The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,631 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

A Year to Confirm Ex-Husband Got Former Wife's Tax Information

Canada Revenue Agency

A woman complained to the OPC after discovering her tax information, held by the Canada Revenue Agency (CRA), was inappropriately accessed by a CRA employee who was the common-law spouse of her ex-husband. The ex-husband subsequently used this information to seek an amendment to a child support arrangement. The CRA's internal investigation confirmed the unauthorized access and disclosure but took 13 months, and the complainant was never informed of the results. The OPC's investigation found the complaint to be well-founded, noting that while the CRA had a discipline policy, allegations of misconduct needed to be addressed more quickly. The OPC also highlighted the need for enhanced privacy training for employees with access to personal tax information.

Quick view

Privacy ActWell-founded

A Year to Confirm Ex-Husband Got Former Wife's Tax Information

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained to the OPC after discovering her tax information, held by the Canada Revenue Agency (CRA), was inappropriately accessed by a CRA employee who was the common-law spouse of her ex-husband. The ex-husband subsequently used this information to seek an amendment to a child support arrangement. The CRA's internal investigation confirmed the unauthorized access and disclosure but took 13 months, and the complainant was never informed of the results. The OPC's investigation found the complaint to be well-founded, noting that while the CRA had a discipline policy, allegations of misconduct needed to be addressed more quickly. The OPC also highlighted the need for enhanced privacy training for employees with access to personal tax information.

Key Issues
  • Whether the Canada Revenue Agency inappropriately disclosed personal tax information
  • Whether the Canada Revenue Agency adequately responded to the internal investigation
  • Whether the Canada Revenue Agency's policies and training were sufficient to protect personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

Drug Scan, Child Access Linked in Inappropriate Disclosure

Correctional Service of Canada

A woman complained that her personal information, specifically positive drug test results from an ion scan during a prison visit, was inappropriately disclosed to her ex-husband, a Correctional Service of Canada (CSC) employee. Her ex-husband used this information to deny her access to their children. While CSC investigated and found that the ex-husband did not directly access the database, they did not determine how he obtained the information. The OPC's investigation confirmed that the drug test results were indeed disclosed to the ex-husband by other CSC employees, though the specific individuals responsible could not be identified. The OPC found that CSC failed to adequately address the core disclosure issue.

Quick view

Privacy ActWell-founded

Drug Scan, Child Access Linked in Inappropriate Disclosure

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained that her personal information, specifically positive drug test results from an ion scan during a prison visit, was inappropriately disclosed to her ex-husband, a Correctional Service of Canada (CSC) employee. Her ex-husband used this information to deny her access to their children. While CSC investigated and found that the ex-husband did not directly access the database, they did not determine how he obtained the information. The OPC's investigation confirmed that the drug test results were indeed disclosed to the ex-husband by other CSC employees, though the specific individuals responsible could not be identified. The OPC found that CSC failed to adequately address the core disclosure issue.

Key Issues
  • Whether the woman's personal information (drug test results) was inappropriately disclosed to her ex-husband
  • Whether Correctional Service of Canada adequately dealt with the disclosure issue
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

Veterans Affairs Withholds Father's Pension File from Family

Veterans Affairs Canada

The adult children of a deceased veteran sought access to their father's pension file from Veterans Affairs Canada to administer his estate. Veterans Affairs refused, citing a 20-year protection period under the Pension Act and the children's ineligibility for pension benefits. The children complained to the OPC, arguing the documents were necessary to determine if pension entitlements were fully paid and if the claim was processed in bad faith. The OPC found it unreasonable for Veterans Affairs to dictate estate information needs. The OPC concluded that under the Privacy Act's Regulations, the complainants were entitled to the file for estate administration. The complaint was upheld as well-founded, and Veterans Affairs subsequently released the file.

Quick view

Privacy ActWell-founded

Veterans Affairs Withholds Father's Pension File from Family

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The adult children of a deceased veteran sought access to their father's pension file from Veterans Affairs Canada to administer his estate. Veterans Affairs refused, citing a 20-year protection period under the Pension Act and the children's ineligibility for pension benefits. The children complained to the OPC, arguing the documents were necessary to determine if pension entitlements were fully paid and if the claim was processed in bad faith. The OPC found it unreasonable for Veterans Affairs to dictate estate information needs. The OPC concluded that under the Privacy Act's Regulations, the complainants were entitled to the file for estate administration. The complaint was upheld as well-founded, and Veterans Affairs subsequently released the file.

