The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

10 decisions matching
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Nov 17, 2020Indexed Jun 30, 2026

Employer’s disclosure related to a transgender individual was contrary to the Privacy Act

A federal government institution

An employee complained that a federal government institution breached her privacy by disclosing her transgender identity and the reasons for her transfer to her new manager and colleagues without her consent. The complainant had explicitly requested confidentiality due to prior workplace harassment related to her gender identity, and the employer had assured her of discretion. The institution's internal review confirmed that managers disclosed this sensitive information, believing it necessary to support the employee and her new supervisor, but acknowledged this was an error and contrary to internal policies. The OPC found that the disclosure was made without consent, contravening section 8(1) of the Privacy Act. The institution recognized the breach and committed to improving policies and providing transgender awareness education. The OPC recommended updating policies to prevent similar incidents, and the institution created new guidance for its staff.

Quick view

Privacy ActWell-founded & resolved

Employer’s disclosure related to a transgender individual was contrary to the Privacy Act

Nov 17, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that a federal government institution breached her privacy by disclosing her transgender identity and the reasons for her transfer to her new manager and colleagues without her consent. The complainant had explicitly requested confidentiality due to prior workplace harassment related to her gender identity, and the employer had assured her of discretion. The institution's internal review confirmed that managers disclosed this sensitive information, believing it necessary to support the employee and her new supervisor, but acknowledged this was an error and contrary to internal policies. The OPC found that the disclosure was made without consent, contravening section 8(1) of the Privacy Act. The institution recognized the breach and committed to improving policies and providing transgender awareness education. The OPC recommended updating policies to prevent similar incidents, and the institution created new guidance for its staff.

Key Issues
  • Whether information about an individual's transgender identity is personal information requiring protection under the Privacy Act
  • Whether the institution disclosed the complainant's personal information without consent
  • Whether the disclosure was contrary to section 8(1) of the Privacy Act
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

RCMP contravened the Act by using certain types of non-conviction information for vulnerable sector checks without consent

Royal Canadian Mounted Police (RCMP)

Three individuals complained about the Royal Canadian Mounted Police's (RCMP) use of non-conviction information in vulnerable sector (VS) checks, which they required for employment or volunteer positions. The complainants alleged that the RCMP inappropriately used non-criminal information, including mental health incidents, without proper consent. The OPC found that for two of the complaints, the RCMP contravened section 7 of the Privacy Act because the consent forms did not clearly inform applicants about the types of non-conviction information that would be used. While the RCMP argued consent was obtained, the OPC determined it was not informed consent in these cases. The OPC also concluded that the RCMP's broad policy of reporting non-conviction information, including mental health incidents, was not proportional or minimally intrusive compared to more restrictive provincial models. However, the complaint regarding the RCMP's retention period for personal information was found not well-founded, as it complied with the minimum requirements of the Privacy Regulations. The RCMP agreed to revise its consent forms and policy to address the OPC's concerns, leading to a well-founded and conditionally resolved outcome for the two complaints.

Quick view

Privacy ActWell-founded & conditionally resolved

RCMP contravened the Act by using certain types of non-conviction information for vulnerable sector checks without consent

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

Three individuals complained about the Royal Canadian Mounted Police's (RCMP) use of non-conviction information in vulnerable sector (VS) checks, which they required for employment or volunteer positions. The complainants alleged that the RCMP inappropriately used non-criminal information, including mental health incidents, without proper consent. The OPC found that for two of the complaints, the RCMP contravened section 7 of the Privacy Act because the consent forms did not clearly inform applicants about the types of non-conviction information that would be used. While the RCMP argued consent was obtained, the OPC determined it was not informed consent in these cases. The OPC also concluded that the RCMP's broad policy of reporting non-conviction information, including mental health incidents, was not proportional or minimally intrusive compared to more restrictive provincial models. However, the complaint regarding the RCMP's retention period for personal information was found not well-founded, as it complied with the minimum requirements of the Privacy Regulations. The RCMP agreed to revise its consent forms and policy to address the OPC's concerns, leading to a well-founded and conditionally resolved outcome for the two complaints.

Key Issues
  • Whether the use of non-conviction information by the RCMP for VS checks was done with informed consent consistent with section 7 of the Privacy Act.
  • Whether the RCMP's policy of reporting non-conviction information broadly, including mental health incidents, in VS checks was proportional or minimally intrusive.
  • Whether the RCMP should amend its policies with respect to the use of non-conviction information in VS checks.
  • Whether the RCMP contravened the Act by retaining Complainant 2’s personal information for too long.
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Investigation into a privacy breach at Public Services and Procurement Canada

Public Services and Procurement Canada (PSPC)

