The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,639 decisions matching
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Nov 9, 20202020 OIC 13Indexed Jun 30, 2026

Privy Council Office (Re), 2020 OIC 13

Privy Council Office

The complainant alleged that the Privy Council Office (PCO) failed to respond to an access request within the statutory time limits. The request sought minutes of the Joint Intelligence Committee from 1968. PCO claimed an extension, partly for consultations, but then closed the file under its 'no late file' policy when consulted institutions did not respond by the deadline. The OIC found that the Act does not permit an institution to cease processing a request due to delayed consultations, concluding that PCO was in deemed refusal under subsection 10(3) of the Act. The Information Commissioner recommended PCO respond to the request and revoke its 'no late file' policy. PCO agreed to revoke the policy and committed to responding by a revised date.

Quick view

Access to Information ActWell-founded

Privy Council Office (Re), 2020 OIC 13

Nov 9, 20202020 OIC 13
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Privy Council Office (PCO) failed to respond to an access request within the statutory time limits. The request sought minutes of the Joint Intelligence Committee from 1968. PCO claimed an extension, partly for consultations, but then closed the file under its 'no late file' policy when consulted institutions did not respond by the deadline. The OIC found that the Act does not permit an institution to cease processing a request due to delayed consultations, concluding that PCO was in deemed refusal under subsection 10(3) of the Act. The Information Commissioner recommended PCO respond to the request and revoke its 'no late file' policy. PCO agreed to revoke the policy and committed to responding by a revised date.

Key Issues
  • Whether the institution responded to the access request within the time limits set out in the Access to Information Act
  • Whether the institution was authorized to close the file due to delayed responses from consulted institutions
  • Whether the institution was in deemed refusal pursuant to subsection 10(3) of the Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 28, 2020PIPEDA Findings #2020-004Indexed Jun 30, 2026

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

The Cadillac Fairview Corporation Limited

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-004: Joint investigation of the Cadillac Fairview Corporation Limited by the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Alberta, and the Information and Privacy Commissioner for British Columbia

Oct 28, 2020PIPEDA Findings #2020-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC), along with its provincial counterparts in Alberta and British Columbia, conducted a joint investigation into The Cadillac Fairview Corporation Limited (CFCL) regarding its use of Anonymous Video Analytics (AVA) technology in mall directories and mobile device geolocation tracking. For the AVA technology, the Offices found that CFCL collected and used personal information, including sensitive biometric numerical representations of faces, without valid consent. CFCL also improperly retained approximately 5 million such representations and video/audio recordings. The Offices concluded that CFCL contravened PIPEDA and provincial privacy acts regarding consent and retention for AVA. In response, CFCL ceased using the AVA technology, deleted the improperly retained data, and committed to staff training, leading to a "well-founded and resolved" outcome for this issue. For mobile device geolocation tracking, the Offices found that data collected from anonymous shoppers (hashed MAC addresses and non-granular zone geolocation) did not constitute personal information. Furthermore, CFCL clarified that geolocation data was not linked to identifiable logged-in Wi-Fi users. Consequently, this aspect of the complaint was deemed "not well-founded." The Offices, however, recommended that CFCL obtain express consent if it were to activate geolocation tracking for identifiable Wi-Fi users in the future.

Key Issues
  • Whether CFCL’s use of Anonymous Video Analytics (AVA) technology, via in-mall directories, resulted in the collection, use, and/or disclosure of personal information.
  • Whether images of individual faces captured by AVA technology constitute personal information.
  • Whether numerical representations of faces (biometric information) generated by AVA technology constitute personal information.
  • Whether age range and gender assessments, combined with other data, constitute personal information.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via AVA technology.
  • Whether CFCL retained personal information collected via AVA technology longer than necessary.
  • Whether CFCL’s use of mobile device geolocation technologies (Anonymous Shopper Journey) resulted in the collection, use, and/or disclosure of personal information.
  • Whether hashed and randomized MAC addresses, combined with non-granular zone geolocation, constitute personal information in the context of anonymous shopper tracking.
  • Whether CFCL’s use of mobile device geolocation technologies (Logged In Shopper Journey) resulted in the collection, use, and/or disclosure of personal information linked to identifiable individuals.
  • Whether CFCL obtained adequate and meaningful consent for the collection, use, and/or disclosure of personal information via mobile device geolocation technologies (Logged In Shopper Journey).
  • Whether CFCL's privacy policy and signage provided sufficient notice and obtained valid consent for its data collection practices.
  • Whether the "serious possibility" threshold for identifying individuals was met for anonymous shopper journey data.
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Oct 16, 20202020 OIC 9Indexed Jun 30, 2026

