The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

40 decisions matching
Federal (Canada)Access to Information ActDiscontinued
Federal (Canada) flag
May 19, 20212021 OIC 16Indexed Jun 30, 2026

Notice under subsection 30(5), 2021 OIC 16

A federal institution

The Office of the Information Commissioner (OIC) ceased an investigation into a complaint alleging that a federal institution failed to conduct a reasonable search for records created in the 1990s. The OIC invoked paragraph 30(4)(b) of the Access to Information Act, which permits ceasing an investigation if it is unnecessary, such as when the matter has already been investigated. The OIC had previously investigated and issued a final report on an identical complaint regarding the same institution and type of records. The complainant was given an opportunity to provide representations on why the investigation should continue but did not respond. As no new evidence was presented to differentiate this complaint from the prior one, the OIC concluded that continuing the investigation was unnecessary.

Quick view

Access to Information ActDiscontinued

Notice under subsection 30(5), 2021 OIC 16

May 19, 20212021 OIC 16
Adjudicator: Caroline Maynard
Plain-Language Summary

The Office of the Information Commissioner (OIC) ceased an investigation into a complaint alleging that a federal institution failed to conduct a reasonable search for records created in the 1990s. The OIC invoked paragraph 30(4)(b) of the Access to Information Act, which permits ceasing an investigation if it is unnecessary, such as when the matter has already been investigated. The OIC had previously investigated and issued a final report on an identical complaint regarding the same institution and type of records. The complainant was given an opportunity to provide representations on why the investigation should continue but did not respond. As no new evidence was presented to differentiate this complaint from the prior one, the OIC concluded that continuing the investigation was unnecessary.

Key Issues
  • Whether the investigation was unnecessary under paragraph 30(4)(b) of the Access to Information Act because the matter had already been the subject of an investigation or final report
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
May 19, 20213218-01553Indexed Jun 30, 2026

3218-01553 — Health Canada

Health Canada

The complainant alleged that Health Canada failed to respond to an access request for information about implantable medical devices within the statutory time limits. Health Canada initially claimed a 90-day time extension under paragraphs 9(1)(a) and 9(1)(c) of the ATIA, but failed to respond by the extended due date, leading to a deemed refusal under subsection 10(3). The institution had consulted nine third parties, one of whom filed a judicial review application under section 44, which Health Canada argued prevented the release of any records. During the OIC's investigation, the third party withdrew its application. Health Canada then indicated that further consultations were needed due to intertwined information and the passage of time. The Information Commissioner found the complaint to be well founded and recommended that Health Canada provide a final response to the complainant by a specified date. The Minister of Health agreed to implement this recommendation.

Quick view

Access to Information ActWell-founded

3218-01553 — Health Canada

May 19, 20213218-01553
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Health Canada failed to respond to an access request for information about implantable medical devices within the statutory time limits. Health Canada initially claimed a 90-day time extension under paragraphs 9(1)(a) and 9(1)(c) of the ATIA, but failed to respond by the extended due date, leading to a deemed refusal under subsection 10(3). The institution had consulted nine third parties, one of whom filed a judicial review application under section 44, which Health Canada argued prevented the release of any records. During the OIC's investigation, the third party withdrew its application. Health Canada then indicated that further consultations were needed due to intertwined information and the passage of time. The Information Commissioner found the complaint to be well founded and recommended that Health Canada provide a final response to the complainant by a specified date. The Minister of Health agreed to implement this recommendation.

Key Issues
  • Whether Health Canada responded to the access request within the time limits set out in the Access to Information Act
  • Whether Health Canada's time extension under paragraphs 9(1)(a) and 9(1)(c) was valid
  • Whether Health Canada was in deemed refusal under subsection 10(3) of the ATIA
  • Whether a third-party judicial review application under section 44 justified the delay in processing the entire request
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
May 12, 20213218-01665Indexed Jun 30, 2026

3218-01665 — Library and Archives Canada and Canadian Security Intelligence Service

Library and Archives Canada

The complainant alleged that Library and Archives Canada (LAC) failed to respond to an access request within the time limits set out in the Access to Information Act. LAC took a 425-day extension but did not meet the extended deadline, leading to a deemed refusal. The investigation revealed that the delay was partly due to a lengthy consultation with the Canadian Security Intelligence Service (CSIS) and LAC's lack of infrastructure to process Top Secret classified records. Despite CSIS not agreeing to downgrade the classification, the Information Commissioner found that the lack of appropriate infrastructure was not a valid justification for LAC's failure to meet its obligations. The Commissioner recommended that the Minister of Canadian Heritage find an interim solution for the request and implement a permanent solution for handling classified records. The Minister confirmed that LAC responded to the request by redacting records by hand and is working towards digital processing capability. The complaint was found to be well founded.

