The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

5 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 1, 2025PIPEDA Findings #2025-004Indexed Jun 30, 2026

PIPEDA Findings #2025-004: Investigation into the privacy practices of Staples Canada ULC related to electronic devices to be resold as part of its Openbox program

Staples Canada ULC

A former employee complained that Staples Canada ULC (Staples) failed to adequately protect and remove personal information from returned laptops before reselling them through its Openbox program. The complainant alleged that Staples lacked adequate internal policies, processes, and training for staff to wipe data from these devices. The OPC's investigation found deficiencies in Staples' policies, procedures, and training, and that employees did not consistently follow manufacturer guidelines for data wiping, leading to residual personal information on 23% of sampled devices. Staples agreed to implement recommendations to improve its data wiping procedures, training, and to arrange for independent third-party spot checks. The OPC concluded that Staples contravened PIPEDA Principles 4.7.1 and 4.7.3.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2025-004: Investigation into the privacy practices of Staples Canada ULC related to electronic devices to be resold as part of its Openbox program

Dec 1, 2025PIPEDA Findings #2025-004
Adjudicator: Philippe Dufresne
Plain-Language Summary

A former employee complained that Staples Canada ULC (Staples) failed to adequately protect and remove personal information from returned laptops before reselling them through its Openbox program. The complainant alleged that Staples lacked adequate internal policies, processes, and training for staff to wipe data from these devices. The OPC's investigation found deficiencies in Staples' policies, procedures, and training, and that employees did not consistently follow manufacturer guidelines for data wiping, leading to residual personal information on 23% of sampled devices. Staples agreed to implement recommendations to improve its data wiping procedures, training, and to arrange for independent third-party spot checks. The OPC concluded that Staples contravened PIPEDA Principles 4.7.1 and 4.7.3.

Key Issues
  • Whether Staples had adequate security safeguards to protect personal information on returned laptops under Principle 4.7.1 PIPEDA
  • Whether Staples' methods of protection included adequate physical, organizational, and technological measures under Principle 4.7.3 PIPEDA
  • Whether Staples' internal policies and procedures for data wiping were clear and consistent
  • Whether Staples provided adequate training to employees responsible for wiping data from returned devices
  • Whether Staples consistently performed full data wipes according to manufacturer instructions on returned laptops
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Nov 25, 2025PIPEDA Findings #2025-005Indexed Jun 30, 2026

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

A privately owned swimming pool

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-005: Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act

Nov 25, 2025PIPEDA Findings #2025-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that a private swimming pool required parents to consent to the use of their children's photos and videos for promotional purposes as a condition of service for swimming lessons. The complainant argued this violated PIPEDA's consent requirements, specifically Principle 4.3.3, which prohibits requiring consent for information beyond what is necessary for the service. The swimming pool contended that the photo policy was a reasonable business need for promotion and staff training, and that tracking individual consent would be burdensome. The OPC found that images of children in swim attire are sensitive personal information and that requiring consent for promotional photos and staff training videos was not strictly necessary for providing swimming lessons. The OPC concluded that this practice contravened PIPEDA Principles 4.3.3 and 4.3.6. The complaint was found to be well-founded and resolved after the swimming pool agreed to implement an opt-in photo policy.

Key Issues
  • Whether requiring consent for promotional photos and videos of children as a condition of service for swimming lessons contravenes Principle 4.3.3 of PIPEDA
  • Whether images of children in swim attire constitute sensitive personal information
  • Whether the collection, use, or disclosure of images for promotional or staff training purposes is strictly necessary for the provision of swimming lessons
  • Whether the organization offered individuals a choice regarding the collection, use, or disclosure of images for promotional or staff training purposes
  • Whether the organization should have sought express consent for the collection, use, or disclosure of images of children
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Sep 23, 2025PIPEDA Findings #2025-003Indexed Jun 30, 2026

PIPEDA Findings #2025-003: Joint investigation of TikTok Pte. Ltd. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, and the Office of the Information and Privacy Commissioner of Alberta

TikTok Pte. Ltd.

