The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

616 decisions matching
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jun 4, 2018Indexed Jun 30, 2026

Disclosure of Canadian Forces members’ medical records by DND authorized under Privacy Act although record retention practices were insufficient

Department of National Defence

The complaint alleged that the Department of National Defence (DND) improperly disclosed deceased Canadian Forces (CF) members’ medical records to Military Police (MP) investigators for "sudden death suicide investigations" under paragraph 8(2)(e) of the Privacy Act, without due consideration for necessity. Complainants argued that CF-NIS investigations should be limited to determining if wounds were self-inflicted, not broader medical history. DND contended that its Directorate of Access to Information and Privacy (DAIP) was not required to "look behind" facially valid requests, and that the lawfulness of an investigation was the responsibility of the investigative body. The Office of the Privacy Commissioner (OPC) found the allegation that DND failed to properly assess the necessity of the information sought under s. 8(2)(e) to be not well-founded, concluding that DAIP generally exercised sufficient scrutiny. However, the OPC also found that DND failed to meet its obligations under subsection 8(4) of the Privacy Act and section 7 of the Privacy Regulations by not retaining copies of 8(2)(e) request forms in several cases and lacking comprehensive records of disclosures. This constituted a well-founded finding regarding DND's recordkeeping practices. The OPC recommended DND update its policies to ensure retention of all request forms, confirmation of statutory authority for investigations, and maintenance of comprehensive disclosure records. DND committed to implementing these recommendations within six months.

Quick view

Privacy ActNot well-founded

Disclosure of Canadian Forces members’ medical records by DND authorized under Privacy Act although record retention practices were insufficient

Jun 4, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complaint alleged that the Department of National Defence (DND) improperly disclosed deceased Canadian Forces (CF) members’ medical records to Military Police (MP) investigators for "sudden death suicide investigations" under paragraph 8(2)(e) of the Privacy Act, without due consideration for necessity. Complainants argued that CF-NIS investigations should be limited to determining if wounds were self-inflicted, not broader medical history. DND contended that its Directorate of Access to Information and Privacy (DAIP) was not required to "look behind" facially valid requests, and that the lawfulness of an investigation was the responsibility of the investigative body. The Office of the Privacy Commissioner (OPC) found the allegation that DND failed to properly assess the necessity of the information sought under s. 8(2)(e) to be not well-founded, concluding that DAIP generally exercised sufficient scrutiny. However, the OPC also found that DND failed to meet its obligations under subsection 8(4) of the Privacy Act and section 7 of the Privacy Regulations by not retaining copies of 8(2)(e) request forms in several cases and lacking comprehensive records of disclosures. This constituted a well-founded finding regarding DND's recordkeeping practices. The OPC recommended DND update its policies to ensure retention of all request forms, confirmation of statutory authority for investigations, and maintenance of comprehensive disclosure records. DND committed to implementing these recommendations within six months.

Key Issues
  • Whether DND's Directorate of Access to Information and Privacy (DAIP) improperly granted full access to deceased Canadian Forces (CF) members’ medical records under paragraph 8(2)(e) of the Privacy Act.
  • Whether the DAIP gave due consideration to the necessity of the requested records for the investigation.
  • Whether CF-NIS requests for medical records were permissible under paragraph 8(2)(e) given their internal policies limiting the scope of suicide investigations.
  • Whether DND's recordkeeping practices for 8(2)(e) requests and disclosures were consistent with subsection 8(4) of the Privacy Act and section 7 of the Privacy Regulations.
  • Whether the DAIP should verify the statutory authority under which an investigative body's lawful investigation is being conducted, in line with the TBS Directive.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 24, 2018PIPEDA Report of Findings #2018-003Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-003: Facebook agrees to stop using non-users’ personal information in users’ address books

Facebook Inc.

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Facebook Inc. following a 2013 privacy breach where contact information, including that of non-users, was inadvertently disclosed via the 'Download Your Information' (DYI) tool. The investigation focused on Facebook's safeguards, consent practices for its 'matching across address books' process for both users and non-users, and the ability for individuals to access and correct their personal information. The OPC found Facebook's safeguards inadequate prior to the breach, but deemed the issue resolved after Facebook implemented a new Privacy Framework. While Facebook's use of user contact information for matching was found not to contravene consent principles, the OPC determined Facebook was not sufficiently open about these practices, an issue conditionally resolved by Facebook's commitment to revise its notices. The OPC also found Facebook used non-users' personal information for matching without meaningful consent, an issue resolved by Facebook's agreement to stop maintaining such data. Finally, Facebook was found not to be providing adequate access to and correction of matched data, which was resolved through an interim solution.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-003: Facebook agrees to stop using non-users’ personal information in users’ address books

