The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

16 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 30, 2019Indexed Jun 30, 2026

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Department of National Defence and Department of Justice

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Quick view

Privacy ActNot well-founded

Disclosure of military officer’s personal information for litigation purposes permissible under the Privacy Act

Dec 30, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A military officer complained that the Department of National Defence (DND) inappropriately disclosed his personal medical information to the Department of Justice (DOJ), and that the DOJ inappropriately collected it, for litigation purposes. The complainant had initiated a lawsuit against DND, naming the Attorney General of Canada as respondent. DND disclosed the information, including physical and mental health files, to the DOJ in response to a document collection order for defending against the lawsuit. The OPC found that both the collection by DOJ and disclosure by DND were permissible under the Privacy Act, specifically paragraph 8(2)(d), as the disclosure was to the Attorney General for use in legal proceedings involving the Government of Canada. The OPC also noted that the Act makes no distinction based on the sensitivity of personal information and that doctor-patient confidentiality is not a general privilege in Canadian law. Both complaints were found to be not well-founded.

Key Issues
  • Whether the collection of the complainant's personal medical information by the DOJ from the DND contravened the Privacy Act
  • Whether the disclosure of the complainant's personal medical information by the DND to the DOJ contravened the Privacy Act
  • Whether the collection by DOJ related directly to an operating program or activity of the institution under s.4 of the Privacy Act
  • Whether the collection by DOJ was permissible under s.5(1) of the Privacy Act given the disclosure under s.8(2)(d)
  • Whether the disclosure by DND was to the Attorney General of Canada under s.8(2)(d) of the Privacy Act
  • Whether the disclosure by DND was for use in legal proceedings involving the Crown in right of Canada or the Government of Canada under s.8(2)(d) of the Privacy Act
  • Whether the sensitivity of medical information impacts the permissibility of disclosure under the Privacy Act
  • Whether doctor-patient confidentiality prevents disclosure under the Privacy Act for litigation purposes
  • Whether the safeguarding measures for the disclosed information were adequate
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Dec 9, 2019PIPEDA Findings #2019-007Indexed Jun 30, 2026

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Trans Union of Canada, Inc.

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2019-007: Credit reporting agency is authorized to rely on exemption to consent in disclosing credit information to Statistics Canada

Dec 9, 2019PIPEDA Findings #2019-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that TransUnion disclosed his credit file information to Statistics Canada without consent, and that this information was subsequently used for debt collection. TransUnion argued that it was authorized to disclose the information under PIPEDA paragraph 7(3)(i) because the disclosure was required by law, specifically section 13 of the Statistics Act. The OPC found that TransUnion was authorized to disclose the information under PIPEDA subparagraph 7(3)(c.1)(iii), as Statistics Canada had identified its lawful authority and the disclosure was for administering the Statistics Act. The OPC also found no evidence that Statistics Canada disclosed the complainant's information for debt collection purposes. Therefore, the complaint was deemed not well-founded.

Key Issues
  • Whether TransUnion disclosed the complainant's credit file information to Statistics Canada without requisite consent
  • Whether TransUnion was authorized to disclose personal information without consent under PIPEDA subparagraph 7(3)(c.1)(iii)
  • Whether Statistics Canada identified its lawful authority to obtain the information
  • Whether the disclosure was requested to administer a law of Canada (the Statistics Act)
  • Whether Statistics Canada subsequently disclosed the complainant's credit file information to other government institutions for debt collection
  • Whether there was sufficient evidence to support the allegation of information misuse for debt collection
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Dec 9, 2019Statistics CanadaIndexed Jun 30, 2026

Statistics Canada: Invasive data initiatives should be redesigned with privacy in mind

