The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,631 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Psychiatric nurse forgets ex-inmate’s treatment file on bus

Correctional Service of Canada (Keele Community Correctional Centre)

A former inmate at Toronto's Keele Community Correctional Centre complained after a psychiatric nurse employed by the facility left an envelope containing his treatment notes on public transit. The director of the centre acknowledged the privacy breach, apologized, and stated that internal actions were taken to prevent recurrence. The nurse was reminded of his duty to safeguard personal information and not to transport patient files from the office unless encrypted. The OPC's investigation confirmed the privacy breach and found the complaint to be well-founded. However, the OPC also concluded that the facility had taken appropriate corrective measures following the incident.

Quick view

Privacy ActWell-founded

Psychiatric nurse forgets ex-inmate’s treatment file on bus

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A former inmate at Toronto's Keele Community Correctional Centre complained after a psychiatric nurse employed by the facility left an envelope containing his treatment notes on public transit. The director of the centre acknowledged the privacy breach, apologized, and stated that internal actions were taken to prevent recurrence. The nurse was reminded of his duty to safeguard personal information and not to transport patient files from the office unless encrypted. The OPC's investigation confirmed the privacy breach and found the complaint to be well-founded. However, the OPC also concluded that the facility had taken appropriate corrective measures following the incident.

Key Issues
  • Whether the psychiatric nurse's actions constituted a privacy breach
  • Whether the institution took appropriate corrective measures after the breach
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Hiring program for ex-military staff makes proper use of information

Public Service Commission of Canada

An individual complained that the Public Service Commission of Canada (PSC) improperly collected and disclosed personal information about his medical release from the Canadian Forces. This information was collected for a program that grants priority consideration to former military personnel for federal public service positions. The OPC's investigation found that the complainant had provided written consent for the collection and disclosure of his medical release record for this specific hiring program. All aspects of the process were determined to be in full conformity with the Privacy Act. Consequently, the complaint was dismissed.

Quick view

Privacy ActNot well-founded

Hiring program for ex-military staff makes proper use of information

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that the Public Service Commission of Canada (PSC) improperly collected and disclosed personal information about his medical release from the Canadian Forces. This information was collected for a program that grants priority consideration to former military personnel for federal public service positions. The OPC's investigation found that the complainant had provided written consent for the collection and disclosure of his medical release record for this specific hiring program. All aspects of the process were determined to be in full conformity with the Privacy Act. Consequently, the complaint was dismissed.

Key Issues
  • Whether the Public Service Commission of Canada improperly collected personal information about the complainant's medical release from the Canadian Forces
  • Whether the Public Service Commission of Canada improperly disclosed personal information about the complainant's medical release from the Canadian Forces
  • Whether the collection and disclosure of personal information conformed with the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Minister’s suspicions about Wheat Board leaks unfounded

Canadian Wheat Board

The Minister of Agriculture and Agri-Food Canada filed a privacy complaint against the Canadian Wheat Board (CWB) following media reports about an internal audit. The audit raised concerns about potential improper disclosure of farmers' personal information, including Social Insurance Numbers (SINs), to third parties like grain handlers and the Canada Revenue Agency. The OPC's investigation found that the CWB had appropriate protocols, procedures, and agreements in place to manage personal information. Specifically, the CWB did not disclose SINs to third parties and only shared personal data with the tax agency when legally required. Consequently, the complaint was dismissed as not well-founded.

Quick view

Privacy ActNot well-founded

Minister’s suspicions about Wheat Board leaks unfounded

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Minister of Agriculture and Agri-Food Canada filed a privacy complaint against the Canadian Wheat Board (CWB) following media reports about an internal audit. The audit raised concerns about potential improper disclosure of farmers' personal information, including Social Insurance Numbers (SINs), to third parties like grain handlers and the Canada Revenue Agency. The OPC's investigation found that the CWB had appropriate protocols, procedures, and agreements in place to manage personal information. Specifically, the CWB did not disclose SINs to third parties and only shared personal data with the tax agency when legally required. Consequently, the complaint was dismissed as not well-founded.

