The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

607 decisions matching
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Feb 18, 20202020 OIC 2Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2020 OIC 2

Royal Canadian Mounted Police

The Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request for over two years, leading to a deemed refusal under the Access to Information Act. During the investigation, the RCMP provided insufficient information regarding the records or the processing of the request to establish a reasonable response date. Due to the continued lack of response, the Information Commissioner found the complaint to be well-founded. The Commissioner ordered the RCMP to respond to the access request within 10 business days from the effective date of the order. However, the RCMP ultimately responded to the request before the order officially came into effect.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2020 OIC 2

Feb 18, 20202020 OIC 2
Adjudicator: Caroline Maynard
Plain-Language Summary

The Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request for over two years, leading to a deemed refusal under the Access to Information Act. During the investigation, the RCMP provided insufficient information regarding the records or the processing of the request to establish a reasonable response date. Due to the continued lack of response, the Information Commissioner found the complaint to be well-founded. The Commissioner ordered the RCMP to respond to the access request within 10 business days from the effective date of the order. However, the RCMP ultimately responded to the request before the order officially came into effect.

Key Issues
  • Whether the institution failed to respond to an access request within the statutory time limits (deemed refusal)
  • Whether the institution provided sufficient information to justify the delay
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 31, 2020Indexed Jun 30, 2026

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Employment and Social Development Canada (ESDC)

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Quick view

Privacy ActWell-founded

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Jan 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Key Issues
  • Whether the collection of video surveillance footage constituted personal information under s.3 of the Privacy Act
  • Whether the initial collection of video surveillance footage by ESDC was in compliance with s.4 of the Privacy Act
  • Whether ESDC informed individuals of the purpose for collecting personal information via video surveillance, as required by s.5 of the Privacy Act
  • Whether ESDC's use of video surveillance footage to monitor an employee's departure times was consistent with the purpose for which it was collected, as required by s.7(a) of the Privacy Act
  • Whether ESDC obtained consent for the use of video surveillance footage for purposes other than security, as required by s.7(a) of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jan 15, 2020Indexed Jun 30, 2026

Public disclosure of medical information during military trial consistent with Privacy Act

Department of National Defence

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

Public disclosure of medical information during military trial consistent with Privacy Act

Jan 15, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Key Issues
  • Whether the Privacy Act applies to military summary trial proceedings conducted by the Canadian Forces
  • Whether the disclosure of the complainant's medical information during the summary trial was made in accordance with section 8 of the Privacy Act
  • Whether the information became publicly available under section 69(2) of the Privacy Act once disclosed in an open court proceeding
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Jan 14, 20205819-00733Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2020 OIC 1

Royal Canadian Mounted Police

The complainant alleged that the Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request within the statutory time limits. The request, submitted on July 3, 2018, had a due date of August 2, 2018. The RCMP was deemed to have refused access under subsection 10(3) of the Act as it did not respond or take an extension. Despite multiple requests from the OIC for information regarding the delay and a proposed disclosure date, the RCMP provided no rationale for the delay, only citing high volume and resource pressures. The OIC found that the responsive records were not voluminous or complex and had been in the RCMP's possession since July 2018. An initial report with an intended order was sent to the Minister, but before the order could be issued, the RCMP released the records. Consequently, the complaint was found to be well-founded, but no order was issued as the records were released.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2020 OIC 1

Jan 14, 20205819-00733
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request within the statutory time limits. The request, submitted on July 3, 2018, had a due date of August 2, 2018. The RCMP was deemed to have refused access under subsection 10(3) of the Act as it did not respond or take an extension. Despite multiple requests from the OIC for information regarding the delay and a proposed disclosure date, the RCMP provided no rationale for the delay, only citing high volume and resource pressures. The OIC found that the responsive records were not voluminous or complex and had been in the RCMP's possession since July 2018. An initial report with an intended order was sent to the Minister, but before the order could be issued, the RCMP released the records. Consequently, the complaint was found to be well-founded, but no order was issued as the records were released.