Statistics Canada

The Office of the Privacy Commissioner of Canada (OPC) investigated over a hundred complaints against Statistics Canada concerning its Credit Information Project and Financial Transactions Project. These initiatives involved collecting detailed personal information from a credit bureau (TransUnion) and financial institutions without individuals' direct knowledge or consent. The OPC found that Statistics Canada had the legal authority under section 13 of the Statistics Act to collect information for the Credit Information Project, as TransUnion provided existing records, thus deeming this aspect of the complaints not well-founded. However, the OPC had serious concerns that the Financial Transactions Project, as originally designed, would have exceeded this authority by requiring financial institutions to create new records; no formal finding was made as the project was halted. While no contravention of the Privacy Act was found, the OPC identified significant privacy concerns regarding the necessity and proportionality of both projects, Statistics Canada's lack of transparency, and deficiencies in internal monitoring safeguards. Statistics Canada committed to implementing all six OPC recommendations, including redesigning both projects with privacy principles in mind, increasing transparency, and enhancing internal security measures. The OPC also called for legislative reform of the Statistics Act and Privacy Act to address modern data collection practices.

Quick view

Privacy ActNot well-founded

Statistics Canada: Invasive data initiatives should be redesigned with privacy in mind

Dec 9, 2019Statistics Canada
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated over a hundred complaints against Statistics Canada concerning its Credit Information Project and Financial Transactions Project. These initiatives involved collecting detailed personal information from a credit bureau (TransUnion) and financial institutions without individuals' direct knowledge or consent. The OPC found that Statistics Canada had the legal authority under section 13 of the Statistics Act to collect information for the Credit Information Project, as TransUnion provided existing records, thus deeming this aspect of the complaints not well-founded. However, the OPC had serious concerns that the Financial Transactions Project, as originally designed, would have exceeded this authority by requiring financial institutions to create new records; no formal finding was made as the project was halted. While no contravention of the Privacy Act was found, the OPC identified significant privacy concerns regarding the necessity and proportionality of both projects, Statistics Canada's lack of transparency, and deficiencies in internal monitoring safeguards. Statistics Canada committed to implementing all six OPC recommendations, including redesigning both projects with privacy principles in mind, increasing transparency, and enhancing internal security measures. The OPC also called for legislative reform of the Statistics Act and Privacy Act to address modern data collection practices.

Key Issues
  • Whether Statistics Canada's collection of personal information for the Credit Information Project was within its legal authority under section 13 of the Statistics Act.
  • Whether Statistics Canada's proposed collection of personal information for the Financial Transactions Project, as originally designed, would have been within its legal authority under section 13 of the Statistics Act.
  • Whether the collection of personal information for the Credit Information Project related directly to an operating program or activity of Statistics Canada under section 4 of the Privacy Act.
  • Whether the collection of personal information for the Financial Transactions Project related directly to an operating program or activity of Statistics Canada under section 4 of the Privacy Act.
  • Whether the Credit Information Project, as originally designed, met the principles of necessity and proportionality.
  • Whether the Financial Transactions Project, as originally designed, met the principles of necessity and proportionality.
  • Whether Statistics Canada provided adequate transparency to individuals regarding the collection of their personal information for the Projects.
  • Whether Statistics Canada had appropriate safeguards, specifically regarding logging and monitoring for internal unauthorized access, to protect personal information collected via the Projects.
  • Whether Statistics Canada's de-identification and encryption safeguards were adequate.
  • Whether Statistics Canada had proper procedures for individuals to access their personal information.
  • Whether there was a risk of personal information collected via the Projects being disclosed for secondary purposes.
  • Whether Statistics Canada's Directive on Discretionary Disclosures adequately considered individuals' privacy interests when making disclosures under section 17(2)(a) of the Statistics Act.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Nov 26, 2019PIPEDA Findings #2019-004Indexed Jun 30, 2026

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

AggregateIQ Data Services Ltd.