May 24, 2018PIPEDA Report of Findings #2018-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint against Facebook Inc. following a 2013 privacy breach where contact information, including that of non-users, was inadvertently disclosed via the 'Download Your Information' (DYI) tool. The investigation focused on Facebook's safeguards, consent practices for its 'matching across address books' process for both users and non-users, and the ability for individuals to access and correct their personal information. The OPC found Facebook's safeguards inadequate prior to the breach, but deemed the issue resolved after Facebook implemented a new Privacy Framework. While Facebook's use of user contact information for matching was found not to contravene consent principles, the OPC determined Facebook was not sufficiently open about these practices, an issue conditionally resolved by Facebook's commitment to revise its notices. The OPC also found Facebook used non-users' personal information for matching without meaningful consent, an issue resolved by Facebook's agreement to stop maintaining such data. Finally, Facebook was found not to be providing adequate access to and correction of matched data, which was resolved through an interim solution.

Key Issues
  • Whether FB had appropriate safeguards in place prior to the breach to protect contact information of users and non-users.
  • Whether FB implemented appropriate safeguards after the breach.
  • Whether FB was using the personal information of users and non-users during the process of matching across address books.
  • Whether FB was obtaining meaningful consent from users for the use of personal information during the matching process.
  • Whether FB was meeting its obligation to be open about its policies and practices regarding the matching process for users.
  • Whether FB was obtaining meaningful consent from non-users for the use of personal information during the matching process.
  • Whether FB was providing users and non-users the ability to obtain access to their personal information/data.
  • Whether FB was providing users and non-users the ability to correct their personal information/data.
  • Whether the breach resulted in unauthorized disclosure of personal information.
  • Whether the testing conducted by FB for the DYI tool was adequate.
  • Whether the notice provided to non-users in email invitations was consistent with PIPEDA s.6.1 and Principles 4.3 and 4.8.
  • Whether providing access to matched data would likely reveal personal information about a third party under PIPEDA s.9(1).
  • Whether providing access to matched data would raise safety and security concerns.
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 15, 2018Indexed Jun 30, 2026

Complaints in regard to Transport Canada’s requirement for owners of unmanned aircraft to display their personal information on the device

Transport Canada

Four complaints were filed against Transport Canada (TC) regarding its Interim Order requiring owners of unmanned aircraft (drones) to display their name, address, and telephone number on the device. Complainants argued this contravened the disclosure provisions of the Privacy Act by forcing public exposure of personal information without consent, and raised concerns about harassment or identity theft. TC stated the Interim Order was an interim measure to address significant safety risks posed by recreational drone users, citing a 200% increase in incidents since 2014. The OPC determined that while the information is personal, the requirement does not constitute a 'collection' of personal information by TC under sections 4 and 5 of the Privacy Act, and thus the disclosure provisions of section 8 do not apply. The OPC found no violation of the Act but noted TC's commitment to rework identification requirements in future regulations to address privacy concerns.

Quick view

Privacy ActNot well-founded

Complaints in regard to Transport Canada’s requirement for owners of unmanned aircraft to display their personal information on the device

May 15, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

Four complaints were filed against Transport Canada (TC) regarding its Interim Order requiring owners of unmanned aircraft (drones) to display their name, address, and telephone number on the device. Complainants argued this contravened the disclosure provisions of the Privacy Act by forcing public exposure of personal information without consent, and raised concerns about harassment or identity theft. TC stated the Interim Order was an interim measure to address significant safety risks posed by recreational drone users, citing a 200% increase in incidents since 2014. The OPC determined that while the information is personal, the requirement does not constitute a 'collection' of personal information by TC under sections 4 and 5 of the Privacy Act, and thus the disclosure provisions of section 8 do not apply. The OPC found no violation of the Act but noted TC's commitment to rework identification requirements in future regulations to address privacy concerns.

