The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

607 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Oct 21, 2014Discontinued Case Summary #2014-004Indexed Jun 30, 2026

Discontinued Case Summary #2014-004: Complaint discontinued on the basis of bad faith as complainant had released the retailer from liability

A retailer

An individual filed a complaint against a retailer, alleging a failure to provide access to personal information under PIPEDA. This complaint arose after the complainant and the retailer had settled a small claims court dispute. As part of that settlement, the complainant had signed a mutual release, receiving financial compensation in exchange for releasing the retailer from all claims and complaints, including those arising under statute, related to events prior to the release date. The OPC found that the complaint was made in bad faith, given the existence of this mutual release. Consequently, the investigation was discontinued under paragraph 12.2(1)(b) of PIPEDA.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Discontinued Case Summary #2014-004: Complaint discontinued on the basis of bad faith as complainant had released the retailer from liability

Oct 21, 2014Discontinued Case Summary #2014-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual filed a complaint against a retailer, alleging a failure to provide access to personal information under PIPEDA. This complaint arose after the complainant and the retailer had settled a small claims court dispute. As part of that settlement, the complainant had signed a mutual release, receiving financial compensation in exchange for releasing the retailer from all claims and complaints, including those arising under statute, related to events prior to the release date. The OPC found that the complaint was made in bad faith, given the existence of this mutual release. Consequently, the investigation was discontinued under paragraph 12.2(1)(b) of PIPEDA.

Key Issues
  • Whether the complaint was made in bad faith under paragraph 12.2(1)(b) of PIPEDA
  • Whether a mutual release agreement impacts the validity of a subsequent privacy complaint
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Sep 16, 2014Indexed Jun 30, 2026

Name tags for border officers not a violation - September 16, 2014

Canada Border Services Agency (CBSA)

A group of Canada Border Services Agency (CBSA) employees complained that a new policy requiring them to wear name tags displaying their surnames, instead of badge numbers, violated sections 7 and 8 of the Privacy Act. They argued this constituted an unreasonable invasion of privacy and made them vulnerable to violence and intimidation, as their names could be used to find personal information. The CBSA contended that the name tags were part of a service excellence initiative, promoted professionalism and accountability, and that an employee's name on a name tag falls under an exception to the definition of personal information in the Act. The OPC found that while a surname on a name tag is information about an identifiable individual, it falls under paragraph (j) of the definition of personal information, which excludes information relating to the position or functions of a government employee for the purposes of sections 7 and 8. Therefore, the OPC concluded that the policy did not violate the Act.

Quick view

Privacy ActNot well-founded

Name tags for border officers not a violation - September 16, 2014

Sep 16, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A group of Canada Border Services Agency (CBSA) employees complained that a new policy requiring them to wear name tags displaying their surnames, instead of badge numbers, violated sections 7 and 8 of the Privacy Act. They argued this constituted an unreasonable invasion of privacy and made them vulnerable to violence and intimidation, as their names could be used to find personal information. The CBSA contended that the name tags were part of a service excellence initiative, promoted professionalism and accountability, and that an employee's name on a name tag falls under an exception to the definition of personal information in the Act. The OPC found that while a surname on a name tag is information about an identifiable individual, it falls under paragraph (j) of the definition of personal information, which excludes information relating to the position or functions of a government employee for the purposes of sections 7 and 8. Therefore, the OPC concluded that the policy did not violate the Act.

Key Issues
  • Whether the surname of a Border Services Officer (BSO) displayed on a name tag constitutes "personal information" under section 3 of the Privacy Act
  • Whether the surname on a name tag falls within the exception to the definition of personal information under paragraph (j) of section 3 of the Privacy Act
  • Whether the CBSA's requirement for BSOs to wear name tags displaying their surnames violates sections 7 and 8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Sep 5, 2014Indexed Jun 30, 2026

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Aboriginal Affairs and Northern Development Canada (AANDC)

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Quick view

Privacy ActWell-founded

Violating principle of 'need-to-know' leads to data breach - September 5, 2014

Sep 5, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Aboriginal Affairs and Northern Development Canada (AANDC) improperly disclosed personal information to La Presse newspaper. The newspaper published an article referencing a document created by AANDC that listed individuals who had made Access to Information Act (ATIA) requests related to former Minister Jim Prentice. AANDC confirmed the document's existence and reported that it had been created to respond to ATIA requests. The OPC found that AANDC improperly disclosed the personal information of those listed in the document, which ultimately reached La Presse. Furthermore, AANDC shared this information with officials who did not have a legitimate need-to-know. The complaint was found to be well-founded.

