The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

137 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Mar 25, 2026Indexed Jun 30, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Nova Scotia Power

This document is a compliance letter from Nova Scotia Power to the OPC, outlining actions taken and commitments made following a significant data breach that occurred in March 2025. The breach, caused by malware, led to the exfiltration of personal information belonging to approximately 375,000 current and 540,000 former customers. The compromised data included names, contact information, financial details, driver's license numbers, and SINs. The OPC received numerous complaints regarding the breach, including concerns about the collection and retention of SINs and the timeliness and method of notification to affected individuals. Nova Scotia Power has committed to deleting customer SINs (subject to legal requirements) and undergoing an external security assessment by October 2026. Upon satisfactory fulfillment of these commitments, the OPC's investigation will be discontinued.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

This document is a compliance letter from Nova Scotia Power to the OPC, outlining actions taken and commitments made following a significant data breach that occurred in March 2025. The breach, caused by malware, led to the exfiltration of personal information belonging to approximately 375,000 current and 540,000 former customers. The compromised data included names, contact information, financial details, driver's license numbers, and SINs. The OPC received numerous complaints regarding the breach, including concerns about the collection and retention of SINs and the timeliness and method of notification to affected individuals. Nova Scotia Power has committed to deleting customer SINs (subject to legal requirements) and undergoing an external security assessment by October 2026. Upon satisfactory fulfillment of these commitments, the OPC's investigation will be discontinued.

Key Issues
  • Whether Nova Scotia Power's security safeguards were adequate to protect personal information
  • Whether Nova Scotia Power's collection and retention of Social Insurance Numbers (SINs) was appropriate
  • Whether Nova Scotia Power's notification of affected individuals was timely and appropriate
  • Whether Nova Scotia Power has taken sufficient corrective measures to address the breach and prevent future incidents
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2026Indexed Jun 30, 2026

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Canada Border Services Agency (CBSA)

An employee of the Canada Border Services Agency (CBSA) filed a complaint after their personal information, including sensitive details about an accommodation request, was inadvertently made accessible to other CBSA employees through the Apollo information management system. The issue stemmed from improperly set permissions on an old ATIP file folder, which allowed document titles and sometimes the first line of emails containing personal information to be visible via Apollo's search function. The OPC found that the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority. While the CBSA corrected the specific permissions and committed to broader reviews and improved naming conventions, it did not agree to implement mandatory and trackable training for employees on Apollo permissions management. Consequently, the OPC found the complaint well-founded but unresolved, as it was not satisfied that sufficient safeguards were in place to prevent recurrence.

Quick view

Privacy ActWell-founded

Unauthorized Disclosure of Employee Personal Information in CBSA’s Information Management System

Mar 24, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

An employee of the Canada Border Services Agency (CBSA) filed a complaint after their personal information, including sensitive details about an accommodation request, was inadvertently made accessible to other CBSA employees through the Apollo information management system. The issue stemmed from improperly set permissions on an old ATIP file folder, which allowed document titles and sometimes the first line of emails containing personal information to be visible via Apollo's search function. The OPC found that the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority. While the CBSA corrected the specific permissions and committed to broader reviews and improved naming conventions, it did not agree to implement mandatory and trackable training for employees on Apollo permissions management. Consequently, the OPC found the complaint well-founded but unresolved, as it was not satisfied that sufficient safeguards were in place to prevent recurrence.

Key Issues
  • Whether the CBSA contravened section 8 of the Privacy Act by disclosing personal information without consent or legal authority
  • Whether the CBSA appropriately responded to the unauthorized disclosure
  • Whether the CBSA's proposed measures, without mandatory and trackable training, are sufficient to prevent future unauthorized disclosures
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
Mar 24, 20265825-04206Indexed Jun 1, 2026

National Defence, 5825-04206

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5825-04206

Mar 24, 20265825-04206

The OIC ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report..

Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Mar 24, 20265825-03707Indexed Jun 30, 2026

Transport Canada (Re), 2026 OIC 35

Transport Canada

The complainant alleged that Transport Canada failed to respond to an access request within the statutory 30-day period and improperly handled the request before opening the file. The request sought correspondence related to the Greater Toronto Airports Authority (GTAA) concerning noise, flight path changes, passenger-based formulas, and airspace redesign. The investigation found that Transport Canada did not respond within the 30-day timeframe, largely due to delays from a primary Office of Primary Interest (OPI) in retrieving records, exacerbated by a building fire that prevented access to paper records. Electronic records were also not processed while waiting for paper records. However, the Commissioner found that Transport Canada did not improperly handle the request initially, as it reasonably sought clarification when the request did not explicitly name the institution. The complaint regarding the delay was found to be well-founded, and Transport Canada was ordered to provide a complete response within 120 business days. Transport Canada indicated it would not fully implement the order, stating it would provide an interim response instead.

Quick view

Access to Information ActWell-founded

Transport Canada (Re), 2026 OIC 35

Mar 24, 20265825-03707
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Transport Canada failed to respond to an access request within the statutory 30-day period and improperly handled the request before opening the file. The request sought correspondence related to the Greater Toronto Airports Authority (GTAA) concerning noise, flight path changes, passenger-based formulas, and airspace redesign. The investigation found that Transport Canada did not respond within the 30-day timeframe, largely due to delays from a primary Office of Primary Interest (OPI) in retrieving records, exacerbated by a building fire that prevented access to paper records. Electronic records were also not processed while waiting for paper records. However, the Commissioner found that Transport Canada did not improperly handle the request initially, as it reasonably sought clarification when the request did not explicitly name the institution. The complaint regarding the delay was found to be well-founded, and Transport Canada was ordered to provide a complete response within 120 business days. Transport Canada indicated it would not fully implement the order, stating it would provide an interim response instead.

Key Issues
  • Whether Transport Canada responded to the access request within the 30-day period as per section 7 of the Access to Information Act
  • Whether Transport Canada improperly handled the request before opening the file
  • Whether Transport Canada met its duty to assist the complainant under subsection 4(2.1)
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Mar 24, 20265822-05248Indexed Jun 30, 2026

Privy Council Office (Re), 2026 OIC 34

Privy Council Office

The complainant alleged that the Privy Council Office (PCO) failed to conduct a reasonable search for records related to a previous access request (A-2012-00683) and a 10-page "Lessons Learned" document. The OIC found that PCO did not provide sufficient evidence to demonstrate that a reasonable search had been conducted, particularly regarding a second search by its Records Operations unit for which details were lacking. The Commissioner concluded that PCO did not conduct a reasonable search. Consequently, the complaint was deemed well founded, and PCO was ordered to conduct a new search, process any additional records found, and provide a supplementary response to the complainant within 36 business days. PCO did not indicate whether it would comply with the order.

Quick view

Access to Information ActWell-founded

Privy Council Office (Re), 2026 OIC 34

Mar 24, 20265822-05248
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Privy Council Office (PCO) failed to conduct a reasonable search for records related to a previous access request (A-2012-00683) and a 10-page "Lessons Learned" document. The OIC found that PCO did not provide sufficient evidence to demonstrate that a reasonable search had been conducted, particularly regarding a second search by its Records Operations unit for which details were lacking. The Commissioner concluded that PCO did not conduct a reasonable search. Consequently, the complaint was deemed well founded, and PCO was ordered to conduct a new search, process any additional records found, and provide a supplementary response to the complainant within 36 business days. PCO did not indicate whether it would comply with the order.

Key Issues
  • Whether the institution conducted a reasonable search for records
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
Mar 23, 20265825-04225Indexed Jun 1, 2026

Communications Security Establishment Canada, 5825-04225

The Information Commissioner ordered Communications Security Establishment Canada to provide a complete response to the access request no later than 36 business days following the date of the final report.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Communications Security Establishment Canada, 5825-04225

Mar 23, 20265825-04225

The Information Commissioner ordered Communications Security Establishment Canada to provide a complete response to the access request no later than 36 business days following the date of the final report.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
Mar 23, 20265825-03819Indexed Jun 1, 2026

National Defence, 5825-03819

The Information Commissioner ordered National Defence to provide a complete response to the access request no later than 36 business days following the date of the final report.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5825-03819

Mar 23, 20265825-03819

The Information Commissioner ordered National Defence to provide a complete response to the access request no later than 36 business days following the date of the final report.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
Mar 23, 20265825-03820Indexed Jun 1, 2026

National Defence, 5825-03820

The Information Commissioner ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5825-03820

Mar 23, 20265825-03820

The Information Commissioner ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
Mar 23, 20265825-03823Indexed Jun 1, 2026

National Defence, 5825-03823

The Information Commissioner ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

National Defence, 5825-03823

Mar 23, 20265825-03823

The Information Commissioner ordered National Defence to provide a complete response to the access request no later than 36 business days after the date of the final report.

Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 18, 2026Indexed Jun 30, 2026

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Treasury Board of Canada Secretariat

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Treasury Board of Canada Secretariat (TBS) regarding its personal information practices for monitoring employee on-site presence under the federal government's hybrid work model. The complainant alleged invasive collection, use, and disclosure of personal information, questioning TBS's compliance with sections 4, 6, 7, and 8 of the Privacy Act, as well as transparency, necessity, proportionality, and Privacy Impact Assessment (PIA) requirements. The OPC found that TBS's collection of aggregated data for organizational compliance was for non-administrative purposes, authorized by existing statutes, and appropriately de-identified to fall outside the scope of the Act for disclosure. For individual compliance, managers primarily relied on observation and self-reporting, supported by internal guidance. While TBS's practices were largely compliant, the OPC encouraged TBS to update its Personal Information Bank (PIB) description for Physical Access Controls (PSU 907) to explicitly reflect the potential use of access logs in formal investigations and to clearly communicate this to employees. Overall, the OPC concluded that TBS's personal information handling practices were compliant with the Privacy Act.

Quick view

Privacy ActNot well-founded

Investigation into the Treasury Board of Canada Secretariat’s implementation of the Direction on Prescribed Presence in the Workplace

Mar 18, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Treasury Board of Canada Secretariat (TBS) regarding its personal information practices for monitoring employee on-site presence under the federal government's hybrid work model. The complainant alleged invasive collection, use, and disclosure of personal information, questioning TBS's compliance with sections 4, 6, 7, and 8 of the Privacy Act, as well as transparency, necessity, proportionality, and Privacy Impact Assessment (PIA) requirements. The OPC found that TBS's collection of aggregated data for organizational compliance was for non-administrative purposes, authorized by existing statutes, and appropriately de-identified to fall outside the scope of the Act for disclosure. For individual compliance, managers primarily relied on observation and self-reporting, supported by internal guidance. While TBS's practices were largely compliant, the OPC encouraged TBS to update its Personal Information Bank (PIB) description for Physical Access Controls (PSU 907) to explicitly reflect the potential use of access logs in formal investigations and to clearly communicate this to employees. Overall, the OPC concluded that TBS's personal information handling practices were compliant with the Privacy Act.

Key Issues
  • Whether the collection of employees' personal information for on-site presence monitoring was related directly to TBS's operating programs or activities under section 4 of the Privacy Act.
  • Whether TBS's retention and disposal practices for personal information collected for on-site presence monitoring complied with section 6 of the Privacy Act, specifically subsections 6(1) and 6(3).
  • Whether TBS's use of personal information for on-site presence monitoring was a 'consistent use' authorized under section 7(a) of the Privacy Act.
  • Whether TBS's disclosure of aggregated on-site presence data to senior management constituted personal information under section 3 of the Privacy Act and complied with section 8.
  • Whether TBS's transparency and openness related to its hybrid compliance monitoring approach, including standard Personal Information Banks (PIBs), was adequate under sections 10 and 11 of the Privacy Act.
  • Whether TBS's personal information practices for on-site presence monitoring complied with the necessity and proportionality data principles.
  • Whether TBS was required to complete a Privacy Impact Assessment (PIA) for its verification regime.
  • Whether managers' practices for monitoring individual compliance with the hybrid work model contravened the Privacy Act.
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Federal (Canada) flag
Mar 17, 2026Indexed Jun 30, 2026

Compliance agreement between the Privacy Commissioner of Canada and the World Anti-Doping Agency

World Anti-Doping Agency (WADA)

