The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

9 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-009Indexed Jun 30, 2026

PIPEDA Findings #2021-009: Opt-in consent required for a donor list trading program

A charitable organization

A complainant alleged that a charitable organization (the Respondent) failed to obtain proper consent before sharing his personal information through a donor list trading program. The Respondent used an opt-out checkbox on its mail-in donation forms, which the complainant found inadequate after receiving solicitations from another charity. The OPC determined that sharing donor information with other charities for solicitation purposes was outside the reasonable expectations of donors, thus requiring express opt-in consent. Furthermore, the information provided by the Respondent on its donation forms, inserts, and privacy policy was deemed insufficient to enable meaningful consent. The OPC recommended that the Respondent obtain express opt-in consent and enhance its privacy communications to clearly explain the nature, purpose, and consequences of the data sharing. The Respondent agreed to implement these recommendations, leading to a conditionally resolved outcome.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-009: Opt-in consent required for a donor list trading program

Mar 30, 2021PIPEDA Findings #2021-009
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a charitable organization (the Respondent) failed to obtain proper consent before sharing his personal information through a donor list trading program. The Respondent used an opt-out checkbox on its mail-in donation forms, which the complainant found inadequate after receiving solicitations from another charity. The OPC determined that sharing donor information with other charities for solicitation purposes was outside the reasonable expectations of donors, thus requiring express opt-in consent. Furthermore, the information provided by the Respondent on its donation forms, inserts, and privacy policy was deemed insufficient to enable meaningful consent. The OPC recommended that the Respondent obtain express opt-in consent and enhance its privacy communications to clearly explain the nature, purpose, and consequences of the data sharing. The Respondent agreed to implement these recommendations, leading to a conditionally resolved outcome.

Key Issues
  • Whether the Respondent obtained meaningful consent for its donor list trading program under PIPEDA
  • Whether opt-out consent was appropriate for sharing donor information with third parties
  • Whether the information shared (donor name, address, donation status) was sensitive in this context
  • Whether sharing donor information with other charities for solicitation was within the reasonable expectations of donors
  • Whether the donor list trading program created a meaningful residual risk of significant harm
  • Whether the information provided to donors on the donation form, insert, and privacy policy was sufficient to support meaningful consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-004Indexed Jun 30, 2026

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Fido Solutions Inc. (a subsidiary of Rogers Communications Inc.)

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Mar 30, 2021PIPEDA Findings #2021-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Key Issues
  • Whether Fido adequately safeguarded the Complainant’s personal information under Principle 4.7
  • Whether Fido responded to the Complainant’s access request in a generally understandable format under Principle 4.9 and 4.9.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-003Indexed Jun 30, 2026

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Bank of Montreal

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Mar 30, 2021PIPEDA Findings #2021-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether BMO implemented appropriate security safeguards to adequately protect personal information under its control, as required by PIPEDA Principle 4.7
  • Adequacy of BMO's developer security testing and evaluation processes
  • Adequacy of BMO's vulnerability management program, including identification, assessment, and remediation of vulnerabilities
  • Adequacy of BMO's oversight and monitoring capabilities, specifically regarding bot management, cyberattack detection, and real-time alerts
  • Adequacy of BMO's organizational policies and procedures for handling cyberattacks and incident response
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 29, 2021PIPEDA Findings #2021-002Indexed Jun 30, 2026

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

CoreFour Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

Mar 29, 2021PIPEDA Findings #2021-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Key Issues
  • Whether CoreFour's security safeguards were appropriate to the sensitivity and volume of personal information under Principle 4.7 PIPEDA
  • Whether CoreFour's weak password requirements for certain Edsby parental accounts constituted an inadequate safeguard
  • Whether CoreFour's safeguards to protect against unauthorized access to thumbnail images of student profile pictures were adequate
  • Whether Edsby's failure to scan for malware when uploading content from third-party applications constituted a safeguard weakness
  • Whether CoreFour lacked a robust overarching information security framework, contravening Principle 4.1.4 and 4.7-4.7.3 PIPEDA
  • Whether CoreFour had an adequate mechanism for handling and reporting privacy breaches under PIPEDA
  • Whether CoreFour was required to report the password management vulnerability, given it occurred before mandatory breach reporting came into effect
  • Whether the student image vulnerability created a "real risk of significant harm" requiring mandatory reporting and notification under s.10.1 PIPEDA
  • Whether CoreFour maintained a breach register as required under s.10.3 PIPEDA
  • Whether CoreFour lacked a privacy management framework, including appropriate written internal policies and practices (e.g., complaint handling, data retention), contravening Principle 4.1.4 PIPEDA
  • Whether CoreFour provided adequate privacy training to its employees, consultants, contractors, and students
  • Whether CoreFour's Privacy Policy was unclear regarding the characterization of personal information, its responsibility for security, and the sharing of user information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 24, 2021PIPEDA Findings #2021-007Indexed Jun 30, 2026