Key Issues
  • Whether the document contained personal information under s.3 of the Privacy Act
  • Whether all AANDC officials who accessed the document had a need-to-know the identity of the requesters under s.7(a) of the Privacy Act and TBS Policy on Access to Information s.6.2.3
  • Whether the disclosure of the information to La Presse constituted a contravention of s.8 of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 9, 2014Indexed Jun 30, 2026

Sharing of health information unjustified - July 9, 2014

Public Service Commission of Canada (PSC)

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Quick view

Privacy ActWell-founded

Sharing of health information unjustified - July 9, 2014

Jul 9, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that the Public Service Commission of Canada (PSC) improperly disclosed her medical information during an investigation into potential fraud in an appointment process. The PSC included a doctor's letter detailing the complainant's medical condition in a factual report, which was then shared with all witnesses in the investigation. The PSC argued this disclosure was necessary to uphold procedural fairness under paragraph 8(2)(a) of the Privacy Act, as all witnesses were "affected persons" who could face adverse conclusions. The OPC found that while procedural fairness may necessitate some disclosure, the PSC failed to demonstrate why the specific medical details were relevant or necessary for the witnesses to know. The OPC concluded that sharing the full doctor's letter was not a "consistent use" of the information and therefore contravened subsection 8(1) of the Privacy Act. The complaint was found to be well-founded, and the PSC committed to implementing new procedures to ensure compliance.

Key Issues
  • Whether the disclosure of the complainant's medical information to witnesses was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the PSC's interpretation of "affected person" and the requirements of procedural fairness justified the disclosure of sensitive medical information to all witnesses
  • Whether the PSC contravened subsection 8(1) of the Privacy Act by disclosing personal information without consent or a valid exception
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
May 22, 2014PIPEDA findings #2014-020Indexed Jun 30, 2026

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

A videographer

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2014-020: Videographer posts client’s wedding video on social media without consent

May 22, 2014PIPEDA findings #2014-020
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that a videographer used her wedding video for promotional purposes online without her consent. The videographer posted the video on social media and embedded it in a business listing to attract new clients. The videographer claimed a verbal agreement for reduced rates in exchange for promotional use and asserted copyright, but no documentation supported this. The OPC determined that using the video for promotional purposes constituted commercial activity under PIPEDA. Since no valid consent was obtained and no exemptions applied, the videographer was found to be in contravention of PIPEDA. The videographer subsequently removed the video and committed to including consent language in future contracts.

Key Issues
  • Whether the use of personal information constituted commercial activity
  • Whether the videographer had consent for this use
  • Whether the videographer needed consent for this use
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apple Canada Inc.

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-007 : Apple called upon to be more open about its collection and use of information for downloads

Apr 22, 2014Commissioner’s Findings - PIPEDA Case Summary #2014-007
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that Apple unnecessarily required payment information and date of birth to download free applications. The OPC found that Apple's privacy policy did not fully identify the purposes for collecting date of birth for authentication, leading to a well-founded and conditionally resolved finding after Apple agreed to revise its policy. Regarding payment information, the OPC determined that Apple did not make instructions for downloading free apps without providing payment details clearly accessible. This aspect was also found to be well-founded, and Apple agreed to implement a clear option for users to proceed without supplying payment information at registration. The OPC was pleased with Apple's commitment to address the issues.

