The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

607 decisions matching
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 23, 20215819-05410Indexed Jun 30, 2026

Immigration, Refugees and Citizenship Canada (Re), 2021 OIC 11

Immigration, Refugees and Citizenship Canada

The Information Commissioner initiated a systemic investigation into Immigration, Refugees and Citizenship Canada's (IRCC) processing of access requests for immigration application files due to a dramatic increase in requests and complaints. The investigation found that IRCC's practice of automatically extending response times for frequent requesters under paragraph 9(1)(a) of the Access to Information Act was improper. This practice disregarded Federal Court of Appeal guidance and the Act's requirement to not consider a requester's identity. The Commissioner issued five recommendations to IRCC, including ceasing the improper extension practice, developing a work plan to improve ATIP office performance, publishing results, improving the availability of client immigration information, and securing adequate short-term resources. IRCC agreed to all recommendations and submitted a work plan. The complaint was found to be well-founded.

Quick view

Access to Information ActWell-founded

Immigration, Refugees and Citizenship Canada (Re), 2021 OIC 11

Apr 23, 20215819-05410
Adjudicator: Caroline Maynard
Plain-Language Summary

The Information Commissioner initiated a systemic investigation into Immigration, Refugees and Citizenship Canada's (IRCC) processing of access requests for immigration application files due to a dramatic increase in requests and complaints. The investigation found that IRCC's practice of automatically extending response times for frequent requesters under paragraph 9(1)(a) of the Access to Information Act was improper. This practice disregarded Federal Court of Appeal guidance and the Act's requirement to not consider a requester's identity. The Commissioner issued five recommendations to IRCC, including ceasing the improper extension practice, developing a work plan to improve ATIP office performance, publishing results, improving the availability of client immigration information, and securing adequate short-term resources. IRCC agreed to all recommendations and submitted a work plan. The complaint was found to be well-founded.

Key Issues
  • Whether IRCC's practice of extending time limits under paragraph 9(1)(a) for frequent requesters was compliant with the ATIA
  • Whether IRCC's extension practice disregarded Federal Court of Appeal guidance on s.9(1)(a)
  • Whether IRCC's extension practice violated subsection 4(2.1) by considering requester identity
  • Whether IRCC had sufficient resources and effective processes to manage the volume of access requests
  • Whether IRCC provided adequate alternative means for clients to obtain immigration application information
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Apr 19, 20213216-00258Indexed Jun 30, 2026

Privy Council Office (Re), 2021 OIC 10

Privy Council Office

The complainant alleged that the Privy Council Office (PCO) improperly withheld the names of employees within the Prime Minister's Office under subsection 19(1) of the Access to Information Act. The request sought records related to the Minister of Revenue's announcement regarding audits of registered charities for political activities. The OIC's investigation focused on the application of subsection 19(1) to the names of exempt staff appearing in email chains. PCO argued that the information was personal information, citing a Supreme Court decision that clarified information about exempt staff is personal information. The OIC agreed that the names, in context, revealed more than just their identity and title, thus meeting the requirements for personal information and not falling under the exceptions in the Privacy Act. Furthermore, the OIC found that none of the circumstances under subsection 19(2) for discretionary disclosure existed, as consent was not given, and the specific context of their involvement was not publicly available. Therefore, the OIC concluded that the complaint was not well founded.

Quick view

Access to Information ActNot well-founded

Privy Council Office (Re), 2021 OIC 10

Apr 19, 20213216-00258
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Privy Council Office (PCO) improperly withheld the names of employees within the Prime Minister's Office under subsection 19(1) of the Access to Information Act. The request sought records related to the Minister of Revenue's announcement regarding audits of registered charities for political activities. The OIC's investigation focused on the application of subsection 19(1) to the names of exempt staff appearing in email chains. PCO argued that the information was personal information, citing a Supreme Court decision that clarified information about exempt staff is personal information. The OIC agreed that the names, in context, revealed more than just their identity and title, thus meeting the requirements for personal information and not falling under the exceptions in the Privacy Act. Furthermore, the OIC found that none of the circumstances under subsection 19(2) for discretionary disclosure existed, as consent was not given, and the specific context of their involvement was not publicly available. Therefore, the OIC concluded that the complaint was not well founded.