Health Canada (Re), 2020 OIC 9

Health Canada

An applicant complained that Health Canada failed to identify all records responsive to an access request and improperly refused to provide an index of all responsive records. The investigation by the Office of the Information Commissioner (OIC) found that Health Canada had conducted a reasonable search for records and there was no evidence that any records were missing. The OIC also determined that Health Canada's refusal to create an index of records did not violate its duty to assist obligations under subsection 4(2.1) of the Access to Information Act. The Commissioner concluded that creating such an index for this specific request would have been unreasonable. Therefore, the complaint was deemed not well-founded.

Quick view

Access to Information ActNot well-founded

Health Canada (Re), 2020 OIC 9

Oct 16, 20202020 OIC 9
Adjudicator: Caroline Maynard
Plain-Language Summary

An applicant complained that Health Canada failed to identify all records responsive to an access request and improperly refused to provide an index of all responsive records. The investigation by the Office of the Information Commissioner (OIC) found that Health Canada had conducted a reasonable search for records and there was no evidence that any records were missing. The OIC also determined that Health Canada's refusal to create an index of records did not violate its duty to assist obligations under subsection 4(2.1) of the Access to Information Act. The Commissioner concluded that creating such an index for this specific request would have been unreasonable. Therefore, the complaint was deemed not well-founded.

Key Issues
  • Whether Health Canada conducted a reasonable search for responsive records
  • Whether Health Canada's refusal to provide an index of responsive records contravened its duty to assist under subsection 4(2.1) ATIA
  • Whether creating an index of records for this request would have been unreasonable
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Oct 14, 20202020 OIC 11Indexed Jun 30, 2026

Privy Council Office (Re), 2020 OIC 11

Privy Council Office

The complainant alleged that the Privy Council Office (PCO) failed to respond to an access request within the statutory time limits. The request sought minutes of the Joint Intelligence Committee from 1957 to 1958. PCO claimed an extension, partly for consultations with other government institutions. When these consultations were not completed by the deadline, PCO closed the file, citing a "no late file" policy and the absence of recommendations from consulted institutions. The Office of the Information Commissioner found that the Access to Information Act does not permit an institution to close a file or fail to respond due to outstanding consultations. Consequently, PCO was deemed to be in refusal under subsection 10(3) of the Act. The Commissioner recommended that PCO respond to the request and revise its policy to comply with the Act. PCO did not implement the recommendations.

Quick view

Access to Information ActWell-founded

Privy Council Office (Re), 2020 OIC 11

Oct 14, 20202020 OIC 11
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Privy Council Office (PCO) failed to respond to an access request within the statutory time limits. The request sought minutes of the Joint Intelligence Committee from 1957 to 1958. PCO claimed an extension, partly for consultations with other government institutions. When these consultations were not completed by the deadline, PCO closed the file, citing a "no late file" policy and the absence of recommendations from consulted institutions. The Office of the Information Commissioner found that the Access to Information Act does not permit an institution to close a file or fail to respond due to outstanding consultations. Consequently, PCO was deemed to be in refusal under subsection 10(3) of the Act. The Commissioner recommended that PCO respond to the request and revise its policy to comply with the Act. PCO did not implement the recommendations.

