The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

21 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 26, 2017Incident case summary #2017-001Indexed Jun 30, 2026

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Multiple organizations (Airline, Retailer, Digital media company)

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Apr 26, 2017Incident case summary #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Key Issues
  • Whether organizations adequately responded to breaches caused by password reuse
  • Whether organizations implemented appropriate safeguards to prevent recurrence of breaches due to password reuse
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 19, 2017Indexed Jun 30, 2026

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Royal Canadian Mounted Police (RCMP)

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Quick view

Privacy ActWell-founded

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Apr 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Key Issues
  • Whether the RCMP inappropriately disclosed the complainant's personal information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(f) of the Privacy Act.
  • Whether CBP's use of the complainant's personal information for an admissibility assessment constituted "criminal justice purposes" or "law enforcement" as defined in the Memorandum of Cooperation (MOC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(a) of the Privacy Act as a "consistent use."
  • Whether the CPIC policies in effect at the time provided sufficient clarity to guard against unauthorized disclosure of sensitive personal information.
  • Whether the revised CPIC policies, including the "SHARE US A" feature and "SIP-OB" entries, adequately protect against unauthorized disclosure of attempted suicide information.
  • Whether the default setting of the "SHARE US A" feature in CPIC should suppress the sharing of SIP-OB entries relating to threatened or attempted suicides with US border officials.
  • Whether CPIC policies should be revised to provide clear guidance for sharing attempted suicide information with US border officials only where an individual presents an ongoing risk to others.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2017PIPEDA findings #2017-011Indexed Jun 30, 2026

PIPEDA findings #2017-011: Financial institution originally misuses confidential commercial information exemption to withhold personal information

A financial institution

A complainant alleged that a financial institution refused to respond to his access to personal information request related to a disputed credit card transaction. Initially, the financial institution withheld documents, claiming they contained confidential commercial information under PIPEDA s.9(3)(b). The OPC found this exemption was inappropriately applied and that the financial institution failed to respond within the statutory 30-day timeframe. Following the OPC's preliminary report, the financial institution provided further clarification, leading the OPC to determine that the information in question was not the complainant's personal information and was correctly redacted under s.9(1) as third-party information. Although the complainant eventually received all personal information he was entitled to, the OPC criticized the financial institution's delay and initial misuse of the exemption. The complaint was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2017-011: Financial institution originally misuses confidential commercial information exemption to withhold personal information

Mar 31, 2017PIPEDA findings #2017-011
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a financial institution refused to respond to his access to personal information request related to a disputed credit card transaction. Initially, the financial institution withheld documents, claiming they contained confidential commercial information under PIPEDA s.9(3)(b). The OPC found this exemption was inappropriately applied and that the financial institution failed to respond within the statutory 30-day timeframe. Following the OPC's preliminary report, the financial institution provided further clarification, leading the OPC to determine that the information in question was not the complainant's personal information and was correctly redacted under s.9(1) as third-party information. Although the complainant eventually received all personal information he was entitled to, the OPC criticized the financial institution's delay and initial misuse of the exemption. The complaint was found to be well-founded and resolved.

Key Issues
  • Whether the financial institution responded to the access request within the 30-day time limit required by PIPEDA s.8(3)
  • Whether the financial institution sent a notice of extension within 30 days of the request as required by PIPEDA s.8(4)
  • Whether the financial institution appropriately applied the confidential commercial information exemption under PIPEDA s.9(3)(b) to withhold documents
  • Whether the withheld information constituted the complainant's personal information
  • Whether the information was properly redacted as third-party information under PIPEDA s.9(1)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 14, 2017PIPEDA Report of Findings #2017-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-003: Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process

An insurance company

An individual complained that an insurance company collected and used his credit score without meaningful consent during an auto insurance claims assessment, over-collected his credit file, and used the score for an inappropriate purpose. The OPC found that the insurance company failed to demonstrate that collecting and using credit scores for fraud detection in auto claims was an appropriate purpose under PIPEDA subsection 5(3) or a "direct business need" under Ontario's Consumer Reporting Act. The OPC also determined that the company did not obtain meaningful consent because it failed to clearly advise the complainant that providing his credit score was optional, contrary to Principle 4.3. Furthermore, the company was found not to be open about its practices regarding credit score collection and use, violating Principle 4.8.1, due to insufficient notifications and inaccurate employee scripts. The allegation of over-collection was not substantiated, as only the credit score was provided. In response to the OPC's preliminary report, the insurance company agreed to cease collecting credit scores for auto accident benefit claims and review its practices for other insurance types. The matter was concluded as well-founded and conditionally resolved, pending the full implementation of these agreed-upon changes.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2017-003: Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process

Mar 14, 2017PIPEDA Report of Findings #2017-003
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an insurance company collected and used his credit score without meaningful consent during an auto insurance claims assessment, over-collected his credit file, and used the score for an inappropriate purpose. The OPC found that the insurance company failed to demonstrate that collecting and using credit scores for fraud detection in auto claims was an appropriate purpose under PIPEDA subsection 5(3) or a "direct business need" under Ontario's Consumer Reporting Act. The OPC also determined that the company did not obtain meaningful consent because it failed to clearly advise the complainant that providing his credit score was optional, contrary to Principle 4.3. Furthermore, the company was found not to be open about its practices regarding credit score collection and use, violating Principle 4.8.1, due to insufficient notifications and inaccurate employee scripts. The allegation of over-collection was not substantiated, as only the credit score was provided. In response to the OPC's preliminary report, the insurance company agreed to cease collecting credit scores for auto accident benefit claims and review its practices for other insurance types. The matter was concluded as well-founded and conditionally resolved, pending the full implementation of these agreed-upon changes.