Key Issues
  • Whether the names of employees within the Prime Minister's Office constitute 'personal information' under s.19(1) ATIA
  • Whether the information falls under exceptions to the definition of 'personal information' in paragraphs 3(j) to 3(m) of the Privacy Act
  • Whether the information falls under the exception in paragraph 3(j.1) of the Privacy Act for ministerial advisers or staff members
  • Whether the individuals consented to the release of their personal information under s.19(2)(a) ATIA
  • Whether the information was publicly available under s.19(2)(b) ATIA
  • Whether disclosure would be consistent with section 8 of the Privacy Act under s.19(2)(c) ATIA
  • Whether the institution reasonably exercised its discretion to disclose the information under s.19(2) ATIA
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 14, 20213217-00342Indexed Jun 30, 2026

3217-00342 — Department of Justice Canada

Department of Justice Canada

The complainant alleged that the Department of Justice Canada (Justice) improperly withheld information under section 23 of the Access to Information Act. The request sought legal fees related to a specific litigation file. Justice claimed solicitor-client privilege over disbursements and details of expenses in a cost-recovery report, citing a presumption of privilege for lawyers' bills of account. The Information Commissioner acknowledged this presumption but found it rebutted in this case. The Commissioner determined there was no reasonable possibility that an inquirer could use the information to deduce privileged communications. Therefore, the Commissioner recommended that Justice disclose all information initially withheld under section 23. Justice agreed to implement the recommendation, and the complaint was found to be well founded.

Quick view

Access to Information ActWell-founded

3217-00342 — Department of Justice Canada

Apr 14, 20213217-00342
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Department of Justice Canada (Justice) improperly withheld information under section 23 of the Access to Information Act. The request sought legal fees related to a specific litigation file. Justice claimed solicitor-client privilege over disbursements and details of expenses in a cost-recovery report, citing a presumption of privilege for lawyers' bills of account. The Information Commissioner acknowledged this presumption but found it rebutted in this case. The Commissioner determined there was no reasonable possibility that an inquirer could use the information to deduce privileged communications. Therefore, the Commissioner recommended that Justice disclose all information initially withheld under section 23. Justice agreed to implement the recommendation, and the complaint was found to be well founded.

Key Issues
  • Whether the information consists of communication between a lawyer or notary and his or her client
  • Whether the communication relates directly to the seeking or giving of legal advice
  • Whether the parties intend the communication and advice to remain confidential
  • Whether the information was prepared or gathered for the dominant purpose of litigation
  • Whether the litigation is either in progress or is reasonably expected to occur
  • Whether the presumption of privilege for lawyers' bills of account was rebutted
  • Whether there was a reasonable possibility that an assiduous inquirer could use the information to deduce or otherwise acquire communications protected by privilege
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-003Indexed Jun 30, 2026

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Bank of Montreal

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Mar 30, 2021PIPEDA Findings #2021-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether BMO implemented appropriate security safeguards to adequately protect personal information under its control, as required by PIPEDA Principle 4.7
  • Adequacy of BMO's developer security testing and evaluation processes
  • Adequacy of BMO's vulnerability management program, including identification, assessment, and remediation of vulnerabilities
  • Adequacy of BMO's oversight and monitoring capabilities, specifically regarding bot management, cyberattack detection, and real-time alerts
  • Adequacy of BMO's organizational policies and procedures for handling cyberattacks and incident response
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-009Indexed Jun 30, 2026

PIPEDA Findings #2021-009: Opt-in consent required for a donor list trading program

A charitable organization

A complainant alleged that a charitable organization (the Respondent) failed to obtain proper consent before sharing his personal information through a donor list trading program. The Respondent used an opt-out checkbox on its mail-in donation forms, which the complainant found inadequate after receiving solicitations from another charity. The OPC determined that sharing donor information with other charities for solicitation purposes was outside the reasonable expectations of donors, thus requiring express opt-in consent. Furthermore, the information provided by the Respondent on its donation forms, inserts, and privacy policy was deemed insufficient to enable meaningful consent. The OPC recommended that the Respondent obtain express opt-in consent and enhance its privacy communications to clearly explain the nature, purpose, and consequences of the data sharing. The Respondent agreed to implement these recommendations, leading to a conditionally resolved outcome.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-009: Opt-in consent required for a donor list trading program

