
PIPEDA Findings #2022-003: Telecommunications firm failed to obtain appropriate consent for voiceprint authentication program
The complainant alleged that Rogers Communications Inc. improperly enrolled her in its Voice ID voiceprint authentication program without her consent and failed to allow her to opt out or delete her voiceprint. Rogers utilized a passive voiceprinting technology, "tuning," to create algorithmic voiceprints for customer authentication and fraud prevention. The Office of the Privacy Commissioner (OPC) found Rogers' purpose for collecting voiceprints to be appropriate, concluding this aspect of the complaint was not well-founded. However, the OPC determined that Rogers failed to obtain valid and meaningful express consent for the collection of sensitive biometric voiceprints, both during the "tuning" process and enrolment, as customers would not reasonably expect this. Furthermore, Rogers did not provide a clearly explained and easily accessible option for individuals to opt out and improperly retained voiceprints of opted-out individuals without any actual purpose. The OPC also identified deficiencies in Rogers' training materials and monitoring protocols for ensuring staff obtained valid consent. In response to OPC recommendations, Rogers committed to significant changes, including obtaining express consent before tuning, clearly informing customers of opt-out/deletion, deleting retained voiceprints, and improving training and monitoring. Consequently, the consent and retention aspects of the complaint were found to be well-founded and conditionally resolved.
Ontario
British Columbia
Alberta
Saskatchewan
Manitoba
Quebec
Nova Scotia
New Brunswick
Prince Edward Island
Newfoundland and Labrador
Yukon
Northwest Territories
Nunavut