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and provincial privacy regulators (CAI, OIPC BC, OIPC AB) examined TikTok Pte. Ltd.'s compliance with federal and provincial private sector privacy laws. The investigation focused on TikTok's collection, use, and disclosure of personal information for ad targeting and content personalization, with a particular emphasis on practices affecting children. The Offices found that TikTok's age assurance measures were inadequate, leading to the collection and use of sensitive personal information from a large number of underage users for purposes deemed inappropriate. Furthermore, TikTok failed to obtain valid and meaningful consent from both adult and youth users due to unclear, inaccessible, and incomplete privacy communications, including regarding biometric information and cross-border data transfers. The CAI specifically identified contraventions related to Quebec's transparency and privacy-by-default obligations. While TikTok disagreed with the findings, it committed to implementing enhanced age assurance mechanisms, improving privacy communications, and limiting ad targeting for under-18 users. The Offices concluded the matter as well-founded and conditionally resolved, contingent on TikTok's satisfactory implementation of these significant commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2025-003: Joint investigation of TikTok Pte. Ltd. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, and the Office of the Information and Privacy Commissioner of Alberta

Sep 23, 2025PIPEDA Findings #2025-003
Adjudicator: Philippe Dufresne
Plain-Language Summary

A joint investigation by the Office of the Privacy Commissioner of Canada (OPC) and provincial privacy regulators (CAI, OIPC BC, OIPC AB) examined TikTok Pte. Ltd.'s compliance with federal and provincial private sector privacy laws. The investigation focused on TikTok's collection, use, and disclosure of personal information for ad targeting and content personalization, with a particular emphasis on practices affecting children. The Offices found that TikTok's age assurance measures were inadequate, leading to the collection and use of sensitive personal information from a large number of underage users for purposes deemed inappropriate. Furthermore, TikTok failed to obtain valid and meaningful consent from both adult and youth users due to unclear, inaccessible, and incomplete privacy communications, including regarding biometric information and cross-border data transfers. The CAI specifically identified contraventions related to Quebec's transparency and privacy-by-default obligations. While TikTok disagreed with the findings, it committed to implementing enhanced age assurance mechanisms, improving privacy communications, and limiting ad targeting for under-18 users. The Offices concluded the matter as well-founded and conditionally resolved, contingent on TikTok's satisfactory implementation of these significant commitments.

Key Issues
  • Whether TikTok was collecting, using, and disclosing personal information, particularly with respect to children, for an appropriate, reasonable, and legitimate purpose.
  • Whether TikTok's age assurance mechanisms were effective in preventing underage users from accessing the platform.
  • Whether TikTok obtained valid and meaningful consent from its users for tracking, profiling, targeting, and content personalization.
  • Whether TikTok's privacy communications provided sufficient upfront, clear, and comprehensive information to adult users to ensure meaningful consent.
  • Whether TikTok adequately explained its collection and use of users' biometric information to ensure meaningful consent.
  • Whether TikTok's privacy communications were adequate to obtain meaningful consent from youth (13-17), considering their cognitive development and potential harms from targeted ads.
  • Whether TikTok met its obligations under Quebec's Private Sector Act to inform persons concerned about the collection and use of personal information for user profiles, ad targeting, and content personalization.
  • Whether TikTok ensured that privacy settings provided the highest level of privacy by default under Quebec's Private Sector Act.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 27, 2025PIPEDA Findings #2025-002Indexed Jun 30, 2026

PIPEDA Findings #2025-002: Investigation and recommendations concerning Google search engine service’s compliance with its obligations under PIPEDA

Google LLC

The OPC investigated a complaint against Google regarding its search engine displaying outdated media articles about the Complainant's HIV status and a stayed criminal charge when their name was searched. The Complainant alleged these articles caused significant harm, including physical assault and lost employment, and sought their de-listing from name-based search results. The OPC's jurisdiction over Google's search engine under PIPEDA was affirmed by the Federal Court and Federal Court of Appeal, rejecting Google's claims of non-commercial activity and journalistic exemption. The OPC found Google did not contravene Principle 4.6 (accuracy), as its responsibility was for the search results accurately reflecting linked content, not the content itself. However, the OPC concluded that Google contravened subsection 5(3) (appropriate purposes), determining that the significant harms to the Complainant's safety and dignity outweighed the limited public interest in the articles remaining linked to their name. The OPC recommended Google de-list the articles from searches for the Complainant's name, balancing privacy rights with freedom of expression. Google declined to implement this recommendation, stating it required further court guidance on the "right to de-listing" and Charter implications. Consequently, the complaint was found well-founded and unresolved regarding subsection 5(3), and not well-founded for the accuracy issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2025-002: Investigation and recommendations concerning Google search engine service’s compliance with its obligations under PIPEDA

