The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,639 decisions matching
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01404Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01404

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by July 29, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01404

May 20, 20225820-01404

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by July 29, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01403Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01403

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 23, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01403

May 20, 20225820-01403

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 23, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01405Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01405

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 11, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01405

May 20, 20225820-01405

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 11, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01406Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01406

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 25, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01406

May 20, 20225820-01406

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 25, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01401Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01401

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 7, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01401

May 20, 20225820-01401

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 7, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01407Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01407

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 5, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01407

May 20, 20225820-01407

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 5, 2022.

Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 20, 2022Indexed Jun 30, 2026

Investigation into a privacy breach at a Canada Border Services Agency contractor

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at a Canada Border Services Agency contractor

May 20, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Key Issues
  • Whether licence plate image files, including associated metadata (jurisdiction, characters, date, time, border crossing site, lane number), constitute personal information under Section 3 of the Privacy Act.
  • Whether the unauthorized access and disclosure of these licence plate image files constituted an improper disclosure under Section 8 of the Privacy Act.
  • Whether the Canada Border Services Agency (CBSA) had adequate security safeguards in place, particularly in its contractual arrangements with a third-party contractor, to protect personal information.
  • Whether the data retention practices for licence plate image files by the CBSA and its contractor were appropriate and compliant with the Privacy Act.
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 19, 20225821-01019Indexed Apr 21, 2026

Communications Security Establishment Canada, 5821-01019

The Information Commissioner ordered Communications Security Establishment Canada to provide a final response to the access request no later than July 24, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Communications Security Establishment Canada, 5821-01019

May 19, 20225821-01019

The Information Commissioner ordered Communications Security Establishment Canada to provide a final response to the access request no later than July 24, 2022.

Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2022PIPEDA Findings #2022-004Indexed Jun 30, 2026

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

MGM Resorts International

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

May 19, 2022PIPEDA Findings #2022-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Key Issues
  • Whether MGM had the obligation to report the breach to the OPC and notify affected Canadians
  • Whether the MGM breach met the RROSH reporting and notification threshold
  • Whether the personal information involved was sensitive
  • Whether there was a high probability of misuse of the personal information
  • Whether MGM notified the OPC and affected Canadians as soon as feasible
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
May 13, 2022Indexed Jun 30, 2026

DND breached the Privacy Act in disclosing the identity of a workplace violence complainant who had an expectation of confidentiality

Department of National Defence (DND)

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

Quick view

Privacy ActWell-founded & conditionally resolved

DND breached the Privacy Act in disclosing the identity of a workplace violence complainant who had an expectation of confidentiality

May 13, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that the Department of National Defence (DND) breached the Privacy Act by disclosing their identity as a workplace violence (WPV) complainant to an investigator conducting a separate administrative investigation into the complainant's conduct. DND argued the disclosure was a "consistent use" under paragraph 8(2)(a) of the Privacy Act, necessary to address allegations against the individual. The OPC found that while disclosure to labour relations was a consistent use, disclosure to the investigator was not, as the consent form created a reasonable expectation of confidentiality for the WPV complaint. The OPC concluded that the disclosure to the investigator was not directly connected to the original purpose of collecting the WPV complaint information. DND committed to implementing recommendations to ensure future disclosures align with participants' reasonable expectations.

Key Issues
  • Whether the disclosure of the WPV complainant's identity to labour relations was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the disclosure of the WPV complainant's identity to an investigator for a separate administrative investigation was a "consistent use" under paragraph 8(2)(a) of the Privacy Act
  • Whether the consent form provided by DND created a reasonable expectation of confidentiality regarding the complainant's identity
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
May 12, 20225820-02800Indexed Jun 30, 2026

5820-02800 — Shared Services Canada and Public Services and Procurement Canada

Shared Services Canada

The complainant alleged that Shared Services Canada (SSC) improperly refused to process an access request for records related to informal official language complaints. SSC argued that the request, even after being narrowed to a one-year timeframe and specific keywords in email subject lines, did not meet the requirements of section 6 of the Access to Information Act because it would require tasking over 8,300 employees and create an unreasonable administrative burden. The Information Commissioner disagreed, stating that the term "reasonable effort" in section 6 refers to identifying records, not limiting the number of individuals tasked. The Commissioner also noted that the Act provides for time extensions for large requests and that the potential for redacting personal information under section 19 is not a valid reason to refuse processing. The Commissioner concluded that the request was sufficiently detailed and ordered SSC to process it.