Quick view

Access to Information ActWell-founded

3218-01665 — Library and Archives Canada and Canadian Security Intelligence Service

May 12, 20213218-01665
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Library and Archives Canada (LAC) failed to respond to an access request within the time limits set out in the Access to Information Act. LAC took a 425-day extension but did not meet the extended deadline, leading to a deemed refusal. The investigation revealed that the delay was partly due to a lengthy consultation with the Canadian Security Intelligence Service (CSIS) and LAC's lack of infrastructure to process Top Secret classified records. Despite CSIS not agreeing to downgrade the classification, the Information Commissioner found that the lack of appropriate infrastructure was not a valid justification for LAC's failure to meet its obligations. The Commissioner recommended that the Minister of Canadian Heritage find an interim solution for the request and implement a permanent solution for handling classified records. The Minister confirmed that LAC responded to the request by redacting records by hand and is working towards digital processing capability. The complaint was found to be well founded.

Key Issues
  • Whether Library and Archives Canada responded to the access request within the time limits set out in the Access to Information Act
  • Whether Library and Archives Canada was in deemed refusal pursuant to subsection 10(3) of the Act
  • Whether the lack of infrastructure to process Top Secret records is a valid justification for delay
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
May 4, 20215819-03939Indexed Jun 30, 2026

5819-03939 — Employment and Social Development Canada

Employment and Social Development Canada

The complainant alleged that Employment and Social Development Canada (ESDC) improperly stated it could not process an access request for emails to and from a named employee, containing specific keywords. ESDC argued the emails were not under its control, despite being on its servers, because they were personal and lacked business value. The Office of the Information Commissioner (OIC) investigated whether the records were "under the control" of ESDC, considering factors such as institutional purpose, relation to ESDC's mandate, and integration with other records. The OIC found the emails were entirely personal, had no institutional purpose, and ESDC had no authority to regulate their use or disposition. Therefore, the OIC concluded the emails were not under ESDC's control and not subject to the Access to Information Act. The complaint was deemed not well founded.

Quick view

Access to Information ActNot well-founded

5819-03939 — Employment and Social Development Canada

May 4, 20215819-03939
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Employment and Social Development Canada (ESDC) improperly stated it could not process an access request for emails to and from a named employee, containing specific keywords. ESDC argued the emails were not under its control, despite being on its servers, because they were personal and lacked business value. The Office of the Information Commissioner (OIC) investigated whether the records were "under the control" of ESDC, considering factors such as institutional purpose, relation to ESDC's mandate, and integration with other records. The OIC found the emails were entirely personal, had no institutional purpose, and ESDC had no authority to regulate their use or disposition. Therefore, the OIC concluded the emails were not under ESDC's control and not subject to the Access to Information Act. The complaint was deemed not well founded.

Key Issues
  • Whether the requested emails were "under the control" of Employment and Social Development Canada (ESDC) as per the Access to Information Act
  • Whether the contents of the emails related to an institutional matter and involved ESDC's mandate, obligations, functions, and operations
  • Whether the emails were created to fulfill any ESDC officer's or employee's duties or functions and/or were intended for any employment-related purpose
  • Whether the emails were created to fulfill a statutory requirement imposed on ESDC
  • Whether ESDC relied on the emails when preparing government records
  • Whether ESDC had any authority with regard to the use or disposition of the emails
  • Whether communicating the contents of the emails required the authorization of an ESDC officer or employee
  • Whether the emails were integrated with other ESDC records
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 28, 20215820-03592Indexed Jun 30, 2026

Public Services and Procurement Canada (Re), 2021 OIC 12

Public Services and Procurement Canada

The complainant alleged that Public Services and Procurement Canada (PSPC) failed to respond to an access request for COVID-19-related contracts within the statutory time limit. PSPC received the request on April 6, 2020, with a response due by May 6, 2020. PSPC stated that the delay was partly due to the request being placed on hold because of COVID-19 measures. However, the Information Commissioner has previously ruled that the pandemic does not justify suspending access request processing. The investigation found that PSPC did not respond by the deadline and did not claim an extension. PSPC finally responded on April 1, 2021, nearly a year after the initial deadline. The Commissioner concluded that PSPC failed to meet its obligations under the Access to Information Act, resulting in a deemed refusal.