Key Issues
  • Whether the requirement to display personal information on unmanned aircraft constitutes a collection of personal information by Transport Canada under sections 4 and 5 of the Privacy Act
  • Whether the disclosure provisions of section 8 of the Privacy Act apply to the personal information displayed on unmanned aircraft as per the Interim Order
  • Whether the Interim Order contravenes the Privacy Act by obligating individuals to expose personal information to the public without consent
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
May 7, 2018Indexed Jun 30, 2026

Statistics Canada takes reasonable measures to safeguard census data transferred to Shared Services Canada

Statistics Canada

An anonymous complainant alleged that Statistics Canada (StatCan) improperly disclosed confidential census information to Shared Services Canada (SSC) when it transferred its informatics infrastructure, contravening the Statistics Act and risking unauthorized disclosure. The complainant raised concerns about StatCan's supervision over SSC employees, the storage of data in shared data centers, and the potential for disclosure during decryption. StatCan argued that SSC took over infrastructure, not data, and that SSC employees with access were 'deemed employees' under the Statistics Act, sworn to confidentiality, and subject to high security clearances. The Office of the Privacy Commissioner (OPC) found that StatCan was legally required to use SSC's services and, under section 16 of the Shared Services Canada Act, StatCan retained control and accountability for the data. The OPC concluded that StatCan took reasonable measures, including comprehensive agreements and security assessments, to define its relationship with SSC and protect the census data. Therefore, the complaint was deemed not well-founded.

Quick view

Privacy ActNot well-founded

Statistics Canada takes reasonable measures to safeguard census data transferred to Shared Services Canada

May 7, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant alleged that Statistics Canada (StatCan) improperly disclosed confidential census information to Shared Services Canada (SSC) when it transferred its informatics infrastructure, contravening the Statistics Act and risking unauthorized disclosure. The complainant raised concerns about StatCan's supervision over SSC employees, the storage of data in shared data centers, and the potential for disclosure during decryption. StatCan argued that SSC took over infrastructure, not data, and that SSC employees with access were 'deemed employees' under the Statistics Act, sworn to confidentiality, and subject to high security clearances. The Office of the Privacy Commissioner (OPC) found that StatCan was legally required to use SSC's services and, under section 16 of the Shared Services Canada Act, StatCan retained control and accountability for the data. The OPC concluded that StatCan took reasonable measures, including comprehensive agreements and security assessments, to define its relationship with SSC and protect the census data. Therefore, the complaint was deemed not well-founded.

Key Issues
  • Whether Statistics Canada improperly disclosed confidential census information to Shared Services Canada by transferring its informatics infrastructure.
  • Whether the sharing of census information with SSC contravenes the Statistics Act.
  • Whether Statistics Canada maintains sufficient supervision over SSC employees accessing census data.
  • Whether the storage of census data in SSC data centers shared with other federal institutions creates a risk of unauthorized disclosure.
  • Whether there is a risk of disclosure of confidential census data when it is decrypted for processing.
  • Whether Statistics Canada has taken sufficient steps to oversee SSC’s handling of census data on its behalf, consistent with its obligations under the Privacy Act.
  • Whether the transfer of personal information by StatCan to SSC for IT infrastructure services is authorized by the SSCA and consistent with the Privacy Act.
  • Whether StatCan has implemented appropriate privacy protection clauses and safeguards in its agreements with SSC.
  • Whether SSC employees with access to confidential census data have been properly sworn in as "deemed employees" under the Statistics Act.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 29, 2018PIPEDA Case Summary #2018-005Indexed Jun 30, 2026

PIPEDA Case Summary #2018-005: Courier company discontinues practice of delivery to a neighbour

A courier company

A complainant alleged that a courier company disclosed her personal information without consent by delivering a package containing financial documents to her neighbour. The courier company's policy allowed drivers to deliver packages to neighbours if the addressee was not home, a practice the complainant was unaware of as she was not expecting the package. The OPC found that the courier company contravened Principle 4.3 of PIPEDA by failing to obtain consent for this practice, either directly from the complainant or by ensuring the shipper had obtained it. The OPC noted that the sensitivity of the package's contents and the complainant's unlisted phone number on the label heightened the need for express consent. The courier company committed to ending the 'delivery to a neighbour' practice in response to the OPC's recommendations. The OPC later confirmed the practice had ceased.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2018-005: Courier company discontinues practice of delivery to a neighbour

Mar 29, 2018PIPEDA Case Summary #2018-005
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a courier company disclosed her personal information without consent by delivering a package containing financial documents to her neighbour. The courier company's policy allowed drivers to deliver packages to neighbours if the addressee was not home, a practice the complainant was unaware of as she was not expecting the package. The OPC found that the courier company contravened Principle 4.3 of PIPEDA by failing to obtain consent for this practice, either directly from the complainant or by ensuring the shipper had obtained it. The OPC noted that the sensitivity of the package's contents and the complainant's unlisted phone number on the label heightened the need for express consent. The courier company committed to ending the 'delivery to a neighbour' practice in response to the OPC's recommendations. The OPC later confirmed the practice had ceased.