Key Issues
  • Whether the institution responded to the access request within the statutory time limits
  • Whether the institution was deemed to have refused access under subsection 10(3) of the Act
  • Whether the institution provided adequate rationale for the delay in responding
  • Whether the institution provided a reasonable disclosure date
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 30, 2019Indexed Jun 30, 2026

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Department of National Defence and Department of Justice

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Quick view

Privacy ActNot well-founded

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Dec 30, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Key Issues
  • Whether the collection of the complainant's personal medical information by the DOJ from the DND contravened the Privacy Act
  • Whether the disclosure of the complainant's personal medical information by the DND to the DOJ contravened the Privacy Act
  • Whether the collection by DOJ related directly to an operating program or activity of the institution under s.4 of the Privacy Act
  • Whether the collection by DOJ was permissible under s.5(1) of the Privacy Act given the disclosure under s.8(2)(d)
  • Whether the disclosure by DND was to the Attorney General of Canada under s.8(2)(d) of the Privacy Act
  • Whether the disclosure by DND was for use in legal proceedings involving the Crown in right of Canada or the Government of Canada under s.8(2)(d) of the Privacy Act
  • Whether the sensitivity of medical information impacts the permissibility of disclosure under the Privacy Act
  • Whether doctor-patient confidentiality prevents disclosure under the Privacy Act for litigation purposes
  • Whether the safeguarding measures for the disclosed information were adequate
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Dec 9, 2019PIPEDA Findings #2019-007Indexed Jun 30, 2026

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Trans Union of Canada, Inc.

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Dec 9, 2019PIPEDA Findings #2019-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Key Issues
  • Whether TransUnion disclosed the complainant's credit file information to Statistics Canada without requisite consent
  • Whether TransUnion was authorized to disclose personal information without consent under PIPEDA subparagraph 7(3)(c.1)(iii)
  • Whether Statistics Canada identified its lawful authority to obtain the information
  • Whether the disclosure was requested to administer a law of Canada (the Statistics Act)
  • Whether Statistics Canada subsequently disclosed the complainant's credit file information to other government institutions for debt collection
  • Whether there was sufficient evidence to support the allegation of information misuse for debt collection
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 21, 2019Indexed Jun 30, 2026

Crossing the line? The CBSA’s examination of digital devices at the border

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Quick view

Privacy ActWell-founded

Crossing the line? The CBSA’s examination of digital devices at the border

Oct 21, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Key Issues
  • Whether CBSA's collection of personal information via digital device searches contravened section 4 of the Privacy Act.
  • Whether the definition of "goods" under the Customs Act extends to electronic documents on digital devices.
  • Whether CBSA's authority to search digital devices is limited to information stored on the device.
  • Whether Border Services Officers (BSOs) complied with CBSA's internal policy (Operational Bulletin PRG-2015-31) regarding digital device examinations (e.g., airplane mode, note-taking, search threshold).
  • Whether the copying of content from a digital device by a BSO was consistent with CBSA's legal authority and policy.
  • Whether the CBSA complied with its obligations under subsection 6(1) of the Privacy Act to retain personal information used for administrative purposes.
  • Whether the CBSA's practices regarding training, awareness, and accountability mechanisms for digital device searches were adequate.
  • Whether the Customs Act requires amendment to include a clear legal framework and a higher threshold for digital device examinations.
  • Whether the threshold for digital device examinations should be "reasonable grounds to suspect".
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 16, 2019PIPEDA Findings #2019-003Indexed Jun 30, 2026

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Loblaw Companies Ltd.

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Oct 16, 2019PIPEDA Findings #2019-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Key Issues
  • Whether Loblaw collected more personal information than necessary for the Loblaw Card Program (Principle 4.4)
  • Whether Loblaw ensured a comparable level of protection for personal information transferred to a third party for processing (Principle 4.1.3)
  • Whether Loblaw was required to obtain additional consent for the transfer of personal information for processing (Principle 4.3)
  • Whether Loblaw was sufficiently open and transparent about its cross-border data transfers (Principle 4.8)
Federal (Canada)Access to Information Acts.6.1 Application Denied (must respond)
Federal (Canada) flag
Aug 1, 20192019 OIC 1Indexed Jun 30, 2026

Decision pursuant to 6.1, 2019 OIC 1

A federal institution

A federal institution applied to the Information Commissioner for approval to decline to act on an access request, alleging it was vexatious, an abuse of the right of access, and made in bad faith. The institution claimed the request was vague, repetitive, involved abusive language from the requester, and raised safety concerns. The Commissioner found the request sufficiently clear and noted no evidence of prior disclosure for repetitive claims. The Commissioner also determined that the provided examples did not establish abusive language or a link between safety concerns and the access request. Regarding abuse of right, the institution cited an increase in requests and processing time due to the requester, but failed to show how this diminished other requesters' rights or impacted its other duties. Finally, the Commissioner found no evidence of bad faith, stating that pursuing legal remedies, even for an alleged unjust dismissal, does not equate to bad faith in making an access request. The Commissioner also noted the institution did not demonstrate it fulfilled its duty to assist the requester. Consequently, the application was denied, and the institution was ordered to process the request.