Quick view

Access to Information ActWell-founded

Public Services and Procurement Canada (Re), 2021 OIC 12

Apr 28, 20215820-03592
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Public Services and Procurement Canada (PSPC) failed to respond to an access request for COVID-19-related contracts within the statutory time limit. PSPC received the request on April 6, 2020, with a response due by May 6, 2020. PSPC stated that the delay was partly due to the request being placed on hold because of COVID-19 measures. However, the Information Commissioner has previously ruled that the pandemic does not justify suspending access request processing. The investigation found that PSPC did not respond by the deadline and did not claim an extension. PSPC finally responded on April 1, 2021, nearly a year after the initial deadline. The Commissioner concluded that PSPC failed to meet its obligations under the Access to Information Act, resulting in a deemed refusal.

Key Issues
  • Whether Public Services and Procurement Canada responded to the access request within the time limit set out in section 7 of the Access to Information Act
  • Whether the COVID-19 pandemic justified suspending the processing of an access request
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 23, 20215819-05410Indexed Jun 30, 2026

Immigration, Refugees and Citizenship Canada (Re), 2021 OIC 11

Immigration, Refugees and Citizenship Canada

The Information Commissioner initiated a systemic investigation into Immigration, Refugees and Citizenship Canada's (IRCC) processing of access requests for immigration application files due to a dramatic increase in requests and complaints. The investigation found that IRCC's practice of automatically extending response times for frequent requesters under paragraph 9(1)(a) of the Access to Information Act was improper. This practice disregarded Federal Court of Appeal guidance and the Act's requirement to not consider a requester's identity. The Commissioner issued five recommendations to IRCC, including ceasing the improper extension practice, developing a work plan to improve ATIP office performance, publishing results, improving the availability of client immigration information, and securing adequate short-term resources. IRCC agreed to all recommendations and submitted a work plan. The complaint was found to be well-founded.

Quick view

Access to Information ActWell-founded

Immigration, Refugees and Citizenship Canada (Re), 2021 OIC 11

Apr 23, 20215819-05410
Adjudicator: Caroline Maynard
Plain-Language Summary

The Information Commissioner initiated a systemic investigation into Immigration, Refugees and Citizenship Canada's (IRCC) processing of access requests for immigration application files due to a dramatic increase in requests and complaints. The investigation found that IRCC's practice of automatically extending response times for frequent requesters under paragraph 9(1)(a) of the Access to Information Act was improper. This practice disregarded Federal Court of Appeal guidance and the Act's requirement to not consider a requester's identity. The Commissioner issued five recommendations to IRCC, including ceasing the improper extension practice, developing a work plan to improve ATIP office performance, publishing results, improving the availability of client immigration information, and securing adequate short-term resources. IRCC agreed to all recommendations and submitted a work plan. The complaint was found to be well-founded.

Key Issues
  • Whether IRCC's practice of extending time limits under paragraph 9(1)(a) for frequent requesters was compliant with the ATIA
  • Whether IRCC's extension practice disregarded Federal Court of Appeal guidance on s.9(1)(a)
  • Whether IRCC's extension practice violated subsection 4(2.1) by considering requester identity
  • Whether IRCC had sufficient resources and effective processes to manage the volume of access requests
  • Whether IRCC provided adequate alternative means for clients to obtain immigration application information
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Apr 19, 20213216-00258Indexed Jun 30, 2026

Privy Council Office (Re), 2021 OIC 10

Privy Council Office

The complainant alleged that the Privy Council Office (PCO) improperly withheld the names of employees within the Prime Minister's Office under subsection 19(1) of the Access to Information Act. The request sought records related to the Minister of Revenue's announcement regarding audits of registered charities for political activities. The OIC's investigation focused on the application of subsection 19(1) to the names of exempt staff appearing in email chains. PCO argued that the information was personal information, citing a Supreme Court decision that clarified information about exempt staff is personal information. The OIC agreed that the names, in context, revealed more than just their identity and title, thus meeting the requirements for personal information and not falling under the exceptions in the Privacy Act. Furthermore, the OIC found that none of the circumstances under subsection 19(2) for discretionary disclosure existed, as consent was not given, and the specific context of their involvement was not publicly available. Therefore, the OIC concluded that the complaint was not well founded.