Key Issues
  • Whether the Canadian Wheat Board improperly disclosed farmers' Social Insurance Numbers (SINs) to third parties
  • Whether the Canadian Wheat Board improperly disclosed other personal information of farmers to third parties
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Nov 17, 2011Indexed Jun 30, 2026

Errant report sparks procedural changes at prison

Correctional Service of Canada

Two prisoners at the Correctional Service of Canada’s Grande Cache Institution filed complaints after a prison report containing their personal information was found among a fellow inmate's personal effects. An investigation revealed that a contract worker had printed the report, which listed personal information of all inmates, and given it to a welding instructor. The report was later discovered in an offender's belongings, though it was unclear how it got there. Correctional Service officials acknowledged the privacy breach and implemented several corrective measures, including restricting the printing of such reports and reinforcing training on safeguarding personal information. The OPC's investigation confirmed a breach of the complainants' privacy rights. Due to the corrective actions already taken, the OPC did not require further action.

Quick view

Privacy ActWell-founded

Errant report sparks procedural changes at prison

Nov 17, 2011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

Two prisoners at the Correctional Service of Canada’s Grande Cache Institution filed complaints after a prison report containing their personal information was found among a fellow inmate's personal effects. An investigation revealed that a contract worker had printed the report, which listed personal information of all inmates, and given it to a welding instructor. The report was later discovered in an offender's belongings, though it was unclear how it got there. Correctional Service officials acknowledged the privacy breach and implemented several corrective measures, including restricting the printing of such reports and reinforcing training on safeguarding personal information. The OPC's investigation confirmed a breach of the complainants' privacy rights. Due to the corrective actions already taken, the OPC did not require further action.

Key Issues
  • Whether the personal information of inmates was inappropriately disclosed
  • Whether the Correctional Service of Canada adequately safeguarded personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 30, 2011Commissioner’s Findings - PIPEDA Report of Findings #2011-011Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2011-011: Public opinion research firm must better inform survey respondents about their personal information use; refrain from collecting full birth dates

A public opinion research firm

A complainant alleged that a public opinion research firm unnecessarily collected her full date of birth and failed to adequately inform her about the purpose of a profiling survey. The firm collected full birth dates for demographic purposes and to verify identity, arguing that month and year alone were insufficient. The OPC found that collecting the full date of birth was not necessary for the firm's stated purposes and that the consent language for profiling surveys was not sufficiently clear. While the firm agreed to clarify its consent language, it refused to stop collecting or delete the day of birth from its records. Consequently, the OPC found the complaint well-founded but partially unresolved regarding the collection of full birth dates.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Commissioner’s Findings - PIPEDA Report of Findings #2011-011: Public opinion research firm must better inform survey respondents about their personal information use; refrain from collecting full birth dates

Jun 30, 2011Commissioner’s Findings - PIPEDA Report of Findings #2011-011
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a public opinion research firm unnecessarily collected her full date of birth and failed to adequately inform her about the purpose of a profiling survey. The firm collected full birth dates for demographic purposes and to verify identity, arguing that month and year alone were insufficient. The OPC found that collecting the full date of birth was not necessary for the firm's stated purposes and that the consent language for profiling surveys was not sufficiently clear. While the firm agreed to clarify its consent language, it refused to stop collecting or delete the day of birth from its records. Consequently, the OPC found the complaint well-founded but partially unresolved regarding the collection of full birth dates.

Key Issues
  • Whether it is necessary for the Respondent to collect all three elements of the date of birth at registration
  • Whether it is necessary for the Respondent to confirm all three elements of the date of birth in profiling surveys
  • Whether the Respondent adequately informed the complainant of the purpose of the profiling survey
  • Whether consent under Principle 4.3 was meaningful
  • Whether the collection of personal information was limited to that which is necessary for the identified purposes under Principle 4.4
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 6, 2010Indexed Jun 30, 2026

Veteran’s complaint highlights significant privacy issues - October 6, 2010

Veterans Affairs Canada

A veteran complained that Veterans Affairs Canada (VAC) inappropriately used his personal information by including excessive medical details in briefing notes for the Minister and by transferring his medical file to a hospital without consent. The OPC investigation found that briefing notes contained sensitive medical information far beyond what was necessary for their stated purpose and that this information was widely shared within VAC on a non-need-to-know basis. It also found that VAC transferred the complainant's medical file to a hospital it administered without obtaining his consent, despite departmental guidelines requiring it. The OPC concluded that VAC's actions violated section 7 of the Privacy Act, which governs the use of personal information. The complaint was found to be well-founded, and the OPC issued several recommendations to VAC, including developing an enhanced privacy policy framework, revising information-management practices, providing employee training, and reviewing consent procedures for information transfers.

