The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

7 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 14, 2026Indexed Jul 15, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

WestJet

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By WestJet, an Alberta Partnership (“WestJet”)

Jul 14, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) launched a Commissioner-initiated investigation (CII) into a privacy breach at WestJet that occurred on June 12, 2025. An unauthorized third party gained access to an employee's administrative account, bypassed multi-factor authentication, deployed ransomware, and exfiltrated data affecting approximately 5.1 million Canadian employees and customers. The breach exposed names, dates of birth, email addresses, mailing addresses, phone numbers, gender, travel booking information, and passport details, but no credit card numbers or SINs. WestJet took immediate containment measures, reported the breach, and provided direct and indirect notifications, credit monitoring, and identity theft protection services. WestJet has committed to further actions, including an external security assessment and providing a summary report to the OPC by August 7, 2026, to ensure the adequacy of its updated security safeguards and prevent future breaches. The CII will be discontinued upon the Commissioner being satisfied that WestJet has fulfilled all commitments.

Key Issues
  • Adequacy of security safeguards under PIPEDA
  • Adequacy of notifications to affected individuals under PIPEDA
  • Whether WestJet's post-breach remediation actions and future commitments provide a fair and reasonable response to the incident
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 11, 2026PIPEDA Findings #2026-004Indexed Jun 30, 2026

PIPEDA Findings #2026-004: Commissioner-initiated complaints concerning X Corp.’s and X.AI LLC’s compliance with PIPEDA

X Corp. and X.AI LLC

The Office of the Privacy Commissioner of Canada (OPC) initiated complaints against X Corp. and X.AI LLC following reports that their AI chatbot, Grok, generated millions of sexualized deepfakes of identifiable individuals. The investigation focused on whether valid consent was obtained for the collection, use, and disclosure of personal information for this purpose, and if such practices were appropriate under PIPEDA. The OPC found that neither company obtained valid consent, noting the sensitive nature of the information, the unreasonableness of individuals' expectations, and the significant risk of harm. Furthermore, the OPC concluded that the generation of sexualized deepfakes was inappropriate, as the loss of privacy and harm far outweighed any benefits, and less privacy-invasive means were available. While the companies implemented some safeguards, the OPC deemed their initial response insufficient and their current measures unproven. Consequently, the matter was found well-founded, with the OPC making several recommendations for improved safeguards, proactive monitoring, and annual third-party audits, while committing to ongoing monitoring.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2026-004: Commissioner-initiated complaints concerning X Corp.’s and X.AI LLC’s compliance with PIPEDA

Jun 11, 2026PIPEDA Findings #2026-004
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated complaints against X Corp. and X.AI LLC following reports that their AI chatbot, Grok, generated millions of sexualized deepfakes of identifiable individuals. The investigation focused on whether valid consent was obtained for the collection, use, and disclosure of personal information for this purpose, and if such practices were appropriate under PIPEDA. The OPC found that neither company obtained valid consent, noting the sensitive nature of the information, the unreasonableness of individuals' expectations, and the significant risk of harm. Furthermore, the OPC concluded that the generation of sexualized deepfakes was inappropriate, as the loss of privacy and harm far outweighed any benefits, and less privacy-invasive means were available. While the companies implemented some safeguards, the OPC deemed their initial response insufficient and their current measures unproven. Consequently, the matter was found well-founded, with the OPC making several recommendations for improved safeguards, proactive monitoring, and annual third-party audits, while committing to ongoing monitoring.

Key Issues
  • Whether PIPEDA applies to X Corp. and X.AI LLC, specifically regarding the existence of a "real and substantial connection" to Canada.
  • Whether deepfakes of identifiable individuals, including sexualized deepfakes, constitute "personal information" under PIPEDA.
  • Whether X Corp. and X.AI LLC obtained valid consent for the collection, use, and disclosure of personal information to generate sexualized deepfakes, as required by Principle 4.3 of PIPEDA.
  • Whether express consent was required for the generation of sexualized deepfakes, considering the sensitivity of the information, individuals' reasonable expectations, and the risk of significant harm (Principle 4.3.4, 4.3.5, and s.6.1 of PIPEDA).
  • Whether X Corp. and X.AI LLC are accountable for ensuring valid consent for content generated by their tools in the course of commercial activity.
  • Whether a reasonable person would consider the collection, use, and disclosure of personal information for the purpose of an image generation service capable of producing sexualized deepfakes to be appropriate in the circumstances, as per subsection 5(3) of PIPEDA.
  • Whether the organizations had a legitimate need or bona fide business interest that extended to providing an image generation tool capable of producing non-consensual sexualized deepfakes.
  • Whether less privacy-invasive means were available to achieve the organizations' purposes at comparable cost and benefits.
  • Whether the loss of privacy and risk of harm associated with sexualized deepfakes were proportionate to the benefits of the practice.
  • Whether X Corp. and X.AI LLC's initial response and implemented safeguards were sufficient and effective in preventing the generation of sexualized deepfakes.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & unresolved
Federal (Canada) flag
May 6, 2026PIPEDA Findings #2026-002Indexed Jun 30, 2026