The World Anti-Doping Agency (WADA) entered into a compliance agreement with the Privacy Commissioner of Canada (OPC) to resolve an investigation into WADA's collection, use, and disclosure practices concerning athletes' personal information in its Anti-Doping Administration and Management System (ADAMS). The OPC launched an investigation after receiving a complaint, and WADA disputed the allegations and challenged the OPC's jurisdiction in Federal Court. Without admitting contravention or waiving jurisdictional rights, WADA agreed to remedial measures. These measures include ceasing to permit Anti-Doping Organizations (ADOs) to use ADAMS data for non-anti-doping purposes, updating the World Anti-Doping Code, and amending agreements with ADOs to restrict data use to anti-doping purposes only. WADA will also provide the OPC with a mechanism to ensure ADOs adhere to these restrictions. The investigation will be placed in abeyance and discontinued upon completion of the remedial measures.

Quick view

Personal Information Protection and Electronic Documents ActDiscontinued

Compliance agreement between the Privacy Commissioner of Canada and the World Anti-Doping Agency

Mar 17, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

The World Anti-Doping Agency (WADA) entered into a compliance agreement with the Privacy Commissioner of Canada (OPC) to resolve an investigation into WADA's collection, use, and disclosure practices concerning athletes' personal information in its Anti-Doping Administration and Management System (ADAMS). The OPC launched an investigation after receiving a complaint, and WADA disputed the allegations and challenged the OPC's jurisdiction in Federal Court. Without admitting contravention or waiving jurisdictional rights, WADA agreed to remedial measures. These measures include ceasing to permit Anti-Doping Organizations (ADOs) to use ADAMS data for non-anti-doping purposes, updating the World Anti-Doping Code, and amending agreements with ADOs to restrict data use to anti-doping purposes only. WADA will also provide the OPC with a mechanism to ensure ADOs adhere to these restrictions. The investigation will be placed in abeyance and discontinued upon completion of the remedial measures.

Key Issues
  • Whether WADA's collection, use, and disclosure practices of athletes' personal information in ADAMS comply with PIPEDA
  • Whether the OPC has statutory, territorial, and/or subject matter jurisdiction over WADA
  • Whether ADOs are permitted to use personal information in ADAMS for purposes other than anti-doping
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Mar 16, 20265825-03323Indexed Jun 30, 2026

Innovation, Science and Economic Development Canada (Re), 2026 OIC 29

Innovation, Science and Economic Development Canada

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) took an unreasonable extension of time to respond to an access request for Microsoft Teams messages and related policies. ISED claimed a 390-day extension, citing the volume of records, complexity, and the need for senior-level review, as well as internal and external consultations. The Commissioner found that ISED failed to demonstrate a link between the reasons for the extension and its length, or that a serious attempt was made to determine the necessary length. Specifically, the 240-day extension for volume and interference was deemed excessive, and the 150-day extension for consultations lacked sufficient justification. The Commissioner concluded that the extension was invalid, leading to a deemed refusal of access. The complaint was found to be well-founded, and ISED was ordered to provide a complete response within 60 business days.

Quick view

Access to Information ActWell-founded

Innovation, Science and Economic Development Canada (Re), 2026 OIC 29

Mar 16, 20265825-03323
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) took an unreasonable extension of time to respond to an access request for Microsoft Teams messages and related policies. ISED claimed a 390-day extension, citing the volume of records, complexity, and the need for senior-level review, as well as internal and external consultations. The Commissioner found that ISED failed to demonstrate a link between the reasons for the extension and its length, or that a serious attempt was made to determine the necessary length. Specifically, the 240-day extension for volume and interference was deemed excessive, and the 150-day extension for consultations lacked sufficient justification. The Commissioner concluded that the extension was invalid, leading to a deemed refusal of access. The complaint was found to be well-founded, and ISED was ordered to provide a complete response within 60 business days.

