The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

615 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 16, 2019PIPEDA Findings #2019-003Indexed Jun 30, 2026

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Loblaw Companies Ltd.

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Oct 16, 2019PIPEDA Findings #2019-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Key Issues
  • Whether Loblaw collected more personal information than necessary for the Loblaw Card Program (Principle 4.4)
  • Whether Loblaw ensured a comparable level of protection for personal information transferred to a third party for processing (Principle 4.1.3)
  • Whether Loblaw was required to obtain additional consent for the transfer of personal information for processing (Principle 4.3)
  • Whether Loblaw was sufficiently open and transparent about its cross-border data transfers (Principle 4.8)
Federal (Canada)Access to Information Acts.6.1 Application Denied (must respond)
Federal (Canada) flag
Aug 1, 20192019 OIC 1Indexed Jun 30, 2026

Decision pursuant to 6.1, 2019 OIC 1

A federal institution

A federal institution applied to the Information Commissioner for approval to decline to act on an access request, alleging it was vexatious, an abuse of the right of access, and made in bad faith. The institution claimed the request was vague, repetitive, involved abusive language from the requester, and raised safety concerns. The Commissioner found the request sufficiently clear and noted no evidence of prior disclosure for repetitive claims. The Commissioner also determined that the provided examples did not establish abusive language or a link between safety concerns and the access request. Regarding abuse of right, the institution cited an increase in requests and processing time due to the requester, but failed to show how this diminished other requesters' rights or impacted its other duties. Finally, the Commissioner found no evidence of bad faith, stating that pursuing legal remedies, even for an alleged unjust dismissal, does not equate to bad faith in making an access request. The Commissioner also noted the institution did not demonstrate it fulfilled its duty to assist the requester. Consequently, the application was denied, and the institution was ordered to process the request.

Quick view

Access to Information Acts.6.1 Application Denied (must respond)

Decision pursuant to 6.1, 2019 OIC 1

Aug 1, 20192019 OIC 1
Adjudicator: Caroline Maynard
Plain-Language Summary

A federal institution applied to the Information Commissioner for approval to decline to act on an access request, alleging it was vexatious, an abuse of the right of access, and made in bad faith. The institution claimed the request was vague, repetitive, involved abusive language from the requester, and raised safety concerns. The Commissioner found the request sufficiently clear and noted no evidence of prior disclosure for repetitive claims. The Commissioner also determined that the provided examples did not establish abusive language or a link between safety concerns and the access request. Regarding abuse of right, the institution cited an increase in requests and processing time due to the requester, but failed to show how this diminished other requesters' rights or impacted its other duties. Finally, the Commissioner found no evidence of bad faith, stating that pursuing legal remedies, even for an alleged unjust dismissal, does not equate to bad faith in making an access request. The Commissioner also noted the institution did not demonstrate it fulfilled its duty to assist the requester. Consequently, the application was denied, and the institution was ordered to process the request.

Key Issues
  • Whether the access request was vexatious due to vagueness
  • Whether the access request was vexatious due to repetitiveness
  • Whether the access request was vexatious due to abusive language from the requester
  • Whether the access request was vexatious due to safety concerns
  • Whether the access request amounted to an abuse of the right to make a request for records
  • Whether the access request was made in bad faith
  • Whether the institution fulfilled its duty to assist the requester under subsection 4(2.1) ATIA
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jun 9, 2019Indexed Jun 30, 2026

Video recording in the workplace at correctional institutions consistent with the Privacy Act

Correctional Service Canada (CSC)

Three complaints alleged that Correctional Service Canada (CSC) improperly used video footage, collected for security, to monitor employee performance. The complainants provided emails from a correctional manager commenting on their patrols as evidence. CSC acknowledged using video for security and incident investigation but denied using it for performance monitoring. The OPC found that CSC reviewed the footage to identify systemic deficiencies in patrols following an inmate's death, aiming to improve security and prevent future deaths. The review was part of an action plan to address deficiencies identified in the death investigation. The OPC concluded that this use was consistent with the original purpose of collection, which was security, and therefore the complaints were not well-founded.

