The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,639 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 9, 2020PIPEDA Findings #2020-003Indexed Jun 30, 2026

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Dell Inc.

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Jul 9, 2020PIPEDA Findings #2020-003
Adjudicator: Daniel Therrien
Plain-Language Summary

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Key Issues
  • Whether Dell adequately safeguarded personal information under its control while using a service provider (PIPEDA Principle 4.1.3 and 4.7).
  • Whether the personal information transferred to the service provider was sensitive enough to require a high degree of protection.
  • Whether Dell's access controls were sufficient to protect customer information.
  • Whether Dell's logging and monitoring practices were adequate to detect anomalous employee requests for customer information.
  • Whether Dell's technical measures, such as USB drive restrictions, were sufficient.
  • Whether Dell adequately investigated the circumstances and scope of the June 2017 breach.
  • Whether Dell adequately responded to customer complaints about potential privacy breaches (PIPEDA Principle 4.10.4).
  • Whether Dell remained responsible for personal information transferred to a third party for processing.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 30, 2020PIPEDA Findings #2020-002Indexed Jun 30, 2026

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

RateMDs.com

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

Jun 30, 2020PIPEDA Findings #2020-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Key Issues
  • Whether RateMDs collected, used, or disclosed the complainant's business contact information without consent (Principle 4.3)
  • Whether the business contact information exemption under s.4.01 of PIPEDA applied to RateMDs' use of the complainant's business contact information
  • Whether the complainant's business contact information was publicly available under s.7(1)(d), 7(2)(c.1), and 7(3)(h.1) of PIPEDA and its Regulations
  • Whether the reviews and ratings posted on RateMDs constituted the complainant's personal information
  • Whether the reviews and ratings also constituted the personal information of the users who posted them
  • Whether RateMDs required the complainant's consent to publish the reviews and ratings about her (Principle 4.3)
  • Whether a balancing of interests was required when the privacy rights of multiple individuals conflicted regarding the same personal information
  • Whether RateMDs ensured the accuracy of information and provided a fair and accessible process for health professionals to challenge and correct inaccurate information (Principle 4.6, 4.9.5)
  • Whether RateMDs made readily available specific information about its policies and practices relating to the management of personal information, particularly regarding review removal and correction (Principle 4.8)
  • Whether RateMDs' "pay-for-takedown" service, allowing subscribers to hide negative reviews for a fee, constituted an appropriate purpose for collecting, using, or disclosing personal information under s.5(3) of PIPEDA
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Jun 25, 20202020 OIC 5Indexed Jun 30, 2026

Department of Justice Canada (Re), 2020 OIC 5

Department of Justice Canada

The complainant challenged the Department of Justice Canada's (Justice) decision to withhold an entire Memorandum of Understanding (MOU) for legal services under section 23 of the Access to Information Act. Justice claimed the entire MOU was protected by solicitor-client privilege. The Commissioner found that Justice failed to demonstrate that general identifying information, such as the title and signature blocks, fell under this privilege. Furthermore, the Commissioner determined that Justice had waived its solicitor-client privilege over certain information within the MOU. Consequently, the Commissioner concluded that the complaint was well founded and recommended the release of part of the record. Justice indicated its intention to implement this recommendation.

Quick view

Access to Information ActWell-founded

Department of Justice Canada (Re), 2020 OIC 5

Jun 25, 20202020 OIC 5
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant challenged the Department of Justice Canada's (Justice) decision to withhold an entire Memorandum of Understanding (MOU) for legal services under section 23 of the Access to Information Act. Justice claimed the entire MOU was protected by solicitor-client privilege. The Commissioner found that Justice failed to demonstrate that general identifying information, such as the title and signature blocks, fell under this privilege. Furthermore, the Commissioner determined that Justice had waived its solicitor-client privilege over certain information within the MOU. Consequently, the Commissioner concluded that the complaint was well founded and recommended the release of part of the record. Justice indicated its intention to implement this recommendation.