Quick view

Privacy ActWell-founded

Veteran’s complaint highlights significant privacy issues - October 6, 2010

Oct 6, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A veteran complained that Veterans Affairs Canada (VAC) inappropriately used his personal information by including excessive medical details in briefing notes for the Minister and by transferring his medical file to a hospital without consent. The OPC investigation found that briefing notes contained sensitive medical information far beyond what was necessary for their stated purpose and that this information was widely shared within VAC on a non-need-to-know basis. It also found that VAC transferred the complainant's medical file to a hospital it administered without obtaining his consent, despite departmental guidelines requiring it. The OPC concluded that VAC's actions violated section 7 of the Privacy Act, which governs the use of personal information. The complaint was found to be well-founded, and the OPC issued several recommendations to VAC, including developing an enhanced privacy policy framework, revising information-management practices, providing employee training, and reviewing consent procedures for information transfers.

Key Issues
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by including excessive medical details in briefing notes for the Minister.
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by widely sharing sensitive personal information within the department on a non-need-to-know basis.
  • Whether Veterans Affairs Canada used the complainant's personal information for purposes not consistent with the purpose for which it was obtained or compiled, without consent, in contravention of section 7 of the Privacy Act, by transferring his medical file to a hospital without obtaining his consent.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Innocent targets of whistleblower law should learn of vindication

Public Works and Government Services Canada

A public servant complained that Public Works and Government Services Canada (PWGSC) refused to provide her with personal information collected during an investigation under the Public Servants Disclosure Protection Act, which had exonerated her. The OPC found that PWGSC correctly applied section 22.3 of the Privacy Act, which mandates refusal to disclose information created for whistleblower disclosures or related investigations. Therefore, the complaint was not well-founded regarding access to information. However, the OPC was concerned that individuals cleared of wrongdoing were not informed of their vindication. The OPC urged PWGSC to inform subjects when allegations are unsubstantiated, and PWGSC subsequently did so for the complainant. The Commissioner also asked the Treasury Board Secretariat to develop guidelines for all departments to inform individuals when allegations of wrongdoing are unsubstantiated, citing procedural fairness and natural justice.

Quick view

Privacy ActNot well-founded

Innocent targets of whistleblower law should learn of vindication

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A public servant complained that Public Works and Government Services Canada (PWGSC) refused to provide her with personal information collected during an investigation under the Public Servants Disclosure Protection Act, which had exonerated her. The OPC found that PWGSC correctly applied section 22.3 of the Privacy Act, which mandates refusal to disclose information created for whistleblower disclosures or related investigations. Therefore, the complaint was not well-founded regarding access to information. However, the OPC was concerned that individuals cleared of wrongdoing were not informed of their vindication. The OPC urged PWGSC to inform subjects when allegations are unsubstantiated, and PWGSC subsequently did so for the complainant. The Commissioner also asked the Treasury Board Secretariat to develop guidelines for all departments to inform individuals when allegations of wrongdoing are unsubstantiated, citing procedural fairness and natural justice.

Key Issues
  • Whether the complainant had a right to access personal information collected during a whistleblower investigation
  • Whether section 22.3 of the Privacy Act was correctly applied to refuse disclosure
  • Whether individuals cleared of wrongdoing in whistleblower investigations should be informed of their vindication
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Personal data of 191 EI claimants disclosed

Human Resources and Skills Development Canada

The Office of the Privacy Commissioner of Canada (OPC) received 82 complaints after Human Resources and Skills Development Canada (HRSDC) inadvertently disclosed the personal information of 191 Employment Insurance (EI) claimants to another individual. The disclosure occurred when an individual appealing an EI claim denial received an appeal docket that included names, dates of birth, employee identification numbers, and Social Insurance Numbers of 191 fellow employees, along with a second list of employment and leave statuses. The OPC's investigation confirmed that in 79 instances, the information was indeed released, leading to well-founded findings. HRSDC took immediate steps to retrieve the data, notify affected parties, and advise on identity theft prevention. They also implemented measures to prevent future recurrences, including reminding officials of proper procedures for protecting personal information during appeals.

