The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

29 decisions matching
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Aug 7, 2020Indexed Jun 30, 2026

RCMP contravened the Act by using certain types of non-conviction information for vulnerable sector checks without consent

Royal Canadian Mounted Police (RCMP)

Three individuals complained about the Royal Canadian Mounted Police's (RCMP) use of non-conviction information in vulnerable sector (VS) checks, which they required for employment or volunteer positions. The complainants alleged that the RCMP inappropriately used non-criminal information, including mental health incidents, without proper consent. The OPC found that for two of the complaints, the RCMP contravened section 7 of the Privacy Act because the consent forms did not clearly inform applicants about the types of non-conviction information that would be used. While the RCMP argued consent was obtained, the OPC determined it was not informed consent in these cases. The OPC also concluded that the RCMP's broad policy of reporting non-conviction information, including mental health incidents, was not proportional or minimally intrusive compared to more restrictive provincial models. However, the complaint regarding the RCMP's retention period for personal information was found not well-founded, as it complied with the minimum requirements of the Privacy Regulations. The RCMP agreed to revise its consent forms and policy to address the OPC's concerns, leading to a well-founded and conditionally resolved outcome for the two complaints.

Quick view

Privacy ActWell-founded & conditionally resolved

RCMP contravened the Act by using certain types of non-conviction information for vulnerable sector checks without consent

Aug 7, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

Three individuals complained about the Royal Canadian Mounted Police's (RCMP) use of non-conviction information in vulnerable sector (VS) checks, which they required for employment or volunteer positions. The complainants alleged that the RCMP inappropriately used non-criminal information, including mental health incidents, without proper consent. The OPC found that for two of the complaints, the RCMP contravened section 7 of the Privacy Act because the consent forms did not clearly inform applicants about the types of non-conviction information that would be used. While the RCMP argued consent was obtained, the OPC determined it was not informed consent in these cases. The OPC also concluded that the RCMP's broad policy of reporting non-conviction information, including mental health incidents, was not proportional or minimally intrusive compared to more restrictive provincial models. However, the complaint regarding the RCMP's retention period for personal information was found not well-founded, as it complied with the minimum requirements of the Privacy Regulations. The RCMP agreed to revise its consent forms and policy to address the OPC's concerns, leading to a well-founded and conditionally resolved outcome for the two complaints.

Key Issues
  • Whether the use of non-conviction information by the RCMP for VS checks was done with informed consent consistent with section 7 of the Privacy Act.
  • Whether the RCMP's policy of reporting non-conviction information broadly, including mental health incidents, in VS checks was proportional or minimally intrusive.
  • Whether the RCMP should amend its policies with respect to the use of non-conviction information in VS checks.
  • Whether the RCMP contravened the Act by retaining Complainant 2’s personal information for too long.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Aug 6, 2020Indexed Jun 30, 2026

PA-055322 (PCO) et PA-055323 (DOJ) — Privy Council Office (PCO) and Department of Justice (DOJ)

Privy Council Office (PCO) and Department of Justice (DOJ)

The OPC investigated a complaint regarding the unauthorized disclosure of personal information about Supreme Court candidate Chief Justice Glenn Joyal. Media reports claimed an anonymous source revealed a disagreement between the Prime Minister's Office (PMO) and the former Attorney General over Joyal's nomination. The complainant alleged breaches of the Privacy Act by the Privy Council Office (PCO), Department of Justice (DOJ), Office of the Commissioner of Federal Judicial Affairs (CFJA), and the PMO. The OPC determined it lacked jurisdiction over the CFJA and PMO, focusing its investigation on the PCO and DOJ. The investigation found no evidence that either the PCO or the DOJ had access to the specific information that was leaked, nor that the disclosure originated from these institutions. While no contravention was found, the OPC highlighted that Chief Justice Joyal's privacy was compromised and called for legislative reform to extend the Privacy Act's coverage to all government institutions, including Ministers' Offices and the PMO.