Key Issues
  • Whether the entire Memorandum of Understanding (MOU) was protected by solicitor-client privilege under s.23 ATIA
  • Whether general identifying information (title, signature blocks) in the MOU was protected by solicitor-client privilege
  • Whether solicitor-client privilege had been waived over any information in the MOU
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
May 25, 20202020 OIC 4Indexed Jun 30, 2026

3218-00001 — National Defence

National Defence

The complainant alleged that National Defence (DND) failed to respond to an access to information request within the statutory time limits. DND argued that the request did not meet the requirements of section 6 of the Access to Information Act, which stipulates that a request must be for a record under the control of a government institution. The OIC investigated whether DND's decision not to process the request was justified. The Commissioner found that DND had made numerous attempts to clarify the request with the applicant, but the applicant did not provide the necessary clarification to enable DND to identify the records sought. Consequently, the Commissioner concluded that DND was not obligated to process a request that did not adequately describe the records. The complaint was therefore deemed not well-founded.

Quick view

Access to Information ActNot well-founded

3218-00001 — National Defence

May 25, 20202020 OIC 4
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that National Defence (DND) failed to respond to an access to information request within the statutory time limits. DND argued that the request did not meet the requirements of section 6 of the Access to Information Act, which stipulates that a request must be for a record under the control of a government institution. The OIC investigated whether DND's decision not to process the request was justified. The Commissioner found that DND had made numerous attempts to clarify the request with the applicant, but the applicant did not provide the necessary clarification to enable DND to identify the records sought. Consequently, the Commissioner concluded that DND was not obligated to process a request that did not adequately describe the records. The complaint was therefore deemed not well-founded.

Key Issues
  • Whether the access request met the requirements of section 6 of the Access to Information Act
  • Whether National Defence was justified in not processing the request due to lack of clarity
  • Whether National Defence failed to respond within the statutory time limits
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 3, 20203215-00087Indexed Jun 30, 2026

Canadian Human Rights Commission (Re), 2020 OIC 3

Canadian Human Rights Commission

The complainant challenged the Canadian Human Rights Commission's (CHRC) decision to withhold information under subsections 19(1) (personal information), section 22 (testing/auditing procedures), and section 23 (solicitor-client privilege) of the Access to Information Act. During the investigation, the CHRC agreed to release all information previously withheld under section 22 and some under section 23. The OIC found that while some information met the requirements for personal information under s.19(1), specific file numbers did not, as their disclosure would not identify an individual. Regarding solicitor-client privilege, the OIC found that certain draft investigation reports were not shown to have received legal review or advice, thus not meeting the exemption's criteria. The Commissioner recommended the disclosure of the file numbers and the draft investigation reports. The CHRC agreed to the recommendations and released the additional information.

Quick view

Access to Information ActWell-founded

Canadian Human Rights Commission (Re), 2020 OIC 3

Apr 3, 20203215-00087
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant challenged the Canadian Human Rights Commission's (CHRC) decision to withhold information under subsections 19(1) (personal information), section 22 (testing/auditing procedures), and section 23 (solicitor-client privilege) of the Access to Information Act. During the investigation, the CHRC agreed to release all information previously withheld under section 22 and some under section 23. The OIC found that while some information met the requirements for personal information under s.19(1), specific file numbers did not, as their disclosure would not identify an individual. Regarding solicitor-client privilege, the OIC found that certain draft investigation reports were not shown to have received legal review or advice, thus not meeting the exemption's criteria. The Commissioner recommended the disclosure of the file numbers and the draft investigation reports. The CHRC agreed to the recommendations and released the additional information.

Key Issues
  • Whether s.19(1) personal information exemption applies to personal contact information of government employees, leave information, and names of CHRC complainants
  • Whether s.19(1) personal information exemption applies to file numbers
  • Whether the institution reasonably exercised discretion under s.19(2) for applicable personal information
  • Whether s.22 testing/auditing procedures exemption applies
  • Whether s.23 solicitor-client privilege exemption applies to communications between client and counsel for legal advice
  • Whether s.23 solicitor-client privilege exemption applies to draft investigation reports
  • Whether the institution reasonably exercised discretion under s.23 for applicable solicitor-client privileged information
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Mar 31, 2020Indexed Jun 30, 2026

CBSA should only retain travellers’ digital device passcodes when necessary

Canada Border Services Agency (CBSA)