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-004: Joint investigation of AggregateIQ Data Services Ltd. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Nov 26, 2019PIPEDA Findings #2019-004
Adjudicator: Daniel Therrien
Plain-Language Summary

This joint investigation by the OPC and OIPC BC examined AggregateIQ Data Services Ltd. (AIQ), a BC-based company providing data services to political campaigns globally, for its compliance with PIPEDA and PIPA. The investigation focused on AIQ's consent practices for collecting, using, and disclosing personal information, and its security safeguards. The Commissioners found that AIQ failed to ensure adequate consent for its work with SCL Elections (US campaigns), Vote Leave (Brexit), and some Canadian campaigns, particularly regarding the use of sensitive information and disclosure to social media platforms for targeted advertising and analytics. They also found that AIQ failed to implement reasonable security measures, leading to a data breach that exposed login credentials and put the personal information of 35 million people at risk. While the security issue was resolved through AIQ's remedial actions, the overall matter was deemed well-founded-conditionally-resolved as AIQ committed to implementing recommendations regarding consent verification and data deletion, with a follow-up planned.

Key Issues
  • Whether AIQ was compliant with consent requirements for the collection, use, or disclosure of personal information under PIPEDA and PIPA.
  • Whether AIQ could rely on consent obtained by its clients for its own collection, use, and disclosure of personal information.
  • Whether consent was adequate for specific uses, such as disclosing personal information to Facebook for "custom audiences" and "lookalike audiences."
  • Whether consent was adequate for sensitive personal information, such as political opinions or psychographic profiles.
  • Whether AIQ took reasonable security measures to protect the personal information in its custody or control under PIPEDA and PIPA.
  • Whether the security breach involving the GitLab repository constituted a failure of reasonable security measures.
  • Whether personal information collected from public telephone directories required consent.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 21, 2019Indexed Jun 30, 2026

Crossing the line? The CBSA’s examination of digital devices at the border

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Quick view

Privacy ActWell-founded

Crossing the line? The CBSA’s examination of digital devices at the border

Oct 21, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated six complaints against the Canada Border Services Agency (CBSA) regarding the examination of personal digital devices at ports of entry. Complainants, all Canadian citizens, questioned the CBSA's authority to conduct these searches. The OPC found that the CBSA contravened section 4 of the Privacy Act by exceeding its legal authority in one case (accessing online banking/social media) and section 6(1) by destroying records in two cases. Systemic issues were identified, including BSOs failing to follow CBSA's own policy on disabling internet connectivity, note-taking, and search thresholds. The OPC concluded all six complaints were well-founded and made several recommendations for operational changes and legislative reform. The CBSA accepted the operational recommendations, committing to new policies, mandatory training, oversight, and transparency, but disagreed with the legislative reform recommendations. Consequently, the operational issues are considered conditionally resolved.

Key Issues
  • Whether CBSA's collection of personal information via digital device searches contravened section 4 of the Privacy Act.
  • Whether the definition of "goods" under the Customs Act extends to electronic documents on digital devices.
  • Whether CBSA's authority to search digital devices is limited to information stored on the device.
  • Whether Border Services Officers (BSOs) complied with CBSA's internal policy (Operational Bulletin PRG-2015-31) regarding digital device examinations (e.g., airplane mode, note-taking, search threshold).
  • Whether the copying of content from a digital device by a BSO was consistent with CBSA's legal authority and policy.
  • Whether the CBSA complied with its obligations under subsection 6(1) of the Privacy Act to retain personal information used for administrative purposes.
  • Whether the CBSA's practices regarding training, awareness, and accountability mechanisms for digital device searches were adequate.
  • Whether the Customs Act requires amendment to include a clear legal framework and a higher threshold for digital device examinations.
  • Whether the threshold for digital device examinations should be "reasonable grounds to suspect".
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Oct 16, 2019PIPEDA Findings #2019-003Indexed Jun 30, 2026

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Loblaw Companies Ltd.