Key Issues
  • Whether the institution responded to the access request within the time limits set out in the Access to Information Act
  • Whether an institution can close an access request file due to outstanding consultations with other government institutions
  • Whether the institution was in deemed refusal pursuant to subsection 10(3) of the Act
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Oct 14, 20203218-01589Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2020 OIC 8

Royal Canadian Mounted Police

The Information Commissioner initiated a systemic investigation into the Royal Canadian Mounted Police's (RCMP) ability to provide timely responses to access to information requests between 2016-2017 and 2018-2019. The investigation was prompted by persistent complaints about the RCMP's failure to meet statutory timeframes and its lack of participation in delay complaint investigations. The Commissioner found that the RCMP's performance had significantly deteriorated, with a substantial increase in requests taking over 365 days to complete and a growing backlog. The RCMP attributed these issues to its geographical dispersion, the volume of requests, and the sensitive nature of its information holdings. The Commissioner made 15 recommendations across six areas, including tasking processes, procedures, training, electronic systems, resources, and a comprehensive strategy. However, the Minister of Public Safety's response largely ignored or inadequately addressed most of these recommendations, failing to commit to concrete plans or provide explanations for not addressing identified failings. Consequently, the Commissioner found the complaint to be well-founded, concluding that the Minister had accepted the status quo despite the dire situation.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2020 OIC 8

Oct 14, 20203218-01589
Adjudicator: Caroline Maynard
Plain-Language Summary

The Information Commissioner initiated a systemic investigation into the Royal Canadian Mounted Police's (RCMP) ability to provide timely responses to access to information requests between 2016-2017 and 2018-2019. The investigation was prompted by persistent complaints about the RCMP's failure to meet statutory timeframes and its lack of participation in delay complaint investigations. The Commissioner found that the RCMP's performance had significantly deteriorated, with a substantial increase in requests taking over 365 days to complete and a growing backlog. The RCMP attributed these issues to its geographical dispersion, the volume of requests, and the sensitive nature of its information holdings. The Commissioner made 15 recommendations across six areas, including tasking processes, procedures, training, electronic systems, resources, and a comprehensive strategy. However, the Minister of Public Safety's response largely ignored or inadequately addressed most of these recommendations, failing to commit to concrete plans or provide explanations for not addressing identified failings. Consequently, the Commissioner found the complaint to be well-founded, concluding that the Minister had accepted the status quo despite the dire situation.

Key Issues
  • Whether the RCMP's tasking processes contributed to delays in responding to access requests
  • Whether the RCMP's procedures for processing access requests were adequate and consistently applied
  • Whether the RCMP provided sufficient training to staff involved in access to information
  • Whether the RCMP's electronic systems were adequate for processing access requests efficiently
  • Whether the RCMP had adequate human and financial resources for its access to information program
  • Whether the RCMP had a comprehensive strategy to meet its access obligations and reduce its backlog
  • Whether the Minister of Public Safety's response to the Commissioner's recommendations was satisfactory
  • Whether the RCMP's failure to provide representations to the OIC during delay complaint investigations was appropriate
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Sep 11, 20203218-00618Indexed Jun 30, 2026

Privy Council Office (Re), 2020 OIC 7

Privy Council Office

The complainant alleged that the Privy Council Office (PCO) failed to respond to an access to information request within the statutory time limits. The request, submitted in July 2016, sought records related to assistance for the 2016 Alberta fire disaster, involving approximately 9,100 pages. PCO initially claimed a 120-day extension but then put the request on indefinite hold for consultations, a practice not permitted by the Act. Despite the Information Commissioner's recommendation to provide a final response by June 1, 2020, PCO failed to meet this deadline, citing ongoing consultations and the impact of the COVID-19 pandemic. The Commissioner found the complaint to be well founded, noting that PCO was deemed to have refused access due to the delay. However, due to the complaint's filing date, the Commissioner lacked the authority to issue a binding order for disclosure.

Quick view

Access to Information ActWell-founded

Privy Council Office (Re), 2020 OIC 7

Sep 11, 20203218-00618
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Privy Council Office (PCO) failed to respond to an access to information request within the statutory time limits. The request, submitted in July 2016, sought records related to assistance for the 2016 Alberta fire disaster, involving approximately 9,100 pages. PCO initially claimed a 120-day extension but then put the request on indefinite hold for consultations, a practice not permitted by the Act. Despite the Information Commissioner's recommendation to provide a final response by June 1, 2020, PCO failed to meet this deadline, citing ongoing consultations and the impact of the COVID-19 pandemic. The Commissioner found the complaint to be well founded, noting that PCO was deemed to have refused access due to the delay. However, due to the complaint's filing date, the Commissioner lacked the authority to issue a binding order for disclosure.

