The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

607 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Oct 26, 2015Early resolved case summary #2015-02Indexed Jun 30, 2026

Early resolved case summary #2015-02: Retailer takes remedial actions after employee inappropriately texted customer

A retailer

An individual complained to the OPC after a retailer's delivery person inappropriately texted her using her phone number, which he had transferred from his faulty work phone to his personal device. The complainant also felt the retailer's management initially showed a lack of concern. The OPC's inquiries revealed the delivery person obtained the customer's number from his work phone. The retailer, disapproving of employees transferring customer information to personal devices, subsequently implemented a new policy requiring delivery employees with faulty work phones to return to the warehouse immediately. The retailer also took disciplinary action against the delivery person, provided mandatory privacy retraining to employees, and the company president met personally with the affected customer. The customer was satisfied with the actions taken by the retailer.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-02: Retailer takes remedial actions after employee inappropriately texted customer

Oct 26, 2015Early resolved case summary #2015-02
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after a retailer's delivery person inappropriately texted her using her phone number, which he had transferred from his faulty work phone to his personal device. The complainant also felt the retailer's management initially showed a lack of concern. The OPC's inquiries revealed the delivery person obtained the customer's number from his work phone. The retailer, disapproving of employees transferring customer information to personal devices, subsequently implemented a new policy requiring delivery employees with faulty work phones to return to the warehouse immediately. The retailer also took disciplinary action against the delivery person, provided mandatory privacy retraining to employees, and the company president met personally with the affected customer. The customer was satisfied with the actions taken by the retailer.

Key Issues
  • Whether the delivery person's use of customer information for personal communication was appropriate
  • Whether the retailer adequately protected customer personal information when work devices were faulty
  • Whether the retailer responded appropriately to the customer's complaint
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Aug 14, 2015Early resolved case summary #2015-07Indexed Jun 30, 2026

Early resolved case summary #2015-07: Employee training a key factor in effectively satisfying customers’ requests about an organization’s personal information handling practices

A car dealership

An individual complained that a car dealership could not provide details about its personal information handling practices. The complainant was asked for her driver's license and credit card for a loaner car, and when she inquired about the collection and safeguards, the employee could not provide satisfactory answers. Her subsequent email to the dealership's privacy officer also went unanswered. The OPC conducted a site visit and reviewed the dealership's policies and practices, finding them satisfactory. However, the OPC emphasized the need for employees to be knowledgeable about these practices. The dealership agreed to conduct a review session for its employees. The complainant was satisfied with the outcome, and the matter was early resolved.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-07: Employee training a key factor in effectively satisfying customers’ requests about an organization’s personal information handling practices

Aug 14, 2015Early resolved case summary #2015-07
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a car dealership could not provide details about its personal information handling practices. The complainant was asked for her driver's license and credit card for a loaner car, and when she inquired about the collection and safeguards, the employee could not provide satisfactory answers. Her subsequent email to the dealership's privacy officer also went unanswered. The OPC conducted a site visit and reviewed the dealership's policies and practices, finding them satisfactory. However, the OPC emphasized the need for employees to be knowledgeable about these practices. The dealership agreed to conduct a review session for its employees. The complainant was satisfied with the outcome, and the matter was early resolved.

Key Issues
  • Whether the car dealership provided sufficient details about its personal information handling practices upon request
  • Whether the car dealership's employees were adequately trained to answer questions about personal information collection, safeguards, and retention
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Aug 1, 2015Early resolved case summary #2015-04Indexed Jun 30, 2026

Early resolved case summary #2015-04: Misidentification and lack of access to personal information leads to mistaken four-year debt pursuit

A collection agency

An individual complained that a collection agency was pursuing him for a debt he did not owe, which was negatively impacting his credit report. The individual alleged that the agency had been calling him for years and disclosed his financial information to his household members. He also claimed he was denied access to documentation validating the debt. The OPC contacted the collection agency, which then investigated the matter after discrepancies were noted in the original credit application. The agency ceased debt collection, acknowledged possible fraud, and committed to correcting the individual's credit report. The individual was satisfied with this resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-04: Misidentification and lack of access to personal information leads to mistaken four-year debt pursuit

Aug 1, 2015Early resolved case summary #2015-04
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a collection agency was pursuing him for a debt he did not owe, which was negatively impacting his credit report. The individual alleged that the agency had been calling him for years and disclosed his financial information to his household members. He also claimed he was denied access to documentation validating the debt. The OPC contacted the collection agency, which then investigated the matter after discrepancies were noted in the original credit application. The agency ceased debt collection, acknowledged possible fraud, and committed to correcting the individual's credit report. The individual was satisfied with this resolution.