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2019-003: Investigation into authentication and transfer practices used during Loblaw gift card offering

Oct 16, 2019PIPEDA Findings #2019-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Loblaw collected more personal information than necessary for its $25 gift card program and was concerned about data transfers to a US-based third party. Loblaw requested ID (utility bill or driver's license) from some registrants to verify eligibility and prevent fraud, but initially failed to specify that only name and address were needed and other information could be redacted. The OPC found that Loblaw initially over-collected information under Principle 4.4, but this issue was resolved when Loblaw clarified its requirements. Regarding the cross-border transfer of data to a US Program Administrator, the OPC found that Loblaw had sufficient contractual safeguards in place to ensure a comparable level of protection (Principle 4.1.3) and was transparent about these transfers (Principle 4.8). No additional consent was required for the transfer of name and address information, as it was for the original purpose. The complaint was found well-founded and resolved for over-collection, and not well-founded for the data transfer issues.

Key Issues
  • Whether Loblaw collected more personal information than necessary for the Loblaw Card Program (Principle 4.4)
  • Whether Loblaw ensured a comparable level of protection for personal information transferred to a third party for processing (Principle 4.1.3)
  • Whether Loblaw was required to obtain additional consent for the transfer of personal information for processing (Principle 4.3)
  • Whether Loblaw was sufficiently open and transparent about its cross-border data transfers (Principle 4.8)
Federal (Canada)Access to Information Acts.6.1 Application Denied (must respond)
Federal (Canada) flag
Aug 1, 20192019 OIC 1Indexed Jun 30, 2026

Decision pursuant to 6.1, 2019 OIC 1

A federal institution

A federal institution applied to the Information Commissioner for approval to decline to act on an access request, alleging it was vexatious, an abuse of the right of access, and made in bad faith. The institution claimed the request was vague, repetitive, involved abusive language from the requester, and raised safety concerns. The Commissioner found the request sufficiently clear and noted no evidence of prior disclosure for repetitive claims. The Commissioner also determined that the provided examples did not establish abusive language or a link between safety concerns and the access request. Regarding abuse of right, the institution cited an increase in requests and processing time due to the requester, but failed to show how this diminished other requesters' rights or impacted its other duties. Finally, the Commissioner found no evidence of bad faith, stating that pursuing legal remedies, even for an alleged unjust dismissal, does not equate to bad faith in making an access request. The Commissioner also noted the institution did not demonstrate it fulfilled its duty to assist the requester. Consequently, the application was denied, and the institution was ordered to process the request.

Quick view

Access to Information Acts.6.1 Application Denied (must respond)

Decision pursuant to 6.1, 2019 OIC 1

Aug 1, 20192019 OIC 1
Adjudicator: Caroline Maynard
Plain-Language Summary

A federal institution applied to the Information Commissioner for approval to decline to act on an access request, alleging it was vexatious, an abuse of the right of access, and made in bad faith. The institution claimed the request was vague, repetitive, involved abusive language from the requester, and raised safety concerns. The Commissioner found the request sufficiently clear and noted no evidence of prior disclosure for repetitive claims. The Commissioner also determined that the provided examples did not establish abusive language or a link between safety concerns and the access request. Regarding abuse of right, the institution cited an increase in requests and processing time due to the requester, but failed to show how this diminished other requesters' rights or impacted its other duties. Finally, the Commissioner found no evidence of bad faith, stating that pursuing legal remedies, even for an alleged unjust dismissal, does not equate to bad faith in making an access request. The Commissioner also noted the institution did not demonstrate it fulfilled its duty to assist the requester. Consequently, the application was denied, and the institution was ordered to process the request.

Key Issues
  • Whether the access request was vexatious due to vagueness
  • Whether the access request was vexatious due to repetitiveness
  • Whether the access request was vexatious due to abusive language from the requester
  • Whether the access request was vexatious due to safety concerns
  • Whether the access request amounted to an abuse of the right to make a request for records
  • Whether the access request was made in bad faith
  • Whether the institution fulfilled its duty to assist the requester under subsection 4(2.1) ATIA
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jun 9, 2019Indexed Jun 30, 2026

Video recording in the workplace at correctional institutions consistent with the Privacy Act

Correctional Service Canada (CSC)

Three complaints alleged that Correctional Service Canada (CSC) improperly used video footage, collected for security, to monitor employee performance. The complainants provided emails from a correctional manager commenting on their patrols as evidence. CSC acknowledged using video for security and incident investigation but denied using it for performance monitoring. The OPC found that CSC reviewed the footage to identify systemic deficiencies in patrols following an inmate's death, aiming to improve security and prevent future deaths. The review was part of an action plan to address deficiencies identified in the death investigation. The OPC concluded that this use was consistent with the original purpose of collection, which was security, and therefore the complaints were not well-founded.

