
Library and Archives Canada, 5821-05725
The Information Commissioner ordered Library and Archives Canada to provide a complete response to the access request on the 36th business day following the date of the final report.
The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

The Information Commissioner ordered Library and Archives Canada to provide a complete response to the access request on the 36th business day following the date of the final report.

The complainant alleged that the Privy Council Office (PCO) improperly withheld information under subsections 15(1) (national security, defence) and 19(1) (personal information) of the Access to Information Act concerning historical Canadian intelligence assessments. The OIC found that PCO was justified in withholding information under subsection 19(1). However, PCO failed to demonstrate how the release of distribution markings, names of former Communications Security Establishment (CSE) employees, a distribution list of allies, information on nuclear development programs, and technology transfer details would cause a reasonable expectation of harm under subsection 15(1). The Commissioner noted that similar information had been previously released by PCO and other institutions, discrediting PCO's claims of harm. Furthermore, the Commissioner was not satisfied that PCO properly exercised its discretion in deciding against disclosure. The complaint was found to be well founded, and PCO was ordered to disclose the records in their entirety, but PCO indicated it would not implement the order.

The Information Commissioner ordered Canada Revenue Agency to provide a complete response to the access request by December 11, 2023.

The Information Commissioner ordered Transport Canada to provide a complete response to the access request as soon as possible, but no later than the 36th business day following the date of the final report.

The Information Commissioner ordered Correctional Service Canada to provide monthly interim releases and a complete response to the access request as soon as possible, but no later than August 31, 2023.

The complainant alleged that the Canada Mortgage and Housing Corporation (CMHC) improperly withheld information in response to an access request for final versions of documents. CMHC initially claimed exemptions under paragraphs 18(a), 18(b), 19(1), 20(1)(b), 21(1)(a), 21(1)(b), and section 23 of the Access to Information Act. During the investigation, the scope of the complaint was narrowed, and CMHC voluntarily disclosed some information previously withheld under paragraphs 18(a), 18(b), 21(1)(a), and 21(1)(b). The remaining information was withheld under paragraph 20(1)(b), concerning third-party financial, commercial, scientific, or technical information. The Information Commissioner found that CMHC and the third parties (TD Bank Financial Group and Andrew Kalotay Associates, Inc.) failed to demonstrate that the information met the requirements of paragraph 20(1)(b), as the third parties did not provide representations and CMHC could not show that all conditions for the exemption were met. Consequently, the Commissioner ordered CMHC to disclose all information withheld under paragraph 20(1)(b). CMHC agreed to implement the order.

The Information Commissioner ordered Transport Canada to provide a complete response to the access request as soon as possible, but no later than the 75th business day following receipt of the final report.

The Information Commissioner ordered Veterans Affairs Canada to provide a complete response to the access request no later than the 36th business day following receipt of the final report.

The Office of the Privacy Commissioner of Canada (OPC) tabled a Special Report to Parliament summarizing investigations and advisory initiatives concerning the federal government's privacy practices during the COVID-19 pandemic. The report examined vaccine mandates for domestic travel, entry into Canada, and federal employees, as well as the ArriveCAN application, the collection of de-identified mobility data, and information sharing under the Emergencies Act. Overall, the OPC found that federal institutions generally complied with the Privacy Act, with some exceptions and areas for improvement. A significant finding was a breach of the Privacy Act by the Canada Border Services Agency (CBSA) due to an error in the ArriveCAN app that inaccurately identified approximately 10,000 fully vaccinated travellers as needing to quarantine; this issue was subsequently corrected. The Treasury Board of Canada also contravened section 11 of the Privacy Act by not timely publishing a Personal Information Bank description, which was later rectified. The report also included a PIPEDA investigation where Biron Health Group improperly used personal information for marketing, which was settled. The OPC made several recommendations to various institutions regarding necessity, proportionality, transparency, and safeguarding of personal information, some of which were accepted, while others, like a recommendation to the Department of National Defence regarding oversight of a data system, were not. The report emphasized the need for modernized privacy laws and clear guidance for information sharing during crises.

The Office of the Privacy Commissioner of Canada (OPC) investigated 40 complaints against the Treasury Board of Canada Secretariat (TBS) and 19 other federal institutions regarding COVID-19 vaccination attestation requirements for federal employees. Complainants alleged unreasonable collection, lack of transparency, and inappropriate disclosure of personal information. The OPC found that the collection of vaccination status and accommodation information related directly to the institutions' operating programs and activities, such as health and safety and human resources management, and that transparency requirements under subsection 5(2) of the Privacy Act were met. However, TBS contravened subsection 11(1) of the Act by failing to update its personal information bank index within the required timeframe, though this issue was subsequently resolved. The OPC also found no systemic contraventions of disclosure provisions under section 8. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed the policy against these principles and found it to be necessary and proportional under the circumstances, despite weaknesses in TBS's documentation. The OPC recommended that TBS assess future privacy-invasive measures using a four-part test, a recommendation TBS did not commit to.