Key Issues
  • Whether the 240-day extension under s.9(1)(a) ATIA for volume and interference was reasonable
  • Whether the 150-day extension under s.9(1)(b) ATIA for consultations was reasonable
  • Whether ISED made a serious effort to assess the necessary length of the extension of time
  • Whether there was a link between the reasons for the extension and its length
  • Whether the calculation of the length of the extension was sufficiently rigorous, logical, and supportable
  • Whether ISED was in deemed refusal under s.10(3) ATIA
Federal (Canada)Access to Information Acts.6.1 Application Granted (refusal authorized)
Federal (Canada) flag
Mar 16, 20262026 OIC 18Indexed Jun 30, 2026

Decision pursuant to 6.1, 2026 OIC 18

A federal institution

An unnamed federal institution applied to the Information Commissioner for approval to decline to act on an access request, arguing it constituted an abuse of the right of access under subsection 6.1(1) of the Access to Information Act. The request sought extensive records related to rare diseases and medications, spanning from the earliest records to the present, across multiple departments and communication types. The institution contended the request was overly broad, would overburden its small staff, and required manual review of an unmanageable volume of records. The Commissioner found that the request, particularly its fifth part, was indeed overly broad and that responding to it would overburden the institution, which has only 15 employees and processes a modest number of pages annually. Despite the requester's offer to provide a more specific list of diseases, the Commissioner concluded that the institution had made reasonable efforts to assist and that the request would still be unduly burdensome. Consequently, the Commissioner granted the institution's application to decline to act on the request.

Quick view

Access to Information Acts.6.1 Application Granted (refusal authorized)

Decision pursuant to 6.1, 2026 OIC 18

Mar 16, 20262026 OIC 18
Adjudicator: Caroline Maynard
Plain-Language Summary

An unnamed federal institution applied to the Information Commissioner for approval to decline to act on an access request, arguing it constituted an abuse of the right of access under subsection 6.1(1) of the Access to Information Act. The request sought extensive records related to rare diseases and medications, spanning from the earliest records to the present, across multiple departments and communication types. The institution contended the request was overly broad, would overburden its small staff, and required manual review of an unmanageable volume of records. The Commissioner found that the request, particularly its fifth part, was indeed overly broad and that responding to it would overburden the institution, which has only 15 employees and processes a modest number of pages annually. Despite the requester's offer to provide a more specific list of diseases, the Commissioner concluded that the institution had made reasonable efforts to assist and that the request would still be unduly burdensome. Consequently, the Commissioner granted the institution's application to decline to act on the request.

Key Issues
  • Whether the access request is an abuse of the right of access under s.6.1(1) ATIA
  • Whether the request is overly broad
  • Whether acting on the request would overburden the institution
  • Whether the institution met its duty to assist the requester under s.4(2.1) ATIA
  • Whether the circumstances warrant granting approval to decline to act on the request
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Mar 13, 20265823-03487Indexed Jun 30, 2026

Employment and Social Development Canada (Re), 2026 OIC 32

Employment and Social Development Canada

The complainant sought records related to the Canada Student Service Grant from Employment and Social Development Canada (ESDC), alleging improper withholding of information under several exemptions and an unreasonable search for records. The Commissioner found that ESDC improperly withheld information claimed under paragraphs 20(1)(b) and 20(1)(c), determining that the institution failed to demonstrate the information's confidentiality, its financial/commercial/scientific/technical nature, or a reasonable expectation of harm from disclosure. For information withheld under paragraphs 21(1)(a) and 21(1)(b), the Commissioner concluded that factual information and final decisions did not meet the exemption requirements and that ESDC failed to reasonably exercise its discretion for other information that did meet the requirements. Similarly, while the majority of information claimed under section 23 met the requirements for solicitor-client privilege, some portions did not, and privilege was waived for other parts by the Privy Council Office. However, the Commissioner found that ESDC conducted a reasonable search for records, despite the complainant's concerns about missing emails, handwritten notes, and cabinet confidences. Consequently, the complaint was found to be well founded regarding the improper application of exemptions and the failure to exercise discretion. The Commissioner ordered ESDC to disclose specific information and to re-exercise its discretion for other information withheld under sections 21 and 23. ESDC notified the Commissioner of its intent to comply with the order, though it also indicated a desire to apply additional exemptions not raised during the investigation, which the Commissioner rejected.

