BreachOfPrivacy

Canadian Privacy Decisions

The comprehensive archive of Canadian privacy decisions from federal, provincial, and territorial commissioners — with AI-summarized plain-language summaries for every decision.

2 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Mar 28, 2024PIPEDA Findings #2024-002· Indexed Apr 12, 2026

PIPEDA Findings #2024-002: Investigation into Brinks Home

Brinks Home

The OPC investigated a complaint that Brinks Home failed to implement adequate safeguards, leading to the compromise of customer personal information via its online portal. While the OPC found Brinks Home had failed to adequately protect customer information, the issue was resolved through corrective actions and the subsequent sale of customer accounts. The OPC also determined that Brinks Home was not required to report the breach to the OPC or notify affected individuals because it did not present a real risk of significant harm.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2024-002: Investigation into Brinks Home

Mar 28, 2024PIPEDA Findings #2024-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint that Brinks Home failed to implement adequate safeguards, leading to the compromise of customer personal information via its online portal. While the OPC found Brinks Home had failed to adequately protect customer information, the issue was resolved through corrective actions and the subsequent sale of customer accounts. The OPC also determined that Brinks Home was not required to report the breach to the OPC or notify affected individuals because it did not present a real risk of significant harm.

Key Issues
  • Adequacy of safeguards for personal information
  • Compliance with mandatory breach reporting requirements
  • Assessment of real risk of significant harm (RROSH)
  • Employee error leading to unauthorized access
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Feb 29, 2024PIPEDA Findings #2024-001· Indexed Apr 12, 2026

PIPEDA Findings #2024-001: Investigation into Aylo (formerly MindGeek)’s Compliance with PIPEDA

Aylo (formerly MindGeek)

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Aylo (formerly MindGeek) concerning its handling of user-uploaded intimate content. The OPC found that MindGeek failed to obtain valid consent for the collection, use, and disclosure of personal information, particularly highly sensitive intimate images. The OPC also determined that MindGeek did not provide an accessible or effective process for individuals to remove their non-consensual content from its websites. Furthermore, the investigation concluded that MindGeek lacked accountability for the personal information under its control. The complaint was found to be well-founded and remains unresolved.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2024-001: Investigation into Aylo (formerly MindGeek)’s Compliance with PIPEDA

Feb 29, 2024PIPEDA Findings #2024-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Aylo (formerly MindGeek) concerning its handling of user-uploaded intimate content. The OPC found that MindGeek failed to obtain valid consent for the collection, use, and disclosure of personal information, particularly highly sensitive intimate images. The OPC also determined that MindGeek did not provide an accessible or effective process for individuals to remove their non-consensual content from its websites. Furthermore, the investigation concluded that MindGeek lacked accountability for the personal information under its control. The complaint was found to be well-founded and remains unresolved.

Key Issues
  • Validity of consent for collecting and using intimate images
  • Effectiveness and accessibility of content takedown processes
  • Accountability for personal information under control
  • Jurisdiction over international operations