Quick view

Privacy ActNot well-founded

Video recording in the workplace at correctional institutions consistent with the Privacy Act

Jun 9, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

Three complaints alleged that Correctional Service Canada (CSC) improperly used video footage, collected for security, to monitor employee performance. The complainants provided emails from a correctional manager commenting on their patrols as evidence. CSC acknowledged using video for security and incident investigation but denied using it for performance monitoring. The OPC found that CSC reviewed the footage to identify systemic deficiencies in patrols following an inmate's death, aiming to improve security and prevent future deaths. The review was part of an action plan to address deficiencies identified in the death investigation. The OPC concluded that this use was consistent with the original purpose of collection, which was security, and therefore the complaints were not well-founded.

Key Issues
  • Whether video footage of employees constitutes personal information under s.3 of the Privacy Act
  • Whether CSC's use of video footage to review employee patrols constituted monitoring employee performance
  • Whether CSC's use of video footage was for the purpose for which it was obtained or compiled, or for a use consistent with that purpose, as per s.7(a) of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Apr 25, 2019PIPEDA Findings #2019-002Indexed Jun 30, 2026

PIPEDA Findings #2019-002: Joint investigation of Facebook, Inc. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Facebook, Inc.

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) conducted a joint investigation into Facebook, Inc.'s compliance with PIPEDA and PIPA following revelations about the "thisisyourdigitallife" (TYDL) app and its data sharing with Cambridge Analytica. The investigation focused on Facebook's consent practices for both installing users and their friends, its data safeguards, and its overall accountability. The OPC found that Facebook failed to obtain meaningful consent from users for the disclosure of their personal information to third-party apps, including the TYDL app, and that its safeguards against unauthorized access and use were inadequate. Furthermore, Facebook was deemed to have abdicated its responsibility for user information, demonstrating a lack of accountability. Despite recommendations from the OPC, Facebook rejected or refused to implement them, leading to a finding that the complaint was well-founded and remains unresolved. The OPC stated it would pursue further action under its authorities.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Findings #2019-002: Joint investigation of Facebook, Inc. by the Privacy Commissioner of Canada and the Information and Privacy Commissioner for British Columbia

Apr 25, 2019PIPEDA Findings #2019-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) conducted a joint investigation into Facebook, Inc.'s compliance with PIPEDA and PIPA following revelations about the "thisisyourdigitallife" (TYDL) app and its data sharing with Cambridge Analytica. The investigation focused on Facebook's consent practices for both installing users and their friends, its data safeguards, and its overall accountability. The OPC found that Facebook failed to obtain meaningful consent from users for the disclosure of their personal information to third-party apps, including the TYDL app, and that its safeguards against unauthorized access and use were inadequate. Furthermore, Facebook was deemed to have abdicated its responsibility for user information, demonstrating a lack of accountability. Despite recommendations from the OPC, Facebook rejected or refused to implement them, leading to a finding that the complaint was well-founded and remains unresolved. The OPC stated it would pursue further action under its authorities.