Key Issues
  • Whether the courier company obtained valid consent for delivering a package to a neighbour
  • Whether the courier company exercised due diligence to ensure the shipper obtained consent for 'delivery to a neighbour'
  • Whether the information disclosed (name, address, unlisted telephone number, and package contents) was sensitive in context
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 12, 2018Indexed Jun 30, 2026

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Health Canada

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Quick view

Privacy ActWell-founded

Health Canada demonstrates that personal information it collects relates directly to the administration of its Non-Insured Health Benefits Program

Mar 12, 2018
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant, representing over twenty physicians, alleged that Health Canada's Non-Insured Health Benefits (NIHB) Program collected more personal information than necessary for adjudicating drug benefit claims for First Nations and Inuit people. Specifically, the complaint focused on the detailed patient information required for the approval of Limited Use drug benefits. Health Canada maintained that it only collects information essential for providing drug benefits, with data fields based on clinical criteria defined by expert drug-review committees. The OPC reviewed submissions from both parties and consulted with the physicians, focusing on a representative sample of Limited Use forms. The investigation concluded that Health Canada demonstrated a direct connection between the information collected and the purpose of collection, and that the information was necessary for administering the NIHB Program. Consequently, this aspect of the complaint was found to be not well-founded.

Key Issues
  • Whether the information collected by Health Canada on Limited Use forms for drug benefits constitutes personal information under the Privacy Act
  • Whether Health Canada's collection of personal information on Limited Use forms relates directly to an operating program or activity of the institution as required by section 4 of the Privacy Act
  • Whether the specific data fields requesting detailed diagnostic information (e.g., exact number of swollen joints) are necessary for the adjudication of drug benefit claims under the NIHB Program
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 7, 2018PIPEDA Report of Findings #2018-006Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-006: Breach of the World Anti-Doping database

World Anti-Doping Agency (WADA)

The Office of the Privacy Commissioner of Canada (OPC) initiated an investigation into the World Anti-Doping Agency (WADA) following a 2016 data breach of its Anti-Doping Administration and Management System (ADAMS) by the "Fancy Bear" hacking group. The breach led to the public disclosure of highly sensitive personal and health information of 127 athletes, with 11,837 athletes' data potentially accessible. The OPC examined whether WADA had sufficient security safeguards under PIPEDA Principles 4.1.4, 4.7, 4.7.1, 4.7.2, and 4.7.3. The investigation found WADA's safeguards to be insufficient, particularly concerning access controls, monitoring, policies, and encryption, given the sensitivity of the data and the sophisticated nature of the attack. WADA agreed to implement most of the OPC's recommendations, including developing a comprehensive information security framework, strengthening access controls, and employing encryption at rest. The OPC accepted WADA's proposal for optional two-factor authentication for athletes, provided WADA actively promotes its use. Consequently, the matter was concluded as well-founded and conditionally resolved, with the OPC entering into a compliance agreement to monitor WADA's implementation.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Report of Findings #2018-006: Breach of the World Anti-Doping database

Feb 7, 2018PIPEDA Report of Findings #2018-006
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated an investigation into the World Anti-Doping Agency (WADA) following a 2016 data breach of its Anti-Doping Administration and Management System (ADAMS) by the "Fancy Bear" hacking group. The breach led to the public disclosure of highly sensitive personal and health information of 127 athletes, with 11,837 athletes' data potentially accessible. The OPC examined whether WADA had sufficient security safeguards under PIPEDA Principles 4.1.4, 4.7, 4.7.1, 4.7.2, and 4.7.3. The investigation found WADA's safeguards to be insufficient, particularly concerning access controls, monitoring, policies, and encryption, given the sensitivity of the data and the sophisticated nature of the attack. WADA agreed to implement most of the OPC's recommendations, including developing a comprehensive information security framework, strengthening access controls, and employing encryption at rest. The OPC accepted WADA's proposal for optional two-factor authentication for athletes, provided WADA actively promotes its use. Consequently, the matter was concluded as well-founded and conditionally resolved, with the OPC entering into a compliance agreement to monitor WADA's implementation.