Key Issues
  • Whether collecting and using a credit score for fraud detection during auto insurance claims assessment is an appropriate purpose under subsection 5(3) of PIPEDA.
  • Whether the insurance company had a "direct business need" for credit scores under Ontario's Consumer Reporting Act (CRA) s.8(1)(d)(vi) for fraud detection in auto claims.
  • Whether the insurance company over-collected personal information by obtaining the complainant's entire credit file.
  • Whether the insurance company properly identified the purposes for collecting the complainant's credit score under Principle 4.2.
  • Whether the insurance company obtained meaningful consent for collecting the credit score, specifically if it advised the complainant that providing the information was optional, under Principle 4.3.
  • Whether the insurance company was open about its policies and practices regarding credit score collection and use under Principle 4.8.1.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 10, 2017PIPEDA Case Summary #2017-005Indexed Jun 30, 2026

PIPEDA Case Summary #2017-005: Insurance company required to delete individual’s personal information after individual withdraws consent

An insurance company

An individual complained that his former automobile insurance company refused to delete his personal information from its records and from third-party organizations. The company initially refused, citing the need to provide insurance history to other insurers. The OPC reframed the request as a withdrawal of consent, and the company subsequently agreed to delete the information from its own records, as there was no legal requirement to retain it. However, the OPC found that the company was not obligated to ensure deletion from third-party records if the information was lawfully disclosed. The investigation also revealed the company lacked clear documentation regarding its disclosure practices to third parties, contravening Principle 4.1.4(d). The company committed to developing a document to track disclosures, which it later provided to the OPC.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2017-005: Insurance company required to delete individual’s personal information after individual withdraws consent

Feb 10, 2017PIPEDA Case Summary #2017-005
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that his former automobile insurance company refused to delete his personal information from its records and from third-party organizations. The company initially refused, citing the need to provide insurance history to other insurers. The OPC reframed the request as a withdrawal of consent, and the company subsequently agreed to delete the information from its own records, as there was no legal requirement to retain it. However, the OPC found that the company was not obligated to ensure deletion from third-party records if the information was lawfully disclosed. The investigation also revealed the company lacked clear documentation regarding its disclosure practices to third parties, contravening Principle 4.1.4(d). The company committed to developing a document to track disclosures, which it later provided to the OPC.

Key Issues
  • Whether the insurance company was required to delete the individual's personal information from its own records upon withdrawal of consent
  • Whether the insurance company was required to ensure deletion of the individual's personal information from third-party organizations' records after lawful disclosure
  • Whether the insurance company contravened Principle 4.1.4(d) by lacking a clear explanation of its disclosure practices to third parties
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Jan 11, 2017PIPEDA Case Summary #2017-004Indexed Jun 30, 2026

PIPEDA Case Summary #2017-004: Consent provided extends to third-party doctor hired to evaluate accident insurance claim

A doctor hired by an independent medical evaluation firm

An individual complained that a doctor collected, used, and disclosed his personal information without consent. The complainant had been in a car accident and his insurance company hired an independent medical evaluation (IME) firm to assess his claim for catastrophic impairment. The doctor in question was hired by the IME firm to compile a summary report based on assessments from other doctors. The complainant argued he had not consented to this specific doctor, though he had consented to other doctors involved in his claim. The doctor contended that the complainant had provided consent through signed accident benefit forms (OCF-1 and OCF-19). The OPC found that the signed forms included explicit consent for health professionals to collect, use, and disclose personal information for the purpose of investigating and processing the insurance claim. The OPC concluded that the doctor's actions were within the scope of the consent provided.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Case Summary #2017-004: Consent provided extends to third-party doctor hired to evaluate accident insurance claim

Jan 11, 2017PIPEDA Case Summary #2017-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a doctor collected, used, and disclosed his personal information without consent. The complainant had been in a car accident and his insurance company hired an independent medical evaluation (IME) firm to assess his claim for catastrophic impairment. The doctor in question was hired by the IME firm to compile a summary report based on assessments from other doctors. The complainant argued he had not consented to this specific doctor, though he had consented to other doctors involved in his claim. The doctor contended that the complainant had provided consent through signed accident benefit forms (OCF-1 and OCF-19). The OPC found that the signed forms included explicit consent for health professionals to collect, use, and disclose personal information for the purpose of investigating and processing the insurance claim. The OPC concluded that the doctor's actions were within the scope of the consent provided.

Key Issues
  • Whether the doctor collected, used, and disclosed the complainant's personal information without consent
  • Whether the consent provided in OCF-1 and OCF-19 forms extended to the doctor preparing the summary report