Quick view

Access to Information Acts.6.1 Application Denied (must respond)

Decision pursuant to 6.1, 2019 OIC 1

Aug 1, 20192019 OIC 1
Adjudicator: Caroline Maynard
Plain-Language Summary

A federal institution applied to the Information Commissioner for approval to decline to act on an access request, alleging it was vexatious, an abuse of the right of access, and made in bad faith. The institution claimed the request was vague, repetitive, involved abusive language from the requester, and raised safety concerns. The Commissioner found the request sufficiently clear and noted no evidence of prior disclosure for repetitive claims. The Commissioner also determined that the provided examples did not establish abusive language or a link between safety concerns and the access request. Regarding abuse of right, the institution cited an increase in requests and processing time due to the requester, but failed to show how this diminished other requesters' rights or impacted its other duties. Finally, the Commissioner found no evidence of bad faith, stating that pursuing legal remedies, even for an alleged unjust dismissal, does not equate to bad faith in making an access request. The Commissioner also noted the institution did not demonstrate it fulfilled its duty to assist the requester. Consequently, the application was denied, and the institution was ordered to process the request.

Key Issues
  • Whether the access request was vexatious due to vagueness
  • Whether the access request was vexatious due to repetitiveness
  • Whether the access request was vexatious due to abusive language from the requester
  • Whether the access request was vexatious due to safety concerns
  • Whether the access request amounted to an abuse of the right to make a request for records
  • Whether the access request was made in bad faith
  • Whether the institution fulfilled its duty to assist the requester under subsection 4(2.1) ATIA
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jun 9, 2019Indexed Jun 30, 2026

Video recording in the workplace at correctional institutions consistent with the Privacy Act

Correctional Service Canada (CSC)

Three complaints alleged that Correctional Service Canada (CSC) improperly used video footage, collected for security, to monitor employee performance. The complainants provided emails from a correctional manager commenting on their patrols as evidence. CSC acknowledged using video for security and incident investigation but denied using it for performance monitoring. The OPC found that CSC reviewed the footage to identify systemic deficiencies in patrols following an inmate's death, aiming to improve security and prevent future deaths. The review was part of an action plan to address deficiencies identified in the death investigation. The OPC concluded that this use was consistent with the original purpose of collection, which was security, and therefore the complaints were not well-founded.

Quick view

Privacy ActNot well-founded

Video recording in the workplace at correctional institutions consistent with the Privacy Act

Jun 9, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

Three complaints alleged that Correctional Service Canada (CSC) improperly used video footage, collected for security, to monitor employee performance. The complainants provided emails from a correctional manager commenting on their patrols as evidence. CSC acknowledged using video for security and incident investigation but denied using it for performance monitoring. The OPC found that CSC reviewed the footage to identify systemic deficiencies in patrols following an inmate's death, aiming to improve security and prevent future deaths. The review was part of an action plan to address deficiencies identified in the death investigation. The OPC concluded that this use was consistent with the original purpose of collection, which was security, and therefore the complaints were not well-founded.

Key Issues
  • Whether video footage of employees constitutes personal information under s.3 of the Privacy Act
  • Whether CSC's use of video footage to review employee patrols constituted monitoring employee performance
  • Whether CSC's use of video footage was for the purpose for which it was obtained or compiled, or for a use consistent with that purpose, as per s.7(a) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Apr 25, 2019PIPEDA Findings #2019-002Indexed Jun 30, 2026

PIPEDA Findings #2019-002: Joint investigation of Facebook, Inc. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Facebook, Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) conducted a joint investigation into Facebook, Inc.'s compliance with PIPEDA and PIPA following revelations about the "thisisyourdigitallife" (TYDL) app and its data sharing with Cambridge Analytica. The investigation focused on Facebook's consent practices for both installing users and their friends, its data safeguards, and its overall accountability. The OPC found that Facebook failed to obtain meaningful consent from users for the disclosure of their personal information to third-party apps, including the TYDL app, and that its safeguards against unauthorized access and use were inadequate. Furthermore, Facebook was deemed to have abdicated its responsibility for user information, demonstrating a lack of accountability. Despite recommendations from the OPC, Facebook rejected or refused to implement them, leading to a finding that the complaint was well-founded and remains unresolved. The OPC stated it would pursue further action under its authorities.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2019-002: Joint investigation of Facebook, Inc. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Apr 25, 2019PIPEDA Findings #2019-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) conducted a joint investigation into Facebook, Inc.'s compliance with PIPEDA and PIPA following revelations about the "thisisyourdigitallife" (TYDL) app and its data sharing with Cambridge Analytica. The investigation focused on Facebook's consent practices for both installing users and their friends, its data safeguards, and its overall accountability. The OPC found that Facebook failed to obtain meaningful consent from users for the disclosure of their personal information to third-party apps, including the TYDL app, and that its safeguards against unauthorized access and use were inadequate. Furthermore, Facebook was deemed to have abdicated its responsibility for user information, demonstrating a lack of accountability. Despite recommendations from the OPC, Facebook rejected or refused to implement them, leading to a finding that the complaint was well-founded and remains unresolved. The OPC stated it would pursue further action under its authorities.