Quick view

Access to Information ActWell-founded

5820-02800 — Shared Services Canada and Public Services and Procurement Canada

May 12, 20225820-02800
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Shared Services Canada (SSC) improperly refused to process an access request for records related to informal official language complaints. SSC argued that the request, even after being narrowed to a one-year timeframe and specific keywords in email subject lines, did not meet the requirements of section 6 of the Access to Information Act because it would require tasking over 8,300 employees and create an unreasonable administrative burden. The Information Commissioner disagreed, stating that the term "reasonable effort" in section 6 refers to identifying records, not limiting the number of individuals tasked. The Commissioner also noted that the Act provides for time extensions for large requests and that the potential for redacting personal information under section 19 is not a valid reason to refuse processing. The Commissioner concluded that the request was sufficiently detailed and ordered SSC to process it.

Key Issues
  • Whether the access request provided sufficient detail to enable an experienced employee to identify records with a reasonable effort under s.6 ATIA
  • Whether the administrative burden on the institution constitutes a valid reason to refuse processing a request under s.6 ATIA
  • Whether the potential for retrieving personal information that would be exempt under s.19 ATIA is a valid reason to refuse processing a request
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
May 10, 2022PIPEDA Findings #2022-002Indexed Jun 30, 2026

PIPEDA Findings #2022-002: Biron Health Group has ceased sending promotional emails to travellers arriving in Canada who undergo COVID-19 testing

Biron Health Group

The complainant alleged that Biron Health Group (Biron) sent him promotional emails without his consent after he underwent mandatory COVID-19 testing upon arrival at Montreal Trudeau Airport. He provided his email solely for test results. Biron initially believed it had implicit consent due to an established business relationship. The OPC found that Biron could not reasonably assume implicit consent, as travellers had no choice but to use Biron for mandatory testing and would not expect their health information to be used for marketing. Biron ceased the practice and deleted affected email addresses from its marketing database. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

PIPEDA Findings #2022-002: Biron Health Group has ceased sending promotional emails to travellers arriving in Canada who undergo COVID-19 testing

May 10, 2022PIPEDA Findings #2022-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Biron Health Group (Biron) sent him promotional emails without his consent after he underwent mandatory COVID-19 testing upon arrival at Montreal Trudeau Airport. He provided his email solely for test results. Biron initially believed it had implicit consent due to an established business relationship. The OPC found that Biron could not reasonably assume implicit consent, as travellers had no choice but to use Biron for mandatory testing and would not expect their health information to be used for marketing. Biron ceased the practice and deleted affected email addresses from its marketing database. The complaint was settled during the investigation.

Key Issues
  • Whether Biron Health Group had implicit consent to send promotional emails to individuals undergoing mandatory COVID-19 testing
  • Whether the collection of personal information for mandatory health testing could be used for secondary marketing purposes
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
May 6, 20223219-00238Indexed Jun 30, 2026

Public Services and Procurement Canada (Re), 2022 OIC 23

Public Services and Procurement Canada

The complainant alleged that Public Services and Procurement Canada (PSPC) failed to provide records in response to an access request concerning a contract awarded to Brookfield Global Integrated Solutions (BGIS) and a related subcontract. PSPC initially stated it could not identify relevant records, arguing the subcontract was not under its control. The investigation found that while the records were not in PSPC's physical possession, they were under its control for the purposes of the Access to Information Act, based on the legal relationship between PSPC and BGIS and the terms of their contract. The Commissioner concluded that PSPC did not conduct a reasonable search because it made no effort to obtain the subcontract and related documents from BGIS. The complaint was found to be well founded, and the Commissioner recommended PSPC retrieve and process the records. However, PSPC declined to implement the recommendations.

Quick view

Access to Information ActWell-founded

Public Services and Procurement Canada (Re), 2022 OIC 23

May 6, 20223219-00238
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Public Services and Procurement Canada (PSPC) failed to provide records in response to an access request concerning a contract awarded to Brookfield Global Integrated Solutions (BGIS) and a related subcontract. PSPC initially stated it could not identify relevant records, arguing the subcontract was not under its control. The investigation found that while the records were not in PSPC's physical possession, they were under its control for the purposes of the Access to Information Act, based on the legal relationship between PSPC and BGIS and the terms of their contract. The Commissioner concluded that PSPC did not conduct a reasonable search because it made no effort to obtain the subcontract and related documents from BGIS. The complaint was found to be well founded, and the Commissioner recommended PSPC retrieve and process the records. However, PSPC declined to implement the recommendations.

