The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

17 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014Indexed Jun 30, 2026

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

An online dating service

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2013-014 — An online dating service and The new owner of the online dating service

Dec 18, 2013Commissioner’s Findings - PIPEDA Case Summary # 2013-014
Adjudicator: Chantal Bernier
Plain-Language Summary

An individual complained that an online dating service continued to send him marketing emails after he cancelled his membership and requested his information be deleted. He also alleged the service denied him access to his personal information. During the investigation, the dating service was sold, and the new owner inherited the customer database. The OPC found the original service violated PIPEDA by denying access, retaining information longer than necessary, continuing to use his email for marketing after consent withdrawal, lacking a privacy policy, and failing to safeguard information. While some issues were resolved by the new owner, the denial of access and destruction of photographs during an access request were found to be well-founded and unresolved.

Key Issues
  • Whether the organization denied the complainant access to his personal information in violation of Principle 4.9
  • Whether the organization failed to respect the 30-day time limit for access requests under subsection 8(3)
  • Whether the organization contravened subsection 8(8) by destroying photographs, limiting the complainant's recourse
  • Whether the organization retained the complainant's information longer than necessary in contravention of Principle 4.5.3
  • Whether the organization continued to use the complainant's personal information for marketing after consent withdrawal, contravening Principle 4.3.8
  • Whether the organization lacked a privacy policy in contravention of Principle 4.1.4(d)
  • Whether the organization failed to safeguard the complainant's personal information as required by Principle 4.7.1
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Nov 28, 2013Indexed Jun 30, 2026

Access to information at risk from instant messaging

Crown-Indigenous Relations and Northern Affairs / Indigenous Services

In August 2012, the Information Commissioner launched a systemic investigation into the use and preservation of non-email, text-based messages on government-issued wireless devices, specifically instant messaging and PINs. This investigation was prompted by a complaint against Indian and Northern Affairs Canada (now Aboriginal Affairs and Northern Development Canada) where a complainant received an email suggesting the use of "pin" instead of email for communication. During the investigation of that complaint, it was discovered that relevant BlackBerry devices had been replaced and destroyed, leading to the permanent loss of potentially responsive information. Due to this incident and a rise in similar complaints about missing records, the Commissioner initiated a self-complaint under section 30(1)(f) of the ATIA to examine the impact of instant messaging on access to information. The investigation focused on 11 federal institutions to assess their practices regarding the retention of these types of communications.

Quick view

Access to Information ActSystemic Investigation

Access to information at risk from instant messaging

Nov 28, 2013
Adjudicator: Suzanne Legault
Plain-Language Summary

In August 2012, the Information Commissioner launched a systemic investigation into the use and preservation of non-email, text-based messages on government-issued wireless devices, specifically instant messaging and PINs. This investigation was prompted by a complaint against Indian and Northern Affairs Canada (now Aboriginal Affairs and Northern Development Canada) where a complainant received an email suggesting the use of "pin" instead of email for communication. During the investigation of that complaint, it was discovered that relevant BlackBerry devices had been replaced and destroyed, leading to the permanent loss of potentially responsive information. Due to this incident and a rise in similar complaints about missing records, the Commissioner initiated a self-complaint under section 30(1)(f) of the ATIA to examine the impact of instant messaging on access to information. The investigation focused on 11 federal institutions to assess their practices regarding the retention of these types of communications.

Key Issues
  • Impact of instant messaging on the right of access to information
  • Preservation of non-email, text-based messages on government-issued wireless devices
  • Retention policies and practices for instant messages and PIN communications
  • Loss of records due to device replacement and destruction
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Aboriginal Affairs and Northern Development Canada wrongly collects information from First Nations activist’s personal Facebook page

Aboriginal Affairs and Northern Development Canada and Department of Justice Canada

First Nations activist Cindy Blackstock complained that Aboriginal Affairs and Northern Development Canada (AANDC) and the Department of Justice Canada (DOJ) contravened the Privacy Act by collecting her personal information from her Facebook page. The departments argued that information posted publicly on Facebook was not personal. The OPC rejected this argument, finding that publicly available information can still be personal under the Privacy Act. The OPC found that the collection of personal information from Ms. Blackstock's personal Facebook page was not directly related to a government operating program or activity. Both departments accepted the OPC's recommendations to cease such collection, destroy previously collected personal information, and develop policies for social media monitoring.