The Office of the Privacy Commissioner (OPC) investigated complaints from federal public servants regarding an improper disclosure of their pay-related information by Public Services and Procurement Canada (PSPC). PSPC inadvertently sent personnel overpayment reports containing personal information of 69,087 public servants to the wrong government institutions. The OPC found that PSPC contravened section 8 of the Privacy Act by disclosing personal information without authorization. However, the complaints were deemed resolved due to PSPC's corrective actions, which included implementing new procedures with quality controls for report generation, requesting deletion of the flawed reports, and notifying affected individuals. The OPC noted that while notification was timely, some departments modified the notification letters, leading to inconsistencies in the information received by individuals.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at Public Services and Procurement Canada

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated complaints from federal public servants regarding an improper disclosure of their pay-related information by Public Services and Procurement Canada (PSPC). PSPC inadvertently sent personnel overpayment reports containing personal information of 69,087 public servants to the wrong government institutions. The OPC found that PSPC contravened section 8 of the Privacy Act by disclosing personal information without authorization. However, the complaints were deemed resolved due to PSPC's corrective actions, which included implementing new procedures with quality controls for report generation, requesting deletion of the flawed reports, and notifying affected individuals. The OPC noted that while notification was timely, some departments modified the notification letters, leading to inconsistencies in the information received by individuals.

Key Issues
  • Whether PSPC improperly disclosed personal information in contravention of section 8 of the Privacy Act
  • Whether the information disclosed constituted 'personal information' under section 3 of the Privacy Act
  • Whether PSPC's response to the breach, including mitigation and notification, was adequate
  • Whether PSPC implemented sufficient measures to prevent recurrence of the breach
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

PA-048557, PA-048561 — Canadian Air Transport Security Authority (CATSA)

Canadian Air Transport Security Authority (CATSA)

An individual complained that the Canadian Air Transport Security Authority (CATSA) contravened the Privacy Act by collecting and disclosing his personal information to police after finding legal medical cannabis during a security screening. The complainant argued that CATSA's mandate is aviation security, not general law enforcement, and that cannabis is not a prohibited item. CATSA maintained that its actions were incidental to its mandate and in the public interest, consistent with its regulator's direction. The OPC found that CATSA lacked the legal authority under section 4 of the Privacy Act to collect personal information for general law enforcement purposes related to cannabis, as cannabis is not on the Prohibited Items List and does not pose an aviation security threat. Similarly, the OPC concluded that the disclosure of this personal information to police was not consistent with section 8 of the Privacy Act. However, the OPC found CATSA's practice of destroying records related to such searches to be consistent with section 6 of the Act. The OPC recommended that CATSA cease unauthorized collection and disclosure of personal information related to cannabis and destroy any existing records, which CATSA agreed to implement.

Quick view

Privacy ActWell-founded & conditionally resolved

PA-048557, PA-048561 — Canadian Air Transport Security Authority (CATSA)

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that the Canadian Air Transport Security Authority (CATSA) contravened the Privacy Act by collecting and disclosing his personal information to police after finding legal medical cannabis during a security screening. The complainant argued that CATSA's mandate is aviation security, not general law enforcement, and that cannabis is not a prohibited item. CATSA maintained that its actions were incidental to its mandate and in the public interest, consistent with its regulator's direction. The OPC found that CATSA lacked the legal authority under section 4 of the Privacy Act to collect personal information for general law enforcement purposes related to cannabis, as cannabis is not on the Prohibited Items List and does not pose an aviation security threat. Similarly, the OPC concluded that the disclosure of this personal information to police was not consistent with section 8 of the Privacy Act. However, the OPC found CATSA's practice of destroying records related to such searches to be consistent with section 6 of the Act. The OPC recommended that CATSA cease unauthorized collection and disclosure of personal information related to cannabis and destroy any existing records, which CATSA agreed to implement.

Key Issues
  • Whether the collection of personal information from travellers found to be in possession of cannabis is consistent with section 4 of the Privacy Act
  • Whether the disclosure of the personal information of travellers found to be in possession of cannabis is consistent with section 8 of the Privacy Act
  • Whether CATSA’s record retention practices in terms of the personal information collected from travellers found to be in possession of cannabis are consistent with section 6 of the Privacy Act
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Review of passport protection practices of four federal institutions

Immigration, Refugees and Citizenship Canada (IRCC)

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Quick view

Privacy ActWell-founded & conditionally resolved

Review of passport protection practices of four federal institutions

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Key Issues
  • Whether the institutions had adequate controls to prevent unauthorized disclosures of passports under s.8 of the Privacy Act
  • Whether the institutions had adequate measures to detect potential unauthorized disclosures of passports
  • Whether the institutions had adequate measures to remediate risks to individuals from unauthorized disclosures of passports
  • Whether the institutions consistently and appropriately assessed the "materiality" of passport-related breaches
  • Whether notifications to affected individuals regarding lost or stolen passports were timely
  • Whether concrete assistance, such as credit monitoring, was offered to individuals affected by lost or stolen passports
  • Whether incident assessment and investigation processes were robust enough to identify suspicious patterns and share lessons learned among relevant stakeholders
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Aug 6, 2020Indexed Jun 30, 2026

PA-055322 (PCO) et PA-055323 (DOJ) — Privy Council Office (PCO) and Department of Justice (DOJ)

