The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,631 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 7, 2016PIPEDA Case Summary #2016-010Indexed Jun 30, 2026

PIPEDA Case Summary #2016-010: Credit reporting agency takes remedial action after failing to maintain accurate records

A credit reporting agency

An individual complained to the OPC after discovering inaccuracies in his credit file, including two unrecognized credit inquiries and a notation that his account had been automatically combined with others. The credit reporting agency acknowledged that his file had been manually combined with another individual's due to similar names and addresses. The OPC investigated two main issues: unauthorized use/disclosure and accuracy of personal information. The OPC found no unauthorized use or disclosure, as the inquiries occurred before the files were combined and only the other individual's information was used. However, the OPC determined that the agency failed to maintain accurate personal information, as combining files compromised accuracy and led to incorrect information being attributed to the complainant. The agency rectified the error by separating the files, notifying creditors of corrections, and committing to enhanced employee training. Consequently, the accuracy issue was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-010: Credit reporting agency takes remedial action after failing to maintain accurate records

Jul 7, 2016PIPEDA Case Summary #2016-010
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained to the OPC after discovering inaccuracies in his credit file, including two unrecognized credit inquiries and a notation that his account had been automatically combined with others. The credit reporting agency acknowledged that his file had been manually combined with another individual's due to similar names and addresses. The OPC investigated two main issues: unauthorized use/disclosure and accuracy of personal information. The OPC found no unauthorized use or disclosure, as the inquiries occurred before the files were combined and only the other individual's information was used. However, the OPC determined that the agency failed to maintain accurate personal information, as combining files compromised accuracy and led to incorrect information being attributed to the complainant. The agency rectified the error by separating the files, notifying creditors of corrections, and committing to enhanced employee training. Consequently, the accuracy issue was found to be well-founded and resolved.

Key Issues
  • Whether the credit reporting agency improperly disclosed the complainant's personal information without consent
  • Whether the credit reporting agency failed to maintain accurate personal information as required by PIPEDA Principle 4.6
  • Whether the credit reporting agency failed to maintain accurate personal information as required by PIPEDA Principle 4.6.3
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Jun 16, 2016Indexed Jun 30, 2026

The importance of leadership

Parks Canada

In 2015-2016, the Commissioner conducted a systemic investigation into Parks Canada's approach to processing access to information requests. The investigation highlighted the importance of collaboration between institutions and the Commissioner to achieve positive systemic changes for access rights. This case illustrated how an institution's engagement during an investigation could lead to improvements in its access to information practices. The Commissioner's findings focused on the institution's overall approach rather than specific exemptions or individual complaints. The outcome emphasized the benefits of leadership and cooperation in addressing systemic issues related to access to information.

Quick view

Access to Information ActSystemic Investigation

The importance of leadership

Jun 16, 2016
Adjudicator: Suzanne Legault
Plain-Language Summary

In 2015-2016, the Commissioner conducted a systemic investigation into Parks Canada's approach to processing access to information requests. The investigation highlighted the importance of collaboration between institutions and the Commissioner to achieve positive systemic changes for access rights. This case illustrated how an institution's engagement during an investigation could lead to improvements in its access to information practices. The Commissioner's findings focused on the institution's overall approach rather than specific exemptions or individual complaints. The outcome emphasized the benefits of leadership and cooperation in addressing systemic issues related to access to information.

Key Issues
  • Parks Canada's approach to processing access requests
  • Systemic issues in access to information practices
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 6, 2016Indexed Jun 30, 2026

TV show raises numerous questions of consent

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Quick view

Privacy ActWell-founded

TV show raises numerous questions of consent

Jun 6, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Canada Border Services Agency (CBSA) regarding its participation in the television series "Border Security: Canada’s Front Line." The complaint, filed by the British Columbia Civil Liberties Association on behalf of an individual, alleged violations of sections 4 and 8 of the Privacy Act concerning the collection and disclosure of personal information. The OPC found that while the CBSA's collection of the complainant's personal information for enforcement purposes met section 4, its disclosure to the production company, Force Four, lacked valid consent under section 8 due to the coercive context. The OPC also found that the CBSA disclosed personal information of an intended subject to Force Four without authorization and that the facial blurring techniques used were insufficient to protect privacy. Consequently, the complaint was found to be well-founded. The OPC recommended that the CBSA cease its participation in the TV Program and conduct Privacy Impact Assessments for future initiatives involving personal information, which the CBSA accepted.

