The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

21 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Dec 27, 2017PIPEDA findings #2017-010Indexed Jun 30, 2026

PIPEDA findings #2017-010: Reasons for retaining customer credit card data explained

A retail store

A complainant objected to a retail store retaining records of her credit card transactions and refusing to delete them upon request. The store initially cited contractual obligations with credit card companies. During the OPC's investigation, the retail company provided a more detailed explanation, including its legal obligations under the Excise Tax Act to retain transactional data. The OPC relayed this information to the complainant, who was satisfied with the explanation and considered the matter resolved. The complainant noted that if this information had been provided initially, she would not have filed a complaint.

Quick view

Personal Information Protection and Electronic Documents ActResolved

PIPEDA findings #2017-010: Reasons for retaining customer credit card data explained

Dec 27, 2017PIPEDA findings #2017-010
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant objected to a retail store retaining records of her credit card transactions and refusing to delete them upon request. The store initially cited contractual obligations with credit card companies. During the OPC's investigation, the retail company provided a more detailed explanation, including its legal obligations under the Excise Tax Act to retain transactional data. The OPC relayed this information to the complainant, who was satisfied with the explanation and considered the matter resolved. The complainant noted that if this information had been provided initially, she would not have filed a complaint.

Key Issues
  • Whether a retail store's retention of credit card transaction records without deletion upon request violated PIPEDA's consent principle
  • Whether legal or contractual obligations justified the retention of personal information despite a withdrawal of consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 20, 2017PIPEDA Case Summary #2017-006Indexed Jun 30, 2026

PIPEDA Case Summary #2017-006: Using SIN for identity verification cannot be a condition of service

A financial institution

A complainant alleged that a financial institution required customers to provide their Social Insurance Number (SIN) to credit reporting agencies for identity verification when opening a savings account, even though the SIN was not needed for income reporting. The financial institution argued that using the SIN for identity verification was beneficial for maintaining data integrity and cited FINTRAC guidelines. The OPC reviewed FINTRAC and Employment and Social Development Canada (ESDC) guidelines and found no requirement or suggestion for using SINs for identity verification. The OPC concluded that requiring consent for this practice as a condition of service contravened Principle 4.3.3 of PIPEDA. The financial institution agreed to make the use of SIN for identity verification optional, and the complaint was deemed well-founded and conditionally resolved. A follow-up confirmed full compliance.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2017-006: Using SIN for identity verification cannot be a condition of service

Dec 20, 2017PIPEDA Case Summary #2017-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a financial institution required customers to provide their Social Insurance Number (SIN) to credit reporting agencies for identity verification when opening a savings account, even though the SIN was not needed for income reporting. The financial institution argued that using the SIN for identity verification was beneficial for maintaining data integrity and cited FINTRAC guidelines. The OPC reviewed FINTRAC and Employment and Social Development Canada (ESDC) guidelines and found no requirement or suggestion for using SINs for identity verification. The OPC concluded that requiring consent for this practice as a condition of service contravened Principle 4.3.3 of PIPEDA. The financial institution agreed to make the use of SIN for identity verification optional, and the complaint was deemed well-founded and conditionally resolved. A follow-up confirmed full compliance.

Key Issues
  • Whether requiring a SIN for identity verification as a condition of service contravenes Principle 4.3.3 of PIPEDA
  • Whether FINTRAC or ESDC guidelines require or suggest the use of SINs for identity verification
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Nov 2, 2017PIPEDA Report of Findings #2017-009Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-009: Airline relies on access exemption to refuse traveler’s access to their personal information

An airline

A traveler complained that an airline failed to provide complete access to his personal information, specifically documents and correspondence related to being denied boarding in 2015. The airline invoked exemptions under PIPEDA, arguing the information was collected to investigate a breach of agreement or contravention of law (s.7(1)(b)) and disclosed to a government institution for law enforcement purposes (s.7(3)(c.1)(ii)). The OPC found that the collection without consent was justified under s.7(1)(b) because it was for investigating potential non-compliance with the Immigration and Refugee Protection Act, and that requiring consent would have compromised the investigation. The OPC also found the disclosure to a government institution was permissible under s.7(3)(c.1)(ii). Furthermore, the OPC determined that the airline was prohibited from providing access to the requested information under s.9(2.4) because the government institution objected to its release. Therefore, the OPC concluded that the airline properly relied on the exemptions.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Report of Findings #2017-009: Airline relies on access exemption to refuse traveler’s access to their personal information