Privy Council Office (PCO) and Department of Justice (DOJ)

The OPC investigated a complaint regarding the unauthorized disclosure of personal information about Supreme Court candidate Chief Justice Glenn Joyal. Media reports claimed an anonymous source revealed a disagreement between the Prime Minister's Office (PMO) and the former Attorney General over Joyal's nomination. The complainant alleged breaches of the Privacy Act by the Privy Council Office (PCO), Department of Justice (DOJ), Office of the Commissioner of Federal Judicial Affairs (CFJA), and the PMO. The OPC determined it lacked jurisdiction over the CFJA and PMO, focusing its investigation on the PCO and DOJ. The investigation found no evidence that either the PCO or the DOJ had access to the specific information that was leaked, nor that the disclosure originated from these institutions. While no contravention was found, the OPC highlighted that Chief Justice Joyal's privacy was compromised and called for legislative reform to extend the Privacy Act's coverage to all government institutions, including Ministers' Offices and the PMO.

Quick view

Privacy ActNot well-founded

PA-055322 (PCO) et PA-055323 (DOJ) — Privy Council Office (PCO) and Department of Justice (DOJ)

Aug 6, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated a complaint regarding the unauthorized disclosure of personal information about Supreme Court candidate Chief Justice Glenn Joyal. Media reports claimed an anonymous source revealed a disagreement between the Prime Minister's Office (PMO) and the former Attorney General over Joyal's nomination. The complainant alleged breaches of the Privacy Act by the Privy Council Office (PCO), Department of Justice (DOJ), Office of the Commissioner of Federal Judicial Affairs (CFJA), and the PMO. The OPC determined it lacked jurisdiction over the CFJA and PMO, focusing its investigation on the PCO and DOJ. The investigation found no evidence that either the PCO or the DOJ had access to the specific information that was leaked, nor that the disclosure originated from these institutions. While no contravention was found, the OPC highlighted that Chief Justice Joyal's privacy was compromised and called for legislative reform to extend the Privacy Act's coverage to all government institutions, including Ministers' Offices and the PMO.

Key Issues
  • Whether the Office of the Commissioner of Federal Judicial Affairs (CFJA) is a 'government institution' under the Privacy Act
  • Whether the Prime Minister's Office (PMO) is a 'government institution' under the Privacy Act
  • Whether the Privy Council Office (PCO) was responsible for the unauthorized disclosure of Chief Justice Joyal's personal information under section 8 of the Privacy Act
  • Whether the Department of Justice (DOJ) was responsible for the unauthorized disclosure of Chief Justice Joyal's personal information under section 8 of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jul 14, 2020Indexed Jun 30, 2026

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Canada Border Services Agency (CBSA)

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Quick view

Privacy ActNot well-founded

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Jul 14, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Key Issues
  • Did the CBSA disclose the complainant’s personal information?
  • Was any disclosed information “publicly available”, such that subsection 69(2) of the Act excludes application of sections 7 and 8?
  • If not, was the disclosure permitted under subsection 8(2) of the Act?
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Mar 31, 2020Indexed Jun 30, 2026

CBSA should only retain travellers’ digital device passcodes when necessary

Canada Border Services Agency (CBSA)

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Quick view

Privacy ActResolved

CBSA should only retain travellers’ digital device passcodes when necessary

Mar 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Key Issues
  • Whether the CBSA has the authority to require a traveller to provide a passcode to unlock a digital device for inspection purposes under the Customs Act
  • Whether the CBSA officer followed internal policies regarding the collection and retention of personal information (passcodes)
  • Whether the CBSA's retention of the passcode was necessary beyond the examination process when no further action was taken
  • Whether passcodes constitute sensitive personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 31, 2020Indexed Jun 30, 2026

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Employment and Social Development Canada (ESDC)

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Quick view

Privacy ActWell-founded

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Jan 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Key Issues
  • Whether the collection of video surveillance footage constituted personal information under s.3 of the Privacy Act
  • Whether the initial collection of video surveillance footage by ESDC was in compliance with s.4 of the Privacy Act
  • Whether ESDC informed individuals of the purpose for collecting personal information via video surveillance, as required by s.5 of the Privacy Act
  • Whether ESDC's use of video surveillance footage to monitor an employee's departure times was consistent with the purpose for which it was collected, as required by s.7(a) of the Privacy Act
  • Whether ESDC obtained consent for the use of video surveillance footage for purposes other than security, as required by s.7(a) of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jan 15, 2020Indexed Jun 30, 2026

Public disclosure of medical information during military trial consistent with Privacy Act

Department of National Defence

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

Public disclosure of medical information during military trial consistent with Privacy Act

Jan 15, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Key Issues
  • Whether the Privacy Act applies to military summary trial proceedings conducted by the Canadian Forces
  • Whether the disclosure of the complainant's medical information during the summary trial was made in accordance with section 8 of the Privacy Act
  • Whether the information became publicly available under section 69(2) of the Privacy Act once disclosed in an open court proceeding