The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

38 decisions matching
Federal (Canada)Access to Information ActResolved
Federal (Canada) flag
May 14, 2015Indexed Jun 30, 2026

Investigation into an access to information request for the Long-gun Registry

Royal Canadian Mounted Police

The complainant requested access to the Firearms Registry database from the Royal Canadian Mounted Police (RCMP) on March 27, 2012, prior to the enactment of the Ending the Long-gun Registry Act. The complainant alleged that the RCMP provided an incomplete response, failed to justify the incompleteness, and obstructed the right of access by destroying responsive records. The investigation focused on whether the RCMP's actions, particularly the destruction of records, constituted an obstruction of the right of access under section 67.1 of the Access to Information Act. The Commissioner examined the circumstances surrounding the destruction of the Long-gun Registry data. The Commissioner found that the destruction of the records was carried out in accordance with a valid legislative process and did not constitute an obstruction of the right of access.

Quick view

Access to Information ActResolved

Investigation into an access to information request for the Long-gun Registry

May 14, 2015
Adjudicator: Suzanne Legault
Plain-Language Summary

The complainant requested access to the Firearms Registry database from the Royal Canadian Mounted Police (RCMP) on March 27, 2012, prior to the enactment of the Ending the Long-gun Registry Act. The complainant alleged that the RCMP provided an incomplete response, failed to justify the incompleteness, and obstructed the right of access by destroying responsive records. The investigation focused on whether the RCMP's actions, particularly the destruction of records, constituted an obstruction of the right of access under section 67.1 of the Access to Information Act. The Commissioner examined the circumstances surrounding the destruction of the Long-gun Registry data. The Commissioner found that the destruction of the records was carried out in accordance with a valid legislative process and did not constitute an obstruction of the right of access.

Key Issues
  • Whether the information provided was incomplete
  • Whether the RCMP justified the incomplete response
  • Whether the destruction of responsive records by the RCMP obstructed the right of access under section 67.1 of the Act
Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Employment and Social Development Canada (ESDC)

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Quick view

Privacy ActWell-founded & resolved

Lost USB key from Employment and Social Development Canada reinforces lessons learned

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details an investigation into the loss of a USB key containing the personal information of 5,045 Canada Pension Plan Disability appellants from an ESDC office. The USB key, which was neither password-protected nor encrypted, contained sensitive data including SINs, medical conditions, and dates of birth. The investigation found weaknesses in physical, technological, administrative, and personnel controls at both ESDC and Justice Canada, as a Justice Canada lawyer had custody of the key when it went missing. The OPC concluded that both departments failed to translate their privacy and security policies into meaningful business practices. Both ESDC and Justice Canada accepted nine recommendations from the OPC to improve their protection of personal information.

Key Issues
  • Whether Employment and Social Development Canada (ESDC) adequately protected personal information on a lost USB key
  • Whether Justice Canada adequately protected personal information on a lost USB key while in its custody
  • Whether physical controls for personal information were adequate
  • Whether technological controls (encryption, password protection) for personal information were adequate
  • Whether administrative controls for personal information were adequate
  • Whether personnel controls for personal information were adequate
  • Whether ESDC translated its privacy and security policies into meaningful business practices
  • Whether Justice Canada translated its privacy and security policies into meaningful business practices
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Oct 30, 2014Indexed Jun 30, 2026

Woman fails in attempt to return personal information to Canada Revenue Agency

Canada Revenue Agency (CRA)

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Quick view

Privacy ActWell-founded

Woman fails in attempt to return personal information to Canada Revenue Agency

Oct 30, 2014
Adjudicator: Daniel Therrien
Plain-Language Summary

A B.C. woman received a package from the Canada Revenue Agency (CRA) containing her deceased daughter's tax information along with the confidential personal information of five other individuals. She attempted to report the data breach and return the misdirected information to the CRA through various channels, including phone calls and an in-person visit to a tax centre, but faced significant difficulties. Only after she contacted a CBC news reporter did the CRA take prompt action to retrieve the misdirected records. The OPC launched a Commissioner-initiated complaint and found that the CRA had breached the privacy rights of the taxpayers involved. The CRA committed to and implemented remedial measures to prevent similar incidents and improve its internal procedures for client service and misdirected mail.