Quick view

Privacy ActWell-founded

Aboriginal Affairs and Northern Development Canada wrongly collects information from First Nations activist’s personal Facebook page

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

First Nations activist Cindy Blackstock complained that Aboriginal Affairs and Northern Development Canada (AANDC) and the Department of Justice Canada (DOJ) contravened the Privacy Act by collecting her personal information from her Facebook page. The departments argued that information posted publicly on Facebook was not personal. The OPC rejected this argument, finding that publicly available information can still be personal under the Privacy Act. The OPC found that the collection of personal information from Ms. Blackstock's personal Facebook page was not directly related to a government operating program or activity. Both departments accepted the OPC's recommendations to cease such collection, destroy previously collected personal information, and develop policies for social media monitoring.

Key Issues
  • Whether information posted on a personal Facebook page constitutes "personal information" under the Privacy Act
  • Whether the public availability of personal information on the Internet renders it non-personal
  • Whether the collection of personal information from Ms. Blackstock's personal Facebook page was directly related to a government operating program or activity
  • Whether the monitoring of Ms. Blackstock's public speeches constituted collection of "personal information" under the Privacy Act
  • Whether repeated accessing of Ms. Blackstock's Indian status records was a contravention of the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Royal Canadian Mounted Police revealed absolute discharge

Royal Canadian Mounted Police (RCMP)

A man applied for a Transportation Security Clearance in July 2010, which was denied by Transport Canada (TC) in September 2011 based on information from the RCMP. The man complained that the RCMP improperly disclosed his personal information to TC. The RCMP had obtained information about an incident involving the complainant in 2009, which resulted in an absolute discharge a few months later. The RCMP provided this information to TC in 2011. The OPC found that the disclosure contravened the Criminal Records Act because more than a year had passed since the absolute discharge and no ministerial approval was obtained. The disclosure was also not authorized under the Privacy Act. The complaint was found to be well-founded.

Quick view

Privacy ActWell-founded

Royal Canadian Mounted Police revealed absolute discharge

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A man applied for a Transportation Security Clearance in July 2010, which was denied by Transport Canada (TC) in September 2011 based on information from the RCMP. The man complained that the RCMP improperly disclosed his personal information to TC. The RCMP had obtained information about an incident involving the complainant in 2009, which resulted in an absolute discharge a few months later. The RCMP provided this information to TC in 2011. The OPC found that the disclosure contravened the Criminal Records Act because more than a year had passed since the absolute discharge and no ministerial approval was obtained. The disclosure was also not authorized under the Privacy Act. The complaint was found to be well-founded.

Key Issues
  • Whether the RCMP's disclosure of personal information to Transport Canada contravened the Criminal Records Act
  • Whether the RCMP's disclosure of personal information to Transport Canada was authorized under the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Concern raised over online disclosure - The Qalipu Mi’kmaq First Nation Band

Aboriginal Affairs and Northern Development Canada (AANDC)

A woman complained to the OPC that Aboriginal Affairs and Northern Development Canada (AANDC) was putting her at risk of identity theft by publishing her full name and date of birth in the Canada Gazette, which is available online. This information was published as part of the enrollment process for the Qalipu Mi’kmaq First Nation Band. The OPC investigated whether this disclosure was consistent with the Privacy Act. The OPC determined that the disclosure was for the purpose for which the information was originally collected, which was for the identification and recognition of Band members. Therefore, the disclosure was permissible under the Privacy Act without the individual's consent. The complaint was found to be not well-founded, but the OPC recommended AANDC explore future options to mitigate identity theft risks.