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

OpenAI OpCo, LLC

This joint investigation by the OPC, CAI, OIPC-BC, and OIPC-AB examined OpenAI OpCo, LLC's compliance with federal and provincial privacy laws regarding its ChatGPT service. The Offices investigated OpenAI's collection, use, and disclosure of personal information for model training, consent practices, openness, accuracy, individual rights (access, correction, deletion), data retention, and accountability. While OpenAI challenged jurisdiction and argued for implied consent, the Offices largely found contraventions in its initial practices, particularly concerning the overbroad collection of personal information from public sources and user interactions without valid consent or sufficient transparency. However, in response to the preliminary report, OpenAI committed to implementing significant privacy-enhancing measures, including a new filtering tool for training data, improved transparency, and enhanced individual rights processes. Consequently, the OPC found the matter well-founded and conditionally resolved under PIPEDA, expecting continued implementation and improvement of these measures. The OIPC-AB and OIPC-BC, due to stricter provincial consent requirements, found the consent issues well-founded and unresolved, while the CAI had mixed outcomes, also finding some issues unresolved. The Offices will monitor OpenAI's implementation of the agreed-upon recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & unresolved

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

May 6, 2026PIPEDA Findings #2026-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

This joint investigation by the OPC, CAI, OIPC-BC, and OIPC-AB examined OpenAI OpCo, LLC's compliance with federal and provincial privacy laws regarding its ChatGPT service. The Offices investigated OpenAI's collection, use, and disclosure of personal information for model training, consent practices, openness, accuracy, individual rights (access, correction, deletion), data retention, and accountability. While OpenAI challenged jurisdiction and argued for implied consent, the Offices largely found contraventions in its initial practices, particularly concerning the overbroad collection of personal information from public sources and user interactions without valid consent or sufficient transparency. However, in response to the preliminary report, OpenAI committed to implementing significant privacy-enhancing measures, including a new filtering tool for training data, improved transparency, and enhanced individual rights processes. Consequently, the OPC found the matter well-founded and conditionally resolved under PIPEDA, expecting continued implementation and improvement of these measures. The OIPC-AB and OIPC-BC, due to stricter provincial consent requirements, found the consent issues well-founded and unresolved, while the CAI had mixed outcomes, also finding some issues unresolved. The Offices will monitor OpenAI's implementation of the agreed-upon recommendations.

Key Issues
  • Whether the Offices had jurisdiction over OpenAI's activities under federal and provincial privacy laws.
  • Whether OpenAI collected, used, and disclosed personal information for purposes that a reasonable person would consider appropriate in the circumstances.
  • Whether OpenAI obtained valid consent for the collection and use of personal information from publicly accessible websites and licensed third-party sources for model training.
  • Whether OpenAI obtained valid consent and met its obligation to inform individuals with respect to the collection and use of personal information included in their interactions with ChatGPT.
  • Whether OpenAI obtained valid consent and met its obligation to inform individuals with respect to the disclosure of personal information collected from various sources via ChatGPT.
  • Whether OpenAI was sufficiently open and transparent about its models and information handling practices.
  • Whether OpenAI took reasonable steps to ensure that the information it generates about individuals is as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used.
  • Whether OpenAI provided individuals with the ability to obtain access to their personal information.
  • Whether OpenAI provided individuals with the ability to correct their personal information.
  • Whether OpenAI provided individuals with the ability to remove/delete their personal information from its models.
  • Whether OpenAI established appropriate retention and disposal procedures for the personal information that it collects, uses, and discloses.
  • Whether OpenAI met its accountability requirements in respect of the personal information under its control.
  • Whether the personal or domestic purposes exemption applied to OpenAI's commercial activities.
  • Whether the publicly available information exception applied to OpenAI's collection of personal information from the Internet.
  • Whether the journalistic, historical, or genealogical material exception under Quebec's Private Sector Act applied to OpenAI's model training data.
  • Whether section 9.1 of Quebec's Private Sector Act (privacy by default) applied to ChatGPT's privacy settings.
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Mar 25, 2026Indexed Jun 30, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Nova Scotia Power