Key Issues
  • Whether the Canada Revenue Agency breached the privacy rights of taxpayers by mistakenly sending confidential personal information to an unauthorized individual
  • Whether the Canada Revenue Agency's procedures for handling misdirected mail and breach reporting were adequate
  • Whether the Canada Revenue Agency's client service channels were accessible for reporting privacy breaches
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Apr 10, 2014Indexed Jun 30, 2026

Interference with Access to Information: Part 2

Public Works and Government Services Canada

The Information Commissioner initiated a systemic investigation under section 39 of the Access to Information Act into Public Works and Government Services Canada (PWGSC). The investigation focused on the processing of eight access to information or consultation requests received by PWGSC between July 22, 2008, and January 19, 2010. The primary concern was the possibility of interference in the processing of these requests. This report, titled "Interference with Access to Information: Part 2," details the Commissioner's findings regarding the alleged interference. The investigation aimed to determine if the institution's handling of these requests was appropriate or if there were instances of improper influence or obstruction.

Quick view

Access to Information ActSystemic Investigation

Interference with Access to Information: Part 2

Apr 10, 2014
Adjudicator: Suzanne Legault
Plain-Language Summary

The Information Commissioner initiated a systemic investigation under section 39 of the Access to Information Act into Public Works and Government Services Canada (PWGSC). The investigation focused on the processing of eight access to information or consultation requests received by PWGSC between July 22, 2008, and January 19, 2010. The primary concern was the possibility of interference in the processing of these requests. This report, titled "Interference with Access to Information: Part 2," details the Commissioner's findings regarding the alleged interference. The investigation aimed to determine if the institution's handling of these requests was appropriate or if there were instances of improper influence or obstruction.

Key Issues
  • Whether there was interference in the processing of access to information requests at Public Works and Government Services Canada
  • Whether Public Works and Government Services Canada properly processed eight specific access to information or consultation requests
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Mar 24, 2014Indexed Jun 30, 2026

IP54-56/2014 — Employment and Social Development Canada

Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Quick view

Privacy ActWell-founded

IP54-56/2014 — Employment and Social Development Canada

Mar 24, 2014
Adjudicator: Chantal Bernier
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) initiated a complaint against Employment and Social Development Canada (ESDC) following the loss of an unencrypted external hard drive containing the personal information of 583,000 Canada student loan borrowers and 250 ESDC employees. The investigation found that ESDC failed to implement adequate physical, technical, administrative, and personnel security controls, leading to contraventions of sections 6(3), 7, or 8 of the Privacy Act. The lost data included highly sensitive details such as Social Insurance Numbers, names, addresses, dates of birth, and comprehensive student loan financial information. While ESDC took extensive mitigation steps post-incident, including public notification and credit protection offers, the OPC concluded the complaint was well-founded due to the systemic failures in safeguarding personal information. ESDC accepted all ten of the OPC's recommendations aimed at improving its privacy management framework, and was well-advanced in their implementation. The OPC will conduct a follow-up review in one year to confirm full implementation.

Key Issues
  • Whether ESDC failed to implement adequate physical security controls for personal information stored on portable media.
  • Whether ESDC failed to implement adequate technical security controls, such as encryption and risk assessments, for personal information on portable media.
  • Whether ESDC failed to implement adequate administrative controls, including asset inventory, information classification, and lifecycle management, for personal information.
  • Whether ESDC failed to implement adequate personnel security controls, such as employee training, awareness, and accountability, regarding personal information.
  • Whether ESDC contravened subsection 6(3) of the Privacy Act by failing to properly dispose of personal information.
  • Whether ESDC contravened section 7 of the Privacy Act regarding the use of personal information.
  • Whether ESDC contravened section 8 of the Privacy Act regarding the disclosure of personal information.
  • Whether the delay in notifying affected individuals of the breach was reasonable.
  • Whether the scope of personal information reported to affected individuals in the notification letters was complete.
Federal (Canada)Access to Information ActSystemic Investigation
Federal (Canada) flag
Nov 28, 2013Indexed Jun 30, 2026