Quick view

Privacy ActNot well-founded

PA-055322 (PCO) et PA-055323 (DOJ) — Privy Council Office (PCO) and Department of Justice (DOJ)

Aug 6, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated a complaint regarding the unauthorized disclosure of personal information about Supreme Court candidate Chief Justice Glenn Joyal. Media reports claimed an anonymous source revealed a disagreement between the Prime Minister's Office (PMO) and the former Attorney General over Joyal's nomination. The complainant alleged breaches of the Privacy Act by the Privy Council Office (PCO), Department of Justice (DOJ), Office of the Commissioner of Federal Judicial Affairs (CFJA), and the PMO. The OPC determined it lacked jurisdiction over the CFJA and PMO, focusing its investigation on the PCO and DOJ. The investigation found no evidence that either the PCO or the DOJ had access to the specific information that was leaked, nor that the disclosure originated from these institutions. While no contravention was found, the OPC highlighted that Chief Justice Joyal's privacy was compromised and called for legislative reform to extend the Privacy Act's coverage to all government institutions, including Ministers' Offices and the PMO.

Key Issues
  • Whether the Office of the Commissioner of Federal Judicial Affairs (CFJA) is a 'government institution' under the Privacy Act
  • Whether the Prime Minister's Office (PMO) is a 'government institution' under the Privacy Act
  • Whether the Privy Council Office (PCO) was responsible for the unauthorized disclosure of Chief Justice Joyal's personal information under section 8 of the Privacy Act
  • Whether the Department of Justice (DOJ) was responsible for the unauthorized disclosure of Chief Justice Joyal's personal information under section 8 of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Aug 4, 2020PIPEDA Findings #2020-001Indexed Jun 30, 2026

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

TD Canada Trust

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Findings #2020-001: Bank ensures openness and comparable protection for personal information transferred to third party

Aug 4, 2020PIPEDA Findings #2020-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A former employee of TD Canada Trust complained that TD outsourced fraud claims processing to a third-party service provider in India without obtaining customer consent or offering an opt-out. The complainant also alleged that TD was not sufficiently open about this practice. The Office of the Privacy Commissioner (OPC) also investigated whether TD maintained accountability by ensuring a comparable level of protection for personal information transferred to the third party. The OPC found that TD was not required to obtain additional consent, as the information was used for the original purpose of fraud claims management for which consent was already obtained. Furthermore, TD was deemed sufficiently open, providing clear information about transfers to foreign jurisdictions in its account agreements and privacy resources. The OPC concluded that TD ensured a comparable level of protection through a robust contract, comprehensive risk assessments, employee controls, cybersecurity measures, and proactive monitoring. Consequently, all aspects of the complaint were found to be not well-founded.

Key Issues
  • Whether TD was required to obtain additional consent for transferring personal information to a third-party service provider in India for fraud claims processing (Principle 4.3 PIPEDA)
  • Whether TD was required to offer customers an opt-out for the transfer of personal information to a third-party service provider in India for fraud claims processing
  • Whether TD was sufficiently open about its practice of transferring personal information to a third-party service provider in a foreign jurisdiction for processing (Principle 4.8 PIPEDA)
  • Whether TD ensured a comparable level of protection for personal information processed by the third-party service provider in India (Principle 4.1.3 PIPEDA)
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jul 14, 2020Indexed Jun 30, 2026

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Canada Border Services Agency (CBSA)

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Quick view

Privacy ActNot well-founded

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Jul 14, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Key Issues
  • Did the CBSA disclose the complainant’s personal information?
  • Was any disclosed information “publicly available”, such that subsection 69(2) of the Act excludes application of sections 7 and 8?
  • If not, was the disclosure permitted under subsection 8(2) of the Act?
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 9, 2020PIPEDA Findings #2020-003Indexed Jun 30, 2026

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Dell Inc.