Key Issues
  • Whether Apple's privacy policy adequately identified the purposes for collecting date of birth information for authentication (Principle 4.2 PIPEDA)
  • Whether Apple's collection of date of birth was limited to what was necessary for identified purposes (Principle 4.4 PIPEDA)
  • Whether Apple made information about its policies and practices concerning the collection of credit card information readily available to individuals (Principle 4.8 PIPEDA)
  • Whether Apple's practices resulted in the over-collection of sensitive payment information (Principle 4.4 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Mar 21, 2014Incident Summary #5Indexed Jun 30, 2026

Incident Summary #5: Life insurance company employs best practices in responding to mass mailing error that risked exposing personal information - March 21, 2014

A life insurance company

A life insurance company discovered that a mass mailing error risked exposing the personal information of 53 pension plan members. The new window envelopes used were larger, potentially revealing certificate numbers, SINs, dates of birth, spouse's names, and beneficiaries if statements shifted. Upon discovering the incident, the company promptly notified affected individuals, apologized, explained the incident, and offered a free one-year credit monitoring service. They also advised members to take harm-reducing steps and ceased using the problematic envelopes. The company informed the OPC about the incident and its response. The OPC concluded that the company demonstrated best practices in its incident response.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #5: Life insurance company employs best practices in responding to mass mailing error that risked exposing personal information - March 21, 2014

Mar 21, 2014Incident Summary #5
Adjudicator: Chantal Bernier
Plain-Language Summary

A life insurance company discovered that a mass mailing error risked exposing the personal information of 53 pension plan members. The new window envelopes used were larger, potentially revealing certificate numbers, SINs, dates of birth, spouse's names, and beneficiaries if statements shifted. Upon discovering the incident, the company promptly notified affected individuals, apologized, explained the incident, and offered a free one-year credit monitoring service. They also advised members to take harm-reducing steps and ceased using the problematic envelopes. The company informed the OPC about the incident and its response. The OPC concluded that the company demonstrated best practices in its incident response.

Key Issues
  • Whether a mass mailing error led to the potential exposure of personal information
  • Whether the life insurance company's response to the incident constituted best practices
Federal (Canada)Privacy ActNo jurisdiction
Federal (Canada) flag
Mar 4, 2014Indexed Jun 30, 2026

Retroactive removal of Privacy Act provisions leaves gun registry complainant with no recourse - 2015

Royal Canadian Mounted Police (RCMP)

The complainant alleged that the RCMP continued to retain and use personal information from the national long-gun registry, which should have been destroyed under the Ending the Long-Gun Registry Act. Specific allegations included a High River RCMP member's statement about locating firearms and an email from a Langley RCMP member referring to non-restricted firearm registration. The RCMP stated that electronic records were destroyed in October 2012 and hard copies by December 2013 (except for Quebec records). They also argued that information extracted from the registry before its destruction and retained in case files could be used consistent with its original purpose. The OPC found no evidence of contravention, noting that recent legislative amendments retroactively excluded the application of the Privacy Act to certain long-gun registry records, preventing further investigation into specific examples.

Quick view

Privacy ActNo jurisdiction

Retroactive removal of Privacy Act provisions leaves gun registry complainant with no recourse - 2015

Mar 4, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The complainant alleged that the RCMP continued to retain and use personal information from the national long-gun registry, which should have been destroyed under the Ending the Long-Gun Registry Act. Specific allegations included a High River RCMP member's statement about locating firearms and an email from a Langley RCMP member referring to non-restricted firearm registration. The RCMP stated that electronic records were destroyed in October 2012 and hard copies by December 2013 (except for Quebec records). They also argued that information extracted from the registry before its destruction and retained in case files could be used consistent with its original purpose. The OPC found no evidence of contravention, noting that recent legislative amendments retroactively excluded the application of the Privacy Act to certain long-gun registry records, preventing further investigation into specific examples.