Key Issues
  • Whether the institution responded to the access request within the time limits set out in the Access to Information Act
  • Whether the institution's indefinite 'hold' for consultations is permissible under the Act
  • Whether the institution was deemed to have refused access under subsection 10(3) due to delay
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Aug 10, 20202020 OIC 6Indexed Jun 30, 2026

Department of Justice Canada (Re), 2020 OIC 6

Department of Justice Canada

The complainant alleged that the Department of Justice Canada (Justice) failed to respond to an access request within the statutory time limits. The OIC had previously investigated a complaint regarding the same request and recommended a response by December 15, 2019. Justice did not accept this recommendation but committed to disclosing the records by April 27, 2020. When Justice failed to meet this extended deadline, a new complaint was filed. The Commissioner found that Justice was deemed to have refused access under subsection 10(3) of the Act due to its failure to provide records within the prescribed timeframes. Consequently, the complaint was found to be well founded, and Justice was ordered to respond to the access request by September 30, 2020.

Quick view

Access to Information ActWell-founded

Department of Justice Canada (Re), 2020 OIC 6

Aug 10, 20202020 OIC 6
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Department of Justice Canada (Justice) failed to respond to an access request within the statutory time limits. The OIC had previously investigated a complaint regarding the same request and recommended a response by December 15, 2019. Justice did not accept this recommendation but committed to disclosing the records by April 27, 2020. When Justice failed to meet this extended deadline, a new complaint was filed. The Commissioner found that Justice was deemed to have refused access under subsection 10(3) of the Act due to its failure to provide records within the prescribed timeframes. Consequently, the complaint was found to be well founded, and Justice was ordered to respond to the access request by September 30, 2020.

Key Issues
  • Whether the institution failed to respond to an access request within the time limits set out in the Act
  • Whether the institution was deemed to have refused access pursuant to subsection 10(3) of the Act
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

RCMP contravened the Act by using certain types of non-conviction information for vulnerable sector checks without consent

Royal Canadian Mounted Police (RCMP)

Three individuals complained about the Royal Canadian Mounted Police's (RCMP) use of non-conviction information in vulnerable sector (VS) checks, which they required for employment or volunteer positions. The complainants alleged that the RCMP inappropriately used non-criminal information, including mental health incidents, without proper consent. The OPC found that for two of the complaints, the RCMP contravened section 7 of the Privacy Act because the consent forms did not clearly inform applicants about the types of non-conviction information that would be used. While the RCMP argued consent was obtained, the OPC determined it was not informed consent in these cases. The OPC also concluded that the RCMP's broad policy of reporting non-conviction information, including mental health incidents, was not proportional or minimally intrusive compared to more restrictive provincial models. However, the complaint regarding the RCMP's retention period for personal information was found not well-founded, as it complied with the minimum requirements of the Privacy Regulations. The RCMP agreed to revise its consent forms and policy to address the OPC's concerns, leading to a well-founded and conditionally resolved outcome for the two complaints.

Quick view

Privacy ActWell-founded & conditionally resolved

RCMP contravened the Act by using certain types of non-conviction information for vulnerable sector checks without consent

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

Three individuals complained about the Royal Canadian Mounted Police's (RCMP) use of non-conviction information in vulnerable sector (VS) checks, which they required for employment or volunteer positions. The complainants alleged that the RCMP inappropriately used non-criminal information, including mental health incidents, without proper consent. The OPC found that for two of the complaints, the RCMP contravened section 7 of the Privacy Act because the consent forms did not clearly inform applicants about the types of non-conviction information that would be used. While the RCMP argued consent was obtained, the OPC determined it was not informed consent in these cases. The OPC also concluded that the RCMP's broad policy of reporting non-conviction information, including mental health incidents, was not proportional or minimally intrusive compared to more restrictive provincial models. However, the complaint regarding the RCMP's retention period for personal information was found not well-founded, as it complied with the minimum requirements of the Privacy Regulations. The RCMP agreed to revise its consent forms and policy to address the OPC's concerns, leading to a well-founded and conditionally resolved outcome for the two complaints.