Quick view

Privacy ActNot well-founded

Concern raised over online disclosure - The Qalipu Mi’kmaq First Nation Band

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained to the OPC that Aboriginal Affairs and Northern Development Canada (AANDC) was putting her at risk of identity theft by publishing her full name and date of birth in the Canada Gazette, which is available online. This information was published as part of the enrollment process for the Qalipu Mi’kmaq First Nation Band. The OPC investigated whether this disclosure was consistent with the Privacy Act. The OPC determined that the disclosure was for the purpose for which the information was originally collected, which was for the identification and recognition of Band members. Therefore, the disclosure was permissible under the Privacy Act without the individual's consent. The complaint was found to be not well-founded, but the OPC recommended AANDC explore future options to mitigate identity theft risks.

Key Issues
  • Whether the disclosure of full name and date of birth in the Canada Gazette was consistent with the Privacy Act
  • Whether personal information can be disclosed without consent when it is for the purpose for which it was originally collected
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

National Defence employee accesses someone’s personal health records for her own personal reasons

National Defence

A complainant alleged that a Canadian Forces (CF) employee, with whom he had a prior personal relationship, inappropriately accessed his personal health information. The investigation found that the employee accessed the complainant’s health information in the Canadian Forces Health Information System (CFHIS) multiple times after receiving an anonymous message about the complainant's health. The employee admitted to accessing and using the information for personal reasons, which was inconsistent with the purpose for its collection. The complaint was found to be well-founded. As a result, National Defence acknowledged the importance of privacy awareness and training, implemented new controls in CFHIS, updated its health service policy, and provided training to CF healthcare staff.

Quick view

Privacy ActWell-founded

National Defence employee accesses someone’s personal health records for her own personal reasons

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a Canadian Forces (CF) employee, with whom he had a prior personal relationship, inappropriately accessed his personal health information. The investigation found that the employee accessed the complainant’s health information in the Canadian Forces Health Information System (CFHIS) multiple times after receiving an anonymous message about the complainant's health. The employee admitted to accessing and using the information for personal reasons, which was inconsistent with the purpose for its collection. The complaint was found to be well-founded. As a result, National Defence acknowledged the importance of privacy awareness and training, implemented new controls in CFHIS, updated its health service policy, and provided training to CF healthcare staff.

Key Issues
  • Whether a National Defence employee inappropriately accessed personal health information for personal reasons
  • Whether the access was inconsistent with the purpose for which the information was collected
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Correctional Service of Canada initially denies access to full report in favour of giving the “gist”

Correctional Service of Canada (CSC)

A complainant alleged that the Correctional Service of Canada (CSC) denied him full access to a report concerning his treatment and supervision. The complainant initially received a three-page summary, but later learned the full report was ten pages with more findings. The OPC's investigation confirmed the existence of the longer report. CSC stated they provided a condensed version because the full report was based on informal interviews. The OPC found that providing an abbreviated version misrepresented the information and was contrary to CSC's obligations under the Privacy Act to process all relevant information. After negotiations, CSC provided the full report with third-party personal information redacted and committed to reviewing its access request handling and educating staff on Privacy Act obligations.

Quick view

Privacy ActResolved

Correctional Service of Canada initially denies access to full report in favour of giving the “gist”

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that the Correctional Service of Canada (CSC) denied him full access to a report concerning his treatment and supervision. The complainant initially received a three-page summary, but later learned the full report was ten pages with more findings. The OPC's investigation confirmed the existence of the longer report. CSC stated they provided a condensed version because the full report was based on informal interviews. The OPC found that providing an abbreviated version misrepresented the information and was contrary to CSC's obligations under the Privacy Act to process all relevant information. After negotiations, CSC provided the full report with third-party personal information redacted and committed to reviewing its access request handling and educating staff on Privacy Act obligations.