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Jul 9, 2020PIPEDA Findings #2020-003
Adjudicator: Daniel Therrien
Plain-Language Summary

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Key Issues
  • Whether Dell adequately safeguarded personal information under its control while using a service provider (PIPEDA Principle 4.1.3 and 4.7).
  • Whether the personal information transferred to the service provider was sensitive enough to require a high degree of protection.
  • Whether Dell's access controls were sufficient to protect customer information.
  • Whether Dell's logging and monitoring practices were adequate to detect anomalous employee requests for customer information.
  • Whether Dell's technical measures, such as USB drive restrictions, were sufficient.
  • Whether Dell adequately investigated the circumstances and scope of the June 2017 breach.
  • Whether Dell adequately responded to customer complaints about potential privacy breaches (PIPEDA Principle 4.10.4).
  • Whether Dell remained responsible for personal information transferred to a third party for processing.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 30, 2020PIPEDA Findings #2020-002Indexed Jun 30, 2026

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

RateMDs.com

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2020-002: Health practitioner ratings site ceases charging for rating takedowns, a PIPEDA “no-go-zone”

Jun 30, 2020PIPEDA Findings #2020-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A dentist complained that RateMDs.com, a health practitioner ratings website, used her personal information without consent, contravening PIPEDA Principle 4.3. The complaint concerned both her business contact information and user-generated reviews and ratings about her practice. The OPC found that the business contact information was publicly available, thus not requiring consent for its collection, use, and disclosure. Regarding the reviews, the OPC acknowledged they were personal information for both the dentist and the reviewers, requiring a balancing of interests, and concluded that the public interest in informing patient decisions outweighed the dentist's lack of consent, deeming this aspect not well-founded. However, RateMDs' explanation of its accuracy and correction policies was found to lack clarity, contravening the Openness Principle, which RateMDs resolved by updating its terms. Crucially, the OPC found RateMDs' "pay-for-takedown" service, which allowed subscribers to hide negative reviews for a fee, to be an inappropriate practice under s.5(3) of PIPEDA, a "no-go zone." RateMDs agreed to cease offering this feature, leading to a conditionally resolved finding for this issue.

Key Issues
  • Whether RateMDs collected, used, or disclosed the complainant's business contact information without consent (Principle 4.3)
  • Whether the business contact information exemption under s.4.01 of PIPEDA applied to RateMDs' use of the complainant's business contact information
  • Whether the complainant's business contact information was publicly available under s.7(1)(d), 7(2)(c.1), and 7(3)(h.1) of PIPEDA and its Regulations
  • Whether the reviews and ratings posted on RateMDs constituted the complainant's personal information
  • Whether the reviews and ratings also constituted the personal information of the users who posted them
  • Whether RateMDs required the complainant's consent to publish the reviews and ratings about her (Principle 4.3)
  • Whether a balancing of interests was required when the privacy rights of multiple individuals conflicted regarding the same personal information
  • Whether RateMDs ensured the accuracy of information and provided a fair and accessible process for health professionals to challenge and correct inaccurate information (Principle 4.6, 4.9.5)
  • Whether RateMDs made readily available specific information about its policies and practices relating to the management of personal information, particularly regarding review removal and correction (Principle 4.8)
  • Whether RateMDs' "pay-for-takedown" service, allowing subscribers to hide negative reviews for a fee, constituted an appropriate purpose for collecting, using, or disclosing personal information under s.5(3) of PIPEDA
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Jun 25, 20202020 OIC 5Indexed Jun 30, 2026

Department of Justice Canada (Re), 2020 OIC 5

Department of Justice Canada

The complainant challenged the Department of Justice Canada's (Justice) decision to withhold an entire Memorandum of Understanding (MOU) for legal services under section 23 of the Access to Information Act. Justice claimed the entire MOU was protected by solicitor-client privilege. The Commissioner found that Justice failed to demonstrate that general identifying information, such as the title and signature blocks, fell under this privilege. Furthermore, the Commissioner determined that Justice had waived its solicitor-client privilege over certain information within the MOU. Consequently, the Commissioner concluded that the complaint was well founded and recommended the release of part of the record. Justice indicated its intention to implement this recommendation.