Nov 2, 2017PIPEDA Report of Findings #2017-009
Adjudicator: Daniel Therrien
Plain-Language Summary

A traveler complained that an airline failed to provide complete access to his personal information, specifically documents and correspondence related to being denied boarding in 2015. The airline invoked exemptions under PIPEDA, arguing the information was collected to investigate a breach of agreement or contravention of law (s.7(1)(b)) and disclosed to a government institution for law enforcement purposes (s.7(3)(c.1)(ii)). The OPC found that the collection without consent was justified under s.7(1)(b) because it was for investigating potential non-compliance with the Immigration and Refugee Protection Act, and that requiring consent would have compromised the investigation. The OPC also found the disclosure to a government institution was permissible under s.7(3)(c.1)(ii). Furthermore, the OPC determined that the airline was prohibited from providing access to the requested information under s.9(2.4) because the government institution objected to its release. Therefore, the OPC concluded that the airline properly relied on the exemptions.

Key Issues
  • Whether the airline's collection of personal information without consent was justified under paragraph 7(1)(b) of PIPEDA
  • Whether the airline's disclosure of personal information without consent was justified under subparagraph 7(3)(c.1)(ii) of PIPEDA
  • Whether the airline was required to provide access to the requested personal information under Principle 4.9 of Schedule 1, given the exemptions under section 9 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 29, 2017PIPEDA findings #2017-012Indexed Jun 30, 2026

PIPEDA findings #2017-012: Financial institution discloses too much information in response to production order

A financial institution

A complainant alleged that his financial institution improperly disclosed his personal information, specifically RESP account details from 1999, to a municipal police service. The financial institution claimed the disclosure was made under a production order or, alternatively, with the complainant's consent via its privacy policy. The OPC found that the disclosed 1999 RESP information fell outside the scope of the production order, which specified a different date range and nature of information. The OPC also rejected the financial institution's argument of consent, stating that the privacy policy's general language was insufficient for informed consent, especially for sensitive financial information. The financial institution agreed to review its procedures and provide training to ensure compliance with production orders. The complaint was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2017-012: Financial institution discloses too much information in response to production order

Aug 29, 2017PIPEDA findings #2017-012
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that his financial institution improperly disclosed his personal information, specifically RESP account details from 1999, to a municipal police service. The financial institution claimed the disclosure was made under a production order or, alternatively, with the complainant's consent via its privacy policy. The OPC found that the disclosed 1999 RESP information fell outside the scope of the production order, which specified a different date range and nature of information. The OPC also rejected the financial institution's argument of consent, stating that the privacy policy's general language was insufficient for informed consent, especially for sensitive financial information. The financial institution agreed to review its procedures and provide training to ensure compliance with production orders. The complaint was found to be well-founded and resolved.

Key Issues
  • Whether the disclosure of RESP account information from 1999 was justified under paragraph 7(3)(c) of PIPEDA as being required by a production order
  • Whether the financial institution could rely on the complainant's consent, as stipulated in its privacy policy, for the disclosure of personal information to law enforcement
  • Whether the RESP account information constituted sensitive personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 28, 2017PIPEDA Report of Findings #2017-001Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-001: Drug activity history in property reports deemed not publicly available

A property report provider

A complainant alleged that a company selling "home history reports" collected, used, and disclosed personal information without consent, specifically sales history, drug activity, and insurance claims. The OPC found that sales history was no longer included in reports and insurance claims information, as clarified by the respondent, related to property damage paid to third parties, not individuals, thus not constituting personal information. However, information about drug activity was deemed personal information because it could be linked to identifiable individuals and suggested their involvement in drug activity. The OPC concluded that this drug activity information was not "publicly available" under PIPEDA Regulations, requiring consent for its use. The respondent agreed to cease including drug activity details in its reports, leading to a well-founded and resolved outcome.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2017-001: Drug activity history in property reports deemed not publicly available

Aug 28, 2017PIPEDA Report of Findings #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a company selling "home history reports" collected, used, and disclosed personal information without consent, specifically sales history, drug activity, and insurance claims. The OPC found that sales history was no longer included in reports and insurance claims information, as clarified by the respondent, related to property damage paid to third parties, not individuals, thus not constituting personal information. However, information about drug activity was deemed personal information because it could be linked to identifiable individuals and suggested their involvement in drug activity. The OPC concluded that this drug activity information was not "publicly available" under PIPEDA Regulations, requiring consent for its use. The respondent agreed to cease including drug activity details in its reports, leading to a well-founded and resolved outcome.

