The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

26 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 9, 2014Indexed Jun 30, 2026

Sharing of health information unjustified - July 9, 2014

Public Service Commission of Canada (PSC)

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Quick view

Privacy ActWell-founded

Sharing of health information unjustified - July 9, 2014

Jul 9, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Key Issues
  • Whether the disclosure of the complainant's medical information to witnesses was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the PSC's interpretation of "affected person" and the requirements of procedural fairness justified the disclosure of sensitive medical information to all witnesses
  • Whether the PSC contravened subsection 8(1) of the Privacy Act by disclosing personal information without consent or a valid exception
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
May 22, 2014PIPEDA findings #2014-020Indexed Jun 30, 2026

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

A videographer

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

May 22, 2014PIPEDA findings #2014-020
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Key Issues
  • Whether the use of personal information constituted commercial activity
  • Whether the videographer had consent for this use
  • Whether the videographer needed consent for this use
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apple Canada Inc.

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Key Issues
  • Whether Apple's privacy policy adequately identified the purposes for collecting date of birth information for authentication (Principle 4.2 PIPEDA)
  • Whether Apple's collection of date of birth was limited to what was necessary for identified purposes (Principle 4.4 PIPEDA)
  • Whether Apple made information about its policies and practices concerning the collection of credit card information readily available to individuals (Principle 4.8 PIPEDA)
  • Whether Apple's practices resulted in the over-collection of sensitive payment information (Principle 4.4 PIPEDA)
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Apr 10, 2014Indexed Jun 30, 2026

Interference with Access to Information: Part 2

Public Works and Government Services Canada

The Information Commissioner initiated a systemic investigation under section 39 of the Access to Information Act into Public Works and Government Services Canada (PWGSC). The investigation focused on the processing of eight access to information or consultation requests received by PWGSC between July 22, 2008, and January 19, 2010. The primary concern was the possibility of interference in the processing of these requests. This report, titled "Interference with Access to Information: Part 2," details the Commissioner's findings regarding the alleged interference. The investigation aimed to determine if the institution's handling of these requests was appropriate or if there were instances of improper influence or obstruction.

Quick view

Access to Information ActSystemic Investigation

Interference with Access to Information: Part 2

Apr 10, 2014
Adjudicator: Suzanne Legault
Plain-Language Summary

The Information Commissioner initiated a systemic investigation under section 39 of the Access to Information Act into Public Works and Government Services Canada (PWGSC). The investigation focused on the processing of eight access to information or consultation requests received by PWGSC between July 22, 2008, and January 19, 2010. The primary concern was the possibility of interference in the processing of these requests. This report, titled "Interference with Access to Information: Part 2," details the Commissioner's findings regarding the alleged interference. The investigation aimed to determine if the institution's handling of these requests was appropriate or if there were instances of improper influence or obstruction.

Key Issues
  • Whether there was interference in the processing of access to information requests at Public Works and Government Services Canada
  • Whether Public Works and Government Services Canada properly processed eight specific access to information or consultation requests
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2014Indexed Jun 30, 2026

IP54-56/2014 — Employment and Social Development Canada

Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Quick view

Privacy ActWell-founded

IP54-56/2014 — Employment and Social Development Canada

Mar 24, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Key Issues
  • Whether ESDC failed to implement adequate physical security controls for personal information stored on portable media.
  • Whether ESDC failed to implement adequate technical security controls, such as encryption and risk assessments, for personal information on portable media.
  • Whether ESDC failed to implement adequate administrative controls, including asset inventory, information classification, and lifecycle management, for personal information.
  • Whether ESDC failed to implement adequate personnel security controls, such as employee training, awareness, and accountability, regarding personal information.
  • Whether ESDC contravened subsection 6(3) of the Privacy Act by failing to properly dispose of personal information.
  • Whether ESDC contravened section 7 of the Privacy Act regarding the use of personal information.
  • Whether ESDC contravened section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether the delay in notifying affected individuals of the breach was reasonable.
  • Whether the scope of personal information reported to affected individuals in the notification letters was complete.
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Mar 21, 2014Incident Summary #5Indexed Jun 30, 2026