Mar 30, 2021PIPEDA Findings #2021-009
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a charitable organization (the Respondent) failed to obtain proper consent before sharing his personal information through a donor list trading program. The Respondent used an opt-out checkbox on its mail-in donation forms, which the complainant found inadequate after receiving solicitations from another charity. The OPC determined that sharing donor information with other charities for solicitation purposes was outside the reasonable expectations of donors, thus requiring express opt-in consent. Furthermore, the information provided by the Respondent on its donation forms, inserts, and privacy policy was deemed insufficient to enable meaningful consent. The OPC recommended that the Respondent obtain express opt-in consent and enhance its privacy communications to clearly explain the nature, purpose, and consequences of the data sharing. The Respondent agreed to implement these recommendations, leading to a conditionally resolved outcome.

Key Issues
  • Whether the Respondent obtained meaningful consent for its donor list trading program under PIPEDA
  • Whether opt-out consent was appropriate for sharing donor information with third parties
  • Whether the information shared (donor name, address, donation status) was sensitive in this context
  • Whether sharing donor information with other charities for solicitation was within the reasonable expectations of donors
  • Whether the donor list trading program created a meaningful residual risk of significant harm
  • Whether the information provided to donors on the donation form, insert, and privacy policy was sufficient to support meaningful consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-004Indexed Jun 30, 2026

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Fido Solutions Inc. (a subsidiary of Rogers Communications Inc.)

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Mar 30, 2021PIPEDA Findings #2021-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Key Issues
  • Whether Fido adequately safeguarded the Complainant’s personal information under Principle 4.7
  • Whether Fido responded to the Complainant’s access request in a generally understandable format under Principle 4.9 and 4.9.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 29, 2021PIPEDA Findings #2021-002Indexed Jun 30, 2026

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

CoreFour Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

Mar 29, 2021PIPEDA Findings #2021-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Key Issues
  • Whether CoreFour's security safeguards were appropriate to the sensitivity and volume of personal information under Principle 4.7 PIPEDA
  • Whether CoreFour's weak password requirements for certain Edsby parental accounts constituted an inadequate safeguard
  • Whether CoreFour's safeguards to protect against unauthorized access to thumbnail images of student profile pictures were adequate
  • Whether Edsby's failure to scan for malware when uploading content from third-party applications constituted a safeguard weakness
  • Whether CoreFour lacked a robust overarching information security framework, contravening Principle 4.1.4 and 4.7-4.7.3 PIPEDA
  • Whether CoreFour had an adequate mechanism for handling and reporting privacy breaches under PIPEDA
  • Whether CoreFour was required to report the password management vulnerability, given it occurred before mandatory breach reporting came into effect
  • Whether the student image vulnerability created a "real risk of significant harm" requiring mandatory reporting and notification under s.10.1 PIPEDA
  • Whether CoreFour maintained a breach register as required under s.10.3 PIPEDA
  • Whether CoreFour lacked a privacy management framework, including appropriate written internal policies and practices (e.g., complaint handling, data retention), contravening Principle 4.1.4 PIPEDA
  • Whether CoreFour provided adequate privacy training to its employees, consultants, contractors, and students
  • Whether CoreFour's Privacy Policy was unclear regarding the characterization of personal information, its responsibility for security, and the sharing of user information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 24, 2021PIPEDA Findings #2021-007Indexed Jun 30, 2026

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

A computer services company

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

Mar 24, 2021PIPEDA Findings #2021-007
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Key Issues
  • Whether the respondent obtained meaningful consent prior to remotely accessing laptops
  • Whether the respondent had adequate safeguards to prevent unauthorized access to customers’ personal information by its personnel
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 22, 2021PIPEDA Findings #2021-008Indexed Jun 30, 2026

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Oculus Transport Ltd.