Key Issues
  • Whether sales history information constituted personal information and was collected, used, or disclosed without consent
  • Whether insurance claims information constituted personal information
  • Whether drug activity information constituted personal information
  • Whether drug activity information was "publicly available" under the Regulations Specifying Publicly Available Information
  • Whether the respondent obtained adequate consent for the collection, use, and disclosure of personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 28, 2017PIPEDA Report of Findings #2017-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-002: Canadian adware developer Wajam Internet Technologies Inc. breaches multiple provisions of PIPEDA

Wajam Internet Technologies Inc.

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Wajam Internet Technologies Inc., an adware developer, regarding its software's installation, consent, uninstallation, and data handling practices. The software, Wajam or Social2Search, tracked online search queries, overlaid social media results, and displayed contextual ads. The OPC investigated whether Wajam obtained meaningful consent for installation, allowed users to withdraw consent, and adequately safeguarded personal information. The investigation found that Wajam lacked a privacy accountability framework, failed to obtain meaningful consent due to problematic third-party distribution methods and misleading information, indefinitely retained unencrypted raw user data, and had insufficient safeguards. All examined matters related to accountability, consent, limiting retention, safeguards, and openness were found to be well-founded. Wajam, having sold its assets to a Hong Kong-based company, IMTL, claimed it was unable to implement the OPC's recommendations, though it agreed to securely destroy Canadian user data. The OPC requested Wajam provide the report to IMTL and stated it would monitor the situation and engage international counterparts.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2017-002: Canadian adware developer Wajam Internet Technologies Inc. breaches multiple provisions of PIPEDA

Aug 28, 2017PIPEDA Report of Findings #2017-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Wajam Internet Technologies Inc., an adware developer, regarding its software's installation, consent, uninstallation, and data handling practices. The software, Wajam or Social2Search, tracked online search queries, overlaid social media results, and displayed contextual ads. The OPC investigated whether Wajam obtained meaningful consent for installation, allowed users to withdraw consent, and adequately safeguarded personal information. The investigation found that Wajam lacked a privacy accountability framework, failed to obtain meaningful consent due to problematic third-party distribution methods and misleading information, indefinitely retained unencrypted raw user data, and had insufficient safeguards. All examined matters related to accountability, consent, limiting retention, safeguards, and openness were found to be well-founded. Wajam, having sold its assets to a Hong Kong-based company, IMTL, claimed it was unable to implement the OPC's recommendations, though it agreed to securely destroy Canadian user data. The OPC requested Wajam provide the report to IMTL and stated it would monitor the situation and engage international counterparts.

Key Issues
  • Whether Wajam Internet Technologies Inc. had an adequate privacy accountability framework in place (Principle 4.1.4 PIPEDA)
  • Whether Wajam obtained meaningful consent from individuals for the installation and operation of its software (Principle 4.3, 4.3.2, 4.3.5 PIPEDA, s.6.1 PIPEDA)
  • Whether Wajam's third-party distribution model ensured meaningful consent for software installation
  • Whether Wajam's multiple-offer consent screens provided sufficient information for meaningful consent
  • Whether the information provided by Wajam about its software's functionality and privacy practices was accurate and complete (Principle 4.2, 4.3.2, 4.3.5 PIPEDA)
  • Whether Wajam permitted users to withdraw consent by making it difficult to uninstall its software (Principle 4.3.8 PIPEDA)
  • Whether Wajam was responsible for unsolicited ads and fake offers presented during the uninstallation process (Principle 4.3 PIPEDA)
  • Whether Wajam limited the retention of personal information to only as long as necessary for identified purposes (Principle 4.5, 4.5.2 PIPEDA)
  • Whether Wajam was open about its policies and practices relating to the management of personal information (Principle 4.8 PIPEDA)
  • Whether Wajam adequately safeguarded users' personal information against loss, theft, or unauthorized access, including during transmission and storage (Principle 4.7.1, 4.7.2, 4.7.3 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Aug 27, 2017Early resolved case summary #2017-002Indexed Jun 30, 2026