Quick view

Privacy ActNot well-founded

Video recording in the workplace at correctional institutions consistent with the Privacy Act

Jun 9, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

Three complaints alleged that Correctional Service Canada (CSC) improperly used video footage, collected for security, to monitor employee performance. The complainants provided emails from a correctional manager commenting on their patrols as evidence. CSC acknowledged using video for security and incident investigation but denied using it for performance monitoring. The OPC found that CSC reviewed the footage to identify systemic deficiencies in patrols following an inmate's death, aiming to improve security and prevent future deaths. The review was part of an action plan to address deficiencies identified in the death investigation. The OPC concluded that this use was consistent with the original purpose of collection, which was security, and therefore the complaints were not well-founded.

Key Issues
  • Whether video footage of employees constitutes personal information under s.3 of the Privacy Act
  • Whether CSC's use of video footage to review employee patrols constituted monitoring employee performance
  • Whether CSC's use of video footage was for the purpose for which it was obtained or compiled, or for a use consistent with that purpose, as per s.7(a) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Apr 25, 2019PIPEDA Findings #2019-002Indexed Jun 30, 2026

PIPEDA Findings #2019-002: Joint investigation of Facebook, Inc. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Facebook, Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) conducted a joint investigation into Facebook, Inc.'s compliance with PIPEDA and PIPA following revelations about the "thisisyourdigitallife" (TYDL) app and its data sharing with Cambridge Analytica. The investigation focused on Facebook's consent practices for both installing users and their friends, its data safeguards, and its overall accountability. The OPC found that Facebook failed to obtain meaningful consent from users for the disclosure of their personal information to third-party apps, including the TYDL app, and that its safeguards against unauthorized access and use were inadequate. Furthermore, Facebook was deemed to have abdicated its responsibility for user information, demonstrating a lack of accountability. Despite recommendations from the OPC, Facebook rejected or refused to implement them, leading to a finding that the complaint was well-founded and remains unresolved. The OPC stated it would pursue further action under its authorities.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2019-002: Joint investigation of Facebook, Inc. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Apr 25, 2019PIPEDA Findings #2019-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) conducted a joint investigation into Facebook, Inc.'s compliance with PIPEDA and PIPA following revelations about the "thisisyourdigitallife" (TYDL) app and its data sharing with Cambridge Analytica. The investigation focused on Facebook's consent practices for both installing users and their friends, its data safeguards, and its overall accountability. The OPC found that Facebook failed to obtain meaningful consent from users for the disclosure of their personal information to third-party apps, including the TYDL app, and that its safeguards against unauthorized access and use were inadequate. Furthermore, Facebook was deemed to have abdicated its responsibility for user information, demonstrating a lack of accountability. Despite recommendations from the OPC, Facebook rejected or refused to implement them, leading to a finding that the complaint was well-founded and remains unresolved. The OPC stated it would pursue further action under its authorities.

Key Issues
  • Whether the OPC and OIPC BC had jurisdiction to investigate the matter.
  • Whether Facebook's provision of access to personal information via its Graph API constitutes a "disclosure" under PIPEDA.
  • Whether Facebook obtained valid and meaningful consent from installing users for the disclosure of their personal information to third-party apps, including the TYDL App.
  • Whether Facebook made reasonable efforts to ensure third-party apps obtained meaningful consent from installing users.
  • Whether Facebook's reliance on overbroad and conflicting language in its privacy communications was sufficient for meaningful consent from installing users.
  • Whether Facebook obtained meaningful consent from friends of installing users (Affected Users) for the disclosure of their personal information to third-party apps.
  • Whether Facebook had adequate safeguards to protect user information against unauthorized access, use, and disclosure by apps.
  • Whether Facebook's monitoring and enforcement of its Platform Policy were adequate.
  • Whether Facebook's implementation of Graph v2 and App Review adequately addressed safeguard concerns for ongoing compliance.
  • Whether Facebook was accountable for the user information under its control.
  • Whether Facebook's policies and practices gave effect to the privacy principles under PIPEDA and PIPA.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 29, 2019Indexed Jun 30, 2026

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Global Affairs Canada

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Quick view

Privacy ActWell-founded

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Mar 29, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Key Issues
  • Whether the information in the diplomatic passport constitutes personal information under s.3 of the Privacy Act
  • Whether Global Affairs Canada's request for the diplomatic passport constituted a collection of personal information
  • Whether Global Affairs Canada demonstrated its authority to collect the personal travel information under s.4 of the Privacy Act
  • Whether the collection of personal travel information related directly to an operating program or activity of Global Affairs Canada
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2019PIPEDA Case Summary #2019-006Indexed Jun 30, 2026

