
Royal Canadian Mounted Police, 5819-05031
The Information Commissioner ordered Royal Canadian Mounted Police to provide a final response to the access request forthwith.
The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

The Information Commissioner ordered Royal Canadian Mounted Police to provide a final response to the access request forthwith.

The complainant alleged that the Immigration and Refugee Board of Canada (IRB) failed to conduct a reasonable search for records in response to a request for "all final decisions rendered pursuant to section 37 of the Immigration and Refugee Protection Act (IRPA) from January 2018 until June 2020." The IRB provided only written decisions, stating that audio recordings are only provided when specifically requested. However, the OIC found that the IRB's ATIP office had erroneously informed its Office of Primary Interest that only written decisions were sought, thereby reducing the scope of the request without the complainant's approval. The Commissioner determined that "all final decisions" includes audio recordings, as a record under the Act means any documentary material regardless of medium or form. Consequently, the Commissioner found that the IRB did not perform a reasonable search.

The Information Commissioner ordered National Defence to provide a final response to the access request as soon as possible and no later than July 19, 2022.

The complainant alleged that the Public Health Agency of Canada (PHAC) took an unreasonable extension of time to respond to an access request for all correspondence, including emails, MS Teams messages, texts, and phone messages, sent and received by Iain Stewart between June 14 and June 21, 2021. PHAC notified the complainant of a 1,950-day extension under paragraphs 9(1)(a) and 9(1)(b) of the Access to Information Act. The Commissioner found that PHAC demonstrated the request involved a large volume of records (30,000 pages) and that meeting the 30-day deadline would unreasonably interfere with its operations, particularly given its role in the COVID-19 pandemic response and increased ATIP workload. The Commissioner also found that consultations were necessary and could not be completed within 30 days. Despite the lengthy extension, the Commissioner concluded that PHAC's calculation was reasonable given the circumstances, including the complexity of the records and the institution's processing capacity. Therefore, the complaint was not well founded.

An anonymous applicant complained that Innovation, Science and Economic Development Canada (ISED) improperly withheld "Total Repayment figures" related to several projects under the Technology Partnerships Canada (TPC) program, involving 21 third parties. ISED initially relied on paragraph 20(1)(c) of the Access to Information Act, while some third parties also raised paragraphs 20(1)(b) and 20(1)(d). The Commissioner found that the information was financial and commercial but not objectively confidential under paragraph 20(1)(b), as there was no reasonable expectation of non-disclosure for public funds, nor would confidentiality foster public benefit. For paragraph 20(1)(c), the Commissioner determined that neither ISED nor the third parties demonstrated a clear and direct connection between disclosure and a reasonable expectation of material financial harm or injury to competitive position, deeming their arguments speculative. Similarly, for paragraph 20(1)(d), insufficient evidence was provided to show that disclosure would interfere with contractual negotiations. Consequently, the complaint was found to be well-founded, and the Commissioner ordered ISED to disclose all the Total Repayments figures at issue.

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 5, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 25, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 7, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 11, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by July 29, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 23, 2022.

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

The Information Commissioner ordered Communications Security Establishment Canada to provide a final response to the access request no later than July 24, 2022.

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.