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Quick view

Privacy ActResolved

CBSA should only retain travellers’ digital device passcodes when necessary

Mar 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Key Issues
  • Whether the CBSA has the authority to require a traveller to provide a passcode to unlock a digital device for inspection purposes under the Customs Act
  • Whether the CBSA officer followed internal policies regarding the collection and retention of personal information (passcodes)
  • Whether the CBSA's retention of the passcode was necessary beyond the examination process when no further action was taken
  • Whether passcodes constitute sensitive personal information
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Feb 18, 20202020 OIC 2Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2020 OIC 2

Royal Canadian Mounted Police

The Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request for over two years, leading to a deemed refusal under the Access to Information Act. During the investigation, the RCMP provided insufficient information regarding the records or the processing of the request to establish a reasonable response date. Due to the continued lack of response, the Information Commissioner found the complaint to be well-founded. The Commissioner ordered the RCMP to respond to the access request within 10 business days from the effective date of the order. However, the RCMP ultimately responded to the request before the order officially came into effect.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2020 OIC 2

Feb 18, 20202020 OIC 2
Adjudicator: Caroline Maynard
Plain-Language Summary

The Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request for over two years, leading to a deemed refusal under the Access to Information Act. During the investigation, the RCMP provided insufficient information regarding the records or the processing of the request to establish a reasonable response date. Due to the continued lack of response, the Information Commissioner found the complaint to be well-founded. The Commissioner ordered the RCMP to respond to the access request within 10 business days from the effective date of the order. However, the RCMP ultimately responded to the request before the order officially came into effect.

Key Issues
  • Whether the institution failed to respond to an access request within the statutory time limits (deemed refusal)
  • Whether the institution provided sufficient information to justify the delay
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 31, 2020Indexed Jun 30, 2026

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Employment and Social Development Canada (ESDC)

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Quick view

Privacy ActWell-founded

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Jan 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Key Issues
  • Whether the collection of video surveillance footage constituted personal information under s.3 of the Privacy Act
  • Whether the initial collection of video surveillance footage by ESDC was in compliance with s.4 of the Privacy Act
  • Whether ESDC informed individuals of the purpose for collecting personal information via video surveillance, as required by s.5 of the Privacy Act
  • Whether ESDC's use of video surveillance footage to monitor an employee's departure times was consistent with the purpose for which it was collected, as required by s.7(a) of the Privacy Act
  • Whether ESDC obtained consent for the use of video surveillance footage for purposes other than security, as required by s.7(a) of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jan 15, 2020Indexed Jun 30, 2026

Public disclosure of medical information during military trial consistent with Privacy Act

Department of National Defence

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

Public disclosure of medical information during military trial consistent with Privacy Act

Jan 15, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Key Issues
  • Whether the Privacy Act applies to military summary trial proceedings conducted by the Canadian Forces
  • Whether the disclosure of the complainant's medical information during the summary trial was made in accordance with section 8 of the Privacy Act
  • Whether the information became publicly available under section 69(2) of the Privacy Act once disclosed in an open court proceeding
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Jan 14, 20205819-00733Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2020 OIC 1

Royal Canadian Mounted Police

The complainant alleged that the Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request within the statutory time limits. The request, submitted on July 3, 2018, had a due date of August 2, 2018. The RCMP was deemed to have refused access under subsection 10(3) of the Act as it did not respond or take an extension. Despite multiple requests from the OIC for information regarding the delay and a proposed disclosure date, the RCMP provided no rationale for the delay, only citing high volume and resource pressures. The OIC found that the responsive records were not voluminous or complex and had been in the RCMP's possession since July 2018. An initial report with an intended order was sent to the Minister, but before the order could be issued, the RCMP released the records. Consequently, the complaint was found to be well-founded, but no order was issued as the records were released.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2020 OIC 1

Jan 14, 20205819-00733
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request within the statutory time limits. The request, submitted on July 3, 2018, had a due date of August 2, 2018. The RCMP was deemed to have refused access under subsection 10(3) of the Act as it did not respond or take an extension. Despite multiple requests from the OIC for information regarding the delay and a proposed disclosure date, the RCMP provided no rationale for the delay, only citing high volume and resource pressures. The OIC found that the responsive records were not voluminous or complex and had been in the RCMP's possession since July 2018. An initial report with an intended order was sent to the Minister, but before the order could be issued, the RCMP released the records. Consequently, the complaint was found to be well-founded, but no order was issued as the records were released.