Early resolved case summary #2017-002: Access to personal information held by insurance company facilitated through the early resolution process

An insurance company

An individual complained after an insurance company refused to provide access to her personal information following an incident at a store. The individual sought access to her insurance claim file, including case management notes and a video of the incident. The company initially refused, citing confidential commercial information and the personal information of third parties. Through the OPC's early resolution process, the company agreed to allow the individual to view the video and provided a redacted copy of the case management notes. The OPC's Early Resolution Officer reviewed the redactions to ensure they were properly applied. The complaint was resolved to the satisfaction of both parties.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2017-002: Access to personal information held by insurance company facilitated through the early resolution process

Aug 27, 2017Early resolved case summary #2017-002
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained after an insurance company refused to provide access to her personal information following an incident at a store. The individual sought access to her insurance claim file, including case management notes and a video of the incident. The company initially refused, citing confidential commercial information and the personal information of third parties. Through the OPC's early resolution process, the company agreed to allow the individual to view the video and provided a redacted copy of the case management notes. The OPC's Early Resolution Officer reviewed the redactions to ensure they were properly applied. The complaint was resolved to the satisfaction of both parties.

Key Issues
  • Whether an organization must provide an individual with access to their personal information upon request
  • Whether case management notes constitute "confidential commercial information" under PIPEDA paragraph 9(3)(b)
  • Whether a video containing images of third parties can be withheld from an access request
  • Whether an organization can fulfill its access obligations by allowing viewing of a record rather than providing a copy
  • Whether redaction of confidential commercial information or third-party personal information is an appropriate method to grant access
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 17, 2017PIPEDA Report of Findings #2017-008Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-008: Jet Airways says possibility of litigation allows it to refuse access to personal information

Jet Airways

The complainant alleged that Jet Airways failed to provide complete access to her personal information related to an incident where she and her companion were removed from a flight. Jet Airways initially failed to respond to the access request within the 30-day timeframe, citing potential litigation and staff medical leave. While Jet Airways eventually provided the Passenger Name Record, it withheld other documents, claiming solicitor-client privilege (including litigation privilege) and that the information was generated during a formal dispute resolution process. The OPC found that Jet Airways contravened its obligations regarding timely response and proper policies for handling access requests and applying exemptions. However, due to binding court decisions, the OPC could not make a finding on the specific application of solicitor-client/litigation privilege to the withheld documents, leading to an impasse on that issue. The OPC recommended that Jet Airways implement proper access request procedures and review its policies for applying exemptions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2017-008: Jet Airways says possibility of litigation allows it to refuse access to personal information

Aug 17, 2017PIPEDA Report of Findings #2017-008
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Jet Airways failed to provide complete access to her personal information related to an incident where she and her companion were removed from a flight. Jet Airways initially failed to respond to the access request within the 30-day timeframe, citing potential litigation and staff medical leave. While Jet Airways eventually provided the Passenger Name Record, it withheld other documents, claiming solicitor-client privilege (including litigation privilege) and that the information was generated during a formal dispute resolution process. The OPC found that Jet Airways contravened its obligations regarding timely response and proper policies for handling access requests and applying exemptions. However, due to binding court decisions, the OPC could not make a finding on the specific application of solicitor-client/litigation privilege to the withheld documents, leading to an impasse on that issue. The OPC recommended that Jet Airways implement proper access request procedures and review its policies for applying exemptions.