Key Issues
  • Whether the use of non-conviction information by the RCMP for VS checks was done with informed consent consistent with section 7 of the Privacy Act.
  • Whether the RCMP's policy of reporting non-conviction information broadly, including mental health incidents, in VS checks was proportional or minimally intrusive.
  • Whether the RCMP should amend its policies with respect to the use of non-conviction information in VS checks.
  • Whether the RCMP contravened the Act by retaining Complainant 2’s personal information for too long.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

PA-048557, PA-048561 — Canadian Air Transport Security Authority (CATSA)

Canadian Air Transport Security Authority (CATSA)

An individual complained that the Canadian Air Transport Security Authority (CATSA) contravened the Privacy Act by collecting and disclosing his personal information to police after finding legal medical cannabis during a security screening. The complainant argued that CATSA's mandate is aviation security, not general law enforcement, and that cannabis is not a prohibited item. CATSA maintained that its actions were incidental to its mandate and in the public interest, consistent with its regulator's direction. The OPC found that CATSA lacked the legal authority under section 4 of the Privacy Act to collect personal information for general law enforcement purposes related to cannabis, as cannabis is not on the Prohibited Items List and does not pose an aviation security threat. Similarly, the OPC concluded that the disclosure of this personal information to police was not consistent with section 8 of the Privacy Act. However, the OPC found CATSA's practice of destroying records related to such searches to be consistent with section 6 of the Act. The OPC recommended that CATSA cease unauthorized collection and disclosure of personal information related to cannabis and destroy any existing records, which CATSA agreed to implement.

Quick view

Privacy ActWell-founded & conditionally resolved

PA-048557, PA-048561 — Canadian Air Transport Security Authority (CATSA)

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that the Canadian Air Transport Security Authority (CATSA) contravened the Privacy Act by collecting and disclosing his personal information to police after finding legal medical cannabis during a security screening. The complainant argued that CATSA's mandate is aviation security, not general law enforcement, and that cannabis is not a prohibited item. CATSA maintained that its actions were incidental to its mandate and in the public interest, consistent with its regulator's direction. The OPC found that CATSA lacked the legal authority under section 4 of the Privacy Act to collect personal information for general law enforcement purposes related to cannabis, as cannabis is not on the Prohibited Items List and does not pose an aviation security threat. Similarly, the OPC concluded that the disclosure of this personal information to police was not consistent with section 8 of the Privacy Act. However, the OPC found CATSA's practice of destroying records related to such searches to be consistent with section 6 of the Act. The OPC recommended that CATSA cease unauthorized collection and disclosure of personal information related to cannabis and destroy any existing records, which CATSA agreed to implement.

Key Issues
  • Whether the collection of personal information from travellers found to be in possession of cannabis is consistent with section 4 of the Privacy Act
  • Whether the disclosure of the personal information of travellers found to be in possession of cannabis is consistent with section 8 of the Privacy Act
  • Whether CATSA’s record retention practices in terms of the personal information collected from travellers found to be in possession of cannabis are consistent with section 6 of the Privacy Act
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Review of passport protection practices of four federal institutions

Immigration, Refugees and Citizenship Canada (IRCC)

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Quick view

Privacy ActWell-founded & conditionally resolved

Review of passport protection practices of four federal institutions

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a review under section 37 of the Privacy Act into the passport protection practices of Immigration, Refugees and Citizenship Canada (IRCC), Employment and Social Development Canada (ESDC), Global Affairs Canada (GAC), and Canada Post Corporation (CPC). While the OPC found generally reasonable measures to prevent unauthorized disclosures of passports, it identified areas for improvement in incident detection, remediation for affected individuals, and lesson-learning from breaches. Specifically, the OPC noted inconsistent assessments of breach materiality, delays in notifying affected individuals, and a lack of concrete assistance such as credit monitoring. The OPC issued recommendations for consistent guidance on materiality, timely notification standards, offering mitigation measures, and robust incident assessment processes. All four institutions agreed to implement these recommendations.

