The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

7 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014Indexed Jun 30, 2026

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

An online dating service

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Key Issues
  • Whether the organization denied the complainant access to his personal information in violation of Principle 4.9
  • Whether the organization failed to respect the 30-day time limit for access requests under subsection 8(3)
  • Whether the organization contravened subsection 8(8) by destroying photographs, limiting the complainant's recourse
  • Whether the organization retained the complainant's information longer than necessary in contravention of Principle 4.5.3
  • Whether the organization continued to use the complainant's personal information for marketing after consent withdrawal, contravening Principle 4.3.8
  • Whether the organization lacked a privacy policy in contravention of Principle 4.1.4(d)
  • Whether the organization failed to safeguard the complainant's personal information as required by Principle 4.7.1
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 2, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-005Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-005: Beneficiary’s access to estate information is limited to his own personal information under PIPEDA

A legal firm

An individual, claiming to be a beneficiary of two estates, sought access under PIPEDA to estate information from a legal firm that had acted as an agent for another firm administering the estates. The complainant requested information pertaining to himself as a beneficiary and general beneficiary entitlements. The legal firm initially failed to respond to the access requests, leading to a complaint with the OPC. The firm later responded, stating it held no personal information about the complainant and that neither he nor the estates were clients. The OPC found that the firm contravened PIPEDA by not responding within the 30-day time limit. However, the OPC also determined that the complainant was only entitled to access information specifically about himself, not general estate information, and was satisfied that the firm had conducted a reasonable search for his personal information. The complaint was deemed well-founded and resolved due to the firm's initial failure to respond.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-005: Beneficiary’s access to estate information is limited to his own personal information under PIPEDA

Oct 2, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-005
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual, claiming to be a beneficiary of two estates, sought access under PIPEDA to estate information from a legal firm that had acted as an agent for another firm administering the estates. The complainant requested information pertaining to himself as a beneficiary and general beneficiary entitlements. The legal firm initially failed to respond to the access requests, leading to a complaint with the OPC. The firm later responded, stating it held no personal information about the complainant and that neither he nor the estates were clients. The OPC found that the firm contravened PIPEDA by not responding within the 30-day time limit. However, the OPC also determined that the complainant was only entitled to access information specifically about himself, not general estate information, and was satisfied that the firm had conducted a reasonable search for his personal information. The complaint was deemed well-founded and resolved due to the firm's initial failure to respond.

Key Issues
  • Whether a legal firm must respond to an access request within 30 days, even if it holds no personal information about the requester
  • Whether a beneficiary of an estate is entitled under PIPEDA to access general estate information
  • Whether the requested information (e.g., statements of accounts, money received, disbursements) constitutes the complainant's personal information under PIPEDA
  • Whether the legal firm conducted a reasonable search for the complainant's personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActDeclined to investigate
Federal (Canada) flag
Sep 11, 2013Declined to Investigate Case Summary #2013-001Indexed Jun 30, 2026

Declined to Investigate Case Summary #2013-001: Court procedures provided a more appropriate means to address access issues in ongoing litigation between complainant and retailer

A retailer

An individual filed a complaint against a retailer, alleging that the retailer withheld access to her personal information, contravening subsection 8(3) and Principle 4.9 of PIPEDA. The complainant and retailer were involved in ongoing small claims court litigation, and the complainant stated the information was necessary for her case. The retailer refused access, citing litigation privilege and prior disclosure. The OPC declined to investigate the complaint, finding that the court's procedures provided a more appropriate means for the complainant to address the access issues. This decision was based on avoiding conflict with provincial court rules and ensuring judicious use of public resources.

Quick view

Personal Information Protection and Electronic Documents ActDeclined to investigate

Declined to Investigate Case Summary #2013-001: Court procedures provided a more appropriate means to address access issues in ongoing litigation between complainant and retailer

Sep 11, 2013Declined to Investigate Case Summary #2013-001
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual filed a complaint against a retailer, alleging that the retailer withheld access to her personal information, contravening subsection 8(3) and Principle 4.9 of PIPEDA. The complainant and retailer were involved in ongoing small claims court litigation, and the complainant stated the information was necessary for her case. The retailer refused access, citing litigation privilege and prior disclosure. The OPC declined to investigate the complaint, finding that the court's procedures provided a more appropriate means for the complainant to address the access issues. This decision was based on avoiding conflict with provincial court rules and ensuring judicious use of public resources.