Incident Summary #5: Life insurance company employs best practices in responding to mass mailing error that risked exposing personal information - March 21, 2014

A life insurance company

A life insurance company discovered that a mass mailing error risked exposing the personal information of 53 pension plan members. The new window envelopes used were larger, potentially revealing certificate numbers, SINs, dates of birth, spouse's names, and beneficiaries if statements shifted. Upon discovering the incident, the company promptly notified affected individuals, apologized, explained the incident, and offered a free one-year credit monitoring service. They also advised members to take harm-reducing steps and ceased using the problematic envelopes. The company informed the OPC about the incident and its response. The OPC concluded that the company demonstrated best practices in its incident response.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #5: Life insurance company employs best practices in responding to mass mailing error that risked exposing personal information - March 21, 2014

Mar 21, 2014Incident Summary #5
Adjudicator: Chantal Bernier
Plain-Language Summary

A life insurance company discovered that a mass mailing error risked exposing the personal information of 53 pension plan members. The new window envelopes used were larger, potentially revealing certificate numbers, SINs, dates of birth, spouse's names, and beneficiaries if statements shifted. Upon discovering the incident, the company promptly notified affected individuals, apologized, explained the incident, and offered a free one-year credit monitoring service. They also advised members to take harm-reducing steps and ceased using the problematic envelopes. The company informed the OPC about the incident and its response. The OPC concluded that the company demonstrated best practices in its incident response.

Key Issues
  • Whether a mass mailing error led to the potential exposure of personal information
  • Whether the life insurance company's response to the incident constituted best practices
Federal (Canada)Privacy ActNo jurisdiction
Federal (Canada) flag
Mar 4, 2014Indexed Jun 30, 2026

Retroactive removal of Privacy Act provisions leaves gun registry complainant with no recourse - 2015

Royal Canadian Mounted Police (RCMP)

The complainant alleged that the RCMP continued to retain and use personal information from the national long-gun registry, which should have been destroyed under the Ending the Long-Gun Registry Act. Specific allegations included a High River RCMP member's statement about locating firearms and an email from a Langley RCMP member referring to non-restricted firearm registration. The RCMP stated that electronic records were destroyed in October 2012 and hard copies by December 2013 (except for Quebec records). They also argued that information extracted from the registry before its destruction and retained in case files could be used consistent with its original purpose. The OPC found no evidence of contravention, noting that recent legislative amendments retroactively excluded the application of the Privacy Act to certain long-gun registry records, preventing further investigation into specific examples.

Quick view

Privacy ActNo jurisdiction

Retroactive removal of Privacy Act provisions leaves gun registry complainant with no recourse - 2015

Mar 4, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The complainant alleged that the RCMP continued to retain and use personal information from the national long-gun registry, which should have been destroyed under the Ending the Long-Gun Registry Act. Specific allegations included a High River RCMP member's statement about locating firearms and an email from a Langley RCMP member referring to non-restricted firearm registration. The RCMP stated that electronic records were destroyed in October 2012 and hard copies by December 2013 (except for Quebec records). They also argued that information extracted from the registry before its destruction and retained in case files could be used consistent with its original purpose. The OPC found no evidence of contravention, noting that recent legislative amendments retroactively excluded the application of the Privacy Act to certain long-gun registry records, preventing further investigation into specific examples.