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Mar 22, 2021PIPEDA Findings #2021-008
Adjudicator: Daniel Therrien
Plain-Language Summary

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Key Issues
  • Whether the collection and use of personal information via audio surveillance technology was for purposes that a reasonable person would consider appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the personal information collected was sensitive
  • Whether the organization's purpose represented a legitimate need / bona fide business interest
  • Whether the collection, use and disclosure would be effective in meeting the organization’s need
  • Whether there are less privacy invasive means of achieving the same ends at comparable cost and with comparable benefits
  • Whether the loss of privacy is proportional to the benefits
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Mar 18, 20215819-00626Indexed Jun 30, 2026

Innovation, Science and Economic Development Canada (Re), 2021 OIC 8

Innovation, Science and Economic Development Canada

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) took an unreasonable extension of time to respond to an access request related to the Competition Bureau’s bread price-fixing investigation. ISED claimed a 1,460-day extension under paragraph 9(1)(a) of the Access to Information Act, citing the large volume of records (over 75 million pages) and the need to search 100 terabytes of information. The OIC found that the request involved a large number of records and that meeting the 30-day deadline would unreasonably interfere with ISED's operations. The OIC also determined that ISED applied sufficient rigour in calculating the extension, considering the time needed by the program area and the Access to Information and Privacy Office, and the complexity of the records. Consequently, the OIC concluded that the 1,460-day extension was reasonable and justified. The complaint was not well founded, and the OIC invited ISED to consider disclosing completed packages of records as they become available.

Quick view

Access to Information ActNot well-founded

Innovation, Science and Economic Development Canada (Re), 2021 OIC 8

Mar 18, 20215819-00626
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) took an unreasonable extension of time to respond to an access request related to the Competition Bureau’s bread price-fixing investigation. ISED claimed a 1,460-day extension under paragraph 9(1)(a) of the Access to Information Act, citing the large volume of records (over 75 million pages) and the need to search 100 terabytes of information. The OIC found that the request involved a large number of records and that meeting the 30-day deadline would unreasonably interfere with ISED's operations. The OIC also determined that ISED applied sufficient rigour in calculating the extension, considering the time needed by the program area and the Access to Information and Privacy Office, and the complexity of the records. Consequently, the OIC concluded that the 1,460-day extension was reasonable and justified. The complaint was not well founded, and the OIC invited ISED to consider disclosing completed packages of records as they become available.

Key Issues
  • Whether the request was for a large number of records or required searching through a large number of records under paragraph 9(1)(a)
  • Whether meeting the 30-day deadline would unreasonably interfere with the institution’s operations under paragraph 9(1)(a)
  • Whether the extension of time was for a reasonable period, given the circumstances, under paragraph 9(1)(a)
  • Whether the institution validly claimed the extension of time by notifying the requester within 30 days
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Mar 16, 20213217-01373Indexed Jun 30, 2026

3217-01373 — Public Safety Canada and Royal Canadian Mounted Police

Public Safety Canada

The complainant alleged that Public Safety Canada (Public Safety) improperly refused to process an access request for records related to keywords such as 'counter-radicalization' and 'cyber radicalization', including associated metadata. Public Safety argued that portions of the request did not meet the requirements of section 6 of the Access to Information Act due to the expansive volume of records and the complexity of identifying relevant information. The Commissioner agreed that some parts of the request were too broad, but found that other parts (Paragraph 1 and Schedule A) were sufficiently detailed and should have been processed. The Commissioner also determined that Public Safety failed to meet its legislated obligations by not claiming an extension of time and by refusing to process any part of the request. The complaint was found to be well founded, and Public Safety committed to processing the valid portions of the request at a rate of 5,000 pages per year.

Quick view

Access to Information ActWell-founded

3217-01373 — Public Safety Canada and Royal Canadian Mounted Police

Mar 16, 20213217-01373
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Public Safety Canada (Public Safety) improperly refused to process an access request for records related to keywords such as 'counter-radicalization' and 'cyber radicalization', including associated metadata. Public Safety argued that portions of the request did not meet the requirements of section 6 of the Access to Information Act due to the expansive volume of records and the complexity of identifying relevant information. The Commissioner agreed that some parts of the request were too broad, but found that other parts (Paragraph 1 and Schedule A) were sufficiently detailed and should have been processed. The Commissioner also determined that Public Safety failed to meet its legislated obligations by not claiming an extension of time and by refusing to process any part of the request. The complaint was found to be well founded, and Public Safety committed to processing the valid portions of the request at a rate of 5,000 pages per year.

