The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

24 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014Indexed Jun 30, 2026

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

An organization

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

Commissioner’s Findings - PIPEDA Case Summary #2014-014 : Organization required to mask detailed personal-leave information available to other employees

May 19, 2015Commissioner’s Findings - PIPEDA Case Summary #2014-014
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that his employer disclosed detailed personal information about his absence from the workplace to other employees in his work unit. The organization used an electronic scheduling program that allowed all employees to view approved leave information, including the reason for absence, for all other employees in their unit. The organization argued this was necessary to facilitate shift exchanges and meet collective agreement obligations. The OPC found that the leave information was personal information and that the disclosure was not for purposes a reasonable person would consider appropriate under subsection 5(3) of PIPEDA. The OPC determined that less privacy-intrusive means existed and that the benefits of the system were not proportional to the loss of privacy. The organization agreed to remove employee leave information viewable by co-workers from its scheduling program within 18 months.

Key Issues
  • Whether the disclosed leave information constituted personal information under PIPEDA
  • Whether the organization's purposes for disclosing employee leave information to other employees were appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the disclosure of leave type was necessary for the organization to meet its employee schedule management needs
  • Whether the benefits of the leave exchange system were proportional to the loss of privacy experienced by employees
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 29, 2015Indexed Jun 30, 2026

Disclosure to Interpol raises concerns regarding electronic transmission of personal information

Canada Border Services Agency

The complainant alleged that the Canada Border Services Agency (CBSA) improperly disclosed his personal information, including a judgment from his country of origin, to the High Commission of Canada in Ghana and subsequently to Interpol, without his consent. This disclosure occurred during the verification of documents submitted for his refugee claim, which alleged persecution by the Nigerian government. The CBSA argued the disclosure was a consistent use under the Privacy Act for refugee determination and enforcement of the IRPA, necessary to verify the authenticity of the judgment after other documents were found fraudulent. The OPC found that the disclosure itself was permitted under paragraph 8(2)(a) of the Privacy Act as a consistent use for refugee determination purposes, thus concluding the primary complaint was "not well-founded." However, the OPC raised significant concerns regarding the CBSA's lack of established procedures for such verifications at the time, and the use of insecure commercial email (Yahoo!) for transmitting sensitive personal information of a refugee claimant. The OPC emphasized the inherent sensitivity of such information and the potential risk to claimants, recommending that CBSA review and strengthen its procedures, particularly concerning secure transmission methods and training. The OPC also noted it lacked jurisdiction over the actions of Interpol or Nigerian authorities.

Quick view

Privacy ActWell-founded

Disclosure to Interpol raises concerns regarding electronic transmission of personal information

Apr 29, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) improperly disclosed his personal information, including a judgment from his country of origin, to the High Commission of Canada in Ghana and subsequently to Interpol, without his consent. This disclosure occurred during the verification of documents submitted for his refugee claim, which alleged persecution by the Nigerian government. The CBSA argued the disclosure was a consistent use under the Privacy Act for refugee determination and enforcement of the IRPA, necessary to verify the authenticity of the judgment after other documents were found fraudulent. The OPC found that the disclosure itself was permitted under paragraph 8(2)(a) of the Privacy Act as a consistent use for refugee determination purposes, thus concluding the primary complaint was "not well-founded." However, the OPC raised significant concerns regarding the CBSA's lack of established procedures for such verifications at the time, and the use of insecure commercial email (Yahoo!) for transmitting sensitive personal information of a refugee claimant. The OPC emphasized the inherent sensitivity of such information and the potential risk to claimants, recommending that CBSA review and strengthen its procedures, particularly concerning secure transmission methods and training. The OPC also noted it lacked jurisdiction over the actions of Interpol or Nigerian authorities.

