The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

21 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 19, 2016Incident Summary #11Indexed Jun 30, 2026

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

A financial institution

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

Feb 19, 2016Incident Summary #11
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Key Issues
  • Whether the financial institution adequately safeguarded personal information during mass mail-outs
  • Whether the financial institution responded appropriately to a privacy breach involving misdirected mail
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 12, 2016PIPEDA Report of Findings #2016-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

An insurance company

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-006: An insurance company’s internal ombudsman office is not a “formal dispute resolution process” under PIPEDA

Feb 12, 2016PIPEDA Report of Findings #2016-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that an insurance company refused to provide her with access to her personal information related to an insurance claim and a subsequent complaint to the company's internal ombudsman. The company initially refused access to a recorded conversation, citing the need for her spouse's consent, and later withheld documents from the ombudsman process, arguing it was a "formal dispute resolution process" exempt under PIPEDA s.9(3)(d) and not a "commercial activity." The OPC found that the company contravened Principles 4.9 and 4.9.1 by initially refusing access to the recorded conversation without severing third-party information. The OPC also determined that the internal ombudsman process was not a "formal dispute resolution process" and that its activities were part of a "commercial activity," thus falling under PIPEDA's scope. The company ultimately agreed to provide the complainant with access to the withheld information.

Key Issues
  • Whether the insurance company contravened Principles 4.9 and 4.9.1 by refusing access to personal information without severing third-party information
  • Whether the insurance company's internal ombudsman office constitutes a "formal dispute resolution process" under PIPEDA s.9(3)(d)
  • Whether the activities of the internal ombudsman office fall under the definition of "commercial activity" under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 9, 2016PIPEDA Case Summary #2016-007Indexed Jun 30, 2026

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

A collection agency

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-007: An organization's privacy policy and procedures must be implemented effectively

Feb 9, 2016PIPEDA Case Summary #2016-007
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that a collection agency repeatedly refused to provide access to their personal information, despite multiple written requests. The individual was disputing a debt the agency was attempting to collect and sought information related to the alleged debt account. The OPC found that the agency failed to respond to several of the individual's access requests, contravening PIPEDA subsections 8(3) and 8(5), and Principle 4.9. Although the agency eventually provided the information during the investigation, the OPC noted that the agency had not followed its own privacy procedures for handling access requests. The agency committed to revising its procedures and providing refresher training to its employees. The complaint was deemed well-founded and resolved.

Key Issues
  • Whether the organization refused to provide access to personal information
  • Whether the organization responded to access requests within the required timeframe
  • Whether the organization followed its own privacy policies and procedures for access requests
  • Whether the organization maintained records of access request processing
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Feb 8, 2016Indexed Jun 30, 2026

Canada Post collection of online signatures for mail tracking draws complaint

Canada Post Corporation

A complaint was filed against Canada Post Corporation (CPC) regarding its collection, use, and disclosure of electronic signatures for parcel tracking. The complainant raised concerns about the clarity of information provided to addressees regarding their option to opt-out of having their signature displayed online, and the absence of labels on signature devices at a specific postal outlet. The investigation also examined the privacy and security controls of CPC's online tracking website. CPC argued that disclosure of signatures to senders was authorized under the Privacy Act and that it provided an opt-out option. The OPC found that the collection and disclosure of signatures for parcel tracking were consistent with the Act, but raised concerns about the adequacy of security controls for online signatures. CPC committed to implementing enhanced security measures.

Quick view

Privacy ActNot well-founded

Canada Post collection of online signatures for mail tracking draws complaint

Feb 8, 2016
Adjudicator: Daniel Therrien
Plain-Language Summary

A complaint was filed against Canada Post Corporation (CPC) regarding its collection, use, and disclosure of electronic signatures for parcel tracking. The complainant raised concerns about the clarity of information provided to addressees regarding their option to opt-out of having their signature displayed online, and the absence of labels on signature devices at a specific postal outlet. The investigation also examined the privacy and security controls of CPC's online tracking website. CPC argued that disclosure of signatures to senders was authorized under the Privacy Act and that it provided an opt-out option. The OPC found that the collection and disclosure of signatures for parcel tracking were consistent with the Act, but raised concerns about the adequacy of security controls for online signatures. CPC committed to implementing enhanced security measures.