Key Issues
  • Whether WADA's security safeguards were appropriate to the sensitivity of the personal information in ADAMS, as required by PIPEDA Principles 4.7, 4.7.1, 4.7.2, and 4.7.3.
  • Whether WADA had implemented adequate policies and practices to give effect to PIPEDA principles, including procedures for protecting personal information, staff training, and policy documentation, under Principle 4.1.4.
  • Whether WADA's access controls, including password management, multi-factor authentication, and oversight of administrative accounts granted to Anti-Doping Organizations (ADOs), were sufficiently robust.
  • Whether WADA's monitoring and logging capabilities were adequate to detect and respond to security anomalies and intrusions.
  • Whether WADA had a proper incident response plan and a documented risk-management framework.
  • Whether WADA employed encryption for data at rest in the ADAMS database.
  • Whether WADA provided sufficient security awareness training to its staff and ADAMS stakeholders.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jan 9, 2018PIPEDA findings #2018-007Indexed Jun 30, 2026

PIPEDA findings #2018-007: Online marketplace needs consent from members before contacting them to join advocacy network

online marketplace

An anonymous complainant challenged an online marketplace's privacy practices after receiving an advocacy email without explicit consent. The complaint alleged unauthorized use of personal information for lobbying, inadequate handling of her privacy complaint, and unnecessary retention of data. The OPC found that the retention allegation was not well-founded. However, the OPC determined that the online marketplace failed to obtain adequate consent for sending advocacy emails and mishandled the complainant's privacy concerns, contravening PIPEDA Principles 4.3 and 4.10 respectively. The organization initially committed to corrective measures, including updating its privacy policy, providing an opt-out for advocacy messages, and improving its complaint handling process. Following the successful implementation of these recommendations, the OPC deemed the consent and challenging compliance matters well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA findings #2018-007: Online marketplace needs consent from members before contacting them to join advocacy network

Jan 9, 2018PIPEDA findings #2018-007
Adjudicator: Daniel Therrien
Plain-Language Summary

An anonymous complainant challenged an online marketplace's privacy practices after receiving an advocacy email without explicit consent. The complaint alleged unauthorized use of personal information for lobbying, inadequate handling of her privacy complaint, and unnecessary retention of data. The OPC found that the retention allegation was not well-founded. However, the OPC determined that the online marketplace failed to obtain adequate consent for sending advocacy emails and mishandled the complainant's privacy concerns, contravening PIPEDA Principles 4.3 and 4.10 respectively. The organization initially committed to corrective measures, including updating its privacy policy, providing an opt-out for advocacy messages, and improving its complaint handling process. Following the successful implementation of these recommendations, the OPC deemed the consent and challenging compliance matters well-founded and resolved.

Key Issues
  • Whether the online marketplace obtained valid consent under PIPEDA Principle 4.3 for using email addresses to send advocacy emails.
  • Whether the online marketplace adequately explained the purposes for using personal information such that the individual could reasonably understand how it would be used (PIPEDA Principle 4.3.2).
  • Whether the form of consent obtained was appropriate given the reasonable expectations of the individual and the sensitivity of the information (PIPEDA Principles 4.3.4, 4.3.5, 4.3.6).
  • Whether the online marketplace enabled the complainant to address concerns to the designated individual accountable for PIPEDA compliance (PIPEDA Principle 4.10).
  • Whether the online marketplace implemented policies and practices to receive and respond to complaints and trained staff (PIPEDA Principles 4.1.4(b), 4.1.4(c)).
  • Whether the online marketplace retained personal information longer than necessary for the identified purpose (PIPEDA Principle 4.5).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jan 8, 2018PIPEDA Report of Findings #2018-001Indexed Jun 30, 2026

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

VTech Holdings Limited

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

Jan 8, 2018PIPEDA Report of Findings #2018-001
Adjudicator: Daniel Therrien
Plain-Language Summary

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Key Issues
  • Whether VTech Holdings Limited failed to adequately safeguard personal information under Principle 4.7 PIPEDA
  • Whether VTech's security safeguards were appropriate to the sensitivity of the information (Principle 4.7 PIPEDA)
  • Whether VTech's safeguards protected against unauthorized access, disclosure, copying, use, or modification (Principle 4.7.1 PIPEDA)
  • Whether the nature of VTech's safeguards varied depending on the sensitivity, amount, distribution, format, and storage method of the information (Principle 4.7.2 PIPEDA)
  • Whether VTech's methods of protection included physical, organizational, and technological measures (Principle 4.7.3 PIPEDA)
  • Whether VTech had adequate testing and maintenance protocols to identify and mitigate vulnerabilities
  • Whether VTech had adequate administrative access controls
  • Whether VTech had adequate cryptographic protection for personal information
  • Whether VTech had sufficient security monitoring and logging to detect threats
  • Whether VTech had a comprehensive security management program
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Dec 27, 2017PIPEDA findings #2017-010Indexed Jun 30, 2026

