The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,631 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Phoenix pay system compromised Public Servants’ privacy

Public Services and Procurement Canada

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Quick view

Privacy ActWell-founded

Phoenix pay system compromised Public Servants’ privacy

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Key Issues
  • Whether personal information was at issue in the reported incidents
  • Whether the personal information at issue was improperly disclosed
  • What was the scope of the improper disclosure
  • Whether the personal information that was improperly disclosed was misused
  • Whether PSPC was aware of potential privacy issues with Phoenix before the launch
  • What kind of harm could result from the unauthorized disclosure of the personal information at issue
  • Whether PSPC resolved all of the vulnerabilities within Phoenix
  • Whether PSPC provided individuals with timely information regarding the breaches and vulnerabilities
  • Whether PSPC developed and implemented controls to monitor and document access to personal information held in Phoenix (Recommendation 1)
  • Whether PSPC developed more robust testing and response procedures (Recommendation 2)
  • Whether PSPC conducted necessary assessments to identify potential risks and vulnerabilities in Phoenix (Recommendation 3)
  • Whether PSPC took measures to mitigate the increased vulnerability of information used by employees in call centres (Recommendation 4)
  • Whether PSPC reviewed its breach notification practices and provided notification of the extent of the Phoenix breaches (Recommendation 5)
  • Whether PSPC completed the review of pages with row-level security (Recommendation 6)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Health Canada

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Quick view

Privacy ActWell-founded

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Key Issues
  • Whether diagnostic information about individual patients constitutes 'personal information' under s.3 of the Privacy Act
  • Whether Health Canada contravened s.4 of the Privacy Act by collecting diagnostic information about patients seeking medical transportation and specialist services that was not directly related to an operating program or activity
  • Whether the collection of diagnostic information was demonstrably necessary to achieve a specific and legitimate purpose
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Apr 26, 2017Incident case summary #2017-001Indexed Jun 30, 2026

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Multiple organizations (Airline, Retailer, Digital media company)

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Apr 26, 2017Incident case summary #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

This case summary details multiple breach incidents reported to the OPC in 2017, all stemming from password reuse by individuals. In each incident, unauthorized third parties gained access to customer accounts using login credentials obtained from previous, unrelated data breaches. An airline, a retailer, and a digital media company were affected, with personal information of thousands of customers compromised. The OPC reviewed the responses of each organization, noting their actions to mitigate risks, notify affected individuals, and enhance security controls. The OPC concluded that each organization's response was appropriate and satisfactory, demonstrating positive steps to prevent recurrence. The report emphasizes the importance of avoiding password reuse and encourages organizations to implement similar preventative measures.

Key Issues
  • Whether organizations adequately responded to breaches caused by password reuse
  • Whether organizations implemented appropriate safeguards to prevent recurrence of breaches due to password reuse
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 19, 2017Indexed Jun 30, 2026

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Royal Canadian Mounted Police (RCMP)

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Quick view

Privacy ActWell-founded

Disclosure of information about complainant's attempted suicide to US Customs and Border Protection not authorized under the Privacy Act

Apr 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Privacy Commissioner of Canada investigated a complaint against the Royal Canadian Mounted Police (RCMP) concerning the disclosure of an individual's attempted suicide information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC). The complainant was denied entry to the US based on this information, which had been uploaded by the Toronto Police Service (TPS). The OPC found that the disclosure was not authorized under paragraphs 8(2)(f) or 8(2)(a) of the Privacy Act, as CBP's use for an admissibility assessment did not constitute "law enforcement" or "criminal justice purposes" under the Memorandum of Cooperation (MOC), nor was it consistent with the original purpose of collection. The OPC also determined that CPIC policies were unclear and remained insufficient to prevent such unauthorized disclosures. The complaint was found well-founded, but the RCMP disagreed with the findings and recommendations. The OPC recommended setting the CPIC "SHARE US A" feature to suppress sharing of sensitive entries by default and revising policies to ensure disclosure only occurs when an individual poses an ongoing risk to others.