Key Issues
  • Whether Correctional Service of Canada denied full access to a report
  • Whether providing a condensed version of a report constitutes a misrepresentation of information
  • Whether Correctional Service of Canada fulfilled its responsibility to identify and process all relevant information under the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed May 13, 2026

Denial was the starting point for Correctional Service of Canada

Correctional Service of Canada

An inmate at a maximum-security penitentiary requested video recordings of incidents involving officers. The Correctional Service of Canada (CSC) denied access, citing third-party information and security concerns. The OPC found complaints regarding 16 destroyed videos to be well-founded, as CSC had not even reviewed them before denial. For two other videos, which CSC claimed contained third-party information and posed security risks, the OPC found CSC correctly applied exemptions, thus resolving those complaints.

Quick view

Privacy ActWell-founded

Denial was the starting point for Correctional Service of Canada

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An inmate at a maximum-security penitentiary requested video recordings of incidents involving officers. The Correctional Service of Canada (CSC) denied access, citing third-party information and security concerns. The OPC found complaints regarding 16 destroyed videos to be well-founded, as CSC had not even reviewed them before denial. For two other videos, which CSC claimed contained third-party information and posed security risks, the OPC found CSC correctly applied exemptions, thus resolving those complaints.

Key Issues
  • Timeliness of responding to access to information requests
  • Destruction of records prior to fulfilling requests
  • Application of exemptions for security of penal institutions
  • Proper review of records before withholding information
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Estranged wife accessed husband’s medical records

National Defence (DND)

A sergeant complained that his estranged wife, a civilian employee at a Canadian Forces Base, had unauthorized access to his military health records. The sergeant provided an audit log showing his wife accessed his Canadian Forces Health Information Services (CFHIS) account and deleted a physiotherapy appointment. National Defence (DND) confirmed the unauthorized access and noted she also accessed a paper physiotherapy file. DND determined she willfully breached departmental rules and implemented system restrictions to bar her access. The OPC found the access and use of medical information inconsistent with its original purpose and not a permissible use under the Privacy Act, upholding the complaint as well-founded. DND has since implemented new CFHIS controls and is evaluating its systems and practices for health information.

Quick view

Privacy ActWell-founded

Estranged wife accessed husband’s medical records

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A sergeant complained that his estranged wife, a civilian employee at a Canadian Forces Base, had unauthorized access to his military health records. The sergeant provided an audit log showing his wife accessed his Canadian Forces Health Information Services (CFHIS) account and deleted a physiotherapy appointment. National Defence (DND) confirmed the unauthorized access and noted she also accessed a paper physiotherapy file. DND determined she willfully breached departmental rules and implemented system restrictions to bar her access. The OPC found the access and use of medical information inconsistent with its original purpose and not a permissible use under the Privacy Act, upholding the complaint as well-founded. DND has since implemented new CFHIS controls and is evaluating its systems and practices for health information.

Key Issues
  • Whether the estranged wife's access to the sergeant's medical records was authorized
  • Whether the access and use of medical information was consistent with the purpose for which it was originally intended
  • Whether the access and use met permissible uses defined in the Privacy Act
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Criminal background check on tenant

Royal Canadian Mounted Police (RCMP)

A woman complained that two RCMP employee landlords performed a criminal background check on her using the Canadian Police Information Centre (CPIC) database when she applied to rent a basement apartment. The landlords requested personal identification to "look into" prospective tenants. An internal RCMP investigation confirmed that one officer accessed CPIC for personal reasons, citing the applicant being from "out of town" and concerns for officer safety and organizational security. The OPC found that the CPIC database contains personal information and its use is restricted to legitimate law enforcement purposes. The investigation concluded that the officer's access was for personal reasons, not authorized operational purposes. The complaint was found to be well-founded, and the RCMP took remedial actions including an apology to the complainant and a communiqué to employees regarding CPIC use policies.