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

A computer services company

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

Mar 24, 2021PIPEDA Findings #2021-007
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Key Issues
  • Whether the respondent obtained meaningful consent prior to remotely accessing laptops
  • Whether the respondent had adequate safeguards to prevent unauthorized access to customers’ personal information by its personnel
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 22, 2021PIPEDA Findings #2021-008Indexed Jun 30, 2026

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Oculus Transport Ltd.

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Mar 22, 2021PIPEDA Findings #2021-008
Adjudicator: Daniel Therrien
Plain-Language Summary

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Key Issues
  • Whether the collection and use of personal information via audio surveillance technology was for purposes that a reasonable person would consider appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the personal information collected was sensitive
  • Whether the organization's purpose represented a legitimate need / bona fide business interest
  • Whether the collection, use and disclosure would be effective in meeting the organization’s need
  • Whether there are less privacy invasive means of achieving the same ends at comparable cost and with comparable benefits
  • Whether the loss of privacy is proportional to the benefits
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 15, 2021PIPEDA Findings #2021-005Indexed Jun 30, 2026

PIPEDA Findings #2021-005: Staying signed in by default to email services poses serious privacy concerns for users accessing their email on a public or shared computer

Yahoo! Canada

The complainant alleged that Yahoo! Canada's default "Stay signed in" setting for Yahoo Mail, particularly for Rogers Yahoo Mail users, posed significant privacy concerns on public or shared computers. The OPC investigated whether Yahoo adequately safeguarded against unauthorized access and obtained valid consent for potential disclosures. The OPC found that Yahoo's safeguards were not appropriate for the sensitivity of email content and that its consent for the "Stay signed in" setting was not meaningful. Yahoo committed to changing the setting to opt-in and providing clearer information about privacy implications. Rogers, while not a respondent, also agreed to implement measures for Rogers Yahoo Mail users. The complaint was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-005: Staying signed in by default to email services poses serious privacy concerns for users accessing their email on a public or shared computer

Mar 15, 2021PIPEDA Findings #2021-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Yahoo! Canada's default "Stay signed in" setting for Yahoo Mail, particularly for Rogers Yahoo Mail users, posed significant privacy concerns on public or shared computers. The OPC investigated whether Yahoo adequately safeguarded against unauthorized access and obtained valid consent for potential disclosures. The OPC found that Yahoo's safeguards were not appropriate for the sensitivity of email content and that its consent for the "Stay signed in" setting was not meaningful. Yahoo committed to changing the setting to opt-in and providing clearer information about privacy implications. Rogers, while not a respondent, also agreed to implement measures for Rogers Yahoo Mail users. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether Yahoo's safeguards against unauthorized third-party access to email content on public or shared computers were adequate under Principle 4.7 PIPEDA
  • Whether Yahoo obtained valid and meaningful consent for the disclosure of personal information to others who subsequently access emails via the "Stay signed in" setting under Principle 4.3 PIPEDA
  • Whether the "Stay signed in" setting was clearly and prominently displayed
  • Whether a reasonable person would understand the "Stay signed in" setting to be "on" by default
  • Whether the "Stay signed in" setting is consistent with industry standards
  • Whether Yahoo's additional safeguards (algorithm, sign-out option, session expiration, password reset, security information) were effective
  • Whether express opt-in consent was required for the "Stay signed in" setting due to sensitivity of information, reasonable expectations, and risk of harm
  • Whether the language "stay signed in" provided users with key information for meaningful consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Mar 12, 2021PIPEDA Findings #2021-006Indexed Jun 30, 2026

PIPEDA Findings #2021-006: A short-term lender collects online banking credentials in the course of payday loan applications

CashHere (2124478 Ontario Corporation)