Key Issues
  • Whether the institution responded to the access request within the statutory time limits
  • Whether the institution was deemed to have refused access under subsection 10(3) of the Act
  • Whether the institution provided adequate rationale for the delay in responding
  • Whether the institution provided a reasonable disclosure date
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 30, 2019Indexed Jun 30, 2026

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Department of National Defence and Department of Justice

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Quick view

Privacy ActNot well-founded

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Dec 30, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Key Issues
  • Whether the collection of the complainant's personal medical information by the DOJ from the DND contravened the Privacy Act
  • Whether the disclosure of the complainant's personal medical information by the DND to the DOJ contravened the Privacy Act
  • Whether the collection by DOJ related directly to an operating program or activity of the institution under s.4 of the Privacy Act
  • Whether the collection by DOJ was permissible under s.5(1) of the Privacy Act given the disclosure under s.8(2)(d)
  • Whether the disclosure by DND was to the Attorney General of Canada under s.8(2)(d) of the Privacy Act
  • Whether the disclosure by DND was for use in legal proceedings involving the Crown in right of Canada or the Government of Canada under s.8(2)(d) of the Privacy Act
  • Whether the sensitivity of medical information impacts the permissibility of disclosure under the Privacy Act
  • Whether doctor-patient confidentiality prevents disclosure under the Privacy Act for litigation purposes
  • Whether the safeguarding measures for the disclosed information were adequate
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 9, 2019Statistics CanadaIndexed Jun 30, 2026

Statistics Canada: Invasive data initiatives should be redesigned with privacy in mind

Statistics Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated over a hundred complaints against Statistics Canada concerning its Credit Information Project and Financial Transactions Project. These initiatives involved collecting detailed personal information from a credit bureau (TransUnion) and financial institutions without individuals' direct knowledge or consent. The OPC found that Statistics Canada had the legal authority under section 13 of the Statistics Act to collect information for the Credit Information Project, as TransUnion provided existing records, thus deeming this aspect of the complaints not well-founded. However, the OPC had serious concerns that the Financial Transactions Project, as originally designed, would have exceeded this authority by requiring financial institutions to create new records; no formal finding was made as the project was halted. While no contravention of the Privacy Act was found, the OPC identified significant privacy concerns regarding the necessity and proportionality of both projects, Statistics Canada's lack of transparency, and deficiencies in internal monitoring safeguards. Statistics Canada committed to implementing all six OPC recommendations, including redesigning both projects with privacy principles in mind, increasing transparency, and enhancing internal security measures. The OPC also called for legislative reform of the Statistics Act and Privacy Act to address modern data collection practices.

Quick view

Privacy ActNot well-founded

Statistics Canada: Invasive data initiatives should be redesigned with privacy in mind

Dec 9, 2019Statistics Canada
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated over a hundred complaints against Statistics Canada concerning its Credit Information Project and Financial Transactions Project. These initiatives involved collecting detailed personal information from a credit bureau (TransUnion) and financial institutions without individuals' direct knowledge or consent. The OPC found that Statistics Canada had the legal authority under section 13 of the Statistics Act to collect information for the Credit Information Project, as TransUnion provided existing records, thus deeming this aspect of the complaints not well-founded. However, the OPC had serious concerns that the Financial Transactions Project, as originally designed, would have exceeded this authority by requiring financial institutions to create new records; no formal finding was made as the project was halted. While no contravention of the Privacy Act was found, the OPC identified significant privacy concerns regarding the necessity and proportionality of both projects, Statistics Canada's lack of transparency, and deficiencies in internal monitoring safeguards. Statistics Canada committed to implementing all six OPC recommendations, including redesigning both projects with privacy principles in mind, increasing transparency, and enhancing internal security measures. The OPC also called for legislative reform of the Statistics Act and Privacy Act to address modern data collection practices.