Quick view

Privacy ActWell-founded

Criminal background check on tenant

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A woman complained that two RCMP employee landlords performed a criminal background check on her using the Canadian Police Information Centre (CPIC) database when she applied to rent a basement apartment. The landlords requested personal identification to "look into" prospective tenants. An internal RCMP investigation confirmed that one officer accessed CPIC for personal reasons, citing the applicant being from "out of town" and concerns for officer safety and organizational security. The OPC found that the CPIC database contains personal information and its use is restricted to legitimate law enforcement purposes. The investigation concluded that the officer's access was for personal reasons, not authorized operational purposes. The complaint was found to be well-founded, and the RCMP took remedial actions including an apology to the complainant and a communiqué to employees regarding CPIC use policies.

Key Issues
  • Whether the CPIC database contains personal information under the Privacy Act
  • Whether the RCMP officer accessed the CPIC database for personal reasons
  • Whether the access to the CPIC database was for an authorized operational purpose
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 29, 2013Indexed Jun 30, 2026

Canada Revenue Agency employee accesses tax file without authorization

Canada Revenue Agency (CRA)

A complainant alleged that the Canada Revenue Agency (CRA) contravened the Privacy Act when an employee accessed his tax file without authorization in 2005 and 2006. The complainant became suspicious after community members showed knowledge of his financial information. An audit trail report revealed that a CRA employee had accessed his T1 tax account twice, viewing sensitive personal information including his Social Insurance Number, income, and family details. The OPC's investigation confirmed that the employee accessed the account without authorization and beyond the scope of their duties. The complaint was found to be well-founded, and CRA confirmed the employee no longer has access to taxpayer information.

Quick view

Privacy ActWell-founded

Canada Revenue Agency employee accesses tax file without authorization

Oct 29, 2013
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that the Canada Revenue Agency (CRA) contravened the Privacy Act when an employee accessed his tax file without authorization in 2005 and 2006. The complainant became suspicious after community members showed knowledge of his financial information. An audit trail report revealed that a CRA employee had accessed his T1 tax account twice, viewing sensitive personal information including his Social Insurance Number, income, and family details. The OPC's investigation confirmed that the employee accessed the account without authorization and beyond the scope of their duties. The complaint was found to be well-founded, and CRA confirmed the employee no longer has access to taxpayer information.

Key Issues
  • Whether a CRA employee accessed the complainant's tax file without authorization
  • Whether the unauthorized access contravened the use and disclosure provisions of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 2, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-005Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-005: Beneficiary’s access to estate information is limited to his own personal information under PIPEDA

A legal firm

An individual, claiming to be a beneficiary of two estates, sought access under PIPEDA to estate information from a legal firm that had acted as an agent for another firm administering the estates. The complainant requested information pertaining to himself as a beneficiary and general beneficiary entitlements. The legal firm initially failed to respond to the access requests, leading to a complaint with the OPC. The firm later responded, stating it held no personal information about the complainant and that neither he nor the estates were clients. The OPC found that the firm contravened PIPEDA by not responding within the 30-day time limit. However, the OPC also determined that the complainant was only entitled to access information specifically about himself, not general estate information, and was satisfied that the firm had conducted a reasonable search for his personal information. The complaint was deemed well-founded and resolved due to the firm's initial failure to respond.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-005: Beneficiary’s access to estate information is limited to his own personal information under PIPEDA

Oct 2, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-005
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual, claiming to be a beneficiary of two estates, sought access under PIPEDA to estate information from a legal firm that had acted as an agent for another firm administering the estates. The complainant requested information pertaining to himself as a beneficiary and general beneficiary entitlements. The legal firm initially failed to respond to the access requests, leading to a complaint with the OPC. The firm later responded, stating it held no personal information about the complainant and that neither he nor the estates were clients. The OPC found that the firm contravened PIPEDA by not responding within the 30-day time limit. However, the OPC also determined that the complainant was only entitled to access information specifically about himself, not general estate information, and was satisfied that the firm had conducted a reasonable search for his personal information. The complaint was deemed well-founded and resolved due to the firm's initial failure to respond.