Key Issues
  • Whether the collection agency ensured the accuracy of personal information used for debt collection (Principle 4.5 PIPEDA)
  • Whether the collection agency provided the individual with access to his personal information (Principle 4.9 PIPEDA)
  • Whether the collection agency disclosed personal financial information to third parties without consent (Principle 4.3 PIPEDA)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 30, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – RCMP

Royal Canadian Mounted Police (RCMP)

The complainant, an RCMP employee, alleged that the RCMP inappropriately used employees' personal information during a training course for Respectful Workplace Advisors on the National Administrative Records Management System (NARMS). During a data entry exercise, participants were given sheets containing real personal information of 91 employees, including names, ranks, and incident descriptions. The complainant raised concerns as participants were not advised real data would be used nor required to sign confidentiality agreements. The RCMP acknowledged that the use of this personal information for training purposes was not authorized under section 7 of the Privacy Act, as training was not a consistent use described in the applicable Personal Information Bank. The RCMP subsequently notified all 91 affected employees of the breach and took steps to prevent future occurrences. The OPC found the complaint to be well-founded.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – RCMP

Jul 30, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, an RCMP employee, alleged that the RCMP inappropriately used employees' personal information during a training course for Respectful Workplace Advisors on the National Administrative Records Management System (NARMS). During a data entry exercise, participants were given sheets containing real personal information of 91 employees, including names, ranks, and incident descriptions. The complainant raised concerns as participants were not advised real data would be used nor required to sign confidentiality agreements. The RCMP acknowledged that the use of this personal information for training purposes was not authorized under section 7 of the Privacy Act, as training was not a consistent use described in the applicable Personal Information Bank. The RCMP subsequently notified all 91 affected employees of the breach and took steps to prevent future occurrences. The OPC found the complaint to be well-founded.

Key Issues
  • Whether the use of employees' personal information for training purposes constituted an unauthorized use under section 7(a) of the Privacy Act
  • Whether training was a consistent use of personal information as described in the applicable Personal Information Bank (PIB PSU 915)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 28, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – Parole Board of Canada

Parole Board of Canada

The complaint alleged that the Parole Board of Canada (PBC) contravened the disclosure provisions of the Privacy Act when a human resources employee disclosed the complainant's medical information to individuals involved in a Public Service Staffing Tribunal (PSST) hearing. The PSST had specifically ordered the PBC to remove medical information from the material provided. The PBC acknowledged the disclosure, apologized to the complainant, and ensured the recipients disposed of the information. The OPC found that the complainant's medical information was disclosed without consent and not under any permitted disclosure provision of subsection 8(2) of the Act. Therefore, the OPC concluded that the complaint was well-founded.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – Parole Board of Canada

Jul 28, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint alleged that the Parole Board of Canada (PBC) contravened the disclosure provisions of the Privacy Act when a human resources employee disclosed the complainant's medical information to individuals involved in a Public Service Staffing Tribunal (PSST) hearing. The PSST had specifically ordered the PBC to remove medical information from the material provided. The PBC acknowledged the disclosure, apologized to the complainant, and ensured the recipients disposed of the information. The OPC found that the complainant's medical information was disclosed without consent and not under any permitted disclosure provision of subsection 8(2) of the Act. Therefore, the OPC concluded that the complaint was well-founded.

