Electronic Documents Act (PIPEDA) applied to SWIFT due to its significant presence and commercial activities in Canada. The key issue was whether SWIFT's disclosure without consent complied with PIPEDA, specifically the exception for subpoenas under paragraph 7(3)(c) and the appropriateness of the disclosure under subsection 5(3). The Commissioner concluded that paragraph 7(3)(c) allows for compliance with valid foreign subpoenas when an organization operates in multiple jurisdictions and legitimately stores data abroad, and that the disclosure was appropriate given the legal compulsion and privacy safeguards SWIFT negotiated. Consequently, the complaint was found not well-founded, as SWIFT's actions did not contravene PIPEDA. The Commissioner, however, recommended that the Canadian government engage with US counterparts to encourage the use of existing information-sharing mechanisms with built-in privacy protections, and noted SWIFT's efforts to explore enhanced privacy solutions.

Key Issues
  • Whether the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to SWIFT’s collection, use, and disclosure of personal information in the course of its operations in Canada.
  • Whether SWIFT is engaged in a commercial activity within Canada under paragraph 4(1)(a) of PIPEDA.
  • Whether personal information collected by SWIFT from Canadian financial institutions was disclosed to US authorities in accordance with PIPEDA.
  • Whether the disclosure of personal information without knowledge or consent was permitted under paragraph 7(3)(c) of PIPEDA (subpoena exception).
  • Whether a "subpoena or warrant" under paragraph 7(3)(c) must be issued only by a body within Canada.
  • Whether SWIFT’s disclosure to the UST was appropriate in the circumstances, as per subsection 5(3) of PIPEDA.
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Feb 5, 2007Settled Case summary #29Indexed Jun 30, 2026

Settled case summary #29 — A department store

A department store

An individual complained that a department store's method of collecting tax exemption information allowed other customers to view her personal data and the data of previous customers. The store used a petition-style form where customers wrote their names, shopping dates, and tax exemption numbers, making this information visible to subsequent customers. The complainant was concerned about the lack of privacy for her personal information. In response to the complaint, the department store first implemented a temporary measure of using a new form where only one customer's information appeared per page. Subsequently, the store reconfigured its cash registers to electronically print a receipt-style form for tax exemptions, which was then completed by the customer and securely stored in the register. This new electronic system prevented customers from viewing each other's personal information. The complainant was satisfied with these changes, and the matter was considered settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #29 — A department store

Feb 5, 2007Settled Case summary #29
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a department store's method of collecting tax exemption information allowed other customers to view her personal data and the data of previous customers. The store used a petition-style form where customers wrote their names, shopping dates, and tax exemption numbers, making this information visible to subsequent customers. The complainant was concerned about the lack of privacy for her personal information. In response to the complaint, the department store first implemented a temporary measure of using a new form where only one customer's information appeared per page. Subsequently, the store reconfigured its cash registers to electronically print a receipt-style form for tax exemptions, which was then completed by the customer and securely stored in the register. This new electronic system prevented customers from viewing each other's personal information. The complainant was satisfied with these changes, and the matter was considered settled.

Key Issues
  • Whether the department store's method of collecting tax exemption information allowed unauthorized disclosure of personal information to other customers
  • Whether the department store adequately safeguarded customers' personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Dec 14, 2006Settled Case summary #28Indexed Jun 30, 2026

Settled case summary #28 — A DVD-rental store

A DVD-rental store

An individual complained that a DVD-rental store required him to provide his driver's license details for entry into their database to become a member, which he believed was unnecessary. The store initially argued this was a business necessity for identity verification and recovering overdue rentals. However, the investigation revealed the store did not use driver's license data for tracing members, but rather publicly available information. Recognizing it was collecting unnecessary information, the store revised its membership process. Under the new process, customers must present two pieces of identification, one with a photo, but driver's license details are no longer entered into the database. The store committed to updating its procedures and training staff on the new process.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #28 — A DVD-rental store

Dec 14, 2006Settled Case summary #28
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a DVD-rental store required him to provide his driver's license details for entry into their database to become a member, which he believed was unnecessary. The store initially argued this was a business necessity for identity verification and recovering overdue rentals. However, the investigation revealed the store did not use driver's license data for tracing members, but rather publicly available information. Recognizing it was collecting unnecessary information, the store revised its membership process. Under the new process, customers must present two pieces of identification, one with a photo, but driver's license details are no longer entered into the database. The store committed to updating its procedures and training staff on the new process.

Key Issues
  • Whether collecting and recording driver's license details was necessary for the DVD-rental store's operations
  • Whether the store's collection practices aligned with the principle of limiting collection to necessary information