Quick view

Privacy ActWell-founded

Personal data of 191 EI claimants disclosed

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) received 82 complaints after Human Resources and Skills Development Canada (HRSDC) inadvertently disclosed the personal information of 191 Employment Insurance (EI) claimants to another individual. The disclosure occurred when an individual appealing an EI claim denial received an appeal docket that included names, dates of birth, employee identification numbers, and Social Insurance Numbers of 191 fellow employees, along with a second list of employment and leave statuses. The OPC's investigation confirmed that in 79 instances, the information was indeed released, leading to well-founded findings. HRSDC took immediate steps to retrieve the data, notify affected parties, and advise on identity theft prevention. They also implemented measures to prevent future recurrences, including reminding officials of proper procedures for protecting personal information during appeals.

Key Issues
  • Whether Human Resources and Skills Development Canada inadvertently disclosed personal information of EI claimants
  • Whether the disclosure of names, dates of birth, employee identification numbers, and Social Insurance Numbers constituted a contravention of the Privacy Act
  • Whether the disclosure of employment and leave status constituted a contravention of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Mechanical malfunction, compounded by human error, leads to data spill

Human Resources and Skills Development Canada

In March 2009, Human Resources and Skills Development Canada (HRSDC) mailed 11,900 forms for the Guaranteed Income Supplement. Due to a mechanical malfunction and human error, some individuals received forms intended for others, containing names, addresses, and Social Insurance Numbers (SINs). The OPC initiated a complaint after HRSDC notified them of 44 reported cases of mix-ups. The investigation found that a technician failed to stop the mailing despite noticing errors and did not report the issue to management. The OPC determined the complaint was well-founded, highlighting both mechanical failure and human error. HRSDC conducted its own investigation, improved equipment, and strengthened quality control procedures. The OPC recommended better employee sensitization to privacy obligations, which HRSDC committed to implementing.

Quick view

Privacy ActWell-founded

Mechanical malfunction, compounded by human error, leads to data spill

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

In March 2009, Human Resources and Skills Development Canada (HRSDC) mailed 11,900 forms for the Guaranteed Income Supplement. Due to a mechanical malfunction and human error, some individuals received forms intended for others, containing names, addresses, and Social Insurance Numbers (SINs). The OPC initiated a complaint after HRSDC notified them of 44 reported cases of mix-ups. The investigation found that a technician failed to stop the mailing despite noticing errors and did not report the issue to management. The OPC determined the complaint was well-founded, highlighting both mechanical failure and human error. HRSDC conducted its own investigation, improved equipment, and strengthened quality control procedures. The OPC recommended better employee sensitization to privacy obligations, which HRSDC committed to implementing.

Key Issues
  • Whether personal information was inappropriately disclosed due to mechanical malfunction
  • Whether personal information was inappropriately disclosed due to human error
  • Whether the institution adequately safeguarded personal information during mass mailings
  • Whether employees were sufficiently sensitized to their obligations to safeguard personal information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Internet posting highlights inappropriate access to tax records by CRA workers

Canada Revenue Agency (CRA)

The Commissioner initiated an investigation following media allegations that a Canada Revenue Agency (CRA) employee posted personal tax information of high-profile sports figures to an Internet chat group. The investigation confirmed that a former CRA employee had posted such information, and that other CRA employees had inappropriately accessed the tax information of these athletes, likely out of curiosity. While there was no evidence that these employees disclosed the information to outside sources, accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act. Consequently, the portion of the complaint concerning the improper use of personal information by CRA employees was found to be well-founded. The CRA took corrective measures, including suspending one employee, firing two others, and modernizing its audit trail system to monitor access to taxpayer information.

Quick view

Privacy ActWell-founded

Internet posting highlights inappropriate access to tax records by CRA workers

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Commissioner initiated an investigation following media allegations that a Canada Revenue Agency (CRA) employee posted personal tax information of high-profile sports figures to an Internet chat group. The investigation confirmed that a former CRA employee had posted such information, and that other CRA employees had inappropriately accessed the tax information of these athletes, likely out of curiosity. While there was no evidence that these employees disclosed the information to outside sources, accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act. Consequently, the portion of the complaint concerning the improper use of personal information by CRA employees was found to be well-founded. The CRA took corrective measures, including suspending one employee, firing two others, and modernizing its audit trail system to monitor access to taxpayer information.