Key Issues
  • Whether the CBSA, as a federal institution, could contract out of its obligations under the Privacy Act
  • Whether the CBSA's collection of personal information in connection with the TV Program related directly to an operating program or activity of the institution (s.4 Privacy Act)
  • Whether the CBSA was involved in the collection of personal information for the purposes of the TV Program
  • Whether there was a real-time disclosure of personal information by the CBSA to Force Four for the purpose of filming the TV Program
  • Whether the CBSA obtained valid, meaningful, and freely given consent from individuals, including the complainant, for the disclosure of their personal information to Force Four (s.8 Privacy Act)
  • Whether the "Voluntary Appearance Release Form" (Waiver) effectively waived individuals' rights under the Privacy Act
  • Whether the practice of "silent filming" by the production crew was consistent with obtaining valid consent
  • Whether the CBSA disclosed personal information of an intended subject to Force Four in advance of filming without authorization (s.8 Privacy Act)
  • Whether the personal information of the intended subject was publicly available at the time of disclosure
  • Whether the facial blurring and other identity concealment techniques used in the TV Program were sufficient to prevent the identification of individuals who had not provided written consent
  • Whether the CBSA demonstrated how the disclosure of personal information of individuals without written consent was consistent with section 8 of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 17, 2016Indexed Jun 30, 2026

Canada Revenue Agency takes adequate measures to ensure personal information not moved to U.S.

Canada Revenue Agency (CRA)

A complainant raised concerns that the Canada Revenue Agency (CRA) outsourced the storage of Canadian taxpayer information to Mobilshred Inc., which the complainant believed was a division of a US-based company, Recall. The complainant was concerned that this could make the personal information vulnerable to disclosure under the USA PATRIOT Act. The OPC investigated whether the CRA had properly safeguarded personal information from unauthorized disclosure. The CRA clarified that Mobilshred Inc. is a Canadian company, and the contract explicitly requires all physical records to remain in Canada. The OPC found that the CRA took appropriate steps to mitigate risks by ensuring all information remained in Canada and that Mobilshred Inc. is a Canadian entity. The complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

Canada Revenue Agency takes adequate measures to ensure personal information not moved to U.S.

May 17, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant raised concerns that the Canada Revenue Agency (CRA) outsourced the storage of Canadian taxpayer information to Mobilshred Inc., which the complainant believed was a division of a US-based company, Recall. The complainant was concerned that this could make the personal information vulnerable to disclosure under the USA PATRIOT Act. The OPC investigated whether the CRA had properly safeguarded personal information from unauthorized disclosure. The CRA clarified that Mobilshred Inc. is a Canadian company, and the contract explicitly requires all physical records to remain in Canada. The OPC found that the CRA took appropriate steps to mitigate risks by ensuring all information remained in Canada and that Mobilshred Inc. is a Canadian entity. The complaint was found to be not well-founded.

Key Issues
  • Whether the CRA properly safeguarded personal information entrusted to Mobilshred Inc. from unauthorized disclosure under the Privacy Act
  • Whether Canadian taxpayer information was vulnerable to disclosure to US authorities under the USA PATRIOT Act due to the contract with Mobilshred Inc.
  • Whether Mobilshred Inc. is a Canadian entity or affiliated with a US-based company
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
May 6, 2016Early resolution case summary #2016-03Indexed Jun 30, 2026

Early resolution case summary #2016-03: First Nation develops a privacy policy following allegations of lost doctor’s notes

First Nation band council

An employee of a First Nation band council complained that two doctor's notes he submitted for leave requests were lost by the band office, leading to non-payment for his leave. The complainant also filed a complaint under the Canada Labour Code. The OPC's Early Resolution Unit engaged with the band council, which, while not confirming the loss of the notes, agreed to develop a privacy policy and adopt best privacy practices. The OPC provided resources to assist in this development. The complainant was satisfied with the band council's commitment to a privacy policy, leading to an early resolution of the privacy complaint, with the issue of lost notes to be addressed via the Canada Labour Code complaint. The band council subsequently adopted a privacy policy with the OPC's guidance.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolution case summary #2016-03: First Nation develops a privacy policy following allegations of lost doctor’s notes