Key Issues
  • Whether the OPC and OIPC BC had jurisdiction to investigate the matter.
  • Whether Facebook's provision of access to personal information via its Graph API constitutes a "disclosure" under PIPEDA.
  • Whether Facebook obtained valid and meaningful consent from installing users for the disclosure of their personal information to third-party apps, including the TYDL App.
  • Whether Facebook made reasonable efforts to ensure third-party apps obtained meaningful consent from installing users.
  • Whether Facebook's reliance on overbroad and conflicting language in its privacy communications was sufficient for meaningful consent from installing users.
  • Whether Facebook obtained meaningful consent from friends of installing users (Affected Users) for the disclosure of their personal information to third-party apps.
  • Whether Facebook had adequate safeguards to protect user information against unauthorized access, use, and disclosure by apps.
  • Whether Facebook's monitoring and enforcement of its Platform Policy were adequate.
  • Whether Facebook's implementation of Graph v2 and App Review adequately addressed safeguard concerns for ongoing compliance.
  • Whether Facebook was accountable for the user information under its control.
  • Whether Facebook's policies and practices gave effect to the privacy principles under PIPEDA and PIPA.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 29, 2019Indexed Jun 30, 2026

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Global Affairs Canada

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Quick view

Privacy ActWell-founded

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Mar 29, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Key Issues
  • Whether the information in the diplomatic passport constitutes personal information under s.3 of the Privacy Act
  • Whether Global Affairs Canada's request for the diplomatic passport constituted a collection of personal information
  • Whether Global Affairs Canada demonstrated its authority to collect the personal travel information under s.4 of the Privacy Act
  • Whether the collection of personal travel information related directly to an operating program or activity of Global Affairs Canada
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2019PIPEDA Case Summary #2019-006Indexed Jun 30, 2026

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Grey House Publishing Canada

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Mar 28, 2019PIPEDA Case Summary #2019-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Key Issues
  • Whether the complainant's contact information constituted 'personal information' under PIPEDA
  • Whether Grey House Publishing Canada was engaged in 'commercial activity' under PIPEDA
  • Whether Grey House obtained adequate consent for the collection, use, and disclosure of the complainant's personal information
  • Whether the 'publicly available information' exceptions to consent applied
  • Whether Grey House's privacy statement met the 'openness' principle under PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 28, 2019Indexed Jun 30, 2026

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Employment and Social Development Canada (ESDC)

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Quick view

Privacy ActWell-founded

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Mar 28, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Key Issues
  • Whether the complainant's name, telephone number, and email address constitute personal information under the Act
  • Whether ESDC was required to collect personal information directly from the complainant under section 5 of the Act
  • Whether ESDC complied with section 4 of the Act regarding the collection of personal information
  • Whether ESDC adequately ensured Grey House Publishing Canada complied with consent requirements as per their contract
  • Whether ESDC improperly collected the complainant's information after he requested removal from the distribution list
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 25, 2019PIPEDA Findings #2019-005Indexed Jun 30, 2026

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

411Numbers

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

Mar 25, 2019PIPEDA Findings #2019-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Key Issues
  • Whether the OPC had jurisdiction over 411Numbers, a Hong Kong-incorporated company with servers outside Canada, due to a 'real and substantial connection' to Canada.
  • Whether 411Numbers collected, used, and disclosed the complainant's personal information (unlisted phone number, name, address) without knowledge and consent, contravening Principle 4.3.
  • Whether information associated with unlisted telephone numbers constitutes 'publicly available' information under paragraph 1(a) of the Regulations Specifying Publicly Available Information.
  • Whether 411Numbers exercised due diligence to ensure its databases did not include unlisted numbers.
  • Whether publishing personal information for the purpose of encouraging individuals to pay to have it removed constitutes an inappropriate purpose under s. 5(3) of PIPEDA.
  • Whether 411Numbers required individuals to provide more information than necessary for removal services, contravening Principle 4.3.3.
  • Whether 411Numbers met its obligations regarding accountability under Principles 4.1, 4.1.2, and 4.1.4.
  • Whether 411Numbers met its obligations regarding openness under Principle 4.8 and 4.8.3.
  • Whether 411Numbers met its obligations regarding challenging compliance under Principle 4.10.