Key Issues
  • Whether the subcontract and related records were "under the control" of Public Services and Procurement Canada (PSPC) for the purposes of the Access to Information Act
  • Whether the contents of the record relate to an institutional matter
  • Whether PSPC could expect to obtain a copy of the record upon request
  • Whether PSPC conducted a reasonable search for records responsive to the request
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
May 3, 20223218-01586Indexed Jun 30, 2026

Innovation, Science and Economic Development Canada (Re), 2022 OIC 22

Innovation, Science and Economic Development Canada

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) improperly withheld information under paragraph 20(1)(c) of the Access to Information Act. The request sought records related to job creation estimates and estimated jobs maintained figures for projects that received assistance between 2011 and 2018. The complaint's scope was narrowed to information concerning eleven third parties, with only Toyota Motor Manufacturing Canada (Toyota) providing representations to support the exemption claim. The Commissioner found that neither Toyota nor ISED demonstrated a clear and direct connection between disclosure and a risk of material financial loss or harm to Toyota's competitive position, beyond mere speculation. Arguments regarding potential public misunderstanding were also deemed insufficient to meet the legal test for harm under s.20(1)(c), especially given that an explanatory note could address such concerns. Consequently, the Commissioner concluded that the information did not qualify for the exemption. The complaint was found to be well founded, and the Commissioner recommended full disclosure, though ISED indicated it would not fully implement the recommendation for some Toyota-related information.

Quick view

Access to Information ActWell-founded

Innovation, Science and Economic Development Canada (Re), 2022 OIC 22

May 3, 20223218-01586
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) improperly withheld information under paragraph 20(1)(c) of the Access to Information Act. The request sought records related to job creation estimates and estimated jobs maintained figures for projects that received assistance between 2011 and 2018. The complaint's scope was narrowed to information concerning eleven third parties, with only Toyota Motor Manufacturing Canada (Toyota) providing representations to support the exemption claim. The Commissioner found that neither Toyota nor ISED demonstrated a clear and direct connection between disclosure and a risk of material financial loss or harm to Toyota's competitive position, beyond mere speculation. Arguments regarding potential public misunderstanding were also deemed insufficient to meet the legal test for harm under s.20(1)(c), especially given that an explanatory note could address such concerns. Consequently, the Commissioner concluded that the information did not qualify for the exemption. The complaint was found to be well founded, and the Commissioner recommended full disclosure, though ISED indicated it would not fully implement the recommendation for some Toyota-related information.

Key Issues
  • Whether s.20(1)(c) ATIA (financial impact on a third party) applies to job creation estimates and estimated jobs maintained figures
  • Whether disclosure could result in material financial loss or gain to a third party
  • Whether there is a reasonable expectation of harm beyond a mere possibility
  • Whether disclosure could injure the competitive position of a third party
  • Whether arguments of public misunderstanding are sufficient to meet the legal test for harm under s.20(1)(c)
  • Whether an explanatory note could prevent potential harm to a third party
  • Whether ISED met its burden of proof for applying s.20(1)(c) to information where third parties did not provide representations
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 26, 2022Indexed Jun 30, 2026

Access at issue: The challenge of accessing our collective memory

Library and Archives Canada

The Information Commissioner initiated a systemic investigation into Library and Archives Canada's (LAC) delayed responses to access requests. This investigation was prompted by a long-standing trend of LAC failing to meet legislative deadlines for responding to access requests, which worsened during the COVID-19 pandemic. The investigation found that during the period under review, nearly 80% of requests completed by LAC did not comply with the timeframes set out in the Access to Information Act. The Commissioner informed the Minister of Canadian Heritage, as the head of LAC, of these findings and made ten recommendations. A special report was subsequently tabled in Parliament, highlighting issues within LAC and broader challenges in Canada's access to information system, specifically regarding inter-institutional consultations and the absence of a government-wide declassification framework.

Quick view

Access to Information ActWell-founded

Access at issue: The challenge of accessing our collective memory

Apr 26, 2022
Adjudicator: Caroline Maynard
Plain-Language Summary

The Information Commissioner initiated a systemic investigation into Library and Archives Canada's (LAC) delayed responses to access requests. This investigation was prompted by a long-standing trend of LAC failing to meet legislative deadlines for responding to access requests, which worsened during the COVID-19 pandemic. The investigation found that during the period under review, nearly 80% of requests completed by LAC did not comply with the timeframes set out in the Access to Information Act. The Commissioner informed the Minister of Canadian Heritage, as the head of LAC, of these findings and made ten recommendations. A special report was subsequently tabled in Parliament, highlighting issues within LAC and broader challenges in Canada's access to information system, specifically regarding inter-institutional consultations and the absence of a government-wide declassification framework.

Key Issues
  • Whether Library and Archives Canada was responding to access requests within the legislative deadlines
  • Whether the delays in responding to access requests constituted a systemic issue