Key Issues
  • Whether the request provided sufficient detail to enable an experienced employee to identify records with reasonable effort (s.6 ATIA)
  • Whether Public Safety was justified in refusing to process the entire request if only parts of it met s.6 ATIA requirements
  • Whether Public Safety complied with its obligation to claim an extension of time under s.9(1) ATIA
  • Whether Public Safety made every reasonable effort to assist the requester (s.4(2.1) ATIA)
  • Whether Public Safety was required to consult on the term 'metadata' and provide records in the requested format
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 15, 2021PIPEDA Findings #2021-005Indexed Jun 30, 2026

PIPEDA Findings #2021-005: Staying signed in by default to email services poses serious privacy concerns for users accessing their email on a public or shared computer

Yahoo! Canada

The complainant alleged that Yahoo! Canada's default "Stay signed in" setting for Yahoo Mail, particularly for Rogers Yahoo Mail users, posed significant privacy concerns on public or shared computers. The OPC investigated whether Yahoo adequately safeguarded against unauthorized access and obtained valid consent for potential disclosures. The OPC found that Yahoo's safeguards were not appropriate for the sensitivity of email content and that its consent for the "Stay signed in" setting was not meaningful. Yahoo committed to changing the setting to opt-in and providing clearer information about privacy implications. Rogers, while not a respondent, also agreed to implement measures for Rogers Yahoo Mail users. The complaint was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-005: Staying signed in by default to email services poses serious privacy concerns for users accessing their email on a public or shared computer

Mar 15, 2021PIPEDA Findings #2021-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Yahoo! Canada's default "Stay signed in" setting for Yahoo Mail, particularly for Rogers Yahoo Mail users, posed significant privacy concerns on public or shared computers. The OPC investigated whether Yahoo adequately safeguarded against unauthorized access and obtained valid consent for potential disclosures. The OPC found that Yahoo's safeguards were not appropriate for the sensitivity of email content and that its consent for the "Stay signed in" setting was not meaningful. Yahoo committed to changing the setting to opt-in and providing clearer information about privacy implications. Rogers, while not a respondent, also agreed to implement measures for Rogers Yahoo Mail users. The complaint was found to be well-founded and conditionally resolved.

Key Issues
  • Whether Yahoo's safeguards against unauthorized third-party access to email content on public or shared computers were adequate under Principle 4.7 PIPEDA
  • Whether Yahoo obtained valid and meaningful consent for the disclosure of personal information to others who subsequently access emails via the "Stay signed in" setting under Principle 4.3 PIPEDA
  • Whether the "Stay signed in" setting was clearly and prominently displayed
  • Whether a reasonable person would understand the "Stay signed in" setting to be "on" by default
  • Whether the "Stay signed in" setting is consistent with industry standards
  • Whether Yahoo's additional safeguards (algorithm, sign-out option, session expiration, password reset, security information) were effective
  • Whether express opt-in consent was required for the "Stay signed in" setting due to sensitivity of information, reasonable expectations, and risk of harm
  • Whether the language "stay signed in" provided users with key information for meaningful consent
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Mar 12, 20215820-00869Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2021 OIC 6

Royal Canadian Mounted Police

The complainant alleged that the Royal Canadian Mounted Police (RCMP) improperly withheld information under subsection 19(1) of the Access to Information Act, concerning a follow-up investigation related to a Code of Conduct decision against the complainant. During the investigation, the RCMP conceded that some of the withheld information was not personal information and issued a supplementary release. However, the RCMP maintained the application of subsection 19(1) on the remaining information. The Office of the Information Commissioner (OIC) found that the remaining withheld information was indeed personal information about another individual, meeting the requirements of the exemption. The OIC also concluded that none of the circumstances under subsection 19(2) that would warrant disclosure existed. Therefore, the complaint was found to be well founded because the RCMP initially withheld information that was not personal information, but the OIC upheld the exemption for the remaining records.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2021 OIC 6

Mar 12, 20215820-00869
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Royal Canadian Mounted Police (RCMP) improperly withheld information under subsection 19(1) of the Access to Information Act, concerning a follow-up investigation related to a Code of Conduct decision against the complainant. During the investigation, the RCMP conceded that some of the withheld information was not personal information and issued a supplementary release. However, the RCMP maintained the application of subsection 19(1) on the remaining information. The Office of the Information Commissioner (OIC) found that the remaining withheld information was indeed personal information about another individual, meeting the requirements of the exemption. The OIC also concluded that none of the circumstances under subsection 19(2) that would warrant disclosure existed. Therefore, the complaint was found to be well founded because the RCMP initially withheld information that was not personal information, but the OIC upheld the exemption for the remaining records.