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Grey House Publishing Canada

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Mar 28, 2019PIPEDA Case Summary #2019-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Key Issues
  • Whether the complainant's contact information constituted 'personal information' under PIPEDA
  • Whether Grey House Publishing Canada was engaged in 'commercial activity' under PIPEDA
  • Whether Grey House obtained adequate consent for the collection, use, and disclosure of the complainant's personal information
  • Whether the 'publicly available information' exceptions to consent applied
  • Whether Grey House's privacy statement met the 'openness' principle under PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 28, 2019Indexed Jun 30, 2026

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Employment and Social Development Canada (ESDC)

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Quick view

Privacy ActWell-founded

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Mar 28, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Key Issues
  • Whether the complainant's name, telephone number, and email address constitute personal information under the Act
  • Whether ESDC was required to collect personal information directly from the complainant under section 5 of the Act
  • Whether ESDC complied with section 4 of the Act regarding the collection of personal information
  • Whether ESDC adequately ensured Grey House Publishing Canada complied with consent requirements as per their contract
  • Whether ESDC improperly collected the complainant's information after he requested removal from the distribution list
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 25, 2019PIPEDA Findings #2019-005Indexed Jun 30, 2026

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

411Numbers

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

Mar 25, 2019PIPEDA Findings #2019-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Key Issues
  • Whether the OPC had jurisdiction over 411Numbers, a Hong Kong-incorporated company with servers outside Canada, due to a 'real and substantial connection' to Canada.
  • Whether 411Numbers collected, used, and disclosed the complainant's personal information (unlisted phone number, name, address) without knowledge and consent, contravening Principle 4.3.
  • Whether information associated with unlisted telephone numbers constitutes 'publicly available' information under paragraph 1(a) of the Regulations Specifying Publicly Available Information.
  • Whether 411Numbers exercised due diligence to ensure its databases did not include unlisted numbers.
  • Whether publishing personal information for the purpose of encouraging individuals to pay to have it removed constitutes an inappropriate purpose under s. 5(3) of PIPEDA.
  • Whether 411Numbers required individuals to provide more information than necessary for removal services, contravening Principle 4.3.3.
  • Whether 411Numbers met its obligations regarding accountability under Principles 4.1, 4.1.2, and 4.1.4.
  • Whether 411Numbers met its obligations regarding openness under Principle 4.8 and 4.8.3.
  • Whether 411Numbers met its obligations regarding challenging compliance under Principle 4.10.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 11, 2019Indexed Jun 30, 2026

The name of an individual is considered personal information if it is accompanied by information that is about the individual

Canadian Transportation Agency (CTA)

The complainant, an air passenger rights advocate, requested access to all records about himself held by the Canadian Transportation Agency (CTA). The CTA initially withheld 760 pages, arguing that most references to the complainant's name were not personal information because he was acting on behalf of an organization. The OPC found that the information was indeed personal information, as the organization was not a separate legal entity and the records contained views and information directly about the complainant. The OPC also found that the CTA incorrectly applied exemptions under section 26 (third-party personal information) and subsection 70(1) (cabinet confidences) in some instances, and over-redacted under section 27 (solicitor-client privilege). The complaint was found to be well-founded, and the CTA agreed to implement the OPC's recommendations to disclose the withheld information.

Quick view

Privacy ActWell-founded

The name of an individual is considered personal information if it is accompanied by information that is about the individual

Feb 11, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, an air passenger rights advocate, requested access to all records about himself held by the Canadian Transportation Agency (CTA). The CTA initially withheld 760 pages, arguing that most references to the complainant's name were not personal information because he was acting on behalf of an organization. The OPC found that the information was indeed personal information, as the organization was not a separate legal entity and the records contained views and information directly about the complainant. The OPC also found that the CTA incorrectly applied exemptions under section 26 (third-party personal information) and subsection 70(1) (cabinet confidences) in some instances, and over-redacted under section 27 (solicitor-client privilege). The complaint was found to be well-founded, and the CTA agreed to implement the OPC's recommendations to disclose the withheld information.