PIPEDA findings #2017-010: Reasons for retaining customer credit card data explained

A retail store

A complainant objected to a retail store retaining records of her credit card transactions and refusing to delete them upon request. The store initially cited contractual obligations with credit card companies. During the OPC's investigation, the retail company provided a more detailed explanation, including its legal obligations under the Excise Tax Act to retain transactional data. The OPC relayed this information to the complainant, who was satisfied with the explanation and considered the matter resolved. The complainant noted that if this information had been provided initially, she would not have filed a complaint.

Quick view

Personal Information Protection and Electronic Documents ActResolved

PIPEDA findings #2017-010: Reasons for retaining customer credit card data explained

Dec 27, 2017PIPEDA findings #2017-010
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant objected to a retail store retaining records of her credit card transactions and refusing to delete them upon request. The store initially cited contractual obligations with credit card companies. During the OPC's investigation, the retail company provided a more detailed explanation, including its legal obligations under the Excise Tax Act to retain transactional data. The OPC relayed this information to the complainant, who was satisfied with the explanation and considered the matter resolved. The complainant noted that if this information had been provided initially, she would not have filed a complaint.

Key Issues
  • Whether a retail store's retention of credit card transaction records without deletion upon request violated PIPEDA's consent principle
  • Whether legal or contractual obligations justified the retention of personal information despite a withdrawal of consent
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Dec 20, 2017PIPEDA Case Summary #2017-006Indexed Jun 30, 2026

PIPEDA Case Summary #2017-006: Using SIN for identity verification cannot be a condition of service

A financial institution

A complainant alleged that a financial institution required customers to provide their Social Insurance Number (SIN) to credit reporting agencies for identity verification when opening a savings account, even though the SIN was not needed for income reporting. The financial institution argued that using the SIN for identity verification was beneficial for maintaining data integrity and cited FINTRAC guidelines. The OPC reviewed FINTRAC and Employment and Social Development Canada (ESDC) guidelines and found no requirement or suggestion for using SINs for identity verification. The OPC concluded that requiring consent for this practice as a condition of service contravened Principle 4.3.3 of PIPEDA. The financial institution agreed to make the use of SIN for identity verification optional, and the complaint was deemed well-founded and conditionally resolved. A follow-up confirmed full compliance.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Case Summary #2017-006: Using SIN for identity verification cannot be a condition of service

Dec 20, 2017PIPEDA Case Summary #2017-006
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a financial institution required customers to provide their Social Insurance Number (SIN) to credit reporting agencies for identity verification when opening a savings account, even though the SIN was not needed for income reporting. The financial institution argued that using the SIN for identity verification was beneficial for maintaining data integrity and cited FINTRAC guidelines. The OPC reviewed FINTRAC and Employment and Social Development Canada (ESDC) guidelines and found no requirement or suggestion for using SINs for identity verification. The OPC concluded that requiring consent for this practice as a condition of service contravened Principle 4.3.3 of PIPEDA. The financial institution agreed to make the use of SIN for identity verification optional, and the complaint was deemed well-founded and conditionally resolved. A follow-up confirmed full compliance.

Key Issues
  • Whether requiring a SIN for identity verification as a condition of service contravenes Principle 4.3.3 of PIPEDA
  • Whether FINTRAC or ESDC guidelines require or suggest the use of SINs for identity verification
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Nov 2, 2017PIPEDA Report of Findings #2017-009Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-009: Airline relies on access exemption to refuse traveler’s access to their personal information

An airline

A traveler complained that an airline failed to provide complete access to his personal information, specifically documents and correspondence related to being denied boarding in 2015. The airline invoked exemptions under PIPEDA, arguing the information was collected to investigate a breach of agreement or contravention of law (s.7(1)(b)) and disclosed to a government institution for law enforcement purposes (s.7(3)(c.1)(ii)). The OPC found that the collection without consent was justified under s.7(1)(b) because it was for investigating potential non-compliance with the Immigration and Refugee Protection Act, and that requiring consent would have compromised the investigation. The OPC also found the disclosure to a government institution was permissible under s.7(3)(c.1)(ii). Furthermore, the OPC determined that the airline was prohibited from providing access to the requested information under s.9(2.4) because the government institution objected to its release. Therefore, the OPC concluded that the airline properly relied on the exemptions.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