Key Issues
  • Whether the RCMP inappropriately disclosed the complainant's personal information to US Customs and Border Protection (CBP) via the Canadian Police Information Centre (CPIC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(f) of the Privacy Act.
  • Whether CBP's use of the complainant's personal information for an admissibility assessment constituted "criminal justice purposes" or "law enforcement" as defined in the Memorandum of Cooperation (MOC).
  • Whether the disclosure of personal information relating to suicide attempts was authorized under paragraph 8(2)(a) of the Privacy Act as a "consistent use."
  • Whether the CPIC policies in effect at the time provided sufficient clarity to guard against unauthorized disclosure of sensitive personal information.
  • Whether the revised CPIC policies, including the "SHARE US A" feature and "SIP-OB" entries, adequately protect against unauthorized disclosure of attempted suicide information.
  • Whether the default setting of the "SHARE US A" feature in CPIC should suppress the sharing of SIP-OB entries relating to threatened or attempted suicides with US border officials.
  • Whether CPIC policies should be revised to provide clear guidance for sharing attempted suicide information with US border officials only where an individual presents an ongoing risk to others.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2017PIPEDA findings #2017-011Indexed Jun 30, 2026

PIPEDA findings #2017-011: Financial institution originally misuses confidential commercial information exemption to withhold personal information

A financial institution

A complainant alleged that a financial institution refused to respond to his access to personal information request related to a disputed credit card transaction. Initially, the financial institution withheld documents, claiming they contained confidential commercial information under PIPEDA s.9(3)(b). The OPC found this exemption was inappropriately applied and that the financial institution failed to respond within the statutory 30-day timeframe. Following the OPC's preliminary report, the financial institution provided further clarification, leading the OPC to determine that the information in question was not the complainant's personal information and was correctly redacted under s.9(1) as third-party information. Although the complainant eventually received all personal information he was entitled to, the OPC criticized the financial institution's delay and initial misuse of the exemption. The complaint was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2017-011: Financial institution originally misuses confidential commercial information exemption to withhold personal information

Mar 31, 2017PIPEDA findings #2017-011
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a financial institution refused to respond to his access to personal information request related to a disputed credit card transaction. Initially, the financial institution withheld documents, claiming they contained confidential commercial information under PIPEDA s.9(3)(b). The OPC found this exemption was inappropriately applied and that the financial institution failed to respond within the statutory 30-day timeframe. Following the OPC's preliminary report, the financial institution provided further clarification, leading the OPC to determine that the information in question was not the complainant's personal information and was correctly redacted under s.9(1) as third-party information. Although the complainant eventually received all personal information he was entitled to, the OPC criticized the financial institution's delay and initial misuse of the exemption. The complaint was found to be well-founded and resolved.

Key Issues
  • Whether the financial institution responded to the access request within the 30-day time limit required by PIPEDA s.8(3)
  • Whether the financial institution sent a notice of extension within 30 days of the request as required by PIPEDA s.8(4)
  • Whether the financial institution appropriately applied the confidential commercial information exemption under PIPEDA s.9(3)(b) to withhold documents
  • Whether the withheld information constituted the complainant's personal information
  • Whether the information was properly redacted as third-party information under PIPEDA s.9(1)
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 14, 2017PIPEDA Report of Findings #2017-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-003: Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process

An insurance company

An individual complained that an insurance company collected and used his credit score without meaningful consent during an auto insurance claims assessment, over-collected his credit file, and used the score for an inappropriate purpose. The OPC found that the insurance company failed to demonstrate that collecting and using credit scores for fraud detection in auto claims was an appropriate purpose under PIPEDA subsection 5(3) or a "direct business need" under Ontario's Consumer Reporting Act. The OPC also determined that the company did not obtain meaningful consent because it failed to clearly advise the complainant that providing his credit score was optional, contrary to Principle 4.3. Furthermore, the company was found not to be open about its practices regarding credit score collection and use, violating Principle 4.8.1, due to insufficient notifications and inaccurate employee scripts. The allegation of over-collection was not substantiated, as only the credit score was provided. In response to the OPC's preliminary report, the insurance company agreed to cease collecting credit scores for auto accident benefit claims and review its practices for other insurance types. The matter was concluded as well-founded and conditionally resolved, pending the full implementation of these agreed-upon changes.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2017-003: Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process