Quick view

Access to Information ActWell-founded

Department of Justice Canada (Re), 2020 OIC 5

Jun 25, 20202020 OIC 5
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant challenged the Department of Justice Canada's (Justice) decision to withhold an entire Memorandum of Understanding (MOU) for legal services under section 23 of the Access to Information Act. Justice claimed the entire MOU was protected by solicitor-client privilege. The Commissioner found that Justice failed to demonstrate that general identifying information, such as the title and signature blocks, fell under this privilege. Furthermore, the Commissioner determined that Justice had waived its solicitor-client privilege over certain information within the MOU. Consequently, the Commissioner concluded that the complaint was well founded and recommended the release of part of the record. Justice indicated its intention to implement this recommendation.

Key Issues
  • Whether the entire Memorandum of Understanding (MOU) was protected by solicitor-client privilege under s.23 ATIA
  • Whether general identifying information (title, signature blocks) in the MOU was protected by solicitor-client privilege
  • Whether solicitor-client privilege had been waived over any information in the MOU
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
May 25, 20202020 OIC 4Indexed Jun 30, 2026

3218-00001 — National Defence

National Defence

The complainant alleged that National Defence (DND) failed to respond to an access to information request within the statutory time limits. DND argued that the request did not meet the requirements of section 6 of the Access to Information Act, which stipulates that a request must be for a record under the control of a government institution. The OIC investigated whether DND's decision not to process the request was justified. The Commissioner found that DND had made numerous attempts to clarify the request with the applicant, but the applicant did not provide the necessary clarification to enable DND to identify the records sought. Consequently, the Commissioner concluded that DND was not obligated to process a request that did not adequately describe the records. The complaint was therefore deemed not well-founded.

Quick view

Access to Information ActNot well-founded

3218-00001 — National Defence

May 25, 20202020 OIC 4
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that National Defence (DND) failed to respond to an access to information request within the statutory time limits. DND argued that the request did not meet the requirements of section 6 of the Access to Information Act, which stipulates that a request must be for a record under the control of a government institution. The OIC investigated whether DND's decision not to process the request was justified. The Commissioner found that DND had made numerous attempts to clarify the request with the applicant, but the applicant did not provide the necessary clarification to enable DND to identify the records sought. Consequently, the Commissioner concluded that DND was not obligated to process a request that did not adequately describe the records. The complaint was therefore deemed not well-founded.

Key Issues
  • Whether the access request met the requirements of section 6 of the Access to Information Act
  • Whether National Defence was justified in not processing the request due to lack of clarity
  • Whether National Defence failed to respond within the statutory time limits
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 3, 20203215-00087Indexed Jun 30, 2026

Canadian Human Rights Commission (Re), 2020 OIC 3

Canadian Human Rights Commission

The complainant challenged the Canadian Human Rights Commission's (CHRC) decision to withhold information under subsections 19(1) (personal information), section 22 (testing/auditing procedures), and section 23 (solicitor-client privilege) of the Access to Information Act. During the investigation, the CHRC agreed to release all information previously withheld under section 22 and some under section 23. The OIC found that while some information met the requirements for personal information under s.19(1), specific file numbers did not, as their disclosure would not identify an individual. Regarding solicitor-client privilege, the OIC found that certain draft investigation reports were not shown to have received legal review or advice, thus not meeting the exemption's criteria. The Commissioner recommended the disclosure of the file numbers and the draft investigation reports. The CHRC agreed to the recommendations and released the additional information.

Quick view

Access to Information ActWell-founded

Canadian Human Rights Commission (Re), 2020 OIC 3

Apr 3, 20203215-00087
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant challenged the Canadian Human Rights Commission's (CHRC) decision to withhold information under subsections 19(1) (personal information), section 22 (testing/auditing procedures), and section 23 (solicitor-client privilege) of the Access to Information Act. During the investigation, the CHRC agreed to release all information previously withheld under section 22 and some under section 23. The OIC found that while some information met the requirements for personal information under s.19(1), specific file numbers did not, as their disclosure would not identify an individual. Regarding solicitor-client privilege, the OIC found that certain draft investigation reports were not shown to have received legal review or advice, thus not meeting the exemption's criteria. The Commissioner recommended the disclosure of the file numbers and the draft investigation reports. The CHRC agreed to the recommendations and released the additional information.