Aug 27, 2025PIPEDA Findings #2025-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

The OPC investigated a complaint against Google regarding its search engine displaying outdated media articles about the Complainant's HIV status and a stayed criminal charge when their name was searched. The Complainant alleged these articles caused significant harm, including physical assault and lost employment, and sought their de-listing from name-based search results. The OPC's jurisdiction over Google's search engine under PIPEDA was affirmed by the Federal Court and Federal Court of Appeal, rejecting Google's claims of non-commercial activity and journalistic exemption. The OPC found Google did not contravene Principle 4.6 (accuracy), as its responsibility was for the search results accurately reflecting linked content, not the content itself. However, the OPC concluded that Google contravened subsection 5(3) (appropriate purposes), determining that the significant harms to the Complainant's safety and dignity outweighed the limited public interest in the articles remaining linked to their name. The OPC recommended Google de-list the articles from searches for the Complainant's name, balancing privacy rights with freedom of expression. Google declined to implement this recommendation, stating it required further court guidance on the "right to de-listing" and Charter implications. Consequently, the complaint was found well-founded and unresolved regarding subsection 5(3), and not well-founded for the accuracy issue.

Key Issues
  • Whether PIPEDA applies to Google's search engine service as a commercial activity within the meaning of paragraph 4(1)(a) of PIPEDA
  • Whether the operation of Google’s search engine service is excluded from the application of Part 1 of PIPEDA by virtue of paragraph 4(2)(c) of PIPEDA because it involves the collection, use or disclosure of personal information for journalistic, artistic or literary purposes and for no other purpose
  • Whether Google is contravening Accuracy requirements under Principle 4.6 of Schedule 1 of PIPEDA by continuing to display the search results in response to searches for the Complainant’s name
  • Whether Google is contravening subsection 5(3) of PIPEDA by continuing to display the search results in response to searches for the Complainant’s name, considering whether the purposes are appropriate in the circumstances
  • Whether the accessibility of information in response to a search for the Complainant's name causes significant harm to the Complainant
  • Whether the significant harm to the Complainant outweighs the public interest in the search results remaining available through Google's search engine by searching the Complainant's name
  • Whether Google collected, used, or disclosed personal information without consent under Principles 4.3.4 and 4.3.8 of Schedule 1 of PIPEDA (OPC declined to address)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 20, 2025PIPEDA Findings #2025-001Indexed Jun 30, 2026

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

23andMe Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

Jun 20, 2025PIPEDA Findings #2025-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.

Key Issues
  • Whether 23andMe had appropriate safeguards to protect highly sensitive personal information under its control, specifically against credential stuffing attacks.
  • Whether 23andMe's prevention measures, including mandatory Multi-factor Authentication (MFA), compromised-password checks, and minimum password requirements, were adequate.
  • Whether 23andMe's detection measures, including detection systems, digital fingerprinting, and device history, were adequate to identify ongoing attacks.
  • Whether 23andMe adequately investigated anomalies and claims of breach prior to public disclosure.
  • Whether 23andMe's breach response, including the timeliness of disabling active user sessions, disabling raw DNA download features, and implementing mandatory MFA, was adequate.
  • Whether 23andMe adequately notified the OPC about the breach, including the completeness of information provided and timeliness.
  • Whether 23andMe adequately notified affected individuals about the breach, including the completeness of information provided and timeliness.
  • Whether the data breach created a real risk of significant harm to affected individuals, triggering notification obligations.
  • Whether 23andMe's methodology for identifying and notifying individuals whose raw DNA was downloaded by the Threat Actor was adequate.