The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

4 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 14, 2022Indexed Jun 30, 2026

IRCC email breach creates risk of harm to individuals seeking Afghan emergency assistance

Immigration, Refugees and Citizenship Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach involving 636 individuals seeking emergency assistance related to the situation in Afghanistan. IRCC inadvertently disclosed recipients' email addresses, and in some cases thumbnail photos, by using the "TO" field instead of "BCC" in four mass emails. This disclosure revealed that individuals had inquired about sensitive emergency measures, posing potential life-threatening risks. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose. While IRCC took immediate steps to mitigate the impact on affected individuals, the OPC determined that its preventative measures were initially insufficient. IRCC subsequently revised its internal procedures, implemented a "two pairs of eyes" rule, limited recipients, introduced a secure webform, and committed to exploring further technological solutions. The OPC was satisfied with IRCC's actions and considered the matter closed.

Quick view

Privacy ActWell-founded & conditionally resolved

IRCC email breach creates risk of harm to individuals seeking Afghan emergency assistance

Dec 14, 2022
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Immigration, Refugees and Citizenship Canada (IRCC) regarding a privacy breach involving 636 individuals seeking emergency assistance related to the situation in Afghanistan. IRCC inadvertently disclosed recipients' email addresses, and in some cases thumbnail photos, by using the "TO" field instead of "BCC" in four mass emails. This disclosure revealed that individuals had inquired about sensitive emergency measures, posing potential life-threatening risks. The OPC found that IRCC contravened section 8 of the Privacy Act by disclosing personal information without a permissible purpose. While IRCC took immediate steps to mitigate the impact on affected individuals, the OPC determined that its preventative measures were initially insufficient. IRCC subsequently revised its internal procedures, implemented a "two pairs of eyes" rule, limited recipients, introduced a secure webform, and committed to exploring further technological solutions. The OPC was satisfied with IRCC's actions and considered the matter closed.

Key Issues
  • Whether IRCC's disclosure of personal information via mass email contravened section 8 of the Privacy Act
  • Whether IRCC had sufficient administrative and procedural controls in place to prevent accidental disclosures of sensitive personal information when communicating by mass email
  • Whether IRCC's measures to mitigate the impact of the incident on affected individuals were adequate
  • Whether IRCC's actions to reduce the risk of recurrence of similar incidents in the future were adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 2, 2022Indexed Jun 30, 2026

Canada Border Services Agency over-discloses personal information to the Information Commissioner in relation to an ATIA request

Canada Border Services Agency (CBSA)

An individual complained that the Canada Border Services Agency (CBSA) over-disclosed their personal information to the Information Commissioner (IC) when seeking approval to decline two Access to Information Act (ATIA) requests. The CBSA provided not only information related to the ATIA requests but also a sensitive labour relations report about the complainant. The CBSA argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, as the information was collected in the context of workplace conflict and the disclosure was to determine how to handle the complainant's requests for their personal information. The OPC found that while information related to the ATIA requests was a consistent use, the disclosure of the labour relations report was not, as its original purpose (addressing workplace conflict) was distinct from responding to ATIA requests. The OPC concluded that the CBSA contravened section 8 of the Privacy Act and recommended the CBSA develop guidance for consistent use disclosures. The CBSA disagreed with the finding and declined to implement the recommendation, leading to a "well-founded and not resolved" outcome.

Quick view

Privacy ActWell-founded

Canada Border Services Agency over-discloses personal information to the Information Commissioner in relation to an ATIA request

Dec 2, 2022
Adjudicator: Philippe Dufresne
Plain-Language Summary

An individual complained that the Canada Border Services Agency (CBSA) over-disclosed their personal information to the Information Commissioner (IC) when seeking approval to decline two Access to Information Act (ATIA) requests. The CBSA provided not only information related to the ATIA requests but also a sensitive labour relations report about the complainant. The CBSA argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, as the information was collected in the context of workplace conflict and the disclosure was to determine how to handle the complainant's requests for their personal information. The OPC found that while information related to the ATIA requests was a consistent use, the disclosure of the labour relations report was not, as its original purpose (addressing workplace conflict) was distinct from responding to ATIA requests. The OPC concluded that the CBSA contravened section 8 of the Privacy Act and recommended the CBSA develop guidance for consistent use disclosures. The CBSA disagreed with the finding and declined to implement the recommendation, leading to a "well-founded and not resolved" outcome.

Key Issues
  • Whether the disclosure of personal information to the Information Commissioner was for a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether information collected for administering ATIA requests can be disclosed to the IC as a consistent use
  • Whether a labour relations report, originally collected for addressing workplace conflict, can be disclosed to the IC as a consistent use in the context of ATIA requests
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 20, 2022Indexed Jun 30, 2026

Investigation into a privacy breach at a Canada Border Services Agency contractor

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at a Canada Border Services Agency contractor

May 20, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Key Issues
  • Whether licence plate image files, including associated metadata (jurisdiction, characters, date, time, border crossing site, lane number), constitute personal information under Section 3 of the Privacy Act.
  • Whether the unauthorized access and disclosure of these licence plate image files constituted an improper disclosure under Section 8 of the Privacy Act.
  • Whether the Canada Border Services Agency (CBSA) had adequate security safeguards in place, particularly in its contractual arrangements with a third-party contractor, to protect personal information.
  • Whether the data retention practices for licence plate image files by the CBSA and its contractor were appropriate and compliant with the Privacy Act.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 13, 2022Indexed Jun 30, 2026

DND breached the Privacy Act in disclosing the identity of a workplace violence complainant who had an expectation of confidentiality

Department of National Defence (DND)

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

Quick view

Privacy ActWell-founded & conditionally resolved

DND breached the Privacy Act in disclosing the identity of a workplace violence complainant who had an expectation of confidentiality

May 13, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

Key Issues
  • Whether the disclosure of the WPV complainant's identity to labour relations was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the disclosure of the WPV complainant's identity to an investigator for a separate administrative investigation was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the consent form provided by DND created a reasonable expectation of confidentiality regarding the complainant's identity