Key Issues
  • Whether Jet Airways responded to the access request within the prescribed 30-day time period under subsection 8(3) of PIPEDA
  • Whether Jet Airways had appropriate policies and practices to give effect to Principle 4.1.4 of Schedule 1 of PIPEDA
  • Whether the withheld information was protected by solicitor-client privilege or litigation privilege under paragraph 9(3)(a) of PIPEDA
  • Whether the withheld information was generated in the course of a formal dispute resolution process under paragraph 9(3)(d) of PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Aug 16, 2017Indexed Jun 30, 2026

Cell site simulators used by RCMP not capable of intercepting private communication

Royal Canadian Mounted Police (RCMP)

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Quick view

Privacy ActWell-founded

Cell site simulators used by RCMP not capable of intercepting private communication

Aug 16, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against the Royal Canadian Mounted Police (RCMP) alleging that it used cell site simulators (MDIs or "Stingray" devices) to monitor large groups, intercept private communications, and extract encryption keys without public knowledge or consent. The RCMP confirmed its use of MDIs, stating they only collect unique device identifiers (IMSI/IMEI) and are not capable of intercepting private communications. The Office of the Privacy Commissioner (OPC) investigated, including a technical demonstration, and found that the RCMP's MDIs are indeed not capable of intercepting private communications. The OPC also reviewed the legal authority for MDI use, finding that for 113 out of 125 deployments, prior judicial authorization was obtained, and for 7 others, exigent circumstances applied. However, in 6 instances, the RCMP deployed MDIs without prior judicial authorization or exigent circumstances, which the OPC found to be a contravention of section 4 of the Privacy Act. The OPC noted that the RCMP has since taken steps to remedy this by requiring prior judicial authorization for all MDI deployments unless exigent circumstances are present. The OPC also found that the RCMP's handling of third-party data collected by MDIs, including segregation, security, retention, and destruction, was appropriate.

Key Issues
  • Whether RCMP uses cell site simulators (MDIs)
  • Whether RCMP's MDIs are capable of intercepting private communications (voice, text, email, encryption keys)
  • Whether RCMP's collection of personal information using MDIs relates directly to an operating program or activity (s.4 Privacy Act)
  • Whether RCMP's collection of personal information using MDIs was lawful and Charter-compliant, specifically regarding prior judicial authorization
  • Whether exigent circumstances justified warrantless MDI deployments in certain cases
  • Whether RCMP's collection of personal information using MDIs complied with direct collection and notification requirements (s.5 Privacy Act)
  • Whether the RCMP adequately handles, retains, and disposes of third-party personal information (IMSI/IMEI numbers) collected by MDIs
  • Whether the wording in warrants and policies provides adequate protection for collected personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 8, 2017PIPEDA Report of Findings #2017-007Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-007: Operator of website that shamed debtors for profit takes down website after OPC takes the matter to Federal Court

Public Executions Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Public Executions Inc., operator of publicexecutions.ca, a website that published personal information of judgment debtors for a fee. Complainants alleged their privacy rights under PIPEDA were breached by the website's practice of "naming and shaming" them into paying debts. The website owner argued PIPEDA did not apply, claiming it was not a commercial activity, was exempt as journalism, and that disclosures were permitted for debt collection. The OPC found that the website's fee-based service constituted a commercial activity under PIPEDA. It rejected the journalistic exemption, noting the lack of original production and journalistic discipline. The OPC concluded that broadly publicizing debtor information for financial gain and coercion was not an appropriate purpose under subsection 5(3) of PIPEDA, especially given existing legal mechanisms and regulations for debt collection. Furthermore, the OPC clarified that paragraph 7(3)(b) of PIPEDA, which allows disclosure for debt collection, does not permit indiscriminate disclosure to the public. Initially, the complaint was found well-founded and unresolved, as the website owner refused to comply with recommendations. However, after the OPC initiated Federal Court proceedings, the website was taken down, leading the OPC to discontinue its application.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2017-007: Operator of website that shamed debtors for profit takes down website after OPC takes the matter to Federal Court

Aug 8, 2017PIPEDA Report of Findings #2017-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated complaints against Public Executions Inc., operator of publicexecutions.ca, a website that published personal information of judgment debtors for a fee. Complainants alleged their privacy rights under PIPEDA were breached by the website's practice of "naming and shaming" them into paying debts. The website owner argued PIPEDA did not apply, claiming it was not a commercial activity, was exempt as journalism, and that disclosures were permitted for debt collection. The OPC found that the website's fee-based service constituted a commercial activity under PIPEDA. It rejected the journalistic exemption, noting the lack of original production and journalistic discipline. The OPC concluded that broadly publicizing debtor information for financial gain and coercion was not an appropriate purpose under subsection 5(3) of PIPEDA, especially given existing legal mechanisms and regulations for debt collection. Furthermore, the OPC clarified that paragraph 7(3)(b) of PIPEDA, which allows disclosure for debt collection, does not permit indiscriminate disclosure to the public. Initially, the complaint was found well-founded and unresolved, as the website owner refused to comply with recommendations. However, after the OPC initiated Federal Court proceedings, the website was taken down, leading the OPC to discontinue its application.