Key Issues
  • Whether information relating to the complainant's advocacy activities, where his name appears, constitutes personal information under section 3 of the Privacy Act
  • Whether the CTA correctly invoked paragraph 12(1)(b) to deny access to information it deemed not to be personal information
  • Whether the CTA correctly withheld third-party personal information under section 26 of the Privacy Act
  • Whether the CTA correctly withheld information under section 27 of the Privacy Act (solicitor-client privilege)
  • Whether the CTA correctly withheld information under subsection 70(1) of the Privacy Act (cabinet confidences)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 20, 2018Indexed Jun 30, 2026

Innovation, Science and Economic Development Canada fails to ensure that the information it used to staff a position was accurate

Innovation, Science and Economic Development Canada (ISED)

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) used inaccurate personal information about him when staffing a position. ISED acknowledged that its Human Resources officials mistakenly selected the complainant's profile in the MyGCHR system instead of another individual with the same name, leading to the complainant being 'hired' by ISED and 'terminated' from his position at Public Services and Procurement Canada (PSPC). This error caused the complainant to miss pay periods. The OPC found that ISED did not take all reasonable steps to ensure the accuracy of the personal information, as officials only used first and last names for the search and did not verify with additional identifiers like a Personal Record Identifier (PRI) or date of birth. The complaint was found to be well-founded, but ISED has since implemented a new policy requiring staff to validate identities using multiple data fields.

Quick view

Privacy ActWell-founded

Innovation, Science and Economic Development Canada fails to ensure that the information it used to staff a position was accurate

Aug 20, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) used inaccurate personal information about him when staffing a position. ISED acknowledged that its Human Resources officials mistakenly selected the complainant's profile in the MyGCHR system instead of another individual with the same name, leading to the complainant being 'hired' by ISED and 'terminated' from his position at Public Services and Procurement Canada (PSPC). This error caused the complainant to miss pay periods. The OPC found that ISED did not take all reasonable steps to ensure the accuracy of the personal information, as officials only used first and last names for the search and did not verify with additional identifiers like a Personal Record Identifier (PRI) or date of birth. The complaint was found to be well-founded, but ISED has since implemented a new policy requiring staff to validate identities using multiple data fields.

Key Issues
  • Whether the information at issue constituted personal information under section 3 of the Privacy Act
  • Whether ISED took all reasonable steps to ensure that the personal information it used for an administrative purpose was as accurate, up-to-date and complete as possible, as required by subsection 6(2) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 20, 2018PIPEDA Report of Findings #2018-004Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-004: Microsoft to obtain opt-in consent, enhance transparency for Windows 10 privacy settings

Microsoft

An anonymous complainant raised concerns that Microsoft Windows 10 defaulted several privacy settings to "on" during installation, and these settings were difficult to understand and change. The OPC investigated whether Microsoft obtained valid consent for collecting, using, and disclosing personal information via these default settings. Initial concerns about clarity and consistency were shared with Microsoft regarding the original Windows 10 version. Following the Creators Update, the OPC identified further issues, particularly regarding the meaningfulness of consent for Location, Diagnostics, Tailored Experiences, Relevant Ads, and Speech Recognition settings, noting confusion caused by conflating related practices. Microsoft cooperated and committed to implementing changes, including obtaining opt-in consent for all installation privacy settings, enhancing transparency, and correcting the functioning of Speech Recognition. The OPC found the complaint well-founded and conditionally resolved, pending Microsoft's implementation of these commitments by the end of 2018.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-004: Microsoft to obtain opt-in consent, enhance transparency for Windows 10 privacy settings

Jun 20, 2018PIPEDA Report of Findings #2018-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant raised concerns that Microsoft Windows 10 defaulted several privacy settings to "on" during installation, and these settings were difficult to understand and change. The OPC investigated whether Microsoft obtained valid consent for collecting, using, and disclosing personal information via these default settings. Initial concerns about clarity and consistency were shared with Microsoft regarding the original Windows 10 version. Following the Creators Update, the OPC identified further issues, particularly regarding the meaningfulness of consent for Location, Diagnostics, Tailored Experiences, Relevant Ads, and Speech Recognition settings, noting confusion caused by conflating related practices. Microsoft cooperated and committed to implementing changes, including obtaining opt-in consent for all installation privacy settings, enhancing transparency, and correcting the functioning of Speech Recognition. The OPC found the complaint well-founded and conditionally resolved, pending Microsoft's implementation of these commitments by the end of 2018.