Mar 14, 2017PIPEDA Report of Findings #2017-003
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an insurance company collected and used his credit score without meaningful consent during an auto insurance claims assessment, over-collected his credit file, and used the score for an inappropriate purpose. The OPC found that the insurance company failed to demonstrate that collecting and using credit scores for fraud detection in auto claims was an appropriate purpose under PIPEDA subsection 5(3) or a "direct business need" under Ontario's Consumer Reporting Act. The OPC also determined that the company did not obtain meaningful consent because it failed to clearly advise the complainant that providing his credit score was optional, contrary to Principle 4.3. Furthermore, the company was found not to be open about its practices regarding credit score collection and use, violating Principle 4.8.1, due to insufficient notifications and inaccurate employee scripts. The allegation of over-collection was not substantiated, as only the credit score was provided. In response to the OPC's preliminary report, the insurance company agreed to cease collecting credit scores for auto accident benefit claims and review its practices for other insurance types. The matter was concluded as well-founded and conditionally resolved, pending the full implementation of these agreed-upon changes.

Key Issues
  • Whether collecting and using a credit score for fraud detection during auto insurance claims assessment is an appropriate purpose under subsection 5(3) of PIPEDA.
  • Whether the insurance company had a "direct business need" for credit scores under Ontario's Consumer Reporting Act (CRA) s.8(1)(d)(vi) for fraud detection in auto claims.
  • Whether the insurance company over-collected personal information by obtaining the complainant's entire credit file.
  • Whether the insurance company properly identified the purposes for collecting the complainant's credit score under Principle 4.2.
  • Whether the insurance company obtained meaningful consent for collecting the credit score, specifically if it advised the complainant that providing the information was optional, under Principle 4.3.
  • Whether the insurance company was open about its policies and practices regarding credit score collection and use under Principle 4.8.1.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 10, 2017PIPEDA Case Summary #2017-005Indexed Jun 30, 2026

PIPEDA Case Summary #2017-005: Insurance company required to delete individual’s personal information after individual withdraws consent

An insurance company

An individual complained that his former automobile insurance company refused to delete his personal information from its records and from third-party organizations. The company initially refused, citing the need to provide insurance history to other insurers. The OPC reframed the request as a withdrawal of consent, and the company subsequently agreed to delete the information from its own records, as there was no legal requirement to retain it. However, the OPC found that the company was not obligated to ensure deletion from third-party records if the information was lawfully disclosed. The investigation also revealed the company lacked clear documentation regarding its disclosure practices to third parties, contravening Principle 4.1.4(d). The company committed to developing a document to track disclosures, which it later provided to the OPC.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2017-005: Insurance company required to delete individual’s personal information after individual withdraws consent

Feb 10, 2017PIPEDA Case Summary #2017-005
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that his former automobile insurance company refused to delete his personal information from its records and from third-party organizations. The company initially refused, citing the need to provide insurance history to other insurers. The OPC reframed the request as a withdrawal of consent, and the company subsequently agreed to delete the information from its own records, as there was no legal requirement to retain it. However, the OPC found that the company was not obligated to ensure deletion from third-party records if the information was lawfully disclosed. The investigation also revealed the company lacked clear documentation regarding its disclosure practices to third parties, contravening Principle 4.1.4(d). The company committed to developing a document to track disclosures, which it later provided to the OPC.