Key Issues
  • Whether the complainant's medical information constitutes personal information under s.3 of the Privacy Act
  • Whether the disclosure of the complainant's medical information by the PBC contravened s.8(1) of the Privacy Act
  • Whether the disclosure was in accordance with any of the permitted categories under s.8(2) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jul 28, 2015Discontinued Case Summary #2015-002Indexed Jun 30, 2026

Discontinued Case Summary #2015-002: OPC discontinues additional complaints against Globe24h.com following investigation into same privacy issues

Globe24h.com

Multiple complainants alleged that Globe24h.com collected, used, and disclosed their personal information without consent by republishing Canadian court and tribunal decisions and charging for removal. The OPC had previously investigated similar complaints against Globe24h.com and found them to be well-founded. Despite this, additional complaints continued to be received. The OPC decided to discontinue these new complaints under paragraph 12.2(1)(e) of PIPEDA, as the matter had already been the subject of a Commissioner's report. The OPC noted its continued interest in Globe24h.com's compliance and later participated in a Federal Court proceeding initiated by one of the original complainants. The Federal Court ultimately confirmed the OPC's findings and ordered Globe24h.com to remove the information and cease contravening PIPEDA, leading to the website's closure.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Discontinued Case Summary #2015-002: OPC discontinues additional complaints against Globe24h.com following investigation into same privacy issues

Jul 28, 2015Discontinued Case Summary #2015-002
Adjudicator: Daniel Therrien
Plain-Language Summary

Multiple complainants alleged that Globe24h.com collected, used, and disclosed their personal information without consent by republishing Canadian court and tribunal decisions and charging for removal. The OPC had previously investigated similar complaints against Globe24h.com and found them to be well-founded. Despite this, additional complaints continued to be received. The OPC decided to discontinue these new complaints under paragraph 12.2(1)(e) of PIPEDA, as the matter had already been the subject of a Commissioner's report. The OPC noted its continued interest in Globe24h.com's compliance and later participated in a Federal Court proceeding initiated by one of the original complainants. The Federal Court ultimately confirmed the OPC's findings and ordered Globe24h.com to remove the information and cease contravening PIPEDA, leading to the website's closure.

Key Issues
  • Whether Globe24h.com collected, used, and disclosed personal information without consent
  • Whether the Commissioner should discontinue investigation of additional complaints when the matter has already been reported on
  • Whether the practices of Globe24h.com contravened PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Jul 22, 2015PIPEDA findings #2015-019Indexed Jun 30, 2026

PIPEDA findings #2015-019: OPC complaint prompts telecom’s fraud investigation

A telecommunications company

A complainant reported a fraudulent telecommunications account causing a false debt statement on their credit report. The complainant alleged they never lived at the address associated with the debt, and the telecommunications company initially refused to correct the debt or provide proof of account opening. The credit-reporting agency had validated the debt with the telecom company. Upon the OPC's intervention, the telecommunications company's fraud team reviewed the file and determined the account was fraudulent. The company then cancelled the fraudulent account and updated the credit-reporting agency with accurate information. The complainant was satisfied with these actions, leading to an early resolution.

Quick view

Personal Information Protection and Electronic Documents ActResolved

PIPEDA findings #2015-019: OPC complaint prompts telecom’s fraud investigation

Jul 22, 2015PIPEDA findings #2015-019
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant reported a fraudulent telecommunications account causing a false debt statement on their credit report. The complainant alleged they never lived at the address associated with the debt, and the telecommunications company initially refused to correct the debt or provide proof of account opening. The credit-reporting agency had validated the debt with the telecom company. Upon the OPC's intervention, the telecommunications company's fraud team reviewed the file and determined the account was fraudulent. The company then cancelled the fraudulent account and updated the credit-reporting agency with accurate information. The complainant was satisfied with these actions, leading to an early resolution.