Key Issues
  • Whether the disclosure of the complainant's personal information (including the Judgment) by CBSA to the High Commission and Interpol without consent contravened section 8 of the Privacy Act.
  • Whether the disclosure was for a purpose consistent with the original collection under paragraph 8(2)(a) of the Privacy Act.
  • Whether CBSA's procedures for verifying documents with countries of origin and Interpol were sufficient at the time of disclosure.
  • Whether the electronic transmission of personal information via commercial email (Yahoo!) was secure and appropriate given the sensitivity.
  • Whether the OPC had jurisdiction over alleged secondary disclosures by Interpol or Nigerian authorities.
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 23, 2015PIPEDA Report of Findings #2015-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

An investment brokerage

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Report of Findings #2015-006: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 23, 2015PIPEDA Report of Findings #2015-006
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that an investment brokerage required excessive personal information, including net worth, marital status, and spouse's occupation, to open a self-directed investment account. The complainant argued this was unnecessary given the self-directed nature of the account and that the collection was a condition of service. The brokerage contended that the information was required to comply with regulatory obligations from the Investment Industry Regulatory Organization of Canada (IIROC), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and provincial securities legislation. The OPC found that the purposes for collection were properly identified and appropriate, and that the information was necessary to meet the brokerage's legal and regulatory obligations. Therefore, the OPC concluded that the complaint was not well-founded.

Key Issues
  • Whether the collection of net worth, marital status, and spouse's occupation was necessary for opening a self-directed investment account under Principle 4.4 PIPEDA
  • Whether the purposes for collecting the personal information were explicitly specified under Principle 4.2 PIPEDA
  • Whether the purposes for collecting the personal information were legitimate and appropriate under subsection 5(3) PIPEDA
  • Whether the organization required consent to the collection of information beyond that required for explicitly specified and legitimate purposes as a condition of service under Principle 4.3.3 PIPEDA
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Apr 16, 2015Indexed Jun 30, 2026

Mishandling employees’ personal information – Public Services and Procurement Canada

Public Services and Procurement Canada (PSPC)

An individual complained that Public Services and Procurement Canada (PSPC) mishandled her personal information by disclosing that she had filed a harassment complaint against her Director. The complainant alleged that the Director revealed this information during a management meeting. The investigation confirmed that the Director disclosed at a management meeting that the complainant had filed a complaint against her, as evidenced by meeting notes and confirmations from attendees. While the Director claimed the information was also her personal information, the OPC found no evidence that the employees present at the meeting needed to know the complainant's identity. The OPC concluded that PSPC did not reasonably consider the appropriateness of disclosing the complainant's identity without her consent, violating the Privacy Act.

Quick view

Privacy ActWell-founded

Mishandling employees’ personal information – Public Services and Procurement Canada

Apr 16, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Public Services and Procurement Canada (PSPC) mishandled her personal information by disclosing that she had filed a harassment complaint against her Director. The complainant alleged that the Director revealed this information during a management meeting. The investigation confirmed that the Director disclosed at a management meeting that the complainant had filed a complaint against her, as evidenced by meeting notes and confirmations from attendees. While the Director claimed the information was also her personal information, the OPC found no evidence that the employees present at the meeting needed to know the complainant's identity. The OPC concluded that PSPC did not reasonably consider the appropriateness of disclosing the complainant's identity without her consent, violating the Privacy Act.

Key Issues
  • Whether the disclosure of the complainant's identity as having filed a harassment complaint constituted personal information under s.3 of the Privacy Act
  • Whether the disclosure of the complainant's identity was made without her consent
  • Whether the disclosure was for a purpose consistent with the purpose for which the information was obtained or compiled, as per s.8(2)(a) of the Privacy Act
  • Whether the employees present at the meeting needed to know the complainant's identity
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 13, 2015PIPEDA Report of Findings #2015-007Indexed Jun 30, 2026

PIPEDA Report of Findings #2015-007: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Peoples Trust

The OPC initiated an investigation into Peoples Trust following a data breach that compromised sensitive personal information of approximately 12,000 customers. The investigation found that Peoples Trust failed to implement adequate technological and organizational safeguards, including using an outdated and vulnerable web editor and lacking ongoing monitoring. Additionally, the organization unnecessarily stored duplicate, unencrypted customer information on a web server for longer than required, contravening its retention policies. Following the OPC's intervention, Peoples Trust implemented comprehensive remedial measures, such as redesigning its web portal, enhancing monitoring, and developing a new Information Security Policy. As a result, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2015-007: Financial institution takes strong remedial measures after insufficient safeguards and unnecessary storage leaves sensitive data vulnerable to breach