Key Issues
  • Whether Veterans Affairs Canada was justified in withholding a deceased veteran's pension file from his adult children
  • Whether the Pension Act's 20-year protection period for personal information overrides the need for estate administration
  • Whether the Privacy Act's Regulations entitle complainants to a deceased pensioner's file for estate administration
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

Canada Post Sharing Personal Information with Credit Bureau

Canada Post

A man complained that Canada Post checked his credit rating when he requested an online change of address. The OPC investigated whether Canada Post's practice of using Equifax for identity verification in online change-of-address requests violated the Privacy Act. The OPC found that Canada Post has a legitimate need to confirm identity to prevent identity theft and that it does not conduct a credit verification. However, the OPC was concerned that individuals were not adequately informed about the sharing of their personal information with Equifax. Canada Post implemented the OPC's recommendations to improve transparency.

Quick view

Privacy ActNot well-founded

Canada Post Sharing Personal Information with Credit Bureau

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A man complained that Canada Post checked his credit rating when he requested an online change of address. The OPC investigated whether Canada Post's practice of using Equifax for identity verification in online change-of-address requests violated the Privacy Act. The OPC found that Canada Post has a legitimate need to confirm identity to prevent identity theft and that it does not conduct a credit verification. However, the OPC was concerned that individuals were not adequately informed about the sharing of their personal information with Equifax. Canada Post implemented the OPC's recommendations to improve transparency.

Key Issues
  • Whether Canada Post's use of Equifax for identity verification constituted a credit check
  • Whether Canada Post had the statutory authority to collect personal information for identity verification
  • Whether individuals were adequately informed about the sharing of their personal information with Equifax
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

Mix-up by Immigration Officials Discloses Personal Information

Citizenship and Immigration Canada

A Canadian woman complained after her personal information, including her passport and income tax assessment, was disclosed to a Bangladeshi man whose work permit application she was supporting. The woman had sent these documents via her MP to the Canadian High Commission in Dhaka. When the man's application was refused, the High Commission returned the entire file, including the woman's documents, to him. Citizenship and Immigration Canada acknowledged the disclosure was made without consent and should not have occurred. The OPC found the complaint to be well-founded and recommended that all High Commissions implement a system to distinguish and prevent the return of third-party documents to applicants.

Quick view

Privacy ActWell-founded

Mix-up by Immigration Officials Discloses Personal Information

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A Canadian woman complained after her personal information, including her passport and income tax assessment, was disclosed to a Bangladeshi man whose work permit application she was supporting. The woman had sent these documents via her MP to the Canadian High Commission in Dhaka. When the man's application was refused, the High Commission returned the entire file, including the woman's documents, to him. Citizenship and Immigration Canada acknowledged the disclosure was made without consent and should not have occurred. The OPC found the complaint to be well-founded and recommended that all High Commissions implement a system to distinguish and prevent the return of third-party documents to applicants.

Key Issues
  • Whether Citizenship and Immigration Canada disclosed personal information without consent
  • Whether the disclosure of personal information was in contravention of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

Mystery of How Newspaper Identified Boat Refugee

Canada Border Services Agency, Canadian Security Intelligence Service, Citizenship and Immigration Canada, and Royal Canadian Mounted Police

A complaint was filed on behalf of a refugee, alleging that personal information about him was disclosed to a National Post reporter. The refugee was a passenger on the 'Ocean Lady' and was later identified in a news story as a fugitive sought by INTERPOL. The complainant named four federal institutions as potentially responsible for the disclosure: the Canada Border Services Agency, the Canadian Security Intelligence Service, Citizenship and Immigration Canada, and the Royal Canadian Mounted Police. The OPC's investigation confirmed the individual was a wanted fugitive with publicly available INTERPOL information. Due to journalistic confidentiality, the OPC could not determine how the reporter obtained the information. In the absence of evidence, the OPC found no support for the allegation that any of the named institutions disclosed the information.

Quick view

Privacy ActNot well-founded

Mystery of How Newspaper Identified Boat Refugee

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complaint was filed on behalf of a refugee, alleging that personal information about him was disclosed to a National Post reporter. The refugee was a passenger on the 'Ocean Lady' and was later identified in a news story as a fugitive sought by INTERPOL. The complainant named four federal institutions as potentially responsible for the disclosure: the Canada Border Services Agency, the Canadian Security Intelligence Service, Citizenship and Immigration Canada, and the Royal Canadian Mounted Police. The OPC's investigation confirmed the individual was a wanted fugitive with publicly available INTERPOL information. Due to journalistic confidentiality, the OPC could not determine how the reporter obtained the information. In the absence of evidence, the OPC found no support for the allegation that any of the named institutions disclosed the information.