Key Issues
  • Whether a legal firm must respond to an access request within 30 days, even if it holds no personal information about the requester
  • Whether a beneficiary of an estate is entitled under PIPEDA to access general estate information
  • Whether the requested information (e.g., statements of accounts, money received, disbursements) constitutes the complainant's personal information under PIPEDA
  • Whether the legal firm conducted a reasonable search for the complainant's personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActDeclined to investigate
Federal (Canada) flag
Sep 11, 2013Declined to Investigate Case Summary #2013-001Indexed Jun 30, 2026

Declined to Investigate Case Summary #2013-001: Court procedures provided a more appropriate means to address access issues in ongoing litigation between complainant and retailer

A retailer

An individual filed a complaint against a retailer, alleging that the retailer withheld access to her personal information, contravening subsection 8(3) and Principle 4.9 of PIPEDA. The complainant and retailer were involved in ongoing small claims court litigation, and the complainant stated the information was necessary for her case. The retailer refused access, citing litigation privilege and prior disclosure. The OPC declined to investigate the complaint, finding that the court's procedures provided a more appropriate means for the complainant to address the access issues. This decision was based on avoiding conflict with provincial court rules and ensuring judicious use of public resources.

Quick view

Personal Information Protection and Electronic Documents ActDeclined to investigate

Declined to Investigate Case Summary #2013-001: Court procedures provided a more appropriate means to address access issues in ongoing litigation between complainant and retailer

Sep 11, 2013Declined to Investigate Case Summary #2013-001
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual filed a complaint against a retailer, alleging that the retailer withheld access to her personal information, contravening subsection 8(3) and Principle 4.9 of PIPEDA. The complainant and retailer were involved in ongoing small claims court litigation, and the complainant stated the information was necessary for her case. The retailer refused access, citing litigation privilege and prior disclosure. The OPC declined to investigate the complaint, finding that the court's procedures provided a more appropriate means for the complainant to address the access issues. This decision was based on avoiding conflict with provincial court rules and ensuring judicious use of public resources.

Key Issues
  • Whether the complaint could more appropriately be dealt with by means of a procedure provided for under the laws of a province under paragraph 12(1)(b) of PIPEDA
  • Whether the retailer withheld access to personal information in contravention of subsection 8(3) of PIPEDA
  • Whether the retailer withheld access to personal information in contravention of Principle 4.9 of Schedule 1 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 11, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-003Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-003: Profiles on PositiveSingles.com dating website turn up on other affiliated dating websites

SuccessfulMatch Inc. (operating PositiveSingles.com)

Three individuals complained that their dating profiles, containing sensitive medical information, posted on PositiveSingles.com appeared on numerous other affiliated dating websites without their knowledge or consent. The complainants were assured of privacy but found their profiles on sites targeting different demographics, causing distress. The OPC's investigation found that PositiveSingles.com, operated by SuccessfulMatch Inc., used a single database across a network of affiliated sites, making profiles automatically available. The OPC concluded that the organization failed to obtain meaningful consent for this use, lacked openness about its network structure, and had inadequate safeguards, as some personal information was accessible via search engines. Following the OPC's recommendations, SuccessfulMatch revamped its website to provide explicit information about the network, ensure informed consent at registration, and improve safeguards. The complaint was found well-founded and resolved due to these corrective measures.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-003: Profiles on PositiveSingles.com dating website turn up on other affiliated dating websites

Jul 11, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-003
Adjudicator: Jennifer Stoddart
Plain-Language Summary

Three individuals complained that their dating profiles, containing sensitive medical information, posted on PositiveSingles.com appeared on numerous other affiliated dating websites without their knowledge or consent. The complainants were assured of privacy but found their profiles on sites targeting different demographics, causing distress. The OPC's investigation found that PositiveSingles.com, operated by SuccessfulMatch Inc., used a single database across a network of affiliated sites, making profiles automatically available. The OPC concluded that the organization failed to obtain meaningful consent for this use, lacked openness about its network structure, and had inadequate safeguards, as some personal information was accessible via search engines. Following the OPC's recommendations, SuccessfulMatch revamped its website to provide explicit information about the network, ensure informed consent at registration, and improve safeguards. The complaint was found well-founded and resolved due to these corrective measures.