Quick view

Access to Information ActNot well-founded

Privy Council Office (Re), 2021 OIC 10

Apr 19, 20213216-00258
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Privy Council Office (PCO) improperly withheld the names of employees within the Prime Minister's Office under subsection 19(1) of the Access to Information Act. The request sought records related to the Minister of Revenue's announcement regarding audits of registered charities for political activities. The OIC's investigation focused on the application of subsection 19(1) to the names of exempt staff appearing in email chains. PCO argued that the information was personal information, citing a Supreme Court decision that clarified information about exempt staff is personal information. The OIC agreed that the names, in context, revealed more than just their identity and title, thus meeting the requirements for personal information and not falling under the exceptions in the Privacy Act. Furthermore, the OIC found that none of the circumstances under subsection 19(2) for discretionary disclosure existed, as consent was not given, and the specific context of their involvement was not publicly available. Therefore, the OIC concluded that the complaint was not well founded.

Key Issues
  • Whether the names of employees within the Prime Minister's Office constitute 'personal information' under s.19(1) ATIA
  • Whether the information falls under exceptions to the definition of 'personal information' in paragraphs 3(j) to 3(m) of the Privacy Act
  • Whether the information falls under the exception in paragraph 3(j.1) of the Privacy Act for ministerial advisers or staff members
  • Whether the individuals consented to the release of their personal information under s.19(2)(a) ATIA
  • Whether the information was publicly available under s.19(2)(b) ATIA
  • Whether disclosure would be consistent with section 8 of the Privacy Act under s.19(2)(c) ATIA
  • Whether the institution reasonably exercised its discretion to disclose the information under s.19(2) ATIA
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Apr 14, 20213217-00342Indexed Jun 30, 2026

3217-00342 — Department of Justice Canada

Department of Justice Canada

The complainant alleged that the Department of Justice Canada (Justice) improperly withheld information under section 23 of the Access to Information Act. The request sought legal fees related to a specific litigation file. Justice claimed solicitor-client privilege over disbursements and details of expenses in a cost-recovery report, citing a presumption of privilege for lawyers' bills of account. The Information Commissioner acknowledged this presumption but found it rebutted in this case. The Commissioner determined there was no reasonable possibility that an inquirer could use the information to deduce privileged communications. Therefore, the Commissioner recommended that Justice disclose all information initially withheld under section 23. Justice agreed to implement the recommendation, and the complaint was found to be well founded.

Quick view

Access to Information ActWell-founded

3217-00342 — Department of Justice Canada

Apr 14, 20213217-00342
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Department of Justice Canada (Justice) improperly withheld information under section 23 of the Access to Information Act. The request sought legal fees related to a specific litigation file. Justice claimed solicitor-client privilege over disbursements and details of expenses in a cost-recovery report, citing a presumption of privilege for lawyers' bills of account. The Information Commissioner acknowledged this presumption but found it rebutted in this case. The Commissioner determined there was no reasonable possibility that an inquirer could use the information to deduce privileged communications. Therefore, the Commissioner recommended that Justice disclose all information initially withheld under section 23. Justice agreed to implement the recommendation, and the complaint was found to be well founded.

Key Issues
  • Whether the information consists of communication between a lawyer or notary and his or her client
  • Whether the communication relates directly to the seeking or giving of legal advice
  • Whether the parties intend the communication and advice to remain confidential
  • Whether the information was prepared or gathered for the dominant purpose of litigation
  • Whether the litigation is either in progress or is reasonably expected to occur
  • Whether the presumption of privilege for lawyers' bills of account was rebutted
  • Whether there was a reasonable possibility that an assiduous inquirer could use the information to deduce or otherwise acquire communications protected by privilege
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-009Indexed Jun 30, 2026

PIPEDA Findings #2021-009: Opt-in consent required for a donor list trading program

A charitable organization

A complainant alleged that a charitable organization (the Respondent) failed to obtain proper consent before sharing his personal information through a donor list trading program. The Respondent used an opt-out checkbox on its mail-in donation forms, which the complainant found inadequate after receiving solicitations from another charity. The OPC determined that sharing donor information with other charities for solicitation purposes was outside the reasonable expectations of donors, thus requiring express opt-in consent. Furthermore, the information provided by the Respondent on its donation forms, inserts, and privacy policy was deemed insufficient to enable meaningful consent. The OPC recommended that the Respondent obtain express opt-in consent and enhance its privacy communications to clearly explain the nature, purpose, and consequences of the data sharing. The Respondent agreed to implement these recommendations, leading to a conditionally resolved outcome.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-009: Opt-in consent required for a donor list trading program