Key Issues
  • Whether the institutions had adequate controls to prevent unauthorized disclosures of passports under s.8 of the Privacy Act
  • Whether the institutions had adequate measures to detect potential unauthorized disclosures of passports
  • Whether the institutions had adequate measures to remediate risks to individuals from unauthorized disclosures of passports
  • Whether the institutions consistently and appropriately assessed the "materiality" of passport-related breaches
  • Whether notifications to affected individuals regarding lost or stolen passports were timely
  • Whether concrete assistance, such as credit monitoring, was offered to individuals affected by lost or stolen passports
  • Whether incident assessment and investigation processes were robust enough to identify suspicious patterns and share lessons learned among relevant stakeholders
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

Investigation into a privacy breach at Public Services and Procurement Canada

Public Services and Procurement Canada (PSPC)

The Office of the Privacy Commissioner (OPC) investigated complaints from federal public servants regarding an improper disclosure of their pay-related information by Public Services and Procurement Canada (PSPC). PSPC inadvertently sent personnel overpayment reports containing personal information of 69,087 public servants to the wrong government institutions. The OPC found that PSPC contravened section 8 of the Privacy Act by disclosing personal information without authorization. However, the complaints were deemed resolved due to PSPC's corrective actions, which included implementing new procedures with quality controls for report generation, requesting deletion of the flawed reports, and notifying affected individuals. The OPC noted that while notification was timely, some departments modified the notification letters, leading to inconsistencies in the information received by individuals.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at Public Services and Procurement Canada

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated complaints from federal public servants regarding an improper disclosure of their pay-related information by Public Services and Procurement Canada (PSPC). PSPC inadvertently sent personnel overpayment reports containing personal information of 69,087 public servants to the wrong government institutions. The OPC found that PSPC contravened section 8 of the Privacy Act by disclosing personal information without authorization. However, the complaints were deemed resolved due to PSPC's corrective actions, which included implementing new procedures with quality controls for report generation, requesting deletion of the flawed reports, and notifying affected individuals. The OPC noted that while notification was timely, some departments modified the notification letters, leading to inconsistencies in the information received by individuals.

Key Issues
  • Whether PSPC improperly disclosed personal information in contravention of section 8 of the Privacy Act
  • Whether the information disclosed constituted 'personal information' under section 3 of the Privacy Act
  • Whether PSPC's response to the breach, including mitigation and notification, was adequate
  • Whether PSPC implemented sufficient measures to prevent recurrence of the breach
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Aug 6, 2020Indexed Jun 30, 2026

PA-055322 (PCO) et PA-055323 (DOJ) — Privy Council Office (PCO) and Department of Justice (DOJ)

Privy Council Office (PCO) and Department of Justice (DOJ)

The OPC investigated a complaint regarding the unauthorized disclosure of personal information about Supreme Court candidate Chief Justice Glenn Joyal. Media reports claimed an anonymous source revealed a disagreement between the Prime Minister's Office (PMO) and the former Attorney General over Joyal's nomination. The complainant alleged breaches of the Privacy Act by the Privy Council Office (PCO), Department of Justice (DOJ), Office of the Commissioner of Federal Judicial Affairs (CFJA), and the PMO. The OPC determined it lacked jurisdiction over the CFJA and PMO, focusing its investigation on the PCO and DOJ. The investigation found no evidence that either the PCO or the DOJ had access to the specific information that was leaked, nor that the disclosure originated from these institutions. While no contravention was found, the OPC highlighted that Chief Justice Joyal's privacy was compromised and called for legislative reform to extend the Privacy Act's coverage to all government institutions, including Ministers' Offices and the PMO.

Quick view

Privacy ActNot well-founded

PA-055322 (PCO) et PA-055323 (DOJ) — Privy Council Office (PCO) and Department of Justice (DOJ)

Aug 6, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated a complaint regarding the unauthorized disclosure of personal information about Supreme Court candidate Chief Justice Glenn Joyal. Media reports claimed an anonymous source revealed a disagreement between the Prime Minister's Office (PMO) and the former Attorney General over Joyal's nomination. The complainant alleged breaches of the Privacy Act by the Privy Council Office (PCO), Department of Justice (DOJ), Office of the Commissioner of Federal Judicial Affairs (CFJA), and the PMO. The OPC determined it lacked jurisdiction over the CFJA and PMO, focusing its investigation on the PCO and DOJ. The investigation found no evidence that either the PCO or the DOJ had access to the specific information that was leaked, nor that the disclosure originated from these institutions. While no contravention was found, the OPC highlighted that Chief Justice Joyal's privacy was compromised and called for legislative reform to extend the Privacy Act's coverage to all government institutions, including Ministers' Offices and the PMO.