Quick view

Access to Information ActWell-founded

Employment and Social Development Canada (Re), 2026 OIC 32

Mar 13, 20265823-03487
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant sought records related to the Canada Student Service Grant from Employment and Social Development Canada (ESDC), alleging improper withholding of information under several exemptions and an unreasonable search for records. The Commissioner found that ESDC improperly withheld information claimed under paragraphs 20(1)(b) and 20(1)(c), determining that the institution failed to demonstrate the information's confidentiality, its financial/commercial/scientific/technical nature, or a reasonable expectation of harm from disclosure. For information withheld under paragraphs 21(1)(a) and 21(1)(b), the Commissioner concluded that factual information and final decisions did not meet the exemption requirements and that ESDC failed to reasonably exercise its discretion for other information that did meet the requirements. Similarly, while the majority of information claimed under section 23 met the requirements for solicitor-client privilege, some portions did not, and privilege was waived for other parts by the Privy Council Office. However, the Commissioner found that ESDC conducted a reasonable search for records, despite the complainant's concerns about missing emails, handwritten notes, and cabinet confidences. Consequently, the complaint was found to be well founded regarding the improper application of exemptions and the failure to exercise discretion. The Commissioner ordered ESDC to disclose specific information and to re-exercise its discretion for other information withheld under sections 21 and 23. ESDC notified the Commissioner of its intent to comply with the order, though it also indicated a desire to apply additional exemptions not raised during the investigation, which the Commissioner rejected.

Key Issues
  • Whether ESDC improperly withheld information under s.16(2) ATIA
  • Whether ESDC improperly withheld information under s.19(1) ATIA
  • Whether the information met the requirements of s.20(1)(b) ATIA (confidential financial, commercial, scientific or technical information)
  • Whether the information met the requirements of s.20(1)(c) ATIA (material financial impact or harm to competitive position)
  • Whether the information met the requirements of s.21(1)(a) ATIA (advice or recommendations)
  • Whether the information met the requirements of s.21(1)(b) ATIA (accounts of consultations or deliberations)
  • Whether the information met the requirements of s.23 ATIA (solicitor-client and litigation privilege)
  • Whether ESDC reasonably exercised its discretion to disclose information under s.20(5) ATIA
  • Whether ESDC reasonably exercised its discretion to disclose information under s.21 ATIA
  • Whether ESDC reasonably exercised its discretion to disclose information under s.23 ATIA
  • Whether ESDC conducted a reasonable search for records
  • Whether PCO waived solicitor-client privilege over certain information
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Mar 12, 2026Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Quick view

Privacy ActNot well-founded

Special report to Parliament: Investigation into the contracting practices of the Canada Border Services Agency related to the development of the ArriveCAN application

Mar 12, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Canada Border Services Agency's (CBSA) contracting practices for the ArriveCAN application, focusing on measures to protect travellers' personal information handled by contractors. An individual's complaint and a parliamentary committee's motion prompted the review into whether contractors accessed personal information without required security clearances, potentially contravening sections 7 and 8 of the Privacy Act. The OPC found that while contracts included appropriate security clauses, there were issues with the accuracy and timeliness of security assessments (SRCLs) and overly broad task descriptions in Task Authorizations (TAs). Although vendors met organizational security requirements, one contractor worked for 18 months with an expired security clearance, exposing the CBSA to increased privacy risks. The CBSA implemented adequate administrative and technical safeguards, such as segregated environments and strict access controls, but six contractors were granted access to personal information not strictly necessary for their duties. Despite these shortcomings, the investigation found no evidence that personal information was actually used or disclosed in contravention of the Act. Consequently, the complaint was found to be not well-founded, but the OPC issued recommendations to the CBSA to strengthen its contracting and privacy practices, which the agency accepted.

Key Issues
  • Whether the CBSA authorized contractors to access personal information collected through ArriveCAN without the required security clearance, in contravention of sections 7 and 8 of the Privacy Act
  • Whether ArriveCAN contracts and Task Authorizations (TAs) contained appropriate clauses to ensure the protection of travellers’ personal information that contractors had access to
  • Whether security requirements identified in contracts and TAs were accurate and specific
  • Whether the CBSA complied with organizational security screening requirements for vendors
  • Whether the CBSA complied with personnel security screening requirements for contractors
  • Whether the CBSA implemented adequate administrative safeguards to protect personal information accessed by contractors
  • Whether the CBSA implemented adequate technical safeguards to protect personal information accessed by contractors
  • Whether the CBSA restricted contractor permissions and access to personal information to what was strictly necessary