Key Issues
  • Whether the complaint could more appropriately be dealt with by means of a procedure provided for under the laws of a province under paragraph 12(1)(b) of PIPEDA
  • Whether the retailer withheld access to personal information in contravention of subsection 8(3) of PIPEDA
  • Whether the retailer withheld access to personal information in contravention of Principle 4.9 of Schedule 1 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 11, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-003Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-003: Profiles on PositiveSingles.com dating website turn up on other affiliated dating websites

SuccessfulMatch Inc. (operating PositiveSingles.com)

Three individuals complained that their dating profiles, containing sensitive medical information, posted on PositiveSingles.com appeared on numerous other affiliated dating websites without their knowledge or consent. The complainants were assured of privacy but found their profiles on sites targeting different demographics, causing distress. The OPC's investigation found that PositiveSingles.com, operated by SuccessfulMatch Inc., used a single database across a network of affiliated sites, making profiles automatically available. The OPC concluded that the organization failed to obtain meaningful consent for this use, lacked openness about its network structure, and had inadequate safeguards, as some personal information was accessible via search engines. Following the OPC's recommendations, SuccessfulMatch revamped its website to provide explicit information about the network, ensure informed consent at registration, and improve safeguards. The complaint was found well-founded and resolved due to these corrective measures.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-003: Profiles on PositiveSingles.com dating website turn up on other affiliated dating websites

Jul 11, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-003
Adjudicator: Jennifer Stoddart
Plain-Language Summary

Three individuals complained that their dating profiles, containing sensitive medical information, posted on PositiveSingles.com appeared on numerous other affiliated dating websites without their knowledge or consent. The complainants were assured of privacy but found their profiles on sites targeting different demographics, causing distress. The OPC's investigation found that PositiveSingles.com, operated by SuccessfulMatch Inc., used a single database across a network of affiliated sites, making profiles automatically available. The OPC concluded that the organization failed to obtain meaningful consent for this use, lacked openness about its network structure, and had inadequate safeguards, as some personal information was accessible via search engines. Following the OPC's recommendations, SuccessfulMatch revamped its website to provide explicit information about the network, ensure informed consent at registration, and improve safeguards. The complaint was found well-founded and resolved due to these corrective measures.

Key Issues
  • Whether PositiveSingles.com obtained meaningful consent for the use of personal information across its network of affiliated sites (Principle 4.3, 4.3.2, 4.3.5 PIPEDA)
  • Whether PositiveSingles.com was sufficiently open about its personal information management policies and practices, particularly regarding its network structure (Principle 4.8, 4.8.1 PIPEDA)
  • Whether PositiveSingles.com implemented adequate security safeguards to protect sensitive personal information from unauthorized access (Principle 4.7, 4.7.1 PIPEDA)
  • Whether PositiveSingles.com's use of cookies, potentially for online behavioral advertising, required express consent given the sensitive nature of the information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 28, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-017Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-017: Apple called upon to provide greater clarity on its use and disclosure of unique device identifiers for targeted advertising

Apple

An individual complained that Apple was using and sharing her unique device identifier (UDID) without her knowledge and consent for tracking and targeted advertising. The OPC determined that UDIDs, and later Advertising IDs (Ad IDs), constituted personal information because Apple could link them to identifiable individuals. While Apple's use of UDIDs for administrative purposes was deemed to have implied consent, the OPC initially found Apple's explanations for using and disclosing UDIDs for targeted advertising to be insufficient for meaningful consent. During the investigation, Apple phased out the use of UDIDs for advertising, introduced the resettable Ad ID, and improved its privacy policy explanations and opt-out mechanisms. Consequently, the OPC found that Apple's updated practices provided sufficient information for meaningful consent regarding the use and disclosure of Ad IDs for advertising. The complaint was found to be well-founded but resolved due to Apple's corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-017: Apple called upon to provide greater clarity on its use and disclosure of unique device identifiers for targeted advertising

Jun 28, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-017
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Apple was using and sharing her unique device identifier (UDID) without her knowledge and consent for tracking and targeted advertising. The OPC determined that UDIDs, and later Advertising IDs (Ad IDs), constituted personal information because Apple could link them to identifiable individuals. While Apple's use of UDIDs for administrative purposes was deemed to have implied consent, the OPC initially found Apple's explanations for using and disclosing UDIDs for targeted advertising to be insufficient for meaningful consent. During the investigation, Apple phased out the use of UDIDs for advertising, introduced the resettable Ad ID, and improved its privacy policy explanations and opt-out mechanisms. Consequently, the OPC found that Apple's updated practices provided sufficient information for meaningful consent regarding the use and disclosure of Ad IDs for advertising. The complaint was found to be well-founded but resolved due to Apple's corrective actions.