Key Issues
  • Whether the Office of the Commissioner of Federal Judicial Affairs (CFJA) is a 'government institution' under the Privacy Act
  • Whether the Prime Minister's Office (PMO) is a 'government institution' under the Privacy Act
  • Whether the Privy Council Office (PCO) was responsible for the unauthorized disclosure of Chief Justice Joyal's personal information under section 8 of the Privacy Act
  • Whether the Department of Justice (DOJ) was responsible for the unauthorized disclosure of Chief Justice Joyal's personal information under section 8 of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Aug 4, 2020PIPEDA Findings #2020-001Indexed Jun 30, 2026

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

TD Canada Trust

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

Aug 4, 2020PIPEDA Findings #2020-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Key Issues
  • Whether TD was required to obtain additional consent for transferring personal information to a third-party service provider in India for fraud claims processing (Principle 4.3 PIPEDA)
  • Whether TD was required to offer customers an opt-out for the transfer of personal information to a third-party service provider in India for fraud claims processing
  • Whether TD was sufficiently open about its practice of transferring personal information to a third-party service provider in a foreign jurisdiction for processing (Principle 4.8 PIPEDA)
  • Whether TD ensured a comparable level of protection for personal information processed by the third-party service provider in India (Principle 4.1.3 PIPEDA)
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Jul 22, 2020Indexed Jun 30, 2026

Access at issue: Nine recommendations regarding the processing of access requests at National Defence

National Defence

The Office of the Information Commissioner (OIC) conducted a systemic investigation into the processing of access to information requests at National Defence (DND). The investigation focused on the six offices of primary interest (OPIs) most frequently tasked with responding to requests between January 2017 and December 2018. OIC officials interviewed OPIs and DND's Directorate of Access to Information and Privacy (DAIP), and reviewed internal documents, manuals, and statistics. The Commissioner identified significant issues with DND's compliance with the Access to Information Act. The Minister of National Defence acknowledged the need for improvements and proposed corrective actions, which were accepted or built upon by the Commissioner. The Commissioner issued nine recommendations to the Minister, who agreed to implement them to address the identified shortcomings.

Quick view

Access to Information ActSystemic Investigation

Access at issue: Nine recommendations regarding the processing of access requests at National Defence

Jul 22, 2020
Adjudicator: Caroline Maynard
Plain-Language Summary

The Office of the Information Commissioner (OIC) conducted a systemic investigation into the processing of access to information requests at National Defence (DND). The investigation focused on the six offices of primary interest (OPIs) most frequently tasked with responding to requests between January 2017 and December 2018. OIC officials interviewed OPIs and DND's Directorate of Access to Information and Privacy (DAIP), and reviewed internal documents, manuals, and statistics. The Commissioner identified significant issues with DND's compliance with the Access to Information Act. The Minister of National Defence acknowledged the need for improvements and proposed corrective actions, which were accepted or built upon by the Commissioner. The Commissioner issued nine recommendations to the Minister, who agreed to implement them to address the identified shortcomings.

Key Issues
  • Processing of access to information requests at National Defence
  • Compliance with the Access to Information Act by National Defence
  • Efficiency and effectiveness of DND's Access to Information and Privacy (ATIP) processes
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jul 14, 2020Indexed Jun 30, 2026

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Canada Border Services Agency (CBSA)

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Quick view

Privacy ActNot well-founded

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Jul 14, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Key Issues
  • Did the CBSA disclose the complainant’s personal information?
  • Was any disclosed information “publicly available”, such that subsection 69(2) of the Act excludes application of sections 7 and 8?
  • If not, was the disclosure permitted under subsection 8(2) of the Act?
Decisions | Condita Research