Key Issues
  • Whether the RCMP continued to retain and use personal information from the national long-gun registry after it was required to be destroyed
  • Whether the High River RCMP used personal information from the long-gun registry in June 2013
  • Whether other RCMP detachments continued to use personal information from the long-gun registry after electronic records were destroyed in October 2012
  • Whether copies of the long-gun registry containing personal information still exist in the possession of the RCMP or other police services
  • Whether the use of personal information from the long-gun registry, retained in case files prior to the Ending the Long-gun Registry Act, is consistent with section 7 of the Privacy Act
  • Whether the retroactive exclusion of the Privacy Act by Bill C-59 affects the investigation
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 20, 2014Early resolved case summary #10Indexed Jun 30, 2026

Early resolved case summary #10: Bank improves its credit card account verification practices after challenge from customer - February 20, 2014

A financial institution

An individual complained that her bank required the last six digits of her Social Insurance Number (SIN) to set up a "verified credit account" for online purchases. She believed this practice was inappropriate and that an alternative method not requiring SIN information should be available. The bank initially stated an alternative existed through commercial websites, but the complainant noted this was not clearly communicated. The OPC highlighted a comparable case where a lack of transparency regarding authentication alternatives was found. Following this, the bank decided to discontinue the SIN-based authentication method entirely and update its website. The complainant was satisfied with this resolution, and the OPC confirmed the website changes.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Early resolved case summary #10: Bank improves its credit card account verification practices after challenge from customer - February 20, 2014

Feb 20, 2014Early resolved case summary #10
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that her bank required the last six digits of her Social Insurance Number (SIN) to set up a "verified credit account" for online purchases. She believed this practice was inappropriate and that an alternative method not requiring SIN information should be available. The bank initially stated an alternative existed through commercial websites, but the complainant noted this was not clearly communicated. The OPC highlighted a comparable case where a lack of transparency regarding authentication alternatives was found. Following this, the bank decided to discontinue the SIN-based authentication method entirely and update its website. The complainant was satisfied with this resolution, and the OPC confirmed the website changes.

Key Issues
  • Whether collecting a partial SIN for credit card account verification was appropriate under PIPEDA
  • Whether the bank provided adequate transparency regarding alternative verification methods
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Feb 10, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-012Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-012: Investment Firm Justified in its Collection of "Know Your Client" Information

An investment firm

A customer complained that his investment firm required an unreasonable amount of personal information on its "Know Your Client" (KYC) form as a condition for maintaining his Tax Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP). The firm requested details such as investment experience, annual income, spouse's income, dependents, assets, liabilities, and net worth. The firm argued this information was necessary to comply with the Investment Industry Regulatory Organization of Canada (IIROC) KYC and suitability requirements. The OPC assessed whether the firm contravened PIPEDA Principle 4.3.3 by requiring consent for information beyond explicitly specified and legitimate purposes. The OPC found that the firm had explicitly specified its purposes, which were legitimate given IIROC's regulatory framework. The OPC also concluded that the requested information, including details beyond IIROC's standard Form 2, was necessary for the firm to meet its regulatory obligations. Therefore, the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Commissioner’s Findings - PIPEDA Report of Findings #2014-012: Investment Firm Justified in its Collection of "Know Your Client" Information

Feb 10, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-012
Adjudicator: Chantal Bernier
Plain-Language Summary

A customer complained that his investment firm required an unreasonable amount of personal information on its "Know Your Client" (KYC) form as a condition for maintaining his Tax Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP). The firm requested details such as investment experience, annual income, spouse's income, dependents, assets, liabilities, and net worth. The firm argued this information was necessary to comply with the Investment Industry Regulatory Organization of Canada (IIROC) KYC and suitability requirements. The OPC assessed whether the firm contravened PIPEDA Principle 4.3.3 by requiring consent for information beyond explicitly specified and legitimate purposes. The OPC found that the firm had explicitly specified its purposes, which were legitimate given IIROC's regulatory framework. The OPC also concluded that the requested information, including details beyond IIROC's standard Form 2, was necessary for the firm to meet its regulatory obligations. Therefore, the complaint was not well-founded.