Key Issues
  • Whether Microsoft obtained valid and meaningful consent for the collection, use, and disclosure of personal information through Windows 10 default privacy settings.
  • Whether the initial Windows 10 (Version 1507) installation process provided sufficient prominence for customizing settings and adequate information via "Learn more" links.
  • Whether the explanations for Advertising ID and Diagnostics settings in Version 1507 were clear, consistent, and comprehensive.
  • Whether opt-out consent was appropriate for the Location setting in the Creators Update, and if Microsoft's explanations were sufficiently transparent regarding exceptions and the use of "de-identified location information."
  • Whether "Full" Diagnostics should be the default setting, and if Microsoft's transparency regarding data collected at this level was adequate for meaningful consent.
  • Whether Microsoft obtained valid consent for Tailored Experiences, particularly concerning the use of broad diagnostic data and the protection of sensitive information.
  • Whether Microsoft's practices for Tailored Experiences complied with accountability requirements under Principle 4.1.4.
  • Whether opt-out consent was appropriate for the Relevant Ads (Advertising ID) setting, and if Microsoft's communications clearly distinguished it from its own advertising program.
  • Whether opt-out consent was appropriate for the Speech Recognition setting, given the sensitivity of voice data and its cloud-based nature.
  • Whether Microsoft's explanations for Speech Recognition clearly distinguished between cloud-based and device-based functionality.
  • Whether Microsoft consistently respected user choices regarding the Speech Recognition setting, especially when conflicting with Cortana settings.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jun 12, 2018PIPEDA Report of Findings #2018-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-002: Company’s re-use of millions of Canadian Facebook user profiles violated privacy law

Profile Technology Ltd.

Multiple complainants alleged that Profile Technology Ltd. copied their personal information from Facebook profiles and groups without consent and posted it on its social networking website, making removal difficult, and indefinitely retaining helpdesk information. The OPC asserted jurisdiction over the New Zealand-based company due to a real and substantial connection to Canada. The OPC found that the information was not "publicly available" under PIPEDA's Regulations, and Profile Technology failed to obtain valid consent for its new purpose of operating a social networking site. Furthermore, the OPC determined that using this information for such a purpose was not appropriate in the circumstances and that the indefinite retention of helpdesk ticket information violated retention principles. Profile Technology refused to implement recommendations for deletion and a retention policy. Although the company later removed profiles from its website, it uploaded much of the data to the Internet Archive, which the OPC found did not resolve the contraventions and created new privacy risks. The matter was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2018-002: Company’s re-use of millions of Canadian Facebook user profiles violated privacy law

Jun 12, 2018PIPEDA Report of Findings #2018-002
Adjudicator: Daniel Therrien
Plain-Language Summary

Multiple complainants alleged that Profile Technology Ltd. copied their personal information from Facebook profiles and groups without consent and posted it on its social networking website, making removal difficult, and indefinitely retaining helpdesk information. The OPC asserted jurisdiction over the New Zealand-based company due to a real and substantial connection to Canada. The OPC found that the information was not "publicly available" under PIPEDA's Regulations, and Profile Technology failed to obtain valid consent for its new purpose of operating a social networking site. Furthermore, the OPC determined that using this information for such a purpose was not appropriate in the circumstances and that the indefinite retention of helpdesk ticket information violated retention principles. Profile Technology refused to implement recommendations for deletion and a retention policy. Although the company later removed profiles from its website, it uploaded much of the data to the Internet Archive, which the OPC found did not resolve the contraventions and created new privacy risks. The matter was found to be well-founded.

Key Issues
  • Whether the OPC had jurisdiction to investigate a New Zealand-based company's activities affecting Canadians.
  • Whether the investigation was time-barred under subsection 13(1) of PIPEDA.
  • Whether PIPEDA's application to commercial activity is constitutionally valid under the federal Trade and Commerce power.
  • Whether personal information copied from Facebook profiles was "publicly available" under PIPEDA's Regulations Specifying Publicly Available Information.
  • Whether Facebook profiles constitute a "publication" for the purposes of the Regulations.
  • Whether Profile Technology obtained valid knowledge and consent (Principle 4.3 PIPEDA) for the collection, use, and disclosure of personal information for its social networking website.
  • Whether consent obtained by Facebook was sufficient for Profile Technology's subsequent use of the data.
  • Whether opt-out consent would be an appropriate form of consent in this context (Principle 4.3.4 PIPEDA).
  • Whether Profile Technology's use of Facebook profile information for its social networking site was for purposes a reasonable person would consider "appropriate in the circumstances" (subsection 5(3) PIPEDA).
  • Whether Profile Technology retained personal information (helpdesk tickets) longer than necessary (Principle 4.5 PIPEDA).
  • Whether Profile Technology was responsible for personal information held by its third-party helpdesk service provider.
  • Whether Profile Technology's actions of removing profiles from its website and uploading data to the Internet Archive resolved the identified contraventions.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 12, 2018Repeat offenderIndexed Jun 30, 2026