This document is a compliance letter from Nova Scotia Power to the OPC, outlining actions taken and commitments made following a significant data breach that occurred in March 2025. The breach, caused by malware, led to the exfiltration of personal information belonging to approximately 375,000 current and 540,000 former customers. The compromised data included names, contact information, financial details, driver's license numbers, and SINs. The OPC received numerous complaints regarding the breach, including concerns about the collection and retention of SINs and the timeliness and method of notification to affected individuals. Nova Scotia Power has committed to deleting customer SINs (subject to legal requirements) and undergoing an external security assessment by October 2026. Upon satisfactory fulfillment of these commitments, the OPC's investigation will be discontinued.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

This document is a compliance letter from Nova Scotia Power to the OPC, outlining actions taken and commitments made following a significant data breach that occurred in March 2025. The breach, caused by malware, led to the exfiltration of personal information belonging to approximately 375,000 current and 540,000 former customers. The compromised data included names, contact information, financial details, driver's license numbers, and SINs. The OPC received numerous complaints regarding the breach, including concerns about the collection and retention of SINs and the timeliness and method of notification to affected individuals. Nova Scotia Power has committed to deleting customer SINs (subject to legal requirements) and undergoing an external security assessment by October 2026. Upon satisfactory fulfillment of these commitments, the OPC's investigation will be discontinued.

Key Issues
  • Whether Nova Scotia Power's security safeguards were adequate to protect personal information
  • Whether Nova Scotia Power's collection and retention of Social Insurance Numbers (SINs) was appropriate
  • Whether Nova Scotia Power's notification of affected individuals was timely and appropriate
  • Whether Nova Scotia Power has taken sufficient corrective measures to address the breach and prevent future incidents
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Mar 17, 2026Indexed Jun 30, 2026

Compliance agreement between the Privacy Commissioner of Canada and the World Anti-Doping Agency

World Anti-Doping Agency (WADA)

The World Anti-Doping Agency (WADA) entered into a compliance agreement with the Privacy Commissioner of Canada (OPC) to resolve an investigation into WADA's collection, use, and disclosure practices concerning athletes' personal information in its Anti-Doping Administration and Management System (ADAMS). The OPC launched an investigation after receiving a complaint, and WADA disputed the allegations and challenged the OPC's jurisdiction in Federal Court. Without admitting contravention or waiving jurisdictional rights, WADA agreed to remedial measures. These measures include ceasing to permit Anti-Doping Organizations (ADOs) to use ADAMS data for non-anti-doping purposes, updating the World Anti-Doping Code, and amending agreements with ADOs to restrict data use to anti-doping purposes only. WADA will also provide the OPC with a mechanism to ensure ADOs adhere to these restrictions. The investigation will be placed in abeyance and discontinued upon completion of the remedial measures.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Compliance agreement between the Privacy Commissioner of Canada and the World Anti-Doping Agency

Mar 17, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The World Anti-Doping Agency (WADA) entered into a compliance agreement with the Privacy Commissioner of Canada (OPC) to resolve an investigation into WADA's collection, use, and disclosure practices concerning athletes' personal information in its Anti-Doping Administration and Management System (ADAMS). The OPC launched an investigation after receiving a complaint, and WADA disputed the allegations and challenged the OPC's jurisdiction in Federal Court. Without admitting contravention or waiving jurisdictional rights, WADA agreed to remedial measures. These measures include ceasing to permit Anti-Doping Organizations (ADOs) to use ADAMS data for non-anti-doping purposes, updating the World Anti-Doping Code, and amending agreements with ADOs to restrict data use to anti-doping purposes only. WADA will also provide the OPC with a mechanism to ensure ADOs adhere to these restrictions. The investigation will be placed in abeyance and discontinued upon completion of the remedial measures.

Key Issues
  • Whether WADA's collection, use, and disclosure practices of athletes' personal information in ADAMS comply with PIPEDA
  • Whether the OPC has statutory, territorial, and/or subject matter jurisdiction over WADA
  • Whether ADOs are permitted to use personal information in ADAMS for purposes other than anti-doping
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 5, 2026PIPEDA Findings #2026-001Indexed Jun 30, 2026

PIPEDA Findings #2026-001: Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program

Loblaw Companies Ltd.

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Loblaw Companies Ltd. (Loblaw) regarding its PC Optimum Loyalty Program, focusing on the handling of privacy challenges and the retention of personal information. The investigation found that Loblaw contravened PIPEDA Principle 4.10 by failing to adequately address privacy challenges and respond to account deletion requests in a timely manner, though this issue was resolved during the investigation as Loblaw enhanced its procedures. The OPC also found that Loblaw contravened PIPEDA Principle 4.5.3 by not sufficiently anonymizing personal information retained from closed PC Optimum accounts, meaning there was a serious possibility of re-identification. Loblaw disagreed with this finding but agreed to engage an independent third party to assess its anonymization process and implement recommendations. A preliminary matter regarding requiring physical card holders to create an online account for deletion was found not well-founded. The overall outcome reflects a mix of resolved and conditionally resolved well-founded findings.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2026-001: Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program