Key Issues
  • Whether any of the named federal institutions disclosed personal information about a refugee to a newspaper reporter
  • Whether the publicly available INTERPOL notice constituted a disclosure by the institutions
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 4, 2012Indexed Jun 30, 2026

Inmate Medical Details Openly Displayed

Correctional Service of Canada

An inmate complained that the Correctional Service of Canada (CSC) contravened the Privacy Act by openly posting details of medical appointments. The postings included his name, appointment time, and partial offender number, which were visible to the general penitentiary population. The inmate also alleged similar disclosures for other inmates, including complete offender numbers and other medical information. The CSC acknowledged the breach and committed to notifying inmates individually rather than posting lists. However, the CSC did not agree to use only partial offender numbers on internal employee lists for notifications. The OPC upheld the complaint as well-founded.

Quick view

Privacy ActWell-founded

Inmate Medical Details Openly Displayed

Oct 4, 2012
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An inmate complained that the Correctional Service of Canada (CSC) contravened the Privacy Act by openly posting details of medical appointments. The postings included his name, appointment time, and partial offender number, which were visible to the general penitentiary population. The inmate also alleged similar disclosures for other inmates, including complete offender numbers and other medical information. The CSC acknowledged the breach and committed to notifying inmates individually rather than posting lists. However, the CSC did not agree to use only partial offender numbers on internal employee lists for notifications. The OPC upheld the complaint as well-founded.

Key Issues
  • Whether the open posting of inmate medical appointment details constituted an unauthorized disclosure of personal information under the Privacy Act
  • Whether the Correctional Service of Canada contravened the Privacy Act by disclosing inmate names, appointment times, and offender numbers to the general penitentiary population
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 22, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-004Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account

A cellular-telephone service provider

An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account

Aug 22, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-004
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.

Key Issues
  • Whether the cellular service provider disclosed personal information without consent to an imposter, contravening Principle 4.3 PIPEDA
  • Whether the cellular service provider adequately responded to the complainant's access request for personal information under Principle 4.9 PIPEDA
  • Whether the cellular service provider responded to the access request within the 30-day timeframe as per s.8(3) PIPEDA
  • Whether the redaction of the CSR's name from the transcript was permissible under s.9(1) PIPEDA
  • Whether the company was required to provide an audio recording of the conversation in addition to a transcript under s.10 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 14, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-010Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings # 2012-010: Telecommunications firm adopts additional accountability measures to ensure a consistent approach in handling access requests

A telecommunications firm

A complainant alleged that a telecommunications firm failed to provide her with access to her personal information, specifically notes and transcripts of recorded conversations related to an account dispute. The firm acknowledged receiving the access request but mistakenly believed it was not necessary to provide the information due to ongoing settlement negotiations. The OPC found that the firm failed to respond to the access request within 30 days and did not issue an extension notice, thus contravening PIPEDA subsections 8(3), 8(4), and 8(5). Furthermore, the firm purged the requested audio records, violating subsection 8(8) and Principles 4.9 and 4.9.4. The firm's internal policies were found to be unclear and staff training inadequate, leading to the erroneous deletion of records. The OPC made several recommendations, which the firm accepted and implemented, including amending policies and providing staff training. As a result, the complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings # 2012-010: Telecommunications firm adopts additional accountability measures to ensure a consistent approach in handling access requests

Aug 14, 2012Commissioner’s Findings - PIPEDA Report of Findings # 2012-010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a telecommunications firm failed to provide her with access to her personal information, specifically notes and transcripts of recorded conversations related to an account dispute. The firm acknowledged receiving the access request but mistakenly believed it was not necessary to provide the information due to ongoing settlement negotiations. The OPC found that the firm failed to respond to the access request within 30 days and did not issue an extension notice, thus contravening PIPEDA subsections 8(3), 8(4), and 8(5). Furthermore, the firm purged the requested audio records, violating subsection 8(8) and Principles 4.9 and 4.9.4. The firm's internal policies were found to be unclear and staff training inadequate, leading to the erroneous deletion of records. The OPC made several recommendations, which the firm accepted and implemented, including amending policies and providing staff training. As a result, the complaint was deemed well-founded and resolved.