Key Issues
  • Whether the OPC and OIPC BC had jurisdiction to investigate the matter.
  • Whether Facebook's provision of access to personal information via its Graph API constitutes a "disclosure" under PIPEDA.
  • Whether Facebook obtained valid and meaningful consent from installing users for the disclosure of their personal information to third-party apps, including the TYDL App.
  • Whether Facebook made reasonable efforts to ensure third-party apps obtained meaningful consent from installing users.
  • Whether Facebook's reliance on overbroad and conflicting language in its privacy communications was sufficient for meaningful consent from installing users.
  • Whether Facebook obtained meaningful consent from friends of installing users (Affected Users) for the disclosure of their personal information to third-party apps.
  • Whether Facebook had adequate safeguards to protect user information against unauthorized access, use, and disclosure by apps.
  • Whether Facebook's monitoring and enforcement of its Platform Policy were adequate.
  • Whether Facebook's implementation of Graph v2 and App Review adequately addressed safeguard concerns for ongoing compliance.
  • Whether Facebook was accountable for the user information under its control.
  • Whether Facebook's policies and practices gave effect to the privacy principles under PIPEDA and PIPA.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Apr 9, 2019PIPEDA Findings #2019-001Indexed Jun 30, 2026

PIPEDA Findings #2019-001: Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information

Equifax Canada Co.

The Office of the Privacy Commissioner of Canada (OPC) investigated a 2017 data breach that compromised the personal information of approximately 19,000 Canadians held by Equifax Inc., the US parent company of Equifax Canada Co. The investigation examined the adequacy of security safeguards by both entities, Equifax Canada's accountability for data processed by Equifax Inc., the validity of consent obtained for data transfers, retention practices, and the sufficiency of post-breach mitigation measures. The OPC concluded that both Equifax Inc. and Equifax Canada contravened PIPEDA in all these areas, citing inadequate vulnerability management, network segregation, basic information security practices, and oversight. Equifax Canada signed a compliance agreement, committing to corrective measures for most findings, which were deemed well-founded and conditionally resolved. However, the finding regarding post-breach safeguards was only partially resolved, as Equifax Canada committed to extended credit monitoring but not a free credit freeze product.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-001: Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information

Apr 9, 2019PIPEDA Findings #2019-001
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a 2017 data breach that compromised the personal information of approximately 19,000 Canadians held by Equifax Inc., the US parent company of Equifax Canada Co. The investigation examined the adequacy of security safeguards by both entities, Equifax Canada's accountability for data processed by Equifax Inc., the validity of consent obtained for data transfers, retention practices, and the sufficiency of post-breach mitigation measures. The OPC concluded that both Equifax Inc. and Equifax Canada contravened PIPEDA in all these areas, citing inadequate vulnerability management, network segregation, basic information security practices, and oversight. Equifax Canada signed a compliance agreement, committing to corrective measures for most findings, which were deemed well-founded and conditionally resolved. However, the finding regarding post-breach safeguards was only partially resolved, as Equifax Canada committed to extended credit monitoring but not a free credit freeze product.

Key Issues
  • Whether Equifax Inc.'s security safeguards were appropriate to the sensitivity of the information as required by PIPEDA Safeguards Principle 4.7.
  • Whether Equifax Inc.'s retention and destruction practices for Canadian personal information complied with PIPEDA Principle 4.5.
  • Whether Equifax Canada demonstrated adequate accountability for protecting Canadian personal information handled by Equifax Inc. as required under PIPEDA Principle 4.1.
  • Whether there was adequate consent from Canadians for the collection of their personal information by Equifax Inc. and disclosure to Equifax Inc. by Equifax Canada, as required under PIPEDA Principle 4.3 and s.6.1.
  • Whether Equifax Canada's security safeguards for personal information it held directly were appropriate as required by PIPEDA Safeguards Principle 4.7.
  • Whether the post-breach mitigation measures offered by Equifax Canada were adequate to protect against unauthorized use of compromised personal information as required by PIPEDA Safeguards Principle 4.7.1.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 29, 2019Indexed Jun 30, 2026

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Global Affairs Canada

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Quick view

Privacy ActWell-founded

Global Affairs Canada fails to demonstrate its authority to collect the personal information contained in diplomatic passports

Mar 29, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

A Global Affairs Canada (GAC) employee complained that GAC contravened the Privacy Act by requesting the return of his diplomatic passport, which contained personal travel information, for an administrative investigation. The complainant argued that GAC's policy required him to use the diplomatic passport for both personal and work travel while posted abroad, and returning it would lead to an improper collection of his personal information. GAC contended that the diplomatic passport is government property and it had the authority to collect the information for an investigation into alleged misconduct. The OPC found that GAC failed to demonstrate how the personal travel history related directly to an operating program or activity, as required by the Privacy Act. Although no collection occurred because the complainant refused to return the passport, the OPC concluded that GAC lacked the authority to collect such personal information. The complaint was deemed well-founded, and the OPC recommended GAC clarify its policies and inform diplomatic passport users of the privacy implications.