Key Issues
  • Whether the investment firm explicitly specified the purposes for collecting personal information under Principle 4.2 PIPEDA
  • Whether the purposes for collecting personal information were legitimate under subsection 5(3) PIPEDA
  • Whether the investment firm required more personal information than necessary to achieve the legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA
  • Whether the collection of personal information was limited to that which was necessary for the identified purposes under Principle 4.4 PIPEDA
  • Whether information on investment experience was necessary to validate investment knowledge and assess risk tolerance
  • Whether spouse's or partner's annual income was necessary to assess overall financial position and suitability
  • Whether detailed assets and liabilities were necessary to establish net worth and understand financial situation
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jan 23, 2014Early resolved case summary #5Indexed Jun 30, 2026

Early resolved case summary #5: Web posting that was removed by individual retained by Internet search engine - January 23, 2014

An Internet search engine

An individual posted her résumé on a job website, which included her address. After having the job website remove the information, she discovered her résumé was still searchable via an Internet search engine. The individual contacted the search engine's Web administrator multiple times to request removal of her personal information, but the search engine did not comply. She then filed a complaint with the OPC. The OPC intervened directly with the search engine, which subsequently removed the cached copy of the individual's information from its search results using its URL removal tool. The complainant was satisfied with the outcome, and the complaint was closed.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #5: Web posting that was removed by individual retained by Internet search engine - January 23, 2014

Jan 23, 2014Early resolved case summary #5
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual posted her résumé on a job website, which included her address. After having the job website remove the information, she discovered her résumé was still searchable via an Internet search engine. The individual contacted the search engine's Web administrator multiple times to request removal of her personal information, but the search engine did not comply. She then filed a complaint with the OPC. The OPC intervened directly with the search engine, which subsequently removed the cached copy of the individual's information from its search results using its URL removal tool. The complainant was satisfied with the outcome, and the complaint was closed.

Key Issues
  • Whether an Internet search engine was obligated to remove cached personal information after the original source was deleted
  • Whether the search engine's refusal to remove the information constituted a contravention of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 14, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-001Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-001: Use of sensitive health information for targeting of Google ads raises privacy concerns

Google Inc.

A complainant alleged that Google's AdSense service displayed targeted advertisements for sleep apnea devices on unrelated websites after he searched for medical devices online. He viewed his online activities related to sleep apnea as sensitive information requiring express consent for targeted advertising. The OPC's technical analysis confirmed that Google was delivering these ads through online behavioural advertising (OBA) and that they persisted over time. Google initially attributed this to a technical issue but later confirmed it was due to 'remarketed ads,' a form of interest-based advertising. The OPC found that Google's practice of delivering tailored ads based on sensitive health information without express consent contravened PIPEDA Principles 4.3 and 4.3.6. Google committed to several remedial measures, including rejecting relevant remarketing campaigns, revising its policies, developing new internal training, and increasing monitoring.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Report of Findings #2014-001: Use of sensitive health information for targeting of Google ads raises privacy concerns

Jan 14, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-001
Adjudicator: Chantal Bernier
Plain-Language Summary

A complainant alleged that Google's AdSense service displayed targeted advertisements for sleep apnea devices on unrelated websites after he searched for medical devices online. He viewed his online activities related to sleep apnea as sensitive information requiring express consent for targeted advertising. The OPC's technical analysis confirmed that Google was delivering these ads through online behavioural advertising (OBA) and that they persisted over time. Google initially attributed this to a technical issue but later confirmed it was due to 'remarketed ads,' a form of interest-based advertising. The OPC found that Google's practice of delivering tailored ads based on sensitive health information without express consent contravened PIPEDA Principles 4.3 and 4.3.6. Google committed to several remedial measures, including rejecting relevant remarketing campaigns, revising its policies, developing new internal training, and increasing monitoring.

Key Issues
  • Whether the delivery of targeted advertisements based on online searches for medical devices constitutes online behavioural advertising (OBA)
  • Whether information related to online searches for medical devices is sensitive personal information
  • Whether express consent is required for the collection and use of sensitive personal health information for OBA purposes
  • Whether Google obtained appropriate consent under Principle 4.3 and 4.3.6 for the use of sensitive health information for targeted advertising
  • Whether Google's privacy policy accurately reflected its practices regarding sensitive categories in tailored ads
  • Whether Google's monitoring tools for preventing policy abuses were scalable and effective