Apr 13, 2015PIPEDA Report of Findings #2015-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated an investigation into Peoples Trust following a data breach that compromised sensitive personal information of approximately 12,000 customers. The investigation found that Peoples Trust failed to implement adequate technological and organizational safeguards, including using an outdated and vulnerable web editor and lacking ongoing monitoring. Additionally, the organization unnecessarily stored duplicate, unencrypted customer information on a web server for longer than required, contravening its retention policies. Following the OPC's intervention, Peoples Trust implemented comprehensive remedial measures, such as redesigning its web portal, enhancing monitoring, and developing a new Information Security Policy. As a result, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether Peoples Trust implemented adequate technological and organizational safeguards appropriate to the sensitivity of the information, as per Principle 4.7 and 4.1.4(a) PIPEDA
  • Whether Peoples Trust retained personal information for longer than necessary to fulfill its purposes, as per Principle 4.5 PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Mar 12, 2015PIPEDA findings #2015-020Indexed Jun 30, 2026

PIPEDA findings #2015-020: Hotel chain alerts its clients about “special offer” telephone scam

A major hotel chain

An individual complained after receiving a promotional phone call from a hotel chain shortly after visiting its website, suspecting the hotel linked her IP address to her phone number. The hotel chain denied making such calls or collecting her personal information, stating the call was part of a telemarketing scam by an unrelated party. The OPC's investigation confirmed the calls were indeed a scam. The complainant suggested the hotel warn its customers, which the hotel did. The matter was resolved through the OPC's early resolution process.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

PIPEDA findings #2015-020: Hotel chain alerts its clients about “special offer” telephone scam

Mar 12, 2015PIPEDA findings #2015-020
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained after receiving a promotional phone call from a hotel chain shortly after visiting its website, suspecting the hotel linked her IP address to her phone number. The hotel chain denied making such calls or collecting her personal information, stating the call was part of a telemarketing scam by an unrelated party. The OPC's investigation confirmed the calls were indeed a scam. The complainant suggested the hotel warn its customers, which the hotel did. The matter was resolved through the OPC's early resolution process.

Key Issues
  • Whether the hotel chain collected the complainant's personal information (phone number) from her website visit
  • Whether the promotional phone call originated from the hotel chain or an unrelated third party
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 3, 2015Indexed Jun 30, 2026

Accidental disclosure by Health Canada - March 3, 2015

Health Canada

The Office of the Privacy Commissioner (OPC) initiated a complaint against Health Canada (HC) after HC sent 41,514 letters to "Marihuana Medical Access Program" (MMAP) clients in windowed envelopes that allowed the program name to be openly visible. The OPC also received 339 individual complaints regarding this incident. Complainants were concerned that the visible program name revealed their association with MMAP to Canada Post employees and the public, potentially impacting their careers, reputation, and safety due to the stigma associated with marihuana. HC argued that the disclosure was implicitly consented to, was a consistent use of information, or was not an unlawful disclosure by HC. The OPC found that the combination of the MMAP name and the individual's name and address constituted sensitive personal information. HC failed to demonstrate appropriate consent or that any permissible disclosures under section 8(2) of the Privacy Act applied. The OPC concluded that HC contravened the Privacy Act.

Quick view

Privacy ActWell-founded

Accidental disclosure by Health Canada - March 3, 2015

Mar 3, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) initiated a complaint against Health Canada (HC) after HC sent 41,514 letters to "Marihuana Medical Access Program" (MMAP) clients in windowed envelopes that allowed the program name to be openly visible. The OPC also received 339 individual complaints regarding this incident. Complainants were concerned that the visible program name revealed their association with MMAP to Canada Post employees and the public, potentially impacting their careers, reputation, and safety due to the stigma associated with marihuana. HC argued that the disclosure was implicitly consented to, was a consistent use of information, or was not an unlawful disclosure by HC. The OPC found that the combination of the MMAP name and the individual's name and address constituted sensitive personal information. HC failed to demonstrate appropriate consent or that any permissible disclosures under section 8(2) of the Privacy Act applied. The OPC concluded that HC contravened the Privacy Act.