The OPC initiated an investigation into CashHere, a short-term lender, after being alerted by the Ontario Ministry of Government and Consumer Services that it was collecting online banking credentials (passwords, usernames, security questions/answers) from loan applicants. The OPC found that while CashHere had a legitimate need to validate identity and income, collecting banking credentials was not an appropriate purpose under PIPEDA s. 5(3) due to less privacy-invasive alternatives and disproportionate privacy risks. The investigation also noted that a related entity, MoneyHome, appeared to be continuing the same practices. CashHere ceased responding to the OPC, and the matter was found to be well-founded and unresolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2021-006: A short-term lender collects online banking credentials in the course of payday loan applications

Mar 12, 2021PIPEDA Findings #2021-006
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated an investigation into CashHere, a short-term lender, after being alerted by the Ontario Ministry of Government and Consumer Services that it was collecting online banking credentials (passwords, usernames, security questions/answers) from loan applicants. The OPC found that while CashHere had a legitimate need to validate identity and income, collecting banking credentials was not an appropriate purpose under PIPEDA s. 5(3) due to less privacy-invasive alternatives and disproportionate privacy risks. The investigation also noted that a related entity, MoneyHome, appeared to be continuing the same practices. CashHere ceased responding to the OPC, and the matter was found to be well-founded and unresolved.

Key Issues
  • Whether CashHere's collection of online banking login credentials was for a purpose that a reasonable person would consider appropriate under s. 5(3) of PIPEDA
  • Whether the collection of banking credentials was effective in meeting CashHere's legitimate need
  • Whether there were less privacy-invasive means of achieving the same ends
  • Whether the loss of privacy was proportional to the benefits for CashHere
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Feb 2, 2021PIPEDA Findings #2021-001Indexed Jun 30, 2026

PIPEDA Findings #2021-001: Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta

Clearview AI, Inc.

A joint investigation by Canadian privacy commissioners examined Clearview AI's facial recognition tool, which scraped billions of images from public websites to create a database for law enforcement and other users. Clearview argued that Canadian privacy laws did not apply due to a lack of jurisdiction and that the information was "publicly available," thus exempt from consent requirements. The Offices asserted jurisdiction, finding a real and substantial connection to Canada through Clearview's marketing and use by Canadian entities. They determined Clearview failed to obtain requisite consent, as the "publicly available" exception did not apply to sensitive biometric data scraped from social media for unrelated purposes. Furthermore, Clearview's mass collection and use of sensitive facial biometric information for commercial purposes were deemed inappropriate. In Quebec, Clearview also failed to report its biometric database and obtain express consent as required by law. The matter was found to be well-founded, with recommendations for Clearview to cease operations in Canada and delete Canadian data, which Clearview did not commit to implementing.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2021-001: Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta

Feb 2, 2021PIPEDA Findings #2021-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A joint investigation by Canadian privacy commissioners examined Clearview AI's facial recognition tool, which scraped billions of images from public websites to create a database for law enforcement and other users. Clearview argued that Canadian privacy laws did not apply due to a lack of jurisdiction and that the information was "publicly available," thus exempt from consent requirements. The Offices asserted jurisdiction, finding a real and substantial connection to Canada through Clearview's marketing and use by Canadian entities. They determined Clearview failed to obtain requisite consent, as the "publicly available" exception did not apply to sensitive biometric data scraped from social media for unrelated purposes. Furthermore, Clearview's mass collection and use of sensitive facial biometric information for commercial purposes were deemed inappropriate. In Quebec, Clearview also failed to report its biometric database and obtain express consent as required by law. The matter was found to be well-founded, with recommendations for Clearview to cease operations in Canada and delete Canadian data, which Clearview did not commit to implementing.

Key Issues
  • Whether the Canadian privacy commissioners had jurisdiction over Clearview AI's activities.
  • Whether Clearview AI obtained requisite consent for its collection, use, and disclosure of personal information under PIPEDA, PIPA AB, PIPA BC, and Quebec's Private Sector Act.
  • Whether the "publicly available" information exception applied to Clearview AI's collection of images from public websites.
  • Whether Clearview AI's collection, use, and disclosure of personal information was for an appropriate purpose under PIPEDA, PIPA AB, PIPA BC, and Quebec's Private Sector Act.
  • Whether Clearview AI satisfied its biometric obligations in Quebec, specifically regarding reporting the creation of a biometric database and obtaining express consent under the LCCJTI.
  • Whether Clearview AI's activities were protected by freedom of expression under the Canadian Charter of Rights and Freedoms.