The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

5 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 14, 2020PIPEDA Findings #2020-005Indexed Jun 30, 2026

PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019

Desjardins

The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019

Dec 14, 2020PIPEDA Findings #2020-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.

Key Issues
  • Whether personal information held by Desjardins was protected throughout its life cycle by security safeguards appropriate to the sensitivity of the information as required by PIPEDA Safeguards Principle 4.7.
  • Whether Desjardins fulfilled its responsibilities to implement procedures to protect personal information and train its staff, as set out in Accountability Principle 4.1.
  • Whether the personal information of individuals was handled in accordance with the retention and destruction requirements as set out in PIPEDA Principle 4.5, limiting use, disclosure and retention.
  • Whether the mitigation measures offered by Desjardins to affected individuals were adequate to protect their personal information from unauthorized use, such as future identity theft, in accordance with PIPEDA Safeguards Principle 4.7.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 28, 2020PIPEDA Findings #2020-004Indexed Jun 30, 2026

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

The Cadillac Fairview Corporation Limited

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

Oct 28, 2020PIPEDA Findings #2020-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Key Issues
  • Whether CFCL’s use of Anonymous Video Analytics (AVA) technology, via in-mall directories, resulted in the collection, use, and/or disclosure of personal information.
  • Whether images of individual faces captured by AVA technology constitute personal information.
  • Whether numerical representations of faces (biometric information) generated by AVA technology constitute personal information.
  • Whether age range and gender assessments, combined with other data, constitute personal information.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via AVA technology.
  • Whether CFCL retained personal information collected via AVA technology longer than necessary.
  • Whether CFCL’s use of mobile device geolocation technologies (Anonymous Shopper Journey) resulted in the collection, use, and/or disclosure of personal information.
  • Whether hashed and randomized MAC addresses, combined with non-granular zone geolocation, constitute personal information in the context of anonymous shopper tracking.
  • Whether CFCL’s use of mobile device geolocation technologies (Logged In Shopper Journey) resulted in the collection, use, and/or disclosure of personal information linked to identifiable individuals.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via mobile device geolocation technologies (Logged In Shopper Journey).
  • Whether CFCL's privacy policy and signage provided sufficient notice and obtained valid consent for its data collection practices.
  • Whether the "serious possibility" threshold for identifying individuals was met for anonymous shopper journey data.
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Aug 4, 2020PIPEDA Findings #2020-001Indexed Jun 30, 2026

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

TD Canada Trust

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

Aug 4, 2020PIPEDA Findings #2020-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Key Issues
  • Whether TD was required to obtain additional consent for transferring personal information to a third-party service provider in India for fraud claims processing (Principle 4.3 PIPEDA)
  • Whether TD was required to offer customers an opt-out for the transfer of personal information to a third-party service provider in India for fraud claims processing
  • Whether TD was sufficiently open about its practice of transferring personal information to a third-party service provider in a foreign jurisdiction for processing (Principle 4.8 PIPEDA)
  • Whether TD ensured a comparable level of protection for personal information processed by the third-party service provider in India (Principle 4.1.3 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 9, 2020PIPEDA Findings #2020-003Indexed Jun 30, 2026

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Dell Inc.

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Jul 9, 2020PIPEDA Findings #2020-003
Adjudicator: Daniel Therrien
Plain-Language Summary

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Key Issues
  • Whether Dell adequately safeguarded personal information under its control while using a service provider (PIPEDA Principle 4.1.3 and 4.7).
  • Whether the personal information transferred to the service provider was sensitive enough to require a high degree of protection.
  • Whether Dell's access controls were sufficient to protect customer information.
  • Whether Dell's logging and monitoring practices were adequate to detect anomalous employee requests for customer information.
  • Whether Dell's technical measures, such as USB drive restrictions, were sufficient.
  • Whether Dell adequately investigated the circumstances and scope of the June 2017 breach.
  • Whether Dell adequately responded to customer complaints about potential privacy breaches (PIPEDA Principle 4.10.4).
  • Whether Dell remained responsible for personal information transferred to a third party for processing.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 30, 2020PIPEDA Findings #2020-002Indexed Jun 30, 2026

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

RateMDs.com

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

Jun 30, 2020PIPEDA Findings #2020-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Key Issues
  • Whether RateMDs collected, used, or disclosed the complainant's business contact information without consent (Principle 4.3)
  • Whether the business contact information exemption under s.4.01 of PIPEDA applied to RateMDs' use of the complainant's business contact information
  • Whether the complainant's business contact information was publicly available under s.7(1)(d), 7(2)(c.1), and 7(3)(h.1) of PIPEDA and its Regulations
  • Whether the reviews and ratings posted on RateMDs constituted the complainant's personal information
  • Whether the reviews and ratings also constituted the personal information of the users who posted them
  • Whether RateMDs required the complainant's consent to publish the reviews and ratings about her (Principle 4.3)
  • Whether a balancing of interests was required when the privacy rights of multiple individuals conflicted regarding the same personal information
  • Whether RateMDs ensured the accuracy of information and provided a fair and accessible process for health professionals to challenge and correct inaccurate information (Principle 4.6, 4.9.5)
  • Whether RateMDs made readily available specific information about its policies and practices relating to the management of personal information, particularly regarding review removal and correction (Principle 4.8)
  • Whether RateMDs' "pay-for-takedown" service, allowing subscribers to hide negative reviews for a fee, constituted an appropriate purpose for collecting, using, or disclosing personal information under s.5(3) of PIPEDA