Mar 30, 2021PIPEDA Findings #2021-009
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a charitable organization (the Respondent) failed to obtain proper consent before sharing his personal information through a donor list trading program. The Respondent used an opt-out checkbox on its mail-in donation forms, which the complainant found inadequate after receiving solicitations from another charity. The OPC determined that sharing donor information with other charities for solicitation purposes was outside the reasonable expectations of donors, thus requiring express opt-in consent. Furthermore, the information provided by the Respondent on its donation forms, inserts, and privacy policy was deemed insufficient to enable meaningful consent. The OPC recommended that the Respondent obtain express opt-in consent and enhance its privacy communications to clearly explain the nature, purpose, and consequences of the data sharing. The Respondent agreed to implement these recommendations, leading to a conditionally resolved outcome.

Key Issues
  • Whether the Respondent obtained meaningful consent for its donor list trading program under PIPEDA
  • Whether opt-out consent was appropriate for sharing donor information with third parties
  • Whether the information shared (donor name, address, donation status) was sensitive in this context
  • Whether sharing donor information with other charities for solicitation was within the reasonable expectations of donors
  • Whether the donor list trading program created a meaningful residual risk of significant harm
  • Whether the information provided to donors on the donation form, insert, and privacy policy was sufficient to support meaningful consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-003Indexed Jun 30, 2026

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Bank of Montreal

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Mar 30, 2021PIPEDA Findings #2021-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Key Issues
  • Whether BMO implemented appropriate security safeguards to adequately protect personal information under its control, as required by PIPEDA Principle 4.7
  • Adequacy of BMO's developer security testing and evaluation processes
  • Adequacy of BMO's vulnerability management program, including identification, assessment, and remediation of vulnerabilities
  • Adequacy of BMO's oversight and monitoring capabilities, specifically regarding bot management, cyberattack detection, and real-time alerts
  • Adequacy of BMO's organizational policies and procedures for handling cyberattacks and incident response
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-004Indexed Jun 30, 2026

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Fido Solutions Inc. (a subsidiary of Rogers Communications Inc.)

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Mar 30, 2021PIPEDA Findings #2021-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Key Issues
  • Whether Fido adequately safeguarded the Complainant’s personal information under Principle 4.7
  • Whether Fido responded to the Complainant’s access request in a generally understandable format under Principle 4.9 and 4.9.4
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 29, 2021PIPEDA Findings #2021-002Indexed Jun 30, 2026

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

CoreFour Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA

Mar 29, 2021PIPEDA Findings #2021-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.

Key Issues
  • Whether CoreFour's security safeguards were appropriate to the sensitivity and volume of personal information under Principle 4.7 PIPEDA
  • Whether CoreFour's weak password requirements for certain Edsby parental accounts constituted an inadequate safeguard
  • Whether CoreFour's safeguards to protect against unauthorized access to thumbnail images of student profile pictures were adequate
  • Whether Edsby's failure to scan for malware when uploading content from third-party applications constituted a safeguard weakness
  • Whether CoreFour lacked a robust overarching information security framework, contravening Principle 4.1.4 and 4.7-4.7.3 PIPEDA
  • Whether CoreFour had an adequate mechanism for handling and reporting privacy breaches under PIPEDA
  • Whether CoreFour was required to report the password management vulnerability, given it occurred before mandatory breach reporting came into effect
  • Whether the student image vulnerability created a "real risk of significant harm" requiring mandatory reporting and notification under s.10.1 PIPEDA
  • Whether CoreFour maintained a breach register as required under s.10.3 PIPEDA
  • Whether CoreFour lacked a privacy management framework, including appropriate written internal policies and practices (e.g., complaint handling, data retention), contravening Principle 4.1.4 PIPEDA
  • Whether CoreFour provided adequate privacy training to its employees, consultants, contractors, and students
  • Whether CoreFour's Privacy Policy was unclear regarding the characterization of personal information, its responsibility for security, and the sharing of user information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 24, 2021PIPEDA Findings #2021-007Indexed Jun 30, 2026

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

A computer services company

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-007: Computer services company accesses customer’s laptop remotely during help desk call without seeking customer’s express consent

Mar 24, 2021PIPEDA Findings #2021-007
Adjudicator: Daniel Therrien
Plain-Language Summary

A customer complained that a computer services company's technician remotely accessed his laptop during a help desk call without his express consent. The OPC found that the company failed to demonstrate it obtained meaningful express consent for remote access, which could expose sensitive personal information. The OPC also found that the company did not have adequate safeguards to prevent unauthorized access by its technicians. During the investigation, the company ceased offering personal help desk services and using the remote access software. Consequently, the OPC found the complaint to be well-founded but resolved due to the company's corporate restructuring and cessation of the problematic practices.