Mar 5, 2026PIPEDA Findings #2026-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Loblaw Companies Ltd. (Loblaw) regarding its PC Optimum Loyalty Program, focusing on the handling of privacy challenges and the retention of personal information. The investigation found that Loblaw contravened PIPEDA Principle 4.10 by failing to adequately address privacy challenges and respond to account deletion requests in a timely manner, though this issue was resolved during the investigation as Loblaw enhanced its procedures. The OPC also found that Loblaw contravened PIPEDA Principle 4.5.3 by not sufficiently anonymizing personal information retained from closed PC Optimum accounts, meaning there was a serious possibility of re-identification. Loblaw disagreed with this finding but agreed to engage an independent third party to assess its anonymization process and implement recommendations. A preliminary matter regarding requiring physical card holders to create an online account for deletion was found not well-founded. The overall outcome reflects a mix of resolved and conditionally resolved well-founded findings.

Key Issues
  • Whether Loblaw adequately addresses privacy challenges raised by individuals concerning account deletion (PIPEDA Principle 4.10)
  • Whether Loblaw retains personal information of PC Optimum members for longer than necessary after account closure (PIPEDA Principle 4.5.3)
  • Whether Loblaw collected unnecessary personal information by requiring physical card holders to create an online account to delete their PC Optimum account (PIPEDA Principle 4.4)
  • Whether Loblaw established retention schedules for customer support logs (PIPEDA Principle 4.5.2)
  • Whether Loblaw retains universal login credentials (PCids) for longer than necessary for members with no other associated accounts (PIPEDA Principle 4.5.3)
  • Whether Loblaw's anonymization process for retained Historical Transaction Data, Loyalty Data, and Usage Data ensures no serious possibility of re-identification
  • Whether Loblaw's retention of public IP address data after account closure is sufficiently anonymized
  • Whether Loblaw's practice of retaining email domain portions after account closure is sufficiently anonymized
  • Whether manual processing errors in Loblaw's de-identification process were adequately detected and addressed
  • Whether Loblaw ensured identifiers were removed from back-up systems as part of its anonymization process
  • Whether Loblaw considered the impact of other factors affecting re-identification risk, such as separately retained PCid data
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 9, 2026PIPEDA Findings #2026-003Indexed Jun 30, 2026

PIPEDA Findings #2026-003: Investigation into Bell’s compliance with PIPEDA when responding to an access request for personal information

Bell Canada

The complainant alleged that Bell Canada contravened PIPEDA by failing to respond to an access request within 30 days and by denying access to his cellphone logs. The OPC found that Bell contravened subsection 8(3) of PIPEDA for the delayed response and Principle 4.9 for denying access, as the phone logs constituted the complainant's personal information. The OPC determined that the complainant's privacy interest in his phone logs outweighed the ex-spouse's interest, and there was a public interest in disclosure. Bell agreed to provide the requested logs to the complainant, resolving that aspect of the complaint. Bell also committed to implementing recommendations to improve its access request procedures and enhance openness regarding data access on shared accounts, leading to a conditionally resolved outcome for these issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2026-003: Investigation into Bell’s compliance with PIPEDA when responding to an access request for personal information

Jan 9, 2026PIPEDA Findings #2026-003
Adjudicator: Philippe Dufresne
Plain-Language Summary

The complainant alleged that Bell Canada contravened PIPEDA by failing to respond to an access request within 30 days and by denying access to his cellphone logs. The OPC found that Bell contravened subsection 8(3) of PIPEDA for the delayed response and Principle 4.9 for denying access, as the phone logs constituted the complainant's personal information. The OPC determined that the complainant's privacy interest in his phone logs outweighed the ex-spouse's interest, and there was a public interest in disclosure. Bell agreed to provide the requested logs to the complainant, resolving that aspect of the complaint. Bell also committed to implementing recommendations to improve its access request procedures and enhance openness regarding data access on shared accounts, leading to a conditionally resolved outcome for these issues.

Key Issues
  • Whether Bell responded to the Complainant’s access request within thirty days as per subsection 8(3) of PIPEDA
  • Whether Bell adequately responded to the Complainant’s request to access his personal information under Principle 4.9 of PIPEDA
  • Whether phone logs relating to a specific phoneline constitute the personal information of the phoneline's user, even if they are not the account holder
  • Whether the Complainant's interest in accessing the phone logs is greater than the ex-spouse's interest in non-disclosure of the phone logs
  • Whether Bell was sufficiently open with individuals about account holders' access to phone usage details on shared accounts, contrary to PIPEDA's Openness principle (Principle 4.8.1)