Key Issues
  • Whether PositiveSingles.com obtained meaningful consent for the use of personal information across its network of affiliated sites (Principle 4.3, 4.3.2, 4.3.5 PIPEDA)
  • Whether PositiveSingles.com was sufficiently open about its personal information management policies and practices, particularly regarding its network structure (Principle 4.8, 4.8.1 PIPEDA)
  • Whether PositiveSingles.com implemented adequate security safeguards to protect sensitive personal information from unauthorized access (Principle 4.7, 4.7.1 PIPEDA)
  • Whether PositiveSingles.com's use of cookies, potentially for online behavioral advertising, required express consent given the sensitive nature of the information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 28, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-017Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Report of Findings #2013-017: Apple called upon to provide greater clarity on its use and disclosure of unique device identifiers for targeted advertising

Apple

An individual complained that Apple was using and sharing her unique device identifier (UDID) without her knowledge and consent for tracking and targeted advertising. The OPC determined that UDIDs, and later Advertising IDs (Ad IDs), constituted personal information because Apple could link them to identifiable individuals. While Apple's use of UDIDs for administrative purposes was deemed to have implied consent, the OPC initially found Apple's explanations for using and disclosing UDIDs for targeted advertising to be insufficient for meaningful consent. During the investigation, Apple phased out the use of UDIDs for advertising, introduced the resettable Ad ID, and improved its privacy policy explanations and opt-out mechanisms. Consequently, the OPC found that Apple's updated practices provided sufficient information for meaningful consent regarding the use and disclosure of Ad IDs for advertising. The complaint was found to be well-founded but resolved due to Apple's corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Commissioner’s Findings - PIPEDA Report of Findings #2013-017: Apple called upon to provide greater clarity on its use and disclosure of unique device identifiers for targeted advertising

Jun 28, 2013Commissioner’s Findings - PIPEDA Report of Findings #2013-017
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that Apple was using and sharing her unique device identifier (UDID) without her knowledge and consent for tracking and targeted advertising. The OPC determined that UDIDs, and later Advertising IDs (Ad IDs), constituted personal information because Apple could link them to identifiable individuals. While Apple's use of UDIDs for administrative purposes was deemed to have implied consent, the OPC initially found Apple's explanations for using and disclosing UDIDs for targeted advertising to be insufficient for meaningful consent. During the investigation, Apple phased out the use of UDIDs for advertising, introduced the resettable Ad ID, and improved its privacy policy explanations and opt-out mechanisms. Consequently, the OPC found that Apple's updated practices provided sufficient information for meaningful consent regarding the use and disclosure of Ad IDs for advertising. The complaint was found to be well-founded but resolved due to Apple's corrective actions.

Key Issues
  • Whether Unique Device Identifiers (UDID) constitute personal information under PIPEDA.
  • Whether Advertising Identifiers (Ad ID) constitute personal information under PIPEDA.
  • Whether Apple obtained meaningful consent for its use of UDID for administration and maintenance purposes (Principle 4.3 PIPEDA).
  • Whether Apple obtained meaningful consent for its use of UDID and Ad ID for targeted advertising purposes (Principle 4.3 PIPEDA).
  • Whether Apple obtained meaningful consent for its disclosure of UDID and Ad ID to third-party app developers (Principle 4.3 PIPEDA).
  • Whether Apple's explanations regarding the use and disclosure of UDID and Ad ID were sufficiently clear and understandable to ensure meaningful consent (Principle 4.3.2 PIPEDA).
  • Whether the sensitivity of UDID and Ad ID in the context of user profiling and online behavioural advertising required express consent (Principle 4.3.6 PIPEDA).
  • Whether the reasonable expectations of the individual were met regarding the use and disclosure of UDID and Ad ID (Principle 4.3.5 PIPEDA).