Key Issues
  • Whether the website's activities constituted "commercial activity" under paragraph 4(1)(a) of PIPEDA.
  • Whether the website qualified for the "journalistic purposes" exemption under paragraph 4(2)(c) of PIPEDA.
  • Whether the collection, use, and disclosure of personal information by the website was for purposes that a reasonable person would consider "appropriate in the circumstances" under subsection 5(3) of PIPEDA.
  • Whether the disclosure of personal information was permitted without consent for the purpose of collecting a debt under paragraph 7(3)(b) of PIPEDA.
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jul 25, 2017Early resolved case summary #2017-001Indexed Jun 30, 2026

Early resolved case summary #2017-001: Privacy obligations under PIPEDA apply to financial technology sector

A FinTech organization

A complainant sought to open an online financial investment account with a FinTech organization. To access the investment account management agreement, the complainant was required to provide personal information, some of which was sensitive. After reviewing the agreement, the complainant decided not to open an account and requested deletion of their personal information. The organization cited "regulatory requirements" for the collection. The OPC clarified that while regulatory requirements exist, they apply once an individual becomes a client, not before. The OPC advised the organization to revise its website so prospective clients could review the agreement without prior personal information disclosure. The organization agreed to revise its website and Privacy Policy, leading to an early resolution.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2017-001: Privacy obligations under PIPEDA apply to financial technology sector

Jul 25, 2017Early resolved case summary #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant sought to open an online financial investment account with a FinTech organization. To access the investment account management agreement, the complainant was required to provide personal information, some of which was sensitive. After reviewing the agreement, the complainant decided not to open an account and requested deletion of their personal information. The organization cited "regulatory requirements" for the collection. The OPC clarified that while regulatory requirements exist, they apply once an individual becomes a client, not before. The OPC advised the organization to revise its website so prospective clients could review the agreement without prior personal information disclosure. The organization agreed to revise its website and Privacy Policy, leading to an early resolution.

Key Issues
  • Whether a FinTech organization can require personal information before a prospective client reviews terms and conditions
  • Whether consent under PIPEDA is meaningful if personal information is collected before a user can review service agreements
  • Whether regulatory requirements justify collecting personal information from prospective clients who do not proceed with opening an account
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jul 19, 2017Indexed Jun 30, 2026

MyDemocracy website not designed in a privacy sensitive way

Privy Council Office

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Quick view

Privacy ActWell-founded

MyDemocracy website not designed in a privacy sensitive way

Jul 19, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against the Privy Council Office (PCO) regarding its MyDemocracy.ca website. The complainant alleged that the website used "Facebook Connect" tracking, sharing user data with Facebook despite promises of anonymity. The OPC found that the website's design facilitated the disclosure of personal information, including IP addresses, browser characteristics, and for logged-in users, Facebook IDs, to Facebook upon loading the homepage and initiating share actions, without obtaining consent. PCO argued that the design was standard and that the shared data did not constitute identifiable personal information. However, the OPC concluded that this constituted a disclosure of personal information under section 3 of the Privacy Act and that PCO failed to meet its obligations under section 8. The complaint was found to be well-founded, and the OPC reiterated recommendations for PCO to ensure privacy-sensitive design, conduct PIAs, and obtain meaningful consent for future initiatives.

Key Issues
  • Whether the MyDemocracy.ca website's design led to the disclosure of personal information to third parties (Facebook, Google Analytics) without consent.
  • Whether IP addresses, browser characteristics, and unique URLs constitute "personal information" under section 3 of the Privacy Act.
  • Whether the Privy Council Office (PCO) met its obligations under section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether PCO's amendments to the website and privacy policy were sufficient to obtain meaningful consent for data disclosure.
  • Whether PCO should have conducted a Privacy Impact Assessment (PIA) for the MyDemocracy.ca initiative.
  • Whether the collection of demographic information was justified and compliant with relevant standards.
  • Whether the use of Google Analytics complied with the Treasury Board of Canada Secretariat's (TBS) Standard on Privacy and Web Analytics.
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jul 5, 2017Early resolved case summary #2017-003Indexed Jun 30, 2026