Key Issues
  • Whether the insurance company was required to delete the individual's personal information from its own records upon withdrawal of consent
  • Whether the insurance company was required to ensure deletion of the individual's personal information from third-party organizations' records after lawful disclosure
  • Whether the insurance company contravened Principle 4.1.4(d) by lacking a clear explanation of its disclosure practices to third parties
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Jan 11, 2017PIPEDA Case Summary #2017-004Indexed Jun 30, 2026

PIPEDA Case Summary #2017-004: Consent provided extends to third-party doctor hired to evaluate accident insurance claim

A doctor hired by an independent medical evaluation firm

An individual complained that a doctor collected, used, and disclosed his personal information without consent. The complainant had been in a car accident and his insurance company hired an independent medical evaluation (IME) firm to assess his claim for catastrophic impairment. The doctor in question was hired by the IME firm to compile a summary report based on assessments from other doctors. The complainant argued he had not consented to this specific doctor, though he had consented to other doctors involved in his claim. The doctor contended that the complainant had provided consent through signed accident benefit forms (OCF-1 and OCF-19). The OPC found that the signed forms included explicit consent for health professionals to collect, use, and disclose personal information for the purpose of investigating and processing the insurance claim. The OPC concluded that the doctor's actions were within the scope of the consent provided.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Case Summary #2017-004: Consent provided extends to third-party doctor hired to evaluate accident insurance claim

Jan 11, 2017PIPEDA Case Summary #2017-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a doctor collected, used, and disclosed his personal information without consent. The complainant had been in a car accident and his insurance company hired an independent medical evaluation (IME) firm to assess his claim for catastrophic impairment. The doctor in question was hired by the IME firm to compile a summary report based on assessments from other doctors. The complainant argued he had not consented to this specific doctor, though he had consented to other doctors involved in his claim. The doctor contended that the complainant had provided consent through signed accident benefit forms (OCF-1 and OCF-19). The OPC found that the signed forms included explicit consent for health professionals to collect, use, and disclose personal information for the purpose of investigating and processing the insurance claim. The OPC concluded that the doctor's actions were within the scope of the consent provided.

Key Issues
  • Whether the doctor collected, used, and disclosed the complainant's personal information without consent
  • Whether the consent provided in OCF-1 and OCF-19 forms extended to the doctor preparing the summary report
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Dec 29, 2016PIPEDA findings #2016-013Indexed Jun 30, 2026

PIPEDA findings #2016-013: Company’s disclosure of information about a debt owed is not covered under exemption to consent

A sports facilities company

An individual complained that a sports facilities company disclosed his personal information, specifically details about an outstanding debt, to a related sports association on two occasions without his consent. The company did not deny the disclosures but argued they were made in response to direct questions and with an expectation of privacy. The OPC found that information about a debt owed by an identifiable individual is personal and sensitive, requiring consent for disclosure unless a specific exemption applies. The OPC determined that the disclosures were not for the purpose of collecting the debt, thus the exemption under paragraph 7(3)(b) of PIPEDA did not apply. The company's reliance on an 'expectation of privacy' or being asked directly was not a valid substitute for obtaining consent. The complaint was found to be well-founded.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA findings #2016-013: Company’s disclosure of information about a debt owed is not covered under exemption to consent

Dec 29, 2016PIPEDA findings #2016-013
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a sports facilities company disclosed his personal information, specifically details about an outstanding debt, to a related sports association on two occasions without his consent. The company did not deny the disclosures but argued they were made in response to direct questions and with an expectation of privacy. The OPC found that information about a debt owed by an identifiable individual is personal and sensitive, requiring consent for disclosure unless a specific exemption applies. The OPC determined that the disclosures were not for the purpose of collecting the debt, thus the exemption under paragraph 7(3)(b) of PIPEDA did not apply. The company's reliance on an 'expectation of privacy' or being asked directly was not a valid substitute for obtaining consent. The complaint was found to be well-founded.