Key Issues
  • Whether CRA employees inappropriately accessed personal tax information
  • Whether CRA employees disclosed personal tax information to outside sources
  • Whether accessing personal tax information without authorization and for purposes unrelated to duties constitutes a breach of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Toronto Port Authority worker misuses personal data for political fundraiser

Toronto Port Authority

A Member of Parliament complained that an employee of the Toronto Port Authority (TPA) misused the organization's email database to invite people to a political fundraising event. The investigation found that a TPA employee sent an email to approximately 60 people, soliciting donations and inviting participation in a fundraiser for another MP. The employee obtained these email addresses from business cards collected by the TPA, including both business and personal addresses. The OPC determined that the employee used this personal information without the TPA's knowledge or authorization and for reasons unrelated to the organization's business activities. The complaint was found to be well-founded, but the TPA took corrective measures, including reminding employees of their responsibilities and pledging Privacy Act training.

Quick view

Privacy ActWell-founded

Toronto Port Authority worker misuses personal data for political fundraiser

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A Member of Parliament complained that an employee of the Toronto Port Authority (TPA) misused the organization's email database to invite people to a political fundraising event. The investigation found that a TPA employee sent an email to approximately 60 people, soliciting donations and inviting participation in a fundraiser for another MP. The employee obtained these email addresses from business cards collected by the TPA, including both business and personal addresses. The OPC determined that the employee used this personal information without the TPA's knowledge or authorization and for reasons unrelated to the organization's business activities. The complaint was found to be well-founded, but the TPA took corrective measures, including reminding employees of their responsibilities and pledging Privacy Act training.

Key Issues
  • Whether a Toronto Port Authority employee misused personal information for a political fundraiser
  • Whether email addresses obtained from business cards constitute personal information
  • Whether the use of personal information was without the knowledge or authorization of the institution
  • Whether the use of personal information was for reasons unrelated to the organization's business activities
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

Border authority absolved of improperly gathering personal data from blog

Canada Border Services Agency (CBSA)

An individual complained that the Canada Border Services Agency (CBSA) improperly collected information from his personal online blog after his term position ended. The complainant alleged that his tracking device showed visits from government computers. The OPC investigated whether the CBSA had inappropriately collected personal information. The investigation found that several CBSA employees had viewed the blog, but did so in a personal capacity, which was deemed to accord with the government's Acceptable Use Policy. The OPC found no evidence that the agency had collected personal information in connection with these visits. Therefore, the complaints were determined to be not well-founded.

Quick view

Privacy ActNot well-founded

Border authority absolved of improperly gathering personal data from blog

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that the Canada Border Services Agency (CBSA) improperly collected information from his personal online blog after his term position ended. The complainant alleged that his tracking device showed visits from government computers. The OPC investigated whether the CBSA had inappropriately collected personal information. The investigation found that several CBSA employees had viewed the blog, but did so in a personal capacity, which was deemed to accord with the government's Acceptable Use Policy. The OPC found no evidence that the agency had collected personal information in connection with these visits. Therefore, the complaints were determined to be not well-founded.

Key Issues
  • Whether the Canada Border Services Agency improperly collected personal information from the complainant's blog
  • Whether employees viewing a public blog from government workstations constitutes collection of personal information by the agency
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 5, 2010Indexed Jun 30, 2026

RCMP and private polling firm safeguarded data on gun licensees

Royal Canadian Mounted Police (RCMP)

The Commissioner initiated a complaint against the RCMP regarding its handling of personal information collected by the Canadian Firearms Program and used by EKOS Research Associates Inc. to survey firearms licensees. The RCMP provided contact information to EKOS, which then collected demographic data and information on guns owned by respondents. The investigation found that EKOS did not provide identifying data in its report to the firearms program and met all contractual requirements for secure data handling. The Assistant Commissioner determined that the collection and use of information for a client-satisfaction survey was consistent with the purpose for which it was initially collected under the Privacy Act. The RCMP was also found compliant in providing information to EKOS, as the contract included appropriate confidentiality and security provisions. The complaint was therefore deemed not well-founded, though the OPC recommended the RCMP clarify its public information on data uses and conduct Privacy Impact Assessments.