Key Issues
  • Whether the telecommunications company failed to ensure the accuracy of personal information
  • Whether the telecommunications company failed to correct inaccurate personal information
  • Whether the credit-reporting agency failed to ensure the accuracy of personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jul 9, 2015Early resolved case summary #2015-01Indexed Jun 30, 2026

Early resolved case summary #2015-01: Store stops practice of posting pictures of suspected shoplifters - July 2015

A department store

A customer complained to the OPC after noticing a department store publicly displaying photographs of individuals, asking for information about them. The store claimed police and legal counsel advised this practice was permissible for alleged shoplifters. The OPC disagreed, explaining that publicly disclosing personal information (photographs) without consent is not allowed under PIPEDA. The store agreed to remove the pictures and discontinue the practice, opting to deal with police directly for such matters. The complainant was satisfied with this resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-01: Store stops practice of posting pictures of suspected shoplifters - July 2015

Jul 9, 2015Early resolved case summary #2015-01
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained to the OPC after noticing a department store publicly displaying photographs of individuals, asking for information about them. The store claimed police and legal counsel advised this practice was permissible for alleged shoplifters. The OPC disagreed, explaining that publicly disclosing personal information (photographs) without consent is not allowed under PIPEDA. The store agreed to remove the pictures and discontinue the practice, opting to deal with police directly for such matters. The complainant was satisfied with this resolution.

Key Issues
  • Whether publicly displaying photographs of suspected shoplifters without consent constitutes an unauthorized disclosure of personal information under PIPEDA
  • Whether photographs of individuals recorded on video surveillance are considered personal information under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 6, 2015PIPEDA Case Summary #2015-010Indexed Jun 30, 2026

PIPEDA Case Summary #2015-010: Customer’s emails sent to her acquaintance following a telecom employee’s attempt to fix a problem with the customer’s email service

A telecommunications provider

An individual complained that her telecommunications provider disclosed her personal information without consent. A technical support representative, while attempting to fix her email service, inadvertently configured her email application to automatically forward her emails, including one containing a temporary password, to an acquaintance. The OPC found that this constituted a disclosure of personal information without consent, contravening Principle 4.3. The telecom provider initially provided inaccurate information to the OPC regarding corrective measures taken, but later clarified its existing measures. The complaint was found to be well-founded and resolved, as the provider had some measures in place to prevent recurrence, despite the initial misrepresentations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2015-010: Customer’s emails sent to her acquaintance following a telecom employee’s attempt to fix a problem with the customer’s email service

Jul 6, 2015PIPEDA Case Summary #2015-010
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that her telecommunications provider disclosed her personal information without consent. A technical support representative, while attempting to fix her email service, inadvertently configured her email application to automatically forward her emails, including one containing a temporary password, to an acquaintance. The OPC found that this constituted a disclosure of personal information without consent, contravening Principle 4.3. The telecom provider initially provided inaccurate information to the OPC regarding corrective measures taken, but later clarified its existing measures. The complaint was found to be well-founded and resolved, as the provider had some measures in place to prevent recurrence, despite the initial misrepresentations.

Key Issues
  • Whether the telecommunications provider disclosed the individual's personal information without consent
  • Whether the disclosure contravened Principle 4.3 of PIPEDA
  • Whether the telecommunications provider provided accurate information to the OPC during the investigation
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jun 28, 2015Early resolved case summary #2015-05Indexed Jun 30, 2026

Early resolved case summary #2015-05: Anti-virus service provider steps up safeguards after customer personal information fraudulently used by someone posing as an employee

Anti-virus service provider

A couple received fraudulent calls from someone posing as an anti-virus service provider technician, who gained remote access to their computer and processed a fraudulent credit card payment. The fraudster used the couple's private account number, which they believed was obtained from the legitimate service provider. The couple struggled to get the service provider to investigate the matter, leading them to file a complaint with the OPC. The OPC requested the service provider conduct an investigation, which revealed an employee had improperly accessed the complainant's account. The employee was dismissed, and the service provider reimbursed the couple and implemented new safeguards, including an auditing system for employee access and a streamlined procedure for escalating privacy concerns. The complainants were satisfied with these outcomes.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-05: Anti-virus service provider steps up safeguards after customer personal information fraudulently used by someone posing as an employee

Jun 28, 2015Early resolved case summary #2015-05
Adjudicator: Daniel Therrien
Plain-Language Summary

A couple received fraudulent calls from someone posing as an anti-virus service provider technician, who gained remote access to their computer and processed a fraudulent credit card payment. The fraudster used the couple's private account number, which they believed was obtained from the legitimate service provider. The couple struggled to get the service provider to investigate the matter, leading them to file a complaint with the OPC. The OPC requested the service provider conduct an investigation, which revealed an employee had improperly accessed the complainant's account. The employee was dismissed, and the service provider reimbursed the couple and implemented new safeguards, including an auditing system for employee access and a streamlined procedure for escalating privacy concerns. The complainants were satisfied with these outcomes.