May 6, 2016Early resolution case summary #2016-03
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee of a First Nation band council complained that two doctor's notes he submitted for leave requests were lost by the band office, leading to non-payment for his leave. The complainant also filed a complaint under the Canada Labour Code. The OPC's Early Resolution Unit engaged with the band council, which, while not confirming the loss of the notes, agreed to develop a privacy policy and adopt best privacy practices. The OPC provided resources to assist in this development. The complainant was satisfied with the band council's commitment to a privacy policy, leading to an early resolution of the privacy complaint, with the issue of lost notes to be addressed via the Canada Labour Code complaint. The band council subsequently adopted a privacy policy with the OPC's guidance.

Key Issues
  • Whether a First Nation band council is a federal work, undertaking or business (FWUB) under PIPEDA
  • Whether the personal information of employees of a FWUB is protected under PIPEDA
  • Whether the First Nation band council adequately protected the complainant's medical information
  • Whether the First Nation band council had appropriate privacy policies and practices in place
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 21, 2016PIPEDA Report of Findings #2016-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Compu-Finder (3510395 Canada Inc.)

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2016-003: Investigation into the personal information handling practices of “Compu-Finder” (3510395 Canada Inc.)

Apr 21, 2016PIPEDA Report of Findings #2016-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against Compu-Finder (3510395 Canada Inc.) for allegedly collecting and using individuals' email addresses without consent to send promotional emails. Compu-Finder argued it had implied consent, that the information was publicly available, or that it fell under the business contact information carve-out. The OPC found that Compu-Finder contravened PIPEDA principles regarding meaningful consent, fair and lawful collection, accountability, and openness. Specifically, its telemarketing script was inadequate, and it failed to prove express consent or justify implied consent or exemptions. Compu-Finder also lacked a designated privacy officer and public privacy policies. As a result, the OPC issued recommendations, which Compu-Finder agreed to implement. The OPC concluded the complaint was well-founded and resolved in part, and well-founded and conditionally resolved in part, entering into a compliance agreement to monitor implementation.

Key Issues
  • Whether Compu-Finder's collection and use of email addresses constituted "personal information" under PIPEDA.
  • Whether the business contact information carve-out under s. 4.01 PIPEDA applied to Compu-Finder's activities.
  • Whether Compu-Finder obtained meaningful express consent for collecting email addresses via telemarketing (Principles 4.2, 4.3, 4.3.2).
  • Whether Compu-Finder collected personal information by fair and lawful means (Principle 4.4).
  • Whether Compu-Finder obtained meaningful implied consent for collecting email addresses from publicly available sources (Principle 4.3.6).
  • Whether the "publicly available information" exemption (s. 7(1)(d), 7(2)(c.1) PIPEDA and s. 1 of the Regulations) applied to Compu-Finder's collection and use of email addresses.
  • Whether the address harvesting provisions (s. 7.1(2) PIPEDA) prohibited the use of email addresses collected via software before the provision came into force.
  • Whether Compu-Finder had a designated individual accountable for PIPEDA compliance (Principle 4.1).
  • Whether Compu-Finder implemented policies and practices to give effect to PIPEDA principles (Principle 4.1.4).
  • Whether Compu-Finder was open about its personal information management policies and practices (Principles 4.8.1, 4.8.2).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 31, 2016PIPEDA Case Summary #2016-012Indexed Jun 30, 2026

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

A bank associated with a retailer

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-012: Customer gets signed up for retailer credit card without his consent

Mar 31, 2016PIPEDA Case Summary #2016-012
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained after receiving a credit card he did not apply for, following an interaction with a salesperson for a loyalty program. He alleged that he never consented to a credit card application or a credit check, and that much of the information on the application was inaccurate. The bank claimed the individual knowingly provided his information and consented via an electronic tablet. The OPC found that the bank failed to demonstrate it obtained the complainant's consent and ensure the accuracy of the collected information. The investigation concluded the bank contravened PIPEDA Principles 4.3 (consent), 4.6 (accuracy), and 4.1.4 (accountability). The bank apologized, cancelled the card, and removed the inquiry from the credit report. It also discontinued its in-store pilot program and committed to implementing measures to ensure proper consent and information accuracy if it relaunches such a program.