Key Issues
  • Whether the information in the diplomatic passport constitutes personal information under s.3 of the Privacy Act
  • Whether Global Affairs Canada's request for the diplomatic passport constituted a collection of personal information
  • Whether Global Affairs Canada demonstrated its authority to collect the personal travel information under s.4 of the Privacy Act
  • Whether the collection of personal travel information related directly to an operating program or activity of Global Affairs Canada
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 28, 2019PIPEDA Case Summary #2019-006Indexed Jun 30, 2026

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Grey House Publishing Canada

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2019-006: Directory company lacked consent to publish complainant's personal information

Mar 28, 2019PIPEDA Case Summary #2019-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that Grey House Publishing Canada (Grey House) collected, used, and disclosed his personal information without consent by publishing it in its directories and selling it to Economic and Social Development Canada (ESDC) for email distribution. Grey House argued the information was business contact information, not personal information, and that its activities were not commercial. The OPC found the information was personal information and Grey House's activities were commercial. The OPC determined Grey House did not obtain adequate consent, as the publicly available information exceptions did not apply and the complainant could not have reasonably expected such use. The OPC also found Grey House's privacy statement contravened the openness principle. Grey House removed the complainant's information and agreed to revise its privacy statement.

Key Issues
  • Whether the complainant's contact information constituted 'personal information' under PIPEDA
  • Whether Grey House Publishing Canada was engaged in 'commercial activity' under PIPEDA
  • Whether Grey House obtained adequate consent for the collection, use, and disclosure of the complainant's personal information
  • Whether the 'publicly available information' exceptions to consent applied
  • Whether Grey House's privacy statement met the 'openness' principle under PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 28, 2019Indexed Jun 30, 2026

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Employment and Social Development Canada (ESDC)

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Quick view

Privacy ActWell-founded

Employment and Social Development Canada collects personal information again despite the complainant’s previous objection

Mar 28, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Employment and Social Development Canada (ESDC) improperly collected his personal information a second time, despite his previous objection, through Grey House Publishing Canada for the Prime Minister’s Volunteer Awards program. ESDC maintained that it acquired the distribution list compliantly, relying on its contract with Grey House which stipulated compliance with Canadian legislation and consent. The OPC found that while ESDC was not required to collect the information directly for administrative purposes, it failed to ensure Grey House obtained proper consent as per their contract and continued to collect the complainant's information despite his explicit request to be removed. The OPC concluded that ESDC did not comply with section 4 of the Privacy Act.

Key Issues
  • Whether the complainant's name, telephone number, and email address constitute personal information under the Act
  • Whether ESDC was required to collect personal information directly from the complainant under section 5 of the Act
  • Whether ESDC complied with section 4 of the Act regarding the collection of personal information
  • Whether ESDC adequately ensured Grey House Publishing Canada complied with consent requirements as per their contract
  • Whether ESDC improperly collected the complainant's information after he requested removal from the distribution list
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 25, 2019PIPEDA Findings #2019-005Indexed Jun 30, 2026

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

411Numbers

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2019-005: 411Numbers ceases practice of removing information for a fee