Key Issues
  • Whether the anti-virus service provider adequately protected personal information against unauthorized access by employees (Principle 4.7 PIPEDA)
  • Whether the anti-virus service provider had adequate procedures to receive and respond to complaints about personal information handling (Principle 4.10 PIPEDA)
  • Whether the anti-virus service provider adequately investigated the complaint (Principle 4.10.4 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
May 22, 2015Early resolved case summary #2015-06Indexed Jun 30, 2026

Early resolved case summary #2015-06: Manager snoops on employee’s personal bank account after employee calls in sick

A credit union

An employee of a credit union complained that her manager accessed her personal financial information without consent. The manager suspected the employee had falsely called in sick and checked her bank account transactions to see if she had used her debit card out of province. The employee discovered this when her employment was terminated and the manager referenced the incident. After receiving an inconclusive response from the credit union, she filed a complaint with the OPC. The OPC initiated its early resolution process, and the credit union acknowledged the manager's actions were without a valid business purpose and constituted an unauthorized use of personal information. The credit union committed to addressing the issue with the manager and sent a letter of apology to the employee. The employee was satisfied with this resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-06: Manager snoops on employee’s personal bank account after employee calls in sick

May 22, 2015Early resolved case summary #2015-06
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee of a credit union complained that her manager accessed her personal financial information without consent. The manager suspected the employee had falsely called in sick and checked her bank account transactions to see if she had used her debit card out of province. The employee discovered this when her employment was terminated and the manager referenced the incident. After receiving an inconclusive response from the credit union, she filed a complaint with the OPC. The OPC initiated its early resolution process, and the credit union acknowledged the manager's actions were without a valid business purpose and constituted an unauthorized use of personal information. The credit union committed to addressing the issue with the manager and sent a letter of apology to the employee. The employee was satisfied with this resolution.

Key Issues
  • Whether a manager accessing an employee's personal bank account without a valid business purpose constitutes unauthorized use of personal information under PIPEDA
  • Whether the credit union's actions to address the manager's conduct and apologize to the employee were satisfactory for early resolution
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

An organization

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Key Issues
  • Whether the disclosed leave information constituted personal information under PIPEDA
  • Whether the organization's purposes for disclosing employee leave information to other employees were appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the disclosure of leave type was necessary for the organization to meet its employee schedule management needs
  • Whether the benefits of the leave exchange system were proportional to the loss of privacy experienced by employees
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 29, 2015Indexed Jun 30, 2026

Disclosure to Interpol raises concerns regarding electronic transmission of personal information

Canada Border Services Agency

The complainant alleged that the Canada Border Services Agency (CBSA) improperly disclosed his personal information, including a judgment from his country of origin, to the High Commission of Canada in Ghana and subsequently to Interpol, without his consent. This disclosure occurred during the verification of documents submitted for his refugee claim, which alleged persecution by the Nigerian government. The CBSA argued the disclosure was a consistent use under the Privacy Act for refugee determination and enforcement of the IRPA, necessary to verify the authenticity of the judgment after other documents were found fraudulent. The OPC found that the disclosure itself was permitted under paragraph 8(2)(a) of the Privacy Act as a consistent use for refugee determination purposes, thus concluding the primary complaint was "not well-founded." However, the OPC raised significant concerns regarding the CBSA's lack of established procedures for such verifications at the time, and the use of insecure commercial email (Yahoo!) for transmitting sensitive personal information of a refugee claimant. The OPC emphasized the inherent sensitivity of such information and the potential risk to claimants, recommending that CBSA review and strengthen its procedures, particularly concerning secure transmission methods and training. The OPC also noted it lacked jurisdiction over the actions of Interpol or Nigerian authorities.