Early resolved case summary #2017-003: Bank agrees to cease performing credit checks on individuals who are no longer clients

A bank

An individual complained that a bank performed numerous credit checks on her without consent, despite her not being a client for many years. The bank initially claimed the inquiries were from its marketing group and not visible to other organizations, but its internal investigation revealed they were 'soft hits' related to inactive accounts from 2013. The bank's privacy policy stated it retained the ability to perform credit inquiries after a service ended, but the OPC expressed concern over the continued collection of sensitive credit information without a legal requirement. To resolve the complaint, the bank agreed to cease this practice and update its privacy policy. The complainant was satisfied, and the matter was early resolved.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2017-003: Bank agrees to cease performing credit checks on individuals who are no longer clients

Jul 5, 2017Early resolved case summary #2017-003
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a bank performed numerous credit checks on her without consent, despite her not being a client for many years. The bank initially claimed the inquiries were from its marketing group and not visible to other organizations, but its internal investigation revealed they were 'soft hits' related to inactive accounts from 2013. The bank's privacy policy stated it retained the ability to perform credit inquiries after a service ended, but the OPC expressed concern over the continued collection of sensitive credit information without a legal requirement. To resolve the complaint, the bank agreed to cease this practice and update its privacy policy. The complainant was satisfied, and the matter was early resolved.

Key Issues
  • Whether a bank can continue to perform credit checks on former clients without their consent
  • Whether the bank's privacy policy adequately justified continued credit inquiries after the termination of a business relationship
  • Whether the bank provided accurate information to the complainant regarding the source and nature of the credit inquiries
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Phoenix pay system compromised Public Servants’ privacy

Public Services and Procurement Canada

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Quick view

Privacy ActWell-founded

Phoenix pay system compromised Public Servants’ privacy

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Key Issues
  • Whether personal information was at issue in the reported incidents
  • Whether the personal information at issue was improperly disclosed
  • What was the scope of the improper disclosure
  • Whether the personal information that was improperly disclosed was misused
  • Whether PSPC was aware of potential privacy issues with Phoenix before the launch
  • What kind of harm could result from the unauthorized disclosure of the personal information at issue
  • Whether PSPC resolved all of the vulnerabilities within Phoenix
  • Whether PSPC provided individuals with timely information regarding the breaches and vulnerabilities
  • Whether PSPC developed and implemented controls to monitor and document access to personal information held in Phoenix (Recommendation 1)
  • Whether PSPC developed more robust testing and response procedures (Recommendation 2)
  • Whether PSPC conducted necessary assessments to identify potential risks and vulnerabilities in Phoenix (Recommendation 3)
  • Whether PSPC took measures to mitigate the increased vulnerability of information used by employees in call centres (Recommendation 4)
  • Whether PSPC reviewed its breach notification practices and provided notification of the extent of the Phoenix breaches (Recommendation 5)
  • Whether PSPC completed the review of pages with row-level security (Recommendation 6)
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Health Canada

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Quick view

Privacy ActWell-founded

Over-collection of Personal Information of First Nations and Inuit people for the Administration of Non-Insured Health Benefits

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Health Canada alleging over-collection of personal information from First Nations and Inuit people for the Non-Insured Health Benefits (NIHB) Program. Specifically, the complaint focused on the requirement for physicians to provide diagnostic information for medical transportation and specialist services. Health Canada acknowledged that its form often led to the unintentional collection of diagnostic information not needed for claims adjudication. The OPC found that the diagnostic information collected constituted personal information and was beyond what was necessary for the NIHB Program. Consequently, the complaint was deemed well-founded, and Health Canada was asked to develop a plan for the over-collected information and to issue guidelines for future data collection.

Key Issues
  • Whether diagnostic information about individual patients constitutes 'personal information' under s.3 of the Privacy Act
  • Whether Health Canada contravened s.4 of the Privacy Act by collecting diagnostic information about patients seeking medical transportation and specialist services that was not directly related to an operating program or activity
  • Whether the collection of diagnostic information was demonstrably necessary to achieve a specific and legitimate purpose