The Office of the Privacy Commissioner (OPC) investigated 18 complaints regarding the collection, use, and disclosure of vaccination information by Transport Canada, VIA Rail, and CATSA for domestic air and rail travel mandates between November 2021 and June 2022. Complainants alleged unlawful privacy violations and unreasonable limitations on mobility. The OPC found that the collection of vaccination information by CATSA and VIA Rail was directly related to their operating programs and activities, specifically administering Ministerial Orders for transportation safety. Furthermore, the uses and disclosures of personal information by CATSA and VIA Rail, and the centralized collection and use by Transport Canada, complied with sections 4, 7, and 8 of the Privacy Act. While necessity and proportionality are not direct legal requirements of the Privacy Act, the OPC assessed these principles and found the collections were overall necessary and proportional. However, the OPC identified concerns with the broad scope of the Orders' objectives and Transport Canada's limited documentation of less privacy-invasive alternatives. Consequently, the complaints were deemed not well-founded, but Transport Canada accepted recommendations for future similar measures to better define objectives and document alternative assessments. This report highlights the need to better reflect necessity and proportionality in public sector privacy law.

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint regarding erroneous quarantine notifications sent by the ArriveCAN application to approximately 10,200 Apple device users. These notifications, issued between June 28 and July 20, 2022, incorrectly instructed fully vaccinated travellers to quarantine due to a defect in ArriveCAN version 3.0. The OPC found that the Canada Border Services Agency (CBSA) failed to take all reasonable steps to ensure the accuracy of personal information used for an administrative purpose, as required by subsection 6(2) of the Privacy Act. Specifically, the OPC identified shortcomings in rigorous pre-release testing, effective human intervention, and timely correction and recourse for affected individuals. The CBSA disagreed with the finding and refused to implement the OPC's recommendation to correct the inaccurate "quarantine_exempted" value in its database. Consequently, the complaint was found to be well-founded and unresolved.

The Office of the Privacy Commissioner of Canada (OPC) investigated 12 complaints against the Public Health Agency of Canada (PHAC) and Health Canada regarding their collection and use of de-identified mobility data during the COVID-19 pandemic. Complainants alleged PHAC secretly collected data on 33 million mobile devices. PHAC maintained it only used de-identified and aggregated data, arguing the Privacy Act did not apply as no personal information was collected. The OPC's primary issue was whether the mobility data constituted "personal information" under Section 3 of the Privacy Act, specifically if de-identification and safeguards reduced re-identification risk below the "serious possibility" threshold. The investigation examined two data streams, from TELUS and BlueDot, and assessed the de-identification techniques, aggregation levels, access controls, and contractual safeguards in place. The OPC concluded that the combination of these measures reduced the risk of identifying individuals below the "serious possibility" threshold. Consequently, the complaints were found to be not well-founded, as the data did not meet the definition of personal information under the Act. Despite this finding, the OPC made several recommendations to PHAC concerning ongoing assessment of de-identification techniques, due diligence with data providers, and enhanced transparency, which PHAC accepted.

The Office of the Privacy Commissioner of Canada (OPC) investigated 16 complaints against the Department of National Defence (DND) and the Canadian Armed Forces (CAF) regarding their COVID-19 vaccination attestation requirements. Complainants alleged unreasonable collection, improper use, insufficient access controls in the Monitor MASS system leading to unauthorized disclosure, and inaccurate data. The OPC found that the collection of vaccination status information, including for accommodation requests, directly related to DND's operating programs for health and safety and operational readiness, satisfying section 4 of the Privacy Act. The use of this information was also deemed consistent with the purposes for which it was collected, in line with section 7. While concerns were raised about Monitor MASS access controls, the OPC found no evidence of actual unauthorized disclosures, thus deeming this allegation not well-founded, though it did recommend improved oversight which DND declined. Furthermore, DND was found to have taken reasonable steps to ensure the accuracy of vaccination status data under section 6(2). The OPC also concluded that the measures were necessary and proportional given the pandemic context and the CAF's unique operational role.

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints from federal public service employees against several separate employers regarding COVID-19 vaccination attestation requirements. Employees alleged that the collection, use, and disclosure of their vaccination status and accommodation requests contravened the Privacy Act. The OPC examined whether the information collected related directly to an operating program or activity (s.4) and if its uses and disclosures were authorized (s.7 and s.8). The OPC found that the collection was directly related to the employers' occupational health and safety programs and that uses and disclosures were consistent with the purpose of collection. Additionally, the OPC assessed the necessity and proportionality of these measures, concluding they were necessary and proportional given the emergency context of the pandemic. Consequently, the OPC found the complaints to be not well-founded. However, the OPC recommended that Canada Post Corporation refine its access controls for sensitive information and that all institutions conduct structured necessity and proportionality analyses for future privacy-invasive programs.