Quick view

Privacy ActNot well-founded

RCMP and private polling firm safeguarded data on gun licensees

Oct 5, 2010
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Commissioner initiated a complaint against the RCMP regarding its handling of personal information collected by the Canadian Firearms Program and used by EKOS Research Associates Inc. to survey firearms licensees. The RCMP provided contact information to EKOS, which then collected demographic data and information on guns owned by respondents. The investigation found that EKOS did not provide identifying data in its report to the firearms program and met all contractual requirements for secure data handling. The Assistant Commissioner determined that the collection and use of information for a client-satisfaction survey was consistent with the purpose for which it was initially collected under the Privacy Act. The RCMP was also found compliant in providing information to EKOS, as the contract included appropriate confidentiality and security provisions. The complaint was therefore deemed not well-founded, though the OPC recommended the RCMP clarify its public information on data uses and conduct Privacy Impact Assessments.

Key Issues
  • Whether the collection of personal information by the Canadian Firearms Program for a client-satisfaction survey was consistent with the purpose for which it was initially collected under the Privacy Act
  • Whether the disclosure of personal information by the RCMP to EKOS Research Associates Inc. for the survey was compliant with the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jan 6, 2010Settled Case summary #2010-001Indexed Jun 30, 2026

Settled Case summary #2010-001: Dental benefit information available to parents with daughter’s consent (January 6, 2010)

A dental plan administrator

The parents of a 17-year-old dependent complained that they could not access their daughter's online dental benefit information from their group dental plan administrator. The administrator's policy required consent from individuals aged 16 or older before their information could be accessed by another plan member, even parents. The administrator defended its policy by citing PIPEDA's consent requirements, the lack of a national age of majority consensus, and the distinction between age of majority and age of consent. The policy was based on the Ontario Health Care Consent Act, which suggests 16 as an age for health care consent. The mother was satisfied with the explanation and understood that she could access her daughter's account if her daughter provided consent by sharing her password.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #2010-001: Dental benefit information available to parents with daughter’s consent (January 6, 2010)

Jan 6, 2010Settled Case summary #2010-001
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The parents of a 17-year-old dependent complained that they could not access their daughter's online dental benefit information from their group dental plan administrator. The administrator's policy required consent from individuals aged 16 or older before their information could be accessed by another plan member, even parents. The administrator defended its policy by citing PIPEDA's consent requirements, the lack of a national age of majority consensus, and the distinction between age of majority and age of consent. The policy was based on the Ontario Health Care Consent Act, which suggests 16 as an age for health care consent. The mother was satisfied with the explanation and understood that she could access her daughter's account if her daughter provided consent by sharing her password.

Key Issues
  • Whether a dental plan administrator requires consent from a 17-year-old dependent to disclose her dental benefit information to her parents
  • Whether the age of majority or age of consent impacts the requirement for consent under PIPEDA for minors
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 21, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-024Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2009-024: Bank Disclosed Personal Information without Consent

A Canadian bank

A married couple applied for a joint mortgage. The husband alleged that a bank mortgage specialist disclosed his account information to his wife without his consent during the application process. The bank argued there was implicit consent given the joint mortgage application. The Assistant Commissioner found that the bank did not make a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed to each other. Therefore, the bank did not have meaningful consent for the disclosure. Although the incident was a one-time error by an employee, the complaint was found to be well-founded and resolved as the bank had adopted reasonable practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Case Summary #2009-024: Bank Disclosed Personal Information without Consent

Dec 21, 2009Commissioner’s Findings - PIPEDA Case Summary #2009-024
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A married couple applied for a joint mortgage. The husband alleged that a bank mortgage specialist disclosed his account information to his wife without his consent during the application process. The bank argued there was implicit consent given the joint mortgage application. The Assistant Commissioner found that the bank did not make a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed to each other. Therefore, the bank did not have meaningful consent for the disclosure. Although the incident was a one-time error by an employee, the complaint was found to be well-founded and resolved as the bank had adopted reasonable practices.

Key Issues
  • Whether the bank had the husband's implicit or explicit consent to disclose his account information to his wife
  • Whether the bank made a reasonable effort to inform the couple of the purposes for which their financial information would be disclosed
  • Whether the bank's mortgage specialist followed the bank's usual practice for informing joint mortgage applicants
  • Whether the presumption of implied consent remained reasonable after the wife's reaction to the initial disclosure