Key Issues
  • Whether the bank obtained valid consent for a credit card application and credit check under Principle 4.3
  • Whether the bank ensured the accuracy of personal information collected under Principle 4.6
  • Whether the bank had adequate procedures to give effect to PIPEDA principles under Principle 4.1.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 10, 2016PIPEDA Case Summary #2016-009Indexed Jun 30, 2026

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

An international trucking company

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-009: Trucking company inappropriately disclosed employee’s drug test results to workers’ compensation board

Mar 10, 2016PIPEDA Case Summary #2016-009
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that his employer, an international trucking company, disclosed his positive drug test results to a provincial workers' compensation board (WCB) without his consent, and also to his co-workers. The employer stated it believed it was legally obligated to inform the WCB due to a change in the employee's work status and cited the provincial Workers' Compensation Act. The WCB clarified that the Act did not create an express duty for unsolicited disclosure of such information. The OPC found that the disclosure to the WCB was a contravention of PIPEDA Principles 4.3 and 4.5, as the information was used for a different purpose than collected without consent, and no legal obligation exception applied. The OPC also investigated the alleged disclosure to co-workers but found no evidence to support this claim. The employer implemented the OPC's recommendations, leading to a 'well-founded and resolved' outcome for the disclosure to the WCB.

Key Issues
  • Whether the disclosure of drug test results to the WCB without consent contravened PIPEDA Principles 4.3 and 4.5
  • Whether the employer had a legal obligation to disclose the drug test results to the WCB under the provincial Workers' Compensation Act, thereby qualifying for an exception to consent under paragraph 7(3)(i) of PIPEDA
  • Whether the employer disclosed the drug test results to co-workers without consent
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 24, 2016Incident Summary #12Indexed Jun 30, 2026

Incident Summary #12: Break with security procedures exposes financial planner’s client to privacy breach

A financial management firm

A financial management firm's employees breached internal security procedures by sending a client's detailed financial plan and federal income tax notice of assessment, containing sensitive personal information including her social insurance number, to her personal email account without secure messaging tools. The client's email account was subsequently hacked, and the alleged hacker used the obtained information to pose as the client and request a significant transfer from her investment account. An employee processed this transfer without following authentication procedures. Although the client's money was not stolen, the firm investigated the incident, advised the client to change passwords, informed the RCMP, and offered credit monitoring. The firm also took measures with the responsible employees, provided additional privacy training to staff, and reviewed its internal processes. The OPC considered the firm's response appropriate.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #12: Break with security procedures exposes financial planner’s client to privacy breach

Feb 24, 2016Incident Summary #12
Adjudicator: Daniel Therrien
Plain-Language Summary

A financial management firm's employees breached internal security procedures by sending a client's detailed financial plan and federal income tax notice of assessment, containing sensitive personal information including her social insurance number, to her personal email account without secure messaging tools. The client's email account was subsequently hacked, and the alleged hacker used the obtained information to pose as the client and request a significant transfer from her investment account. An employee processed this transfer without following authentication procedures. Although the client's money was not stolen, the firm investigated the incident, advised the client to change passwords, informed the RCMP, and offered credit monitoring. The firm also took measures with the responsible employees, provided additional privacy training to staff, and reviewed its internal processes. The OPC considered the firm's response appropriate.

