BreachOfPrivacy

Canadian Privacy Decisions

The comprehensive archive of Canadian privacy decisions from federal, provincial, and territorial commissioners — with AI-summarized plain-language summaries for every decision.

19,605 decisions in archive
Flag of Newfoundland and Labrador
Newfoundland and Labrador
Subscribers only
Access to Information and Protection of Privacy Act, 2015

P-2026-001 — Department of Education and Early Childhood Development

Subscribe to access Newfoundland and Labrador decisions.

Flag of Saskatchewan
Saskatchewan
Subscribers only
Local Authority Freedom of Information and Protection of Privacy Act

Review Report 192-2025

Subscribe to access Saskatchewan decisions.

Quebec
Subscribers only
Act respecting access to documents held by public bodies and the protection of personal information

Kamel c. Ministère du Conseil exécutif, 2026 QCCAI 167 (CanLII)

Subscribe to access Quebec decisions.

Flag of Ontario
Ontario
Subscribers only
Freedom of Information and Protection of Privacy Act

Order PO-4826 - 2026-05-07

Subscribe to access Ontario decisions.

Flag of British Columbia
British Columbia
Subscribers only
Freedom of Information and Protection of Privacy Act

Order qathet Regional District

Subscribe to access British Columbia decisions.

Flag of British Columbia
British Columbia
Subscribers only
Personal Information Protection Act

Order Altrad Services Ltd.

Subscribe to access British Columbia decisions.

Federal (Canada)Privacy ActWell-founded & conditionally resolved
May 7, 2026Special report to Parliament· Indexed May 8, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

Canada Revenue Agency

This special report details an investigation into unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency (CRA). The Office of the Privacy Commissioner (OPC) found that the CRA contravened the Privacy Act regarding accuracy and disclosure of personal information. While the CRA has made efforts to improve its security, shortcomings remain in prevention, monitoring, detection, remediation, and governance, particularly concerning the handling of "Unauthorized Use of Taxpayer Information by a Third Party" (UUTP) incidents. The investigation concluded that the CRA contravened subsections 6(2) and 8(2) of the Act.

Quick View

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency

May 7, 2026Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

This special report details an investigation into unauthorized disclosures and modifications of taxpayer personal information at the Canada Revenue Agency (CRA). The Office of the Privacy Commissioner (OPC) found that the CRA contravened the Privacy Act regarding accuracy and disclosure of personal information. While the CRA has made efforts to improve its security, shortcomings remain in prevention, monitoring, detection, remediation, and governance, particularly concerning the handling of "Unauthorized Use of Taxpayer Information by a Third Party" (UUTP) incidents. The investigation concluded that the CRA contravened subsections 6(2) and 8(2) of the Act.

Key Issues
  • Adequacy of safeguards to protect taxpayer personal information from unauthorized disclosure and modification.
  • Timeliness and strength of multi-factor authentication implementation.
  • Effectiveness of monitoring and detection mechanisms for UUTPs.
  • Coordination and proactivity of the CRA's governance for addressing UUTPs.
Flag of Ontario
Ontario
Subscribers only
Freedom of Information and Protection of Privacy Act

Order PO-4824 - 2026-05-06

Subscribe to access Ontario decisions.

Flag of Ontario
Ontario
Subscribers only
Freedom of Information and Protection of Privacy Act

Order PO-4823-F - 2026-05-06

Subscribe to access Ontario decisions.

Flag of Ontario
Ontario
Subscribers only
Freedom of Information and Protection of Privacy Act

Order PO-4825 - 2026-05-06

Subscribe to access Ontario decisions.

Flag of Ontario
Ontario
Subscribers only
Municipal Freedom of Information and Protection of Privacy Act

Order MO-4794 - 2026-05-06

Subscribe to access Ontario decisions.

Flag of British Columbia
British Columbia
Subscribers only
Personal Information Protection Act

Overview of Joint investigation of OpenAI OpCo, LLC

Subscribe to access British Columbia decisions.

Flag of British Columbia
British Columbia
Subscribers only
Personal Information Protection Act

INVESTIGATION REPORT 26-03

Subscribe to access British Columbia decisions.

Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & unresolved
May 6, 2026PIPEDA Findings #2026-002· Indexed May 6, 2026

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

OpenAI OpCo, LLC

This joint investigation by privacy authorities across Canada found that OpenAI contravened privacy laws in its collection, use, and disclosure of personal information through its ChatGPT models GPT-3.5 and GPT-4. Specifically, the investigation found that OpenAI's collection of personal information from publicly accessible websites for training purposes was overbroad and inappropriate. The company also failed to obtain valid consent and be sufficiently transparent about its data practices. While OpenAI has since implemented new mitigation measures and committed to further improvements, some provincial authorities found the new measures insufficient to meet their specific legislative requirements.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded & unresolved

PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC

May 6, 2026PIPEDA Findings #2026-002
Adjudicator: Philippe Dufresne
Plain-Language Summary

This joint investigation by privacy authorities across Canada found that OpenAI contravened privacy laws in its collection, use, and disclosure of personal information through its ChatGPT models GPT-3.5 and GPT-4. Specifically, the investigation found that OpenAI's collection of personal information from publicly accessible websites for training purposes was overbroad and inappropriate. The company also failed to obtain valid consent and be sufficiently transparent about its data practices. While OpenAI has since implemented new mitigation measures and committed to further improvements, some provincial authorities found the new measures insufficient to meet their specific legislative requirements.

Key Issues
  • Appropriateness of purpose for data collection and use
  • Validity of consent and transparency obligations
  • Accuracy of generated information
  • Individual rights to access, correction, and deletion