Key Issues
  • Whether the phrase "Marihuana Medical Access Program" combined with an individual's name and address constitutes personal information under section 3 of the Privacy Act
  • Whether subsequent actions by individuals (e.g., media communication) alter Health Canada's obligations under the Privacy Act
  • Whether mail recipients implicitly consented to the disclosure of their personal information under section 8(1) of the Privacy Act
  • Whether the disclosure was a "consistent use" under section 8(2)(a) of the Privacy Act
  • Whether limiting information on return address blocks would have broad implications for government communication
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 10, 2015Indexed Jun 30, 2026

Records deemed 'transitory' prematurely destroyed - February 10, 2015

Department of National Defence (DND)

A former Canadian Forces member complained that the Department of National Defence (DND) prematurely destroyed an audio recording of his Progress Review Board (PRB) hearing, thereby contravening the retention and disposal provisions of the Privacy Act. The complainant argued that the recording was personal information used for an administrative purpose and should have been retained for a reasonable period to allow him access. DND contended the recording was a "transitory" record, destroyed after minutes were drafted, and that the complainant had implicitly consented to its disposal by signing the minutes. The OPC found that the audio recording contained personal information used for an administrative purpose and that the complainant had not consented to its disposal. Therefore, DND was obligated to retain the recording for at least two years.

Quick view

Privacy ActWell-founded

Records deemed 'transitory' prematurely destroyed - February 10, 2015

Feb 10, 2015
Adjudicator: Daniel Therrien
Plain-Language Summary

A former Canadian Forces member complained that the Department of National Defence (DND) prematurely destroyed an audio recording of his Progress Review Board (PRB) hearing, thereby contravening the retention and disposal provisions of the Privacy Act. The complainant argued that the recording was personal information used for an administrative purpose and should have been retained for a reasonable period to allow him access. DND contended the recording was a "transitory" record, destroyed after minutes were drafted, and that the complainant had implicitly consented to its disposal by signing the minutes. The OPC found that the audio recording contained personal information used for an administrative purpose and that the complainant had not consented to its disposal. Therefore, DND was obligated to retain the recording for at least two years.

Key Issues
  • Whether the audio recording contained the complainant's "personal information" as defined by the Act
  • Whether the personal information in the audio recording was used for an "administrative purpose"
  • Whether the complainant consented to the disposal of the information
  • Whether DND's classification of the recording as "transitory" exempted it from Privacy Act retention requirements
Federal (Canada)Personal Information Protection and Electronic Documents ActEarly-resolved
Federal (Canada) flag
Jan 21, 2015Early resolved case summary #2015-03Indexed Jun 30, 2026

Early resolved case summary #2015-03: Office building tenant reconsiders placement of video surveillance cameras

An office building tenant (call centre company)

An office building tenant complained about five video surveillance cameras installed in a shared common area by another tenant, a call centre company. The complainant found it disturbing that the cameras recorded his and his clients' movements, particularly two cameras positioned between his office, the washrooms, and the elevators. The installing tenant claimed the cameras were for safety following a security incident and that building management had authorized their installation. After the OPC became involved, the building management facilitated the relocation of the two most concerning cameras from the shared hallway into the installing tenant's offices. The complainant expressed satisfaction that his and his clients' privacy rights were now respected. The case was resolved early.

Quick view

Personal Information Protection and Electronic Documents ActEarly-resolved

Early resolved case summary #2015-03: Office building tenant reconsiders placement of video surveillance cameras

Jan 21, 2015Early resolved case summary #2015-03
Adjudicator: Daniel Therrien
Plain-Language Summary

An office building tenant complained about five video surveillance cameras installed in a shared common area by another tenant, a call centre company. The complainant found it disturbing that the cameras recorded his and his clients' movements, particularly two cameras positioned between his office, the washrooms, and the elevators. The installing tenant claimed the cameras were for safety following a security incident and that building management had authorized their installation. After the OPC became involved, the building management facilitated the relocation of the two most concerning cameras from the shared hallway into the installing tenant's offices. The complainant expressed satisfaction that his and his clients' privacy rights were now respected. The case was resolved early.

Key Issues
  • Whether the installation of video surveillance cameras in a shared common area by one tenant infringed on the privacy of another tenant and their clients
  • Whether the collection of personal information via video surveillance was appropriate and proportionate to the stated safety purpose
  • Whether consent was obtained for the video surveillance