Key Issues
  • Whether the telecommunications firm responded to the access request within the 30-day time limit under subsection 8(3) PIPEDA
  • Whether the telecommunications firm issued a notice of extension for the access request under subsection 8(4) PIPEDA
  • Whether the telecommunications firm was deemed to have refused the access request under subsection 8(5) PIPEDA
  • Whether the telecommunications firm provided access to personal information as required by Principle 4.9 PIPEDA
  • Whether the telecommunications firm responded to the access request within a reasonable time and at minimal or no cost under Principle 4.9.4 PIPEDA
  • Whether the telecommunications firm retained personal information that was the subject of an access request for as long as necessary to allow the individual to exhaust any recourse under subsection 8(8) PIPEDA
  • Whether the telecommunications firm implemented policies and practices to give effect to the principles, including training staff and communicating policies and practices under Principle 4.1.4(c) PIPEDA
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Driver’s licence suitable ID for postal box rental

Canada Post

An individual complained that Canada Post required his driver's licence number to terminate his postal box rental. Canada Post stated it requires personal identification to prevent fraudulent use or closure of postal boxes and has used recorded ID to investigate illegal shipments. The OPC's investigation found that Canada Post has a statutory obligation to provide a secure postal service. The collection and use of personal information, including driver's licence numbers, was deemed consistent with this mandate. The OPC concluded that the collection of identification numbers was reasonable. The complaint was dismissed as not well-founded.

Quick view

Privacy ActNot well-founded

Driver’s licence suitable ID for postal box rental

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Canada Post required his driver's licence number to terminate his postal box rental. Canada Post stated it requires personal identification to prevent fraudulent use or closure of postal boxes and has used recorded ID to investigate illegal shipments. The OPC's investigation found that Canada Post has a statutory obligation to provide a secure postal service. The collection and use of personal information, including driver's licence numbers, was deemed consistent with this mandate. The OPC concluded that the collection of identification numbers was reasonable. The complaint was dismissed as not well-founded.

Key Issues
  • Whether requiring a driver's licence number to terminate a postal box rental is a reasonable collection of personal information under PIPEDA
  • Whether Canada Post's collection and use of personal information for security purposes is consistent with its statutory obligations
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Prison to put sensitive mail in envelopes after document intercepted

Correctional Service of Canada (Kent Institution)

An inmate at Kent Institution complained after a 10-page National Parole Board decision containing graphic details of his offence was intercepted and circulated among other inmates. The document was supposed to be delivered via internal mail but was only folded and stapled, not placed in an envelope. Prison officials acknowledged the breach and launched an investigation, which confirmed the document was viewed by various inmates. The OPC's investigation found that the disclosure violated the Privacy Act. As a result, the warden implemented changes to ensure confidential documents are now placed in sealed envelopes.

Quick view

Privacy ActWell-founded

Prison to put sensitive mail in envelopes after document intercepted

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An inmate at Kent Institution complained after a 10-page National Parole Board decision containing graphic details of his offence was intercepted and circulated among other inmates. The document was supposed to be delivered via internal mail but was only folded and stapled, not placed in an envelope. Prison officials acknowledged the breach and launched an investigation, which confirmed the document was viewed by various inmates. The OPC's investigation found that the disclosure violated the Privacy Act. As a result, the warden implemented changes to ensure confidential documents are now placed in sealed envelopes.

Key Issues
  • Whether the disclosure of the inmate's National Parole Board decision to other inmates violated the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Canada Post demands too much information for leave requests

Canada Post

An individual complained that Canada Post collected excessive personal information for special paid leave requests to care for an ailing relative. The application form, intended for supervisors, was mistakenly given to the complainant to complete, requiring extensive personal information about herself, the ill person, and third parties. Canada Post argued that arbitration rulings and fraud prevention concerns necessitated the collection of substantial information. The OPC found that more personal information was collected than necessary to establish leave entitlement, particularly regarding third parties. The complaint was upheld as well-founded, and the OPC recommended measures to address privacy concerns. Canada Post agreed to some changes, but insisted on collecting information about other family members working at Canada Post, which the OPC still had reservations about.

Quick view

Privacy ActWell-founded

Canada Post demands too much information for leave requests

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Canada Post collected excessive personal information for special paid leave requests to care for an ailing relative. The application form, intended for supervisors, was mistakenly given to the complainant to complete, requiring extensive personal information about herself, the ill person, and third parties. Canada Post argued that arbitration rulings and fraud prevention concerns necessitated the collection of substantial information. The OPC found that more personal information was collected than necessary to establish leave entitlement, particularly regarding third parties. The complaint was upheld as well-founded, and the OPC recommended measures to address privacy concerns. Canada Post agreed to some changes, but insisted on collecting information about other family members working at Canada Post, which the OPC still had reservations about.