Key Issues
  • Whether the respondent obtained meaningful consent prior to remotely accessing laptops
  • Whether the respondent had adequate safeguards to prevent unauthorized access to customers’ personal information by its personnel
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Mar 22, 2021PIPEDA Findings #2021-008Indexed Jun 30, 2026

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Oculus Transport Ltd.

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-008: Transportation company's constant surveillance of drivers is more intrusive than necessary

Mar 22, 2021PIPEDA Findings #2021-008
Adjudicator: Daniel Therrien
Plain-Language Summary

A truck driver complained that his employer, Oculus Transport Ltd., collected audio recordings of all conversations in his truck cab, including when he was off-duty, which he considered an inappropriate collection of personal information. The OPC investigated whether the company's purposes for audio surveillance were appropriate under PIPEDA. While the OPC acknowledged the company's legitimate business needs for safety and incident investigation, it found the constant, 24/7 audio recording to be overly intrusive and disproportionate to the benefits. The OPC concluded that less privacy-invasive means were available. Oculus Transport Ltd. informed the OPC during the investigation that it had ceased using audio surveillance. Therefore, the complaint was found to be well-founded but resolved.

Key Issues
  • Whether the collection and use of personal information via audio surveillance technology was for purposes that a reasonable person would consider appropriate in the circumstances under subsection 5(3) of PIPEDA
  • Whether the personal information collected was sensitive
  • Whether the organization's purpose represented a legitimate need / bona fide business interest
  • Whether the collection, use and disclosure would be effective in meeting the organization’s need
  • Whether there are less privacy invasive means of achieving the same ends at comparable cost and with comparable benefits
  • Whether the loss of privacy is proportional to the benefits
Federal (Canada)Access to Information ActNot well-founded
Federal (Canada) flag
Mar 18, 20215819-00626Indexed Jun 30, 2026

Innovation, Science and Economic Development Canada (Re), 2021 OIC 8

Innovation, Science and Economic Development Canada

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) took an unreasonable extension of time to respond to an access request related to the Competition Bureau’s bread price-fixing investigation. ISED claimed a 1,460-day extension under paragraph 9(1)(a) of the Access to Information Act, citing the large volume of records (over 75 million pages) and the need to search 100 terabytes of information. The OIC found that the request involved a large number of records and that meeting the 30-day deadline would unreasonably interfere with ISED's operations. The OIC also determined that ISED applied sufficient rigour in calculating the extension, considering the time needed by the program area and the Access to Information and Privacy Office, and the complexity of the records. Consequently, the OIC concluded that the 1,460-day extension was reasonable and justified. The complaint was not well founded, and the OIC invited ISED to consider disclosing completed packages of records as they become available.

Quick view

Access to Information ActNot well-founded

Innovation, Science and Economic Development Canada (Re), 2021 OIC 8

Mar 18, 20215819-00626
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that Innovation, Science and Economic Development Canada (ISED) took an unreasonable extension of time to respond to an access request related to the Competition Bureau’s bread price-fixing investigation. ISED claimed a 1,460-day extension under paragraph 9(1)(a) of the Access to Information Act, citing the large volume of records (over 75 million pages) and the need to search 100 terabytes of information. The OIC found that the request involved a large number of records and that meeting the 30-day deadline would unreasonably interfere with ISED's operations. The OIC also determined that ISED applied sufficient rigour in calculating the extension, considering the time needed by the program area and the Access to Information and Privacy Office, and the complexity of the records. Consequently, the OIC concluded that the 1,460-day extension was reasonable and justified. The complaint was not well founded, and the OIC invited ISED to consider disclosing completed packages of records as they become available.

Key Issues
  • Whether the request was for a large number of records or required searching through a large number of records under paragraph 9(1)(a)
  • Whether meeting the 30-day deadline would unreasonably interfere with the institution’s operations under paragraph 9(1)(a)
  • Whether the extension of time was for a reasonable period, given the circumstances, under paragraph 9(1)(a)
  • Whether the institution validly claimed the extension of time by notifying the requester within 30 days