PIPEDA Report of Findings #2017-009: Airline relies on access exemption to refuse traveler’s access to their personal information

Nov 2, 2017PIPEDA Report of Findings #2017-009
Adjudicator: Daniel Therrien
Plain-Language Summary

A traveler complained that an airline failed to provide complete access to his personal information, specifically documents and correspondence related to being denied boarding in 2015. The airline invoked exemptions under PIPEDA, arguing the information was collected to investigate a breach of agreement or contravention of law (s.7(1)(b)) and disclosed to a government institution for law enforcement purposes (s.7(3)(c.1)(ii)). The OPC found that the collection without consent was justified under s.7(1)(b) because it was for investigating potential non-compliance with the Immigration and Refugee Protection Act, and that requiring consent would have compromised the investigation. The OPC also found the disclosure to a government institution was permissible under s.7(3)(c.1)(ii). Furthermore, the OPC determined that the airline was prohibited from providing access to the requested information under s.9(2.4) because the government institution objected to its release. Therefore, the OPC concluded that the airline properly relied on the exemptions.

Key Issues
  • Whether the airline's collection of personal information without consent was justified under paragraph 7(1)(b) of PIPEDA
  • Whether the airline's disclosure of personal information without consent was justified under subparagraph 7(3)(c.1)(ii) of PIPEDA
  • Whether the airline was required to provide access to the requested personal information under Principle 4.9 of Schedule 1, given the exemptions under section 9 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 29, 2017PIPEDA findings #2017-012Indexed Jun 30, 2026

PIPEDA findings #2017-012: Financial institution discloses too much information in response to production order

A financial institution

A complainant alleged that his financial institution improperly disclosed his personal information, specifically RESP account details from 1999, to a municipal police service. The financial institution claimed the disclosure was made under a production order or, alternatively, with the complainant's consent via its privacy policy. The OPC found that the disclosed 1999 RESP information fell outside the scope of the production order, which specified a different date range and nature of information. The OPC also rejected the financial institution's argument of consent, stating that the privacy policy's general language was insufficient for informed consent, especially for sensitive financial information. The financial institution agreed to review its procedures and provide training to ensure compliance with production orders. The complaint was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA findings #2017-012: Financial institution discloses too much information in response to production order

Aug 29, 2017PIPEDA findings #2017-012
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that his financial institution improperly disclosed his personal information, specifically RESP account details from 1999, to a municipal police service. The financial institution claimed the disclosure was made under a production order or, alternatively, with the complainant's consent via its privacy policy. The OPC found that the disclosed 1999 RESP information fell outside the scope of the production order, which specified a different date range and nature of information. The OPC also rejected the financial institution's argument of consent, stating that the privacy policy's general language was insufficient for informed consent, especially for sensitive financial information. The financial institution agreed to review its procedures and provide training to ensure compliance with production orders. The complaint was found to be well-founded and resolved.

Key Issues
  • Whether the disclosure of RESP account information from 1999 was justified under paragraph 7(3)(c) of PIPEDA as being required by a production order
  • Whether the financial institution could rely on the complainant's consent, as stipulated in its privacy policy, for the disclosure of personal information to law enforcement
  • Whether the RESP account information constituted sensitive personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Aug 28, 2017PIPEDA Report of Findings #2017-001Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-001: Drug activity history in property reports deemed not publicly available

A property report provider

A complainant alleged that a company selling "home history reports" collected, used, and disclosed personal information without consent, specifically sales history, drug activity, and insurance claims. The OPC found that sales history was no longer included in reports and insurance claims information, as clarified by the respondent, related to property damage paid to third parties, not individuals, thus not constituting personal information. However, information about drug activity was deemed personal information because it could be linked to identifiable individuals and suggested their involvement in drug activity. The OPC concluded that this drug activity information was not "publicly available" under PIPEDA Regulations, requiring consent for its use. The respondent agreed to cease including drug activity details in its reports, leading to a well-founded and resolved outcome.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2017-001: Drug activity history in property reports deemed not publicly available

Aug 28, 2017PIPEDA Report of Findings #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a company selling "home history reports" collected, used, and disclosed personal information without consent, specifically sales history, drug activity, and insurance claims. The OPC found that sales history was no longer included in reports and insurance claims information, as clarified by the respondent, related to property damage paid to third parties, not individuals, thus not constituting personal information. However, information about drug activity was deemed personal information because it could be linked to identifiable individuals and suggested their involvement in drug activity. The OPC concluded that this drug activity information was not "publicly available" under PIPEDA Regulations, requiring consent for its use. The respondent agreed to cease including drug activity details in its reports, leading to a well-founded and resolved outcome.