Key Issues
  • Whether the RCMP continued to retain and use personal information from the national long-gun registry after it was required to be destroyed
  • Whether the High River RCMP used personal information from the long-gun registry in June 2013
  • Whether other RCMP detachments continued to use personal information from the long-gun registry after electronic records were destroyed in October 2012
  • Whether copies of the long-gun registry containing personal information still exist in the possession of the RCMP or other police services
  • Whether the use of personal information from the long-gun registry, retained in case files prior to the Ending the Long-gun Registry Act, is consistent with section 7 of the Privacy Act
  • Whether the retroactive exclusion of the Privacy Act by Bill C-59 affects the investigation
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 20, 2014Early resolved case summary #10Indexed Jun 30, 2026

Early resolved case summary #10: Bank improves its credit card account verification practices after challenge from customer - February 20, 2014

A financial institution

An individual complained that her bank required the last six digits of her Social Insurance Number (SIN) to set up a "verified credit account" for online purchases. She believed this practice was inappropriate and that an alternative method not requiring SIN information should be available. The bank initially stated an alternative existed through commercial websites, but the complainant noted this was not clearly communicated. The OPC highlighted a comparable case where a lack of transparency regarding authentication alternatives was found. Following this, the bank decided to discontinue the SIN-based authentication method entirely and update its website. The complainant was satisfied with this resolution, and the OPC confirmed the website changes.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Early resolved case summary #10: Bank improves its credit card account verification practices after challenge from customer - February 20, 2014

Feb 20, 2014Early resolved case summary #10
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that her bank required the last six digits of her Social Insurance Number (SIN) to set up a "verified credit account" for online purchases. She believed this practice was inappropriate and that an alternative method not requiring SIN information should be available. The bank initially stated an alternative existed through commercial websites, but the complainant noted this was not clearly communicated. The OPC highlighted a comparable case where a lack of transparency regarding authentication alternatives was found. Following this, the bank decided to discontinue the SIN-based authentication method entirely and update its website. The complainant was satisfied with this resolution, and the OPC confirmed the website changes.

Key Issues
  • Whether collecting a partial SIN for credit card account verification was appropriate under PIPEDA
  • Whether the bank provided adequate transparency regarding alternative verification methods
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Feb 10, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-012Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-012: Investment Firm Justified in its Collection of "Know Your Client" Information

An investment firm

A customer complained that his investment firm required an unreasonable amount of personal information on its "Know Your Client" (KYC) form as a condition for maintaining his Tax Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP). The firm requested details such as investment experience, annual income, spouse's income, dependents, assets, liabilities, and net worth. The firm argued this information was necessary to comply with the Investment Industry Regulatory Organization of Canada (IIROC) KYC and suitability requirements. The OPC assessed whether the firm contravened PIPEDA Principle 4.3.3 by requiring consent for information beyond explicitly specified and legitimate purposes. The OPC found that the firm had explicitly specified its purposes, which were legitimate given IIROC's regulatory framework. The OPC also concluded that the requested information, including details beyond IIROC's standard Form 2, was necessary for the firm to meet its regulatory obligations. Therefore, the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Commissioner’s Findings - PIPEDA Report of Findings #2014-012: Investment Firm Justified in its Collection of "Know Your Client" Information

Feb 10, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-012
Adjudicator: Chantal Bernier
Plain-Language Summary

A customer complained that his investment firm required an unreasonable amount of personal information on its "Know Your Client" (KYC) form as a condition for maintaining his Tax Free Savings Account (TFSA) and Registered Retirement Savings Plan (RRSP). The firm requested details such as investment experience, annual income, spouse's income, dependents, assets, liabilities, and net worth. The firm argued this information was necessary to comply with the Investment Industry Regulatory Organization of Canada (IIROC) KYC and suitability requirements. The OPC assessed whether the firm contravened PIPEDA Principle 4.3.3 by requiring consent for information beyond explicitly specified and legitimate purposes. The OPC found that the firm had explicitly specified its purposes, which were legitimate given IIROC's regulatory framework. The OPC also concluded that the requested information, including details beyond IIROC's standard Form 2, was necessary for the firm to meet its regulatory obligations. Therefore, the complaint was not well-founded.