Key Issues
  • Whether the disclosure of debt information without consent contravened Principle 4.3 of PIPEDA
  • Whether the disclosure was exempt from consent under paragraph 7(3)(b) of PIPEDA for debt collection purposes
  • Whether an 'expectation of privacy' or responding to a direct question constitutes a valid exception to consent requirements
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Dec 20, 2016Indexed Jun 30, 2026

The PBC refuses to process requests for record suspension information

Parole Board of Canada

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Quick view

Privacy ActWell-founded

The PBC refuses to process requests for record suspension information

Dec 20, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated two complaints against the Parole Board of Canada (PBC) concerning access to record suspension information under the Privacy Act. The first complaint involved the PBC's refusal to process requests from a third-party background screening company, citing section 22(1)(b) of the Privacy Act and arguing injury to the enforcement of the Criminal Records Act (CRA). The second complaint challenged the PBC's requirement for extensive identification, such as Fingerprint Serial (FPS) numbers or copies of criminal records, from individuals making direct access requests. The OPC found that individuals have a right to confirm if no responsive records exist and that the PBC erred in its broad application of section 22(1)(b), which was only justified in specific cases where identity could not be confirmed without additional information. The OPC also concluded that the PBC's identification requirements were excessive for initial processing. Consequently, the OPC found both complaints to be well-founded and issued recommendations to the PBC.

Key Issues
  • Whether an individual can make a request under the Privacy Act to confirm that no personal information relating to record suspensions exists.
  • Whether the PBC properly applied the exemption under paragraph 22(1)(b) of the Privacy Act to refuse access requests for record suspension information.
  • Whether the disclosure of record suspension information under the Privacy Act would injure the enforcement of the Criminal Records Act.
  • Whether the PBC's requirement for additional identification (FPS number, PBC reference number, criminal record copy) is necessary to adequately identify a requester under the Privacy Act.
  • Whether the company's record suspension verification service circumvents the vulnerable sector verification process under the CRA.
  • Whether the consent obtained by the company for its service is valid.
  • Whether the proposed use of personal information by the company violates human rights legislation.
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Sep 23, 2016Early resolved case summary #2016-01Indexed Jun 30, 2026

Early resolved case summary #2016-01: Access to personal information request revised to accommodate both requestor and organization

A condominium developer

A condominium owner filed a complaint after his request for access to his personal information was met with a demand for payment for photocopies or an offer to view documents at the organization's lawyer's office. The individual argued that this was not access at "minimal or no cost" as required by PIPEDA Principle 4.9.4. The OPC's early resolution unit intervened, and the organization initially offered free viewing with the option to select pages for free copies. The complainant, citing a disability, found viewing 1000 pages unreasonable. The OPC proposed that the individual narrow his request, which he accepted. Consequently, the organization agreed to provide free copies of the specific documents containing his personal information, leading to the complainant's satisfaction.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2016-01: Access to personal information request revised to accommodate both requestor and organization

Sep 23, 2016Early resolved case summary #2016-01
Adjudicator: Daniel Therrien
Plain-Language Summary

A condominium owner filed a complaint after his request for access to his personal information was met with a demand for payment for photocopies or an offer to view documents at the organization's lawyer's office. The individual argued that this was not access at "minimal or no cost" as required by PIPEDA Principle 4.9.4. The OPC's early resolution unit intervened, and the organization initially offered free viewing with the option to select pages for free copies. The complainant, citing a disability, found viewing 1000 pages unreasonable. The OPC proposed that the individual narrow his request, which he accepted. Consequently, the organization agreed to provide free copies of the specific documents containing his personal information, leading to the complainant's satisfaction.

Key Issues
  • Whether the organization's initial response to an access request met the "minimal or no cost" requirement under Principle 4.9.4 of PIPEDA
  • Whether an offer to view documents without free copies constitutes adequate access under PIPEDA
  • Whether the organization's proposed solution of viewing documents at a lawyer's office was reasonable given the complainant's disability
  • Whether narrowing the scope of an access request can facilitate resolution and compliance with PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 22, 2016PIPEDA Report of Findings #2016-005Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Avid Life Media Inc. (ALM)

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-005: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner

Aug 22, 2016PIPEDA Report of Findings #2016-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Australian Information Commissioner (OAIC) jointly investigated Avid Life Media Inc. (ALM), operator of the Ashley Madison dating website, following a massive data breach in 2015 that exposed approximately 36 million user accounts. The investigation focused on ALM's information handling practices, including its security safeguards, data retention policies, email address accuracy, and transparency with users. The OPC found multiple contraventions of PIPEDA, concluding that ALM lacked an adequate security framework, retained personal information indefinitely, charged a fee for account deletion, and failed to ensure the accuracy of email addresses. Furthermore, ALM's use of a deceptive "trusted security award" trust-mark and unclear retention policies invalidated user consent. ALM agreed to implement all recommendations, leading to a "well-founded and conditionally resolved" outcome, and entered into a compliance agreement with the OPC. Corrective measures included enhancing security, revising retention periods, offering free deletion, and improving transparency.

Key Issues
  • Whether ALM's security safeguards were appropriate to the sensitivity of the information under PIPEDA Principle 4.7.
  • Whether ALM implemented policies and practices to give effect to the Principles, including procedures to protect personal information, under PIPEDA Principle 4.1.4.
  • Whether ALM's indefinite retention of personal information for deactivated or inactive accounts contravened PIPEDA Principle 4.5.
  • Whether ALM's failure to establish maximum retention periods for personal information contravened PIPEDA Principle 4.5.2.
  • Whether ALM's practice of charging a fee for the complete deletion of personal information contravened an individual's right to withdraw consent under PIPEDA Principle 4.3.8.
  • Whether ALM took reasonable steps to ensure personal information (email addresses) was accurate, complete, and up-to-date as necessary for its purposes, taking into account the interests of the individual, under PIPEDA Principle 4.6 and 4.6.1.
  • Whether ALM's consent for the collection, use, or disclosure of personal information was valid, given the nature, purpose, and consequences, under PIPEDA s.6.1 and Principle 4.3.
  • Whether ALM made information about its personal information handling policies and practices readily available and understandable, and did not obtain consent through deception, under PIPEDA Principle 4.8, 4.8.1, and 4.3.5.
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Aug 10, 2016Early resolved case summary #2016-02Indexed Jun 30, 2026

Early resolved case summary #2016-02: Organization’s technical glitch results in the disclosure of a client’s personal information to another client

An online service company

An individual complained to the OPC after an online service company failed to resolve a technical glitch that caused another person's personal information to appear in his account. Despite months of attempts, the company's customer service and IT specialists could not fix the issue, nor could the individual escalate his concerns to a privacy officer. The OPC intervened, prompting the company to investigate and discover the glitch originated from another organization's software interface. The online company, in collaboration with the other organization, corrected the technical glitch for all users. The online company also revised its internal policies to include an escalation process for privacy concerns and established a new contractual agreement with the other organization to prevent future issues and enhance PIPEDA compliance. The complainant confirmed the issue was resolved to his satisfaction.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2016-02: Organization’s technical glitch results in the disclosure of a client’s personal information to another client

Aug 10, 2016Early resolved case summary #2016-02
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after an online service company failed to resolve a technical glitch that caused another person's personal information to appear in his account. Despite months of attempts, the company's customer service and IT specialists could not fix the issue, nor could the individual escalate his concerns to a privacy officer. The OPC intervened, prompting the company to investigate and discover the glitch originated from another organization's software interface. The online company, in collaboration with the other organization, corrected the technical glitch for all users. The online company also revised its internal policies to include an escalation process for privacy concerns and established a new contractual agreement with the other organization to prevent future issues and enhance PIPEDA compliance. The complainant confirmed the issue was resolved to his satisfaction.