Mar 25, 2019PIPEDA Findings #2019-005
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint concerned 411Numbers, an operator of websites providing free access to telephone numbers and associated information, including unlisted numbers, and formerly charging a fee for removal. The complainant alleged collection without consent, use for an inappropriate purpose (paid removal), over-collection of information for removal services, and unresponsiveness to privacy queries. The OPC asserted jurisdiction over 411Numbers due to a 'real and substantial connection' to Canada, despite its Hong Kong incorporation. The OPC found that 411Numbers contravened Principle 4.3 by publishing unlisted numbers without consent, as they are not 'publicly available' under the Regulations. The practice of charging for removal ceased during the investigation, resolving that aspect, though the OPC noted it would likely be an inappropriate purpose. The OPC also found contraventions of Principle 4.3.3 for over-collecting identification for removal requests and Principles 4.1, 4.1.2, 4.1.4, 4.8, and 4.10 regarding accountability, openness, and challenging compliance. Based on 411Numbers' commitments to remove unlisted data, improve due diligence, and enhance its privacy practices, the matter was deemed well-founded and conditionally resolved.

Key Issues
  • Whether the OPC had jurisdiction over 411Numbers, a Hong Kong-incorporated company with servers outside Canada, due to a 'real and substantial connection' to Canada.
  • Whether 411Numbers collected, used, and disclosed the complainant's personal information (unlisted phone number, name, address) without knowledge and consent, contravening Principle 4.3.
  • Whether information associated with unlisted telephone numbers constitutes 'publicly available' information under paragraph 1(a) of the Regulations Specifying Publicly Available Information.
  • Whether 411Numbers exercised due diligence to ensure its databases did not include unlisted numbers.
  • Whether publishing personal information for the purpose of encouraging individuals to pay to have it removed constitutes an inappropriate purpose under s. 5(3) of PIPEDA.
  • Whether 411Numbers required individuals to provide more information than necessary for removal services, contravening Principle 4.3.3.
  • Whether 411Numbers met its obligations regarding accountability under Principles 4.1, 4.1.2, and 4.1.4.
  • Whether 411Numbers met its obligations regarding openness under Principle 4.8 and 4.8.3.
  • Whether 411Numbers met its obligations regarding challenging compliance under Principle 4.10.
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 11, 2019Indexed Jun 30, 2026

The name of an individual is considered personal information if it is accompanied by information that is about the individual

Canadian Transportation Agency (CTA)

The complainant, an air passenger rights advocate, requested access to all records about himself held by the Canadian Transportation Agency (CTA). The CTA initially withheld 760 pages, arguing that most references to the complainant's name were not personal information because he was acting on behalf of an organization. The OPC found that the information was indeed personal information, as the organization was not a separate legal entity and the records contained views and information directly about the complainant. The OPC also found that the CTA incorrectly applied exemptions under section 26 (third-party personal information) and subsection 70(1) (cabinet confidences) in some instances, and over-redacted under section 27 (solicitor-client privilege). The complaint was found to be well-founded, and the CTA agreed to implement the OPC's recommendations to disclose the withheld information.

Quick view

Privacy ActWell-founded

The name of an individual is considered personal information if it is accompanied by information that is about the individual

Feb 11, 2019
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, an air passenger rights advocate, requested access to all records about himself held by the Canadian Transportation Agency (CTA). The CTA initially withheld 760 pages, arguing that most references to the complainant's name were not personal information because he was acting on behalf of an organization. The OPC found that the information was indeed personal information, as the organization was not a separate legal entity and the records contained views and information directly about the complainant. The OPC also found that the CTA incorrectly applied exemptions under section 26 (third-party personal information) and subsection 70(1) (cabinet confidences) in some instances, and over-redacted under section 27 (solicitor-client privilege). The complaint was found to be well-founded, and the CTA agreed to implement the OPC's recommendations to disclose the withheld information.

Key Issues
  • Whether information relating to the complainant's advocacy activities, where his name appears, constitutes personal information under section 3 of the Privacy Act
  • Whether the CTA correctly invoked paragraph 12(1)(b) to deny access to information it deemed not to be personal information
  • Whether the CTA correctly withheld third-party personal information under section 26 of the Privacy Act
  • Whether the CTA correctly withheld information under section 27 of the Privacy Act (solicitor-client privilege)
  • Whether the CTA correctly withheld information under subsection 70(1) of the Privacy Act (cabinet confidences)