Key Issues
  • Whether the investment firm explicitly specified the purposes for collecting personal information under Principle 4.2 PIPEDA
  • Whether the purposes for collecting personal information were legitimate under subsection 5(3) PIPEDA
  • Whether the investment firm required more personal information than necessary to achieve the legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA
  • Whether the collection of personal information was limited to that which was necessary for the identified purposes under Principle 4.4 PIPEDA
  • Whether information on investment experience was necessary to validate investment knowledge and assess risk tolerance
  • Whether spouse's or partner's annual income was necessary to assess overall financial position and suitability
  • Whether detailed assets and liabilities were necessary to establish net worth and understand financial situation
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jan 23, 2014Early resolved case summary #5Indexed Jun 30, 2026

Early resolved case summary #5: Web posting that was removed by individual retained by Internet search engine - January 23, 2014

An Internet search engine

An individual posted her résumé on a job website, which included her address. After having the job website remove the information, she discovered her résumé was still searchable via an Internet search engine. The individual contacted the search engine's Web administrator multiple times to request removal of her personal information, but the search engine did not comply. She then filed a complaint with the OPC. The OPC intervened directly with the search engine, which subsequently removed the cached copy of the individual's information from its search results using its URL removal tool. The complainant was satisfied with the outcome, and the complaint was closed.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #5: Web posting that was removed by individual retained by Internet search engine - January 23, 2014

Jan 23, 2014Early resolved case summary #5
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual posted her résumé on a job website, which included her address. After having the job website remove the information, she discovered her résumé was still searchable via an Internet search engine. The individual contacted the search engine's Web administrator multiple times to request removal of her personal information, but the search engine did not comply. She then filed a complaint with the OPC. The OPC intervened directly with the search engine, which subsequently removed the cached copy of the individual's information from its search results using its URL removal tool. The complainant was satisfied with the outcome, and the complaint was closed.

Key Issues
  • Whether an Internet search engine was obligated to remove cached personal information after the original source was deleted
  • Whether the search engine's refusal to remove the information constituted a contravention of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 14, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-001Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2014-001: Use of sensitive health information for targeting of Google ads raises privacy concerns

Google Inc.

A complainant alleged that Google's AdSense service displayed targeted advertisements for sleep apnea devices on unrelated websites after he searched for medical devices online. He viewed his online activities related to sleep apnea as sensitive information requiring express consent for targeted advertising. The OPC's technical analysis confirmed that Google was delivering these ads through online behavioural advertising (OBA) and that they persisted over time. Google initially attributed this to a technical issue but later confirmed it was due to 'remarketed ads,' a form of interest-based advertising. The OPC found that Google's practice of delivering tailored ads based on sensitive health information without express consent contravened PIPEDA Principles 4.3 and 4.3.6. Google committed to several remedial measures, including rejecting relevant remarketing campaigns, revising its policies, developing new internal training, and increasing monitoring.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Report of Findings #2014-001: Use of sensitive health information for targeting of Google ads raises privacy concerns

Jan 14, 2014Commissioner’s Findings - PIPEDA Report of Findings #2014-001
Adjudicator: Chantal Bernier
Plain-Language Summary

A complainant alleged that Google's AdSense service displayed targeted advertisements for sleep apnea devices on unrelated websites after he searched for medical devices online. He viewed his online activities related to sleep apnea as sensitive information requiring express consent for targeted advertising. The OPC's technical analysis confirmed that Google was delivering these ads through online behavioural advertising (OBA) and that they persisted over time. Google initially attributed this to a technical issue but later confirmed it was due to 'remarketed ads,' a form of interest-based advertising. The OPC found that Google's practice of delivering tailored ads based on sensitive health information without express consent contravened PIPEDA Principles 4.3 and 4.3.6. Google committed to several remedial measures, including rejecting relevant remarketing campaigns, revising its policies, developing new internal training, and increasing monitoring.