Key Issues
  • Whether Unique Device Identifiers (UDID) constitute personal information under PIPEDA.
  • Whether Advertising Identifiers (Ad ID) constitute personal information under PIPEDA.
  • Whether Apple obtained meaningful consent for its use of UDID for administration and maintenance purposes (Principle 4.3 PIPEDA).
  • Whether Apple obtained meaningful consent for its use of UDID and Ad ID for targeted advertising purposes (Principle 4.3 PIPEDA).
  • Whether Apple obtained meaningful consent for its disclosure of UDID and Ad ID to third-party app developers (Principle 4.3 PIPEDA).
  • Whether Apple's explanations regarding the use and disclosure of UDID and Ad ID were sufficiently clear and understandable to ensure meaningful consent (Principle 4.3.2 PIPEDA).
  • Whether the sensitivity of UDID and Ad ID in the context of user profiling and online behavioural advertising required express consent (Principle 4.3.6 PIPEDA).
  • Whether the reasonable expectations of the individual were met regarding the use and disclosure of UDID and Ad ID (Principle 4.3.5 PIPEDA).
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 25, 2013Early resolved case summary #2013-01Indexed Jun 30, 2026

Early resolved case summary #2013-01: Property management company alters its rental application form to make clear that Social Insurance Number is optional

A property management company

An individual complained that a property management company was over-collecting personal information on rental application forms, specifically requesting Social Insurance Numbers (SINs), driver's licence information, and banking details as a condition of application. The complainant also noted the absence of a privacy policy on the company's website. The OPC contacted the company, which stated its website was under construction and would include a privacy policy. The company used third-party generated forms and believed SINs were necessary for credit checks, a point the OPC disputed. The OPC suggested marking SIN requests as 'optional' and advised against collecting unique driver's licence numbers. The company committed to updating its forms and website, satisfying the complainant. The OPC later confirmed these changes were implemented.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Early resolved case summary #2013-01: Property management company alters its rental application form to make clear that Social Insurance Number is optional

Apr 25, 2013Early resolved case summary #2013-01
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a property management company was over-collecting personal information on rental application forms, specifically requesting Social Insurance Numbers (SINs), driver's licence information, and banking details as a condition of application. The complainant also noted the absence of a privacy policy on the company's website. The OPC contacted the company, which stated its website was under construction and would include a privacy policy. The company used third-party generated forms and believed SINs were necessary for credit checks, a point the OPC disputed. The OPC suggested marking SIN requests as 'optional' and advised against collecting unique driver's licence numbers. The company committed to updating its forms and website, satisfying the complainant. The OPC later confirmed these changes were implemented.

Key Issues
  • Whether the collection of Social Insurance Numbers (SINs) was appropriate
  • Whether the collection of driver's licence numbers was appropriate
  • Whether the collection of banking information was appropriate
  • Whether the organization made its privacy policy readily available as required by PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 15, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-002Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-002: Bank misinformed client of purpose of requesting personal information for picking up credit card

A Canadian bank

A bank customer complained after being asked to provide his driver's license to pick up a replacement credit card, despite having other identification on file and being known to staff. The bank initially cited anti-money laundering regulations (PCMLTFA) but later admitted this rationale was incorrect. The OPC investigated two issues: whether the bank improperly demanded to record information (collection) and whether it could explain the purpose of collection. Since the customer refused to provide his driver's license, no actual collection occurred, so that aspect of the complaint was not well-founded. However, the bank's inaccurate explanation for requesting the information contravened Principle 4.2.5. The bank revised its procedures and circulated new guidelines to staff, leading to a well-founded and resolved outcome for the latter issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-002: Bank misinformed client of purpose of requesting personal information for picking up credit card

Apr 15, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-002
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A bank customer complained after being asked to provide his driver's license to pick up a replacement credit card, despite having other identification on file and being known to staff. The bank initially cited anti-money laundering regulations (PCMLTFA) but later admitted this rationale was incorrect. The OPC investigated two issues: whether the bank improperly demanded to record information (collection) and whether it could explain the purpose of collection. Since the customer refused to provide his driver's license, no actual collection occurred, so that aspect of the complaint was not well-founded. However, the bank's inaccurate explanation for requesting the information contravened Principle 4.2.5. The bank revised its procedures and circulated new guidelines to staff, leading to a well-founded and resolved outcome for the latter issue.

Key Issues
  • Whether the bank limited its collection of personal information to that which was necessary for the purposes identified by the organization (Principle 4.4 PIPEDA)
  • Whether the bank ensured its employees were able to explain the purposes for which personal information was being collected (Principle 4.2.5 PIPEDA)