Key Issues
  • Whether Statistics Canada's collection of personal information for the Credit Information Project was within its legal authority under section 13 of the Statistics Act.
  • Whether Statistics Canada's proposed collection of personal information for the Financial Transactions Project, as originally designed, would have been within its legal authority under section 13 of the Statistics Act.
  • Whether the collection of personal information for the Credit Information Project related directly to an operating program or activity of Statistics Canada under section 4 of the Privacy Act.
  • Whether the collection of personal information for the Financial Transactions Project related directly to an operating program or activity of Statistics Canada under section 4 of the Privacy Act.
  • Whether the Credit Information Project, as originally designed, met the principles of necessity and proportionality.
  • Whether the Financial Transactions Project, as originally designed, met the principles of necessity and proportionality.
  • Whether Statistics Canada provided adequate transparency to individuals regarding the collection of their personal information for the Projects.
  • Whether Statistics Canada had appropriate safeguards, specifically regarding logging and monitoring for internal unauthorized access, to protect personal information collected via the Projects.
  • Whether Statistics Canada's de-identification and encryption safeguards were adequate.
  • Whether Statistics Canada had proper procedures for individuals to access their personal information.
  • Whether there was a risk of personal information collected via the Projects being disclosed for secondary purposes.
  • Whether Statistics Canada's Directive on Discretionary Disclosures adequately considered individuals' privacy interests when making disclosures under section 17(2)(a) of the Statistics Act.
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Dec 9, 2019PIPEDA Findings #2019-007Indexed Jun 30, 2026

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Trans Union of Canada, Inc.

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Dec 9, 2019PIPEDA Findings #2019-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Key Issues
  • Whether TransUnion disclosed the complainant's credit file information to Statistics Canada without requisite consent
  • Whether TransUnion was authorized to disclose personal information without consent under PIPEDA subparagraph 7(3)(c.1)(iii)
  • Whether Statistics Canada identified its lawful authority to obtain the information
  • Whether the disclosure was requested to administer a law of Canada (the Statistics Act)
  • Whether Statistics Canada subsequently disclosed the complainant's credit file information to other government institutions for debt collection
  • Whether there was sufficient evidence to support the allegation of information misuse for debt collection
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Nov 26, 2019PIPEDA Findings #2019-004Indexed Jun 30, 2026

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

AggregateIQ Data Services Ltd.

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Nov 26, 2019PIPEDA Findings #2019-004
Adjudicator: Daniel Therrien
Plain-Language Summary

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Key Issues
  • Whether AIQ was compliant with consent requirements for the collection, use, or disclosure of personal information under PIPEDA and PIPA.
  • Whether AIQ could rely on consent obtained by its clients for its own collection, use, and disclosure of personal information.
  • Whether consent was adequate for specific uses, such as disclosing personal information to Facebook for "custom audiences" and "lookalike audiences."
  • Whether consent was adequate for sensitive personal information, such as political opinions or psychographic profiles.
  • Whether AIQ took reasonable security measures to protect the personal information in its custody or control under PIPEDA and PIPA.
  • Whether the security breach involving the GitLab repository constituted a failure of reasonable security measures.
  • Whether personal information collected from public telephone directories required consent.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 21, 2019Indexed Jun 30, 2026

Crossing the line? The CBSA’s examination of digital devices at the border

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Quick view

Privacy ActWell-founded

Crossing the line? The CBSA’s examination of digital devices at the border

Oct 21, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Key Issues
  • Whether CBSA's collection of personal information via digital device searches contravened section 4 of the Privacy Act.
  • Whether the definition of "goods" under the Customs Act extends to electronic documents on digital devices.
  • Whether CBSA's authority to search digital devices is limited to information stored on the device.
  • Whether Border Services Officers (BSOs) complied with CBSA's internal policy (Operational Bulletin PRG-2015-31) regarding digital device examinations (e.g., airplane mode, note-taking, search threshold).
  • Whether the copying of content from a digital device by a BSO was consistent with CBSA's legal authority and policy.
  • Whether the CBSA complied with its obligations under subsection 6(1) of the Privacy Act to retain personal information used for administrative purposes.
  • Whether the CBSA's practices regarding training, awareness, and accountability mechanisms for digital device searches were adequate.
  • Whether the Customs Act requires amendment to include a clear legal framework and a higher threshold for digital device examinations.
  • Whether the threshold for digital device examinations should be "reasonable grounds to suspect".