Key Issues
  • Whether s.19(1) personal information exemption applies to personal contact information of government employees, leave information, and names of CHRC complainants
  • Whether s.19(1) personal information exemption applies to file numbers
  • Whether the institution reasonably exercised discretion under s.19(2) for applicable personal information
  • Whether s.22 testing/auditing procedures exemption applies
  • Whether s.23 solicitor-client privilege exemption applies to communications between client and counsel for legal advice
  • Whether s.23 solicitor-client privilege exemption applies to draft investigation reports
  • Whether the institution reasonably exercised discretion under s.23 for applicable solicitor-client privileged information
Federal (Canada)Privacy ActResolved
Federal (Canada) flag
Mar 31, 2020Indexed Jun 30, 2026

CBSA should only retain travellers’ digital device passcodes when necessary

Canada Border Services Agency (CBSA)

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Quick view

Privacy ActResolved

CBSA should only retain travellers’ digital device passcodes when necessary

Mar 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian traveler complained that the Canada Border Services Agency (CBSA) inappropriately collected his cell phone passcode during a border inspection. The complainant argued the collection was unauthorized and unnecessary, as he offered to unlock the phone himself. The OPC acknowledged CBSA's authority under the Customs Act to require passcodes for digital device inspections, citing reasons such as preventing data alteration and ensuring evidence continuity. However, the OPC found that the CBSA officer failed to follow policy by not taking notes and not informing the complainant about passcode retention and the option to change it. The OPC also questioned the necessity of retaining passcodes when no further action was taken. The CBSA committed to providing more training and revising its policy to ensure passcodes are handled more sensitively.

Key Issues
  • Whether the CBSA has the authority to require a traveller to provide a passcode to unlock a digital device for inspection purposes under the Customs Act
  • Whether the CBSA officer followed internal policies regarding the collection and retention of personal information (passcodes)
  • Whether the CBSA's retention of the passcode was necessary beyond the examination process when no further action was taken
  • Whether passcodes constitute sensitive personal information
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Feb 18, 20202020 OIC 2Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2020 OIC 2

Royal Canadian Mounted Police

The Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request for over two years, leading to a deemed refusal under the Access to Information Act. During the investigation, the RCMP provided insufficient information regarding the records or the processing of the request to establish a reasonable response date. Due to the continued lack of response, the Information Commissioner found the complaint to be well-founded. The Commissioner ordered the RCMP to respond to the access request within 10 business days from the effective date of the order. However, the RCMP ultimately responded to the request before the order officially came into effect.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2020 OIC 2

Feb 18, 20202020 OIC 2
Adjudicator: Caroline Maynard
Plain-Language Summary

The Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request for over two years, leading to a deemed refusal under the Access to Information Act. During the investigation, the RCMP provided insufficient information regarding the records or the processing of the request to establish a reasonable response date. Due to the continued lack of response, the Information Commissioner found the complaint to be well-founded. The Commissioner ordered the RCMP to respond to the access request within 10 business days from the effective date of the order. However, the RCMP ultimately responded to the request before the order officially came into effect.

Key Issues
  • Whether the institution failed to respond to an access request within the statutory time limits (deemed refusal)
  • Whether the institution provided sufficient information to justify the delay
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jan 31, 2020Indexed Jun 30, 2026

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Employment and Social Development Canada (ESDC)

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Quick view

Privacy ActWell-founded

ESDC’s usage of images obtained through video surveillance for a fact finding exercise to monitor an employee’s departure is not compliant with the Privacy Act

Jan 31, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

An employee complained that ESDC used video surveillance footage to monitor their departure times, alleging contraventions of the Privacy Act regarding collection and use of personal information. ESDC stated the footage was used for a fact-finding exercise due to allegations of early departures, and that the cameras were for security purposes. The OPC found that while the initial collection for security was compliant, ESDC failed to inform individuals about the collection purposes and used the footage for a purpose inconsistent with its original collection without consent. The OPC concluded that ESDC contravened sections 5 and 7 of the Privacy Act. ESDC agreed to adopt a clear policy for video surveillance use and to inform individuals about data collection purposes.