Key Issues
  • Whether the firm adequately protected personal information by sending sensitive documents via unsecure email
  • Whether the firm had adequate procedures for authenticating clients for financial transactions
  • Whether the firm's response to the privacy breach was appropriate
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 19, 2016Incident Summary #11Indexed Jun 30, 2026

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

A financial institution

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

Feb 19, 2016Incident Summary #11
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Key Issues
  • Whether the financial institution adequately safeguarded personal information during mass mail-outs
  • Whether the financial institution responded appropriately to a privacy breach involving misdirected mail
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 19, 2016PIPEDA Report of Findings #2016-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

A property management company

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

Feb 19, 2016PIPEDA Report of Findings #2016-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Key Issues
  • Whether the collection, use, and disclosure of personal information for a "bad tenant list" was for purposes that a reasonable person would consider appropriate in the circumstances (s.5(3) PIPEDA)
  • Whether the property management company was acting as an unlicensed credit reporting agency under provincial legislation
  • Whether meaningful knowledge and consent of individuals were obtained for the collection, use, and disclosure of their personal information for the "bad tenant list" (Principle 4.3, 4.3.2 PIPEDA)
  • Whether the personal information on the "bad tenant list" was accurate, complete, and up-to-date (Principle 4.6, 4.6.1 PIPEDA)
  • Whether individuals had the ability to challenge the accuracy of information about them on the list (Principle 4.10 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 18, 2016Incident Summary #13Indexed Jun 30, 2026

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

A Canadian financial institution

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

Feb 18, 2016Incident Summary #13
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Key Issues
  • Whether the financial institution adequately protected customer personal information from unauthorized disclosure by a fraudster
  • Whether the financial institution took appropriate steps to mitigate the impact of the breach and prevent recurrence
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 12, 2016PIPEDA Report of Findings #2016-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

An insurance company

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

Feb 12, 2016PIPEDA Report of Findings #2016-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Key Issues
  • Whether the insurance company contravened Principles 4.9 and 4.9.1 by refusing access to personal information without severing third-party information
  • Whether the insurance company's internal ombudsman office constitutes a "formal dispute resolution process" under PIPEDA s.9(3)(d)
  • Whether the activities of the internal ombudsman office fall under the definition of "commercial activity" under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 9, 2016PIPEDA Case Summary #2016-007Indexed Jun 30, 2026

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

A collection agency

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

Feb 9, 2016PIPEDA Case Summary #2016-007
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the organization refused to provide access to personal information
  • Whether the organization responded to access requests within the required timeframe
  • Whether the organization followed its own privacy policies and procedures for access requests
  • Whether the organization maintained records of access request processing
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Feb 8, 2016Indexed Jun 30, 2026

Canada Post collection of online signatures for mail tracking draws complaint

Canada Post Corporation

A complaint was filed against Canada Post Corporation (CPC) regarding its collection, use, and disclosure of electronic signatures for parcel tracking. The complainant raised concerns about the clarity of information provided to addressees regarding their option to opt-out of having their signature displayed online, and the absence of labels on signature devices at a specific postal outlet. The investigation also examined the privacy and security controls of CPC's online tracking website. CPC argued that disclosure of signatures to senders was authorized under the Privacy Act and that it provided an opt-out option. The OPC found that the collection and disclosure of signatures for parcel tracking were consistent with the Act, but raised concerns about the adequacy of security controls for online signatures. CPC committed to implementing enhanced security measures.

Quick view

Privacy ActNot well-founded

Canada Post collection of online signatures for mail tracking draws complaint

Feb 8, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Canada Post Corporation (CPC) regarding its collection, use, and disclosure of electronic signatures for parcel tracking. The complainant raised concerns about the clarity of information provided to addressees regarding their option to opt-out of having their signature displayed online, and the absence of labels on signature devices at a specific postal outlet. The investigation also examined the privacy and security controls of CPC's online tracking website. CPC argued that disclosure of signatures to senders was authorized under the Privacy Act and that it provided an opt-out option. The OPC found that the collection and disclosure of signatures for parcel tracking were consistent with the Act, but raised concerns about the adequacy of security controls for online signatures. CPC committed to implementing enhanced security measures.

Key Issues
  • Whether the collection of electronic signatures by CPC contravenes the Privacy Act
  • Whether the disclosure of electronic signatures to the sender of a parcel contravenes the Privacy Act
  • Whether the disclosure of electronic signatures online contravenes the Privacy Act
  • Whether CPC adequately safeguards digitized signatures displayed online
  • Whether the information provided to addressees about opting out of online signature display is sufficiently clear