Key Issues
  • Whether the information initially withheld by the RCMP constituted personal information under s.19(1) ATIA
  • Whether the remaining withheld information was personal information about another individual under s.19(1) ATIA
  • Whether the circumstances for disclosure under s.19(2) ATIA existed
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Mar 12, 2021PIPEDA Findings #2021-006Indexed Jun 30, 2026

PIPEDA Findings #2021-006: A short-term lender collects online banking credentials in the course of payday loan applications

CashHere (2124478 Ontario Corporation)

The OPC initiated an investigation into CashHere, a short-term lender, after being alerted by the Ontario Ministry of Government and Consumer Services that it was collecting online banking credentials (passwords, usernames, security questions/answers) from loan applicants. The OPC found that while CashHere had a legitimate need to validate identity and income, collecting banking credentials was not an appropriate purpose under PIPEDA s. 5(3) due to less privacy-invasive alternatives and disproportionate privacy risks. The investigation also noted that a related entity, MoneyHome, appeared to be continuing the same practices. CashHere ceased responding to the OPC, and the matter was found to be well-founded and unresolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2021-006: A short-term lender collects online banking credentials in the course of payday loan applications

Mar 12, 2021PIPEDA Findings #2021-006
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated an investigation into CashHere, a short-term lender, after being alerted by the Ontario Ministry of Government and Consumer Services that it was collecting online banking credentials (passwords, usernames, security questions/answers) from loan applicants. The OPC found that while CashHere had a legitimate need to validate identity and income, collecting banking credentials was not an appropriate purpose under PIPEDA s. 5(3) due to less privacy-invasive alternatives and disproportionate privacy risks. The investigation also noted that a related entity, MoneyHome, appeared to be continuing the same practices. CashHere ceased responding to the OPC, and the matter was found to be well-founded and unresolved.

Key Issues
  • Whether CashHere's collection of online banking login credentials was for a purpose that a reasonable person would consider appropriate under s. 5(3) of PIPEDA
  • Whether the collection of banking credentials was effective in meeting CashHere's legitimate need
  • Whether there were less privacy-invasive means of achieving the same ends
  • Whether the loss of privacy was proportional to the benefits for CashHere
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Mar 5, 20212021 OIC 5Indexed Jun 30, 2026

Canadian Security Intelligence Service (Re), 2021 OIC 5

Canadian Security Intelligence Service

The complainant alleged that the Canadian Security Intelligence Service (CSIS) took an unreasonable time extension under paragraph 9(1)(b) of the Access to Information Act for consultations. CSIS justified a 240-day extension, citing the necessity of consulting with two other government institutions, the high classification and sensitivity of the records, the need for on-site review, and limited workplace access due to the pandemic. The Office of the Information Commissioner (OIC) found that CSIS made a serious effort to determine the extension's length based on the pandemic's realities. The OIC concluded that the time extension was reasonable given the circumstances and that CSIS met the three requirements for claiming such an extension. Therefore, the complaint was not well founded.

Quick view

Access to Information ActNot well-founded

Canadian Security Intelligence Service (Re), 2021 OIC 5

Mar 5, 20212021 OIC 5
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Canadian Security Intelligence Service (CSIS) took an unreasonable time extension under paragraph 9(1)(b) of the Access to Information Act for consultations. CSIS justified a 240-day extension, citing the necessity of consulting with two other government institutions, the high classification and sensitivity of the records, the need for on-site review, and limited workplace access due to the pandemic. The Office of the Information Commissioner (OIC) found that CSIS made a serious effort to determine the extension's length based on the pandemic's realities. The OIC concluded that the time extension was reasonable given the circumstances and that CSIS met the three requirements for claiming such an extension. Therefore, the complaint was not well founded.

Key Issues
  • Whether the time extension taken under paragraph 9(1)(b) for consultations was reasonable
  • Whether CSIS met the three requirements to claim the time extension