Quick view

Privacy ActWell-founded

Disclosure to Interpol raises concerns regarding electronic transmission of personal information

Apr 29, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) improperly disclosed his personal information, including a judgment from his country of origin, to the High Commission of Canada in Ghana and subsequently to Interpol, without his consent. This disclosure occurred during the verification of documents submitted for his refugee claim, which alleged persecution by the Nigerian government. The CBSA argued the disclosure was a consistent use under the Privacy Act for refugee determination and enforcement of the IRPA, necessary to verify the authenticity of the judgment after other documents were found fraudulent. The OPC found that the disclosure itself was permitted under paragraph 8(2)(a) of the Privacy Act as a consistent use for refugee determination purposes, thus concluding the primary complaint was "not well-founded." However, the OPC raised significant concerns regarding the CBSA's lack of established procedures for such verifications at the time, and the use of insecure commercial email (Yahoo!) for transmitting sensitive personal information of a refugee claimant. The OPC emphasized the inherent sensitivity of such information and the potential risk to claimants, recommending that CBSA review and strengthen its procedures, particularly concerning secure transmission methods and training. The OPC also noted it lacked jurisdiction over the actions of Interpol or Nigerian authorities.

Key Issues
  • Whether the disclosure of the complainant's personal information (including the Judgment) by CBSA to the High Commission and Interpol without consent contravened section 8 of the Privacy Act.
  • Whether the disclosure was for a purpose consistent with the original collection under paragraph 8(2)(a) of the Privacy Act.
  • Whether CBSA's procedures for verifying documents with countries of origin and Interpol were sufficient at the time of disclosure.
  • Whether the electronic transmission of personal information via commercial email (Yahoo!) was secure and appropriate given the sensitivity.
  • Whether the OPC had jurisdiction over alleged secondary disclosures by Interpol or Nigerian authorities.
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 23, 2015PIPEDA Report of Findings #2015-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

An investment brokerage

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 23, 2015PIPEDA Report of Findings #2015-006
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Key Issues
  • Whether the collection of net worth, marital status, and spouse's occupation was necessary for opening a self-directed investment account under Principle 4.4 PIPEDA
  • Whether the purposes for collecting the personal information were explicitly specified under Principle 4.2 PIPEDA
  • Whether the purposes for collecting the personal information were legitimate and appropriate under subsection 5(3) PIPEDA
  • Whether the organization required consent to the collection of information beyond that required for explicitly specified and legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 16, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – Public Services and Procurement Canada

Public Services and Procurement Canada (PSPC)

An individual complained that Public Services and Procurement Canada (PSPC) mishandled her personal information by disclosing that she had filed a harassment complaint against her Director. The complainant alleged that the Director revealed this information during a management meeting. The investigation confirmed that the Director disclosed at a management meeting that the complainant had filed a complaint against her, as evidenced by meeting notes and confirmations from attendees. While the Director claimed the information was also her personal information, the OPC found no evidence that the employees present at the meeting needed to know the complainant's identity. The OPC concluded that PSPC did not reasonably consider the appropriateness of disclosing the complainant's identity without her consent, violating the Privacy Act.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – Public Services and Procurement Canada

Apr 16, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Public Services and Procurement Canada (PSPC) mishandled her personal information by disclosing that she had filed a harassment complaint against her Director. The complainant alleged that the Director revealed this information during a management meeting. The investigation confirmed that the Director disclosed at a management meeting that the complainant had filed a complaint against her, as evidenced by meeting notes and confirmations from attendees. While the Director claimed the information was also her personal information, the OPC found no evidence that the employees present at the meeting needed to know the complainant's identity. The OPC concluded that PSPC did not reasonably consider the appropriateness of disclosing the complainant's identity without her consent, violating the Privacy Act.

Key Issues
  • Whether the disclosure of the complainant's identity as having filed a harassment complaint constituted personal information under s.3 of the Privacy Act
  • Whether the disclosure of the complainant's identity was made without her consent
  • Whether the disclosure was for a purpose consistent with the purpose for which the information was obtained or compiled, as per s.8(2)(a) of the Privacy Act
  • Whether the employees present at the meeting needed to know the complainant's identity