Key Issues
  • Whether sales history information constituted personal information and was collected, used, or disclosed without consent
  • Whether insurance claims information constituted personal information
  • Whether drug activity information constituted personal information
  • Whether drug activity information was "publicly available" under the Regulations Specifying Publicly Available Information
  • Whether the respondent obtained adequate consent for the collection, use, and disclosure of personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Aug 28, 2017PIPEDA Report of Findings #2017-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2017-002: Canadian adware developer Wajam Internet Technologies Inc. breaches multiple provisions of PIPEDA

Wajam Internet Technologies Inc.

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Wajam Internet Technologies Inc., an adware developer, regarding its software's installation, consent, uninstallation, and data handling practices. The software, Wajam or Social2Search, tracked online search queries, overlaid social media results, and displayed contextual ads. The OPC investigated whether Wajam obtained meaningful consent for installation, allowed users to withdraw consent, and adequately safeguarded personal information. The investigation found that Wajam lacked a privacy accountability framework, failed to obtain meaningful consent due to problematic third-party distribution methods and misleading information, indefinitely retained unencrypted raw user data, and had insufficient safeguards. All examined matters related to accountability, consent, limiting retention, safeguards, and openness were found to be well-founded. Wajam, having sold its assets to a Hong Kong-based company, IMTL, claimed it was unable to implement the OPC's recommendations, though it agreed to securely destroy Canadian user data. The OPC requested Wajam provide the report to IMTL and stated it would monitor the situation and engage international counterparts.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

PIPEDA Report of Findings #2017-002: Canadian adware developer Wajam Internet Technologies Inc. breaches multiple provisions of PIPEDA

Aug 28, 2017PIPEDA Report of Findings #2017-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Wajam Internet Technologies Inc., an adware developer, regarding its software's installation, consent, uninstallation, and data handling practices. The software, Wajam or Social2Search, tracked online search queries, overlaid social media results, and displayed contextual ads. The OPC investigated whether Wajam obtained meaningful consent for installation, allowed users to withdraw consent, and adequately safeguarded personal information. The investigation found that Wajam lacked a privacy accountability framework, failed to obtain meaningful consent due to problematic third-party distribution methods and misleading information, indefinitely retained unencrypted raw user data, and had insufficient safeguards. All examined matters related to accountability, consent, limiting retention, safeguards, and openness were found to be well-founded. Wajam, having sold its assets to a Hong Kong-based company, IMTL, claimed it was unable to implement the OPC's recommendations, though it agreed to securely destroy Canadian user data. The OPC requested Wajam provide the report to IMTL and stated it would monitor the situation and engage international counterparts.

Key Issues
  • Whether Wajam Internet Technologies Inc. had an adequate privacy accountability framework in place (Principle 4.1.4 PIPEDA)
  • Whether Wajam obtained meaningful consent from individuals for the installation and operation of its software (Principle 4.3, 4.3.2, 4.3.5 PIPEDA, s.6.1 PIPEDA)
  • Whether Wajam's third-party distribution model ensured meaningful consent for software installation
  • Whether Wajam's multiple-offer consent screens provided sufficient information for meaningful consent
  • Whether the information provided by Wajam about its software's functionality and privacy practices was accurate and complete (Principle 4.2, 4.3.2, 4.3.5 PIPEDA)
  • Whether Wajam permitted users to withdraw consent by making it difficult to uninstall its software (Principle 4.3.8 PIPEDA)
  • Whether Wajam was responsible for unsolicited ads and fake offers presented during the uninstallation process (Principle 4.3 PIPEDA)
  • Whether Wajam limited the retention of personal information to only as long as necessary for identified purposes (Principle 4.5, 4.5.2 PIPEDA)
  • Whether Wajam was open about its policies and practices relating to the management of personal information (Principle 4.8 PIPEDA)
  • Whether Wajam adequately safeguarded users' personal information against loss, theft, or unauthorized access, including during transmission and storage (Principle 4.7.1, 4.7.2, 4.7.3 PIPEDA)