Key Issues
  • Whether the collection of video surveillance footage constituted personal information under s.3 of the Privacy Act
  • Whether the initial collection of video surveillance footage by ESDC was in compliance with s.4 of the Privacy Act
  • Whether ESDC informed individuals of the purpose for collecting personal information via video surveillance, as required by s.5 of the Privacy Act
  • Whether ESDC's use of video surveillance footage to monitor an employee's departure times was consistent with the purpose for which it was collected, as required by s.7(a) of the Privacy Act
  • Whether ESDC obtained consent for the use of video surveillance footage for purposes other than security, as required by s.7(a) of the Privacy Act
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jan 15, 2020Indexed Jun 30, 2026

Public disclosure of medical information during military trial consistent with Privacy Act

Department of National Defence

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Quick view

Privacy ActNot well-founded

Public disclosure of medical information during military trial consistent with Privacy Act

Jan 15, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

A former military member complained that the Department of National Defence (DND) wrongfully compelled him to publicly disclose medical information during an open military summary trial. The complainant argued this disclosure, made as part of his defense against an absence-without-leave charge, violated the Privacy Act. DND contended that summary trials are subject to the "open courts" principle, and since the complainant did not request confidentiality, the disclosure was permissible. The OPC found that the Privacy Act applies to summary trials conducted by the Canadian Forces. However, it concluded that the disclosure was consistent with sections 8(2)(a) and 8(2)(b) of the Privacy Act, which allow disclosure for the purpose for which information was obtained or compiled, or in accordance with an Act of Parliament. The OPC also noted that once information is disclosed in an open court proceeding, it becomes publicly available under section 69(2) of the Act. Therefore, the complaint was found to be not well-founded.

Key Issues
  • Whether the Privacy Act applies to military summary trial proceedings conducted by the Canadian Forces
  • Whether the disclosure of the complainant's medical information during the summary trial was made in accordance with section 8 of the Privacy Act
  • Whether the information became publicly available under section 69(2) of the Privacy Act once disclosed in an open court proceeding
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Jan 14, 20205819-00733Indexed Jun 30, 2026

Royal Canadian Mounted Police (Re), 2020 OIC 1

Royal Canadian Mounted Police

The complainant alleged that the Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request within the statutory time limits. The request, submitted on July 3, 2018, had a due date of August 2, 2018. The RCMP was deemed to have refused access under subsection 10(3) of the Act as it did not respond or take an extension. Despite multiple requests from the OIC for information regarding the delay and a proposed disclosure date, the RCMP provided no rationale for the delay, only citing high volume and resource pressures. The OIC found that the responsive records were not voluminous or complex and had been in the RCMP's possession since July 2018. An initial report with an intended order was sent to the Minister, but before the order could be issued, the RCMP released the records. Consequently, the complaint was found to be well-founded, but no order was issued as the records were released.

Quick view

Access to Information ActWell-founded

Royal Canadian Mounted Police (Re), 2020 OIC 1

Jan 14, 20205819-00733
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Royal Canadian Mounted Police (RCMP) failed to respond to an access to information request within the statutory time limits. The request, submitted on July 3, 2018, had a due date of August 2, 2018. The RCMP was deemed to have refused access under subsection 10(3) of the Act as it did not respond or take an extension. Despite multiple requests from the OIC for information regarding the delay and a proposed disclosure date, the RCMP provided no rationale for the delay, only citing high volume and resource pressures. The OIC found that the responsive records were not voluminous or complex and had been in the RCMP's possession since July 2018. An initial report with an intended order was sent to the Minister, but before the order could be issued, the RCMP released the records. Consequently, the complaint was found to be well-founded, but no order was issued as the records were released.

Key Issues
  • Whether the institution responded to the access request within the statutory time limits
  • Whether the institution was deemed to have refused access under subsection 10(3) of the Act
  • Whether the institution provided adequate rationale for the delay in responding
  • Whether the institution provided a reasonable disclosure date