Key Issues
  • Whether the delivery of targeted advertisements based on online searches for medical devices constitutes online behavioural advertising (OBA)
  • Whether information related to online searches for medical devices is sensitive personal information
  • Whether express consent is required for the collection and use of sensitive personal health information for OBA purposes
  • Whether Google obtained appropriate consent under Principle 4.3 and 4.3.6 for the use of sensitive health information for targeted advertising
  • Whether Google's privacy policy accurately reflected its practices regarding sensitive categories in tailored ads
  • Whether Google's monitoring tools for preventing policy abuses were scalable and effective
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014Indexed Jun 30, 2026

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

An online dating service

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Key Issues
  • Whether the organization denied the complainant access to his personal information in violation of Principle 4.9
  • Whether the organization failed to respect the 30-day time limit for access requests under subsection 8(3)
  • Whether the organization contravened subsection 8(8) by destroying photographs, limiting the complainant's recourse
  • Whether the organization retained the complainant's information longer than necessary in contravention of Principle 4.5.3
  • Whether the organization continued to use the complainant's personal information for marketing after consent withdrawal, contravening Principle 4.3.8
  • Whether the organization lacked a privacy policy in contravention of Principle 4.1.4(d)
  • Whether the organization failed to safeguard the complainant's personal information as required by Principle 4.7.1
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Canada Revenue Agency employee accesses tax file without authorization

Canada Revenue Agency (CRA)

A complainant alleged that the Canada Revenue Agency (CRA) contravened the Privacy Act when an employee accessed his tax file without authorization in 2005 and 2006. The complainant became suspicious after community members showed knowledge of his financial information. An audit trail report revealed that a CRA employee had accessed his T1 tax account twice, viewing sensitive personal information including his Social Insurance Number, income, and family details. The OPC's investigation confirmed that the employee accessed the account without authorization and beyond the scope of their duties. The complaint was found to be well-founded, and CRA confirmed the employee no longer has access to taxpayer information.

Quick view

Privacy ActWell-founded

Canada Revenue Agency employee accesses tax file without authorization

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that the Canada Revenue Agency (CRA) contravened the Privacy Act when an employee accessed his tax file without authorization in 2005 and 2006. The complainant became suspicious after community members showed knowledge of his financial information. An audit trail report revealed that a CRA employee had accessed his T1 tax account twice, viewing sensitive personal information including his Social Insurance Number, income, and family details. The OPC's investigation confirmed that the employee accessed the account without authorization and beyond the scope of their duties. The complaint was found to be well-founded, and CRA confirmed the employee no longer has access to taxpayer information.

Key Issues
  • Whether a CRA employee accessed the complainant's tax file without authorization
  • Whether the unauthorized access contravened the use and disclosure provisions of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Criminal background check on tenant

Royal Canadian Mounted Police (RCMP)

A woman complained that two RCMP employee landlords performed a criminal background check on her using the Canadian Police Information Centre (CPIC) database when she applied to rent a basement apartment. The landlords requested personal identification to "look into" prospective tenants. An internal RCMP investigation confirmed that one officer accessed CPIC for personal reasons, citing the applicant being from "out of town" and concerns for officer safety and organizational security. The OPC found that the CPIC database contains personal information and its use is restricted to legitimate law enforcement purposes. The investigation concluded that the officer's access was for personal reasons, not authorized operational purposes. The complaint was found to be well-founded, and the RCMP took remedial actions including an apology to the complainant and a communiqué to employees regarding CPIC use policies.

Quick view

Privacy ActWell-founded

Criminal background check on tenant

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained that two RCMP employee landlords performed a criminal background check on her using the Canadian Police Information Centre (CPIC) database when she applied to rent a basement apartment. The landlords requested personal identification to "look into" prospective tenants. An internal RCMP investigation confirmed that one officer accessed CPIC for personal reasons, citing the applicant being from "out of town" and concerns for officer safety and organizational security. The OPC found that the CPIC database contains personal information and its use is restricted to legitimate law enforcement purposes. The investigation concluded that the officer's access was for personal reasons, not authorized operational purposes. The complaint was found to be well-founded, and the RCMP took remedial actions including an apology to the complainant and a communiqué to employees regarding CPIC use policies.

Key Issues
  • Whether the CPIC database contains personal information under the Privacy Act
  • Whether the RCMP officer accessed the CPIC database for personal reasons
  • Whether the access to the CPIC database was for an authorized operational purpose