Key Issues
  • Whether an online service company adequately addressed a technical glitch leading to unauthorized disclosure of personal information
  • Whether the online service company had appropriate internal policies for escalating privacy concerns
  • Whether the online service company had adequate contractual agreements with third-party service providers regarding privacy and data breaches
Federal (Canada)Personal Information Protection and Electronic Documents ActNo jurisdiction
Federal (Canada) flag
Jul 18, 2016PIPEDA Case Summary #2016-011Indexed Jun 30, 2026

PIPEDA Case Summary #2016-011: Defending against a civil lawsuit not considered a commercial activity

A psychiatrist retained by an independent medical evaluation provider

An individual (the plaintiff) filed a complaint after a psychiatrist, retained by an insurance company to assess the plaintiff's well-being for a civil lawsuit, did not provide full access to his personal information. The plaintiff had requested access to his personal information held by the psychiatrist and received only a redacted report, leading to concerns about the completeness and accuracy of the information. The OPC investigated whether the psychiatrist's collection and use of the plaintiff's personal information constituted a "commercial activity" under PIPEDA. The OPC determined that defending against a civil lawsuit is not a commercial activity, and therefore, PIPEDA did not apply. The complaint was ultimately dismissed due to lack of jurisdiction.

Quick view

Personal Information Protection and Electronic Documents ActNo jurisdiction

PIPEDA Case Summary #2016-011: Defending against a civil lawsuit not considered a commercial activity

Jul 18, 2016PIPEDA Case Summary #2016-011
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual (the plaintiff) filed a complaint after a psychiatrist, retained by an insurance company to assess the plaintiff's well-being for a civil lawsuit, did not provide full access to his personal information. The plaintiff had requested access to his personal information held by the psychiatrist and received only a redacted report, leading to concerns about the completeness and accuracy of the information. The OPC investigated whether the psychiatrist's collection and use of the plaintiff's personal information constituted a "commercial activity" under PIPEDA. The OPC determined that defending against a civil lawsuit is not a commercial activity, and therefore, PIPEDA did not apply. The complaint was ultimately dismissed due to lack of jurisdiction.

Key Issues
  • Whether the collection and use of a plaintiff’s personal information for the purpose of defending against a civil lawsuit constitutes a "commercial activity" under PIPEDA
  • Whether PIPEDA applies to the activities of a third-party retained to carry out an activity exempt from PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 14, 2016PIPEDA Case Summary #2016-008Indexed Jun 30, 2026

PIPEDA Case Summary #2016-008: Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties

A telecommunications company

An individual complained that a telecommunications company (telco) provided an incomplete response to her access request for information about disclosures of her personal information to other parties, including law enforcement. The telco initially responded by stating it was in compliance with specific PIPEDA subsections, without confirming or denying disclosures. The OPC found that the telco's response did not meet its obligation under Principle 4.9 of PIPEDA, which requires organizations to inform individuals of the existence, use, and disclosure of their personal information. The OPC clarified that an organization must provide a clear 'yes' or 'no' answer regarding disclosures, unless a government institution objects to such disclosure under PIPEDA s.9(2.4). Following the OPC's recommendation, the telco provided a complete response to the complainant and updated its policy for handling future access requests. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-008: Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties

Jul 14, 2016PIPEDA Case Summary #2016-008
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a telecommunications company (telco) provided an incomplete response to her access request for information about disclosures of her personal information to other parties, including law enforcement. The telco initially responded by stating it was in compliance with specific PIPEDA subsections, without confirming or denying disclosures. The OPC found that the telco's response did not meet its obligation under Principle 4.9 of PIPEDA, which requires organizations to inform individuals of the existence, use, and disclosure of their personal information. The OPC clarified that an organization must provide a clear 'yes' or 'no' answer regarding disclosures, unless a government institution objects to such disclosure under PIPEDA s.9(2.4). Following the OPC's recommendation, the telco provided a complete response to the complainant and updated its policy for handling future access requests. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the telco's initial response to an access request for disclosure information met its obligations under Principle 4.9 of PIPEDA
  • Whether the telco's practice of stating compliance with PIPEDA s.9(2.1)-(2.4) was sufficient for access requests
  • Whether the telco had an obligation to provide a 'yes' or 'no' answer regarding disclosures to all third parties, including those not covered by PIPEDA s.9(2.1)-(2.4)
  • How an organization should respond to an access request for disclosure information when a government institution objects under PIPEDA s.9(2.4)