The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

616 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Jul 