Key Issues
  • Whether the collection of electronic signatures by CPC contravenes the Privacy Act
  • Whether the disclosure of electronic signatures to the sender of a parcel contravenes the Privacy Act
  • Whether the disclosure of electronic signatures online contravenes the Privacy Act
  • Whether CPC adequately safeguards digitized signatures displayed online
  • Whether the information provided to addressees about opting out of online signature display is sufficiently clear
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Jan 25, 2016Incident Summary #10Indexed Jun 30, 2026

Incident Summary #10: Cable provider removes personal information posted online of customers with overdue accounts

A cable provider

The OPC was alerted to a cable provider posting a list of customers with overdue accounts and the amounts owed on a municipal Facebook page. The cable provider believed this practice was permissible, citing municipal tax arrears publications as an example. The OPC informed the provider that publicly disseminating personal information for debt collection without consent is not permitted under PIPEDA, even though disclosure to a third-party debt collector may be. The cable provider subsequently removed the posting. The OPC also clarified with the NWT Commissioner that municipal tax arrears publications are mandated by territorial law, unlike the cable provider's actions. The OPC explained that PIPEDA's debt collection exemption does not authorize public disclosure.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #10: Cable provider removes personal information posted online of customers with overdue accounts

Jan 25, 2016Incident Summary #10
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC was alerted to a cable provider posting a list of customers with overdue accounts and the amounts owed on a municipal Facebook page. The cable provider believed this practice was permissible, citing municipal tax arrears publications as an example. The OPC informed the provider that publicly disseminating personal information for debt collection without consent is not permitted under PIPEDA, even though disclosure to a third-party debt collector may be. The cable provider subsequently removed the posting. The OPC also clarified with the NWT Commissioner that municipal tax arrears publications are mandated by territorial law, unlike the cable provider's actions. The OPC explained that PIPEDA's debt collection exemption does not authorize public disclosure.

Key Issues
  • Whether publicly posting customer debt information on social media is permissible under PIPEDA
  • Whether the debt collection exemption under paragraph 7(3)(b) of PIPEDA authorizes public dissemination of personal information
  • Whether municipal practices of publishing tax arrears are comparable to private organizations publishing customer debt under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 9, 2016PIPEDA Case Summary #2016-004Indexed Jun 30, 2026

PIPEDA Case Summary #2016-004: Retailer shares customer’s in-store behaviour with the customer’s employer

A retail store

A customer complained that a retail store employee disclosed his personal information to his employer, including his name, in-store behavior, and statements made to staff. The store argued the information was not personal because it was made publicly, and that it had implied consent for the disclosure. The OPC found that information overheard by others is still personal information under PIPEDA. The OPC also determined that implied consent was not appropriate given the sensitive nature of the information, which had the potential to negatively affect the customer's employment. The store's disclosure without knowledge or consent contravened Principle 4.3 of PIPEDA. The complaint was found to be well-founded and resolved after the store implemented the OPC's recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Case Summary #2016-004: Retailer shares customer’s in-store behaviour with the customer’s employer

Jan 9, 2016PIPEDA Case Summary #2016-004
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a retail store employee disclosed his personal information to his employer, including his name, in-store behavior, and statements made to staff. The store argued the information was not personal because it was made publicly, and that it had implied consent for the disclosure. The OPC found that information overheard by others is still personal information under PIPEDA. The OPC also determined that implied consent was not appropriate given the sensitive nature of the information, which had the potential to negatively affect the customer's employment. The store's disclosure without knowledge or consent contravened Principle 4.3 of PIPEDA. The complaint was found to be well-founded and resolved after the store implemented the OPC's recommendations.

Key Issues
  • Whether the information shared was personal information under PIPEDA
  • Whether the customer provided implied consent for the disclosure of his personal information
  • Whether the disclosed information was sensitive
  • Whether the customer had a reasonable expectation that his information would be shared with his employer
  • Whether the publicly available information exception to consent applied