Repeat offender: CSC unlawfully denies complainant access to his personal information a second time

Correctional Service Canada (CSC)

A federal inmate complained that Correctional Service Canada (CSC) repeatedly denied him access to his personal information, specifically video and audio recordings, in contravention of the Privacy Act. This complaint followed a similar investigation in 2012 where the OPC found serious deficiencies in CSC's handling of the complainant's requests, including failure to retain video recordings before destruction. In the current investigation, the OPC found that CSC again failed to retrieve and retain requested video recordings within their short retention period in two cases, and failed to respond to four other requests for grievance-related records. The OPC concluded that CSC contravened subsection 12(1) of the Privacy Act by denying the complainant access to his personal information. CSC accepted the OPC's recommendations to improve its processes for handling access requests for records with short retention periods and to respond to outstanding requests.

Quick view

Privacy ActWell-founded

Repeat offender: CSC unlawfully denies complainant access to his personal information a second time

Jun 12, 2018Repeat offender
Adjudicator: Daniel Therrien
Plain-Language Summary

A federal inmate complained that Correctional Service Canada (CSC) repeatedly denied him access to his personal information, specifically video and audio recordings, in contravention of the Privacy Act. This complaint followed a similar investigation in 2012 where the OPC found serious deficiencies in CSC's handling of the complainant's requests, including failure to retain video recordings before destruction. In the current investigation, the OPC found that CSC again failed to retrieve and retain requested video recordings within their short retention period in two cases, and failed to respond to four other requests for grievance-related records. The OPC concluded that CSC contravened subsection 12(1) of the Privacy Act by denying the complainant access to his personal information. CSC accepted the OPC's recommendations to improve its processes for handling access requests for records with short retention periods and to respond to outstanding requests.

Key Issues
  • Whether CSC contravened subsection 6(1) of the Privacy Act by failing to retain personal information for a prescribed period
  • Whether CSC contravened subsection 12(1) of the Privacy Act by failing to provide access to personal information
  • Whether CSC contravened subsection 16(3) of the Privacy Act by failing to respond to access requests within statutory time limits
  • Whether CSC appropriately applied paragraph 22(1)(c) of the Privacy Act to withhold video recordings
  • Whether CSC appropriately applied section 26 of the Privacy Act to withhold video recordings
  • Whether CSC made reasonable efforts to secure video recordings before destruction as per previous OPC recommendations
  • Whether CSC's processes for handling access requests for records with short retention periods are adequate
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 4, 2018Indexed Jun 30, 2026

Employee text messages intercepted without authorization at the Warkworth Institution

Correctional Service Canada (CSC)

The OPC received complaints alleging that Correctional Service Canada (CSC) contravened the Privacy Act by intercepting cell phone conversations and text messages near Warkworth Institution. CSC confirmed intercepting six text messages but denied recording conversations, stating it did not intend to collect text messages. The investigation found that CSC used a cell-site simulator, operated by a contractor, to detect unauthorized cell phone use by inmates. While the collection of metadata was deemed consistent with the Act due to security concerns, the interception of text message content was not authorized. The OPC concluded that CSC was responsible for the contractor's actions and that the collection of text messages contravened the Privacy Act. The complaints were found to be well-founded.

Quick view

Privacy ActWell-founded

Employee text messages intercepted without authorization at the Warkworth Institution

Jun 4, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC received complaints alleging that Correctional Service Canada (CSC) contravened the Privacy Act by intercepting cell phone conversations and text messages near Warkworth Institution. CSC confirmed intercepting six text messages but denied recording conversations, stating it did not intend to collect text messages. The investigation found that CSC used a cell-site simulator, operated by a contractor, to detect unauthorized cell phone use by inmates. While the collection of metadata was deemed consistent with the Act due to security concerns, the interception of text message content was not authorized. The OPC concluded that CSC was responsible for the contractor's actions and that the collection of text messages contravened the Privacy Act. The complaints were found to be well-founded.