Key Issues
  • Whether Canada Post collected excessive personal information for special paid leave requests
  • Whether the information collected about third parties was necessary
  • Whether the collection of information about other family members working at Canada Post was justified for fraud prevention
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Letter carrier accuses boss of intercepting and reading a document

Canada Post

A Canada Post letter carrier complained that his supervisor accessed and used his medical information without authorization. The complainant alleged he gave a sealed medical form for a disability insurance claim to his supervisor to forward to the insurer, but the supervisor opened and read it. The supervisor admitted she might have read the form but denied opening a sealed envelope. The investigation could not confirm if the envelope was sealed, but it did confirm the supervisor used the health information to challenge other medical documentation provided by the employee. The OPC concluded that the personal information was used for an inconsistent purpose without permission, finding the complaint well-founded. The OPC recommended Canada Post remind staff to submit forms directly to the insurer and managers to refuse to accept such forms.

Quick view

Privacy ActWell-founded

Letter carrier accuses boss of intercepting and reading a document

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A Canada Post letter carrier complained that his supervisor accessed and used his medical information without authorization. The complainant alleged he gave a sealed medical form for a disability insurance claim to his supervisor to forward to the insurer, but the supervisor opened and read it. The supervisor admitted she might have read the form but denied opening a sealed envelope. The investigation could not confirm if the envelope was sealed, but it did confirm the supervisor used the health information to challenge other medical documentation provided by the employee. The OPC concluded that the personal information was used for an inconsistent purpose without permission, finding the complaint well-founded. The OPC recommended Canada Post remind staff to submit forms directly to the insurer and managers to refuse to accept such forms.

Key Issues
  • Whether the supervisor gained unauthorized access to the medical form
  • Whether the personal information was used for a purpose inconsistent with its collection
  • Whether the use of information was without the complainant's permission
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Health Canada erred in withholding personal information

Health Canada

An individual complained after Health Canada refused to provide him with personal information collected during a fitness-for-work evaluation. Health Canada cited section 28 of the Privacy Act, arguing that disclosing information related to his physical or mental health would be contrary to his best interests. The OPC's investigation found that the requested information was not limited to sensitive health records. Therefore, section 28 did not provide a valid reason to withhold access. The complaint was upheld as well-founded, and Health Canada subsequently agreed to release the information, leading to a resolved outcome.

Quick view

Privacy ActWell-founded

Health Canada erred in withholding personal information

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained after Health Canada refused to provide him with personal information collected during a fitness-for-work evaluation. Health Canada cited section 28 of the Privacy Act, arguing that disclosing information related to his physical or mental health would be contrary to his best interests. The OPC's investigation found that the requested information was not limited to sensitive health records. Therefore, section 28 did not provide a valid reason to withhold access. The complaint was upheld as well-founded, and Health Canada subsequently agreed to release the information, leading to a resolved outcome.

Key Issues
  • Whether Health Canada erred in withholding personal information
  • Whether section 28 of the Privacy Act applied to the requested information
  • Whether the information was confined to sensitive records related to mental or physical health
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Custodian of Social Insurance Numbers loses list of them

Human Resources and Skills Development Canada (HRSDC)

A woman complained to the OPC after an attendance sheet containing her Social Insurance Number (SIN), name, and telephone number, along with those of 31 other employment insurance (EI) claimants, went missing from an HRSDC information session. HRSDC officials notified affected individuals, apologized, and provided information on identity theft protection. The OPC investigated and found that HRSDC had failed to properly safeguard the personal information. The OPC was particularly concerned that the breach involved SINs, which are highly vulnerable to misuse. HRSDC subsequently directed officials to black out SINs on attendance sheets for future sessions.

Quick view

Privacy ActWell-founded

Custodian of Social Insurance Numbers loses list of them

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained to the OPC after an attendance sheet containing her Social Insurance Number (SIN), name, and telephone number, along with those of 31 other employment insurance (EI) claimants, went missing from an HRSDC information session. HRSDC officials notified affected individuals, apologized, and provided information on identity theft protection. The OPC investigated and found that HRSDC had failed to properly safeguard the personal information. The OPC was particularly concerned that the breach involved SINs, which are highly vulnerable to misuse. HRSDC subsequently directed officials to black out SINs on attendance sheets for future sessions.

Key Issues
  • Whether Human Resources and Skills Development Canada (HRSDC) properly safeguarded personal information, specifically Social Insurance Numbers (SINs), names, and telephone numbers, on an attendance sheet at an employment insurance information session.