Access to information at risk from instant messaging

Crown-Indigenous Relations and Northern Affairs / Indigenous Services

In August 2012, the Information Commissioner launched a systemic investigation into the use and preservation of non-email, text-based messages on government-issued wireless devices, specifically instant messaging and PINs. This investigation was prompted by a complaint against Indian and Northern Affairs Canada (now Aboriginal Affairs and Northern Development Canada) where a complainant received an email suggesting the use of "pin" instead of email for communication. During the investigation of that complaint, it was discovered that relevant BlackBerry devices had been replaced and destroyed, leading to the permanent loss of potentially responsive information. Due to this incident and a rise in similar complaints about missing records, the Commissioner initiated a self-complaint under section 30(1)(f) of the ATIA to examine the impact of instant messaging on access to information. The investigation focused on 11 federal institutions to assess their practices regarding the retention of these types of communications.

Quick view

Access to Information ActSystemic Investigation

Access to information at risk from instant messaging

Nov 28, 2013
Adjudicator: Suzanne Legault
Plain-Language Summary

In August 2012, the Information Commissioner launched a systemic investigation into the use and preservation of non-email, text-based messages on government-issued wireless devices, specifically instant messaging and PINs. This investigation was prompted by a complaint against Indian and Northern Affairs Canada (now Aboriginal Affairs and Northern Development Canada) where a complainant received an email suggesting the use of "pin" instead of email for communication. During the investigation of that complaint, it was discovered that relevant BlackBerry devices had been replaced and destroyed, leading to the permanent loss of potentially responsive information. Due to this incident and a rise in similar complaints about missing records, the Commissioner initiated a self-complaint under section 30(1)(f) of the ATIA to examine the impact of instant messaging on access to information. The investigation focused on 11 federal institutions to assess their practices regarding the retention of these types of communications.

Key Issues
  • Impact of instant messaging on the right of access to information
  • Preservation of non-email, text-based messages on government-issued wireless devices
  • Retention policies and practices for instant messages and PIN communications
  • Loss of records due to device replacement and destruction
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 4, 2006Incident Summary #3Indexed Jun 30, 2026

Incident Summary #3: Misdirected faxes - December 4, 2006

Two Canadian banks

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #3: Misdirected faxes - December 4, 2006

Dec 4, 2006Incident Summary #3
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Key Issues
  • Whether organizations adequately safeguard personal information to prevent inappropriate disclosure (Principle 4.7 PIPEDA)
  • Whether organizations implement effective policies and procedures to give effect to fair information practices (Principle 4.1 PIPEDA)
  • Whether employees are attuned to privacy issues and can respond to problems when they arise
  • Whether organizations notify affected customers of privacy breaches
  • Whether organizations have processes for confirming correct fax transmission
  • Whether organizations have measures to recover erroneously transmitted customer information
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Apr 18, 2005Incident Summary #2Indexed Jun 30, 2026

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

CIBC

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #2: CIBC's privacy practices failed in cases of misdirected faxes - April 18, 2005

Apr 18, 2005Incident Summary #2
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated incidents where CIBC misdirected faxes containing customer personal information to a US company and a business in Dorval, Quebec, over several years. Despite repeated notifications from the recipients, CIBC's attempts to resolve the issue were ineffective, and the bank failed to adequately recover the misdirected information or notify affected customers. The OPC found that CIBC's privacy practices failed at a basic organizational level, as employees did not fully recognize the misdirected faxes as privacy breaches and privacy officials were not informed. CIBC subsequently implemented remedial measures, including banning branch faxing, reviewing fax processes, and restructuring internal privacy management. The OPC recommended full implementation of planned changes, immediate notification of affected individuals in future breaches, and reporting back to the Assistant Privacy Commissioner. The OPC's Audit and Review Branch planned to verify the bank's actions.

Key Issues
  • Whether CIBC's privacy practices adequately protected personal information from misdirected faxes
  • Whether CIBC effectively responded to notifications of misdirected faxes
  • Whether CIBC appropriately recovered misdirected personal information
  • Whether CIBC adequately notified affected customers of privacy breaches
  • Whether CIBC employees recognized misdirected faxes as privacy issues
  • Whether CIBC's internal privacy management structure was sufficient to address breaches