Key Issues
  • Whether cell phone metadata constitutes personal information under the Privacy Act
  • Whether text messages constitute personal information under the Privacy Act
  • Whether the collection of cell phone metadata by CSC was consistent with section 4 of the Privacy Act
  • Whether the interception and collection of text message content by CSC was consistent with section 4 of the Privacy Act
  • Whether CSC is responsible for the actions of its contractor in collecting personal information
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jun 4, 2018Indexed Jun 30, 2026

Disclosure of Canadian Forces members’ medical records by DND authorized under Privacy Act although record retention practices were insufficient

Department of National Defence

The complaint alleged that the Department of National Defence (DND) improperly disclosed deceased Canadian Forces (CF) members’ medical records to Military Police (MP) investigators for "sudden death suicide investigations" under paragraph 8(2)(e) of the Privacy Act, without due consideration for necessity. Complainants argued that CF-NIS investigations should be limited to determining if wounds were self-inflicted, not broader medical history. DND contended that its Directorate of Access to Information and Privacy (DAIP) was not required to "look behind" facially valid requests, and that the lawfulness of an investigation was the responsibility of the investigative body. The Office of the Privacy Commissioner (OPC) found the allegation that DND failed to properly assess the necessity of the information sought under s. 8(2)(e) to be not well-founded, concluding that DAIP generally exercised sufficient scrutiny. However, the OPC also found that DND failed to meet its obligations under subsection 8(4) of the Privacy Act and section 7 of the Privacy Regulations by not retaining copies of 8(2)(e) request forms in several cases and lacking comprehensive records of disclosures. This constituted a well-founded finding regarding DND's recordkeeping practices. The OPC recommended DND update its policies to ensure retention of all request forms, confirmation of statutory authority for investigations, and maintenance of comprehensive disclosure records. DND committed to implementing these recommendations within six months.

Quick view

Privacy ActNot well-founded

Disclosure of Canadian Forces members’ medical records by DND authorized under Privacy Act although record retention practices were insufficient

Jun 4, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint alleged that the Department of National Defence (DND) improperly disclosed deceased Canadian Forces (CF) members’ medical records to Military Police (MP) investigators for "sudden death suicide investigations" under paragraph 8(2)(e) of the Privacy Act, without due consideration for necessity. Complainants argued that CF-NIS investigations should be limited to determining if wounds were self-inflicted, not broader medical history. DND contended that its Directorate of Access to Information and Privacy (DAIP) was not required to "look behind" facially valid requests, and that the lawfulness of an investigation was the responsibility of the investigative body. The Office of the Privacy Commissioner (OPC) found the allegation that DND failed to properly assess the necessity of the information sought under s. 8(2)(e) to be not well-founded, concluding that DAIP generally exercised sufficient scrutiny. However, the OPC also found that DND failed to meet its obligations under subsection 8(4) of the Privacy Act and section 7 of the Privacy Regulations by not retaining copies of 8(2)(e) request forms in several cases and lacking comprehensive records of disclosures. This constituted a well-founded finding regarding DND's recordkeeping practices. The OPC recommended DND update its policies to ensure retention of all request forms, confirmation of statutory authority for investigations, and maintenance of comprehensive disclosure records. DND committed to implementing these recommendations within six months.

Key Issues
  • Whether DND's Directorate of Access to Information and Privacy (DAIP) improperly granted full access to deceased Canadian Forces (CF) members’ medical records under paragraph 8(2)(e) of the Privacy Act.
  • Whether the DAIP gave due consideration to the necessity of the requested records for the investigation.
  • Whether CF-NIS requests for medical records were permissible under paragraph 8(2)(e) given their internal policies limiting the scope of suicide investigations.
  • Whether DND's recordkeeping practices for 8(2)(e) requests and disclosures were consistent with subsection 8(4) of the Privacy Act and section 7 of the Privacy Regulations.
  • Whether the DAIP should verify the statutory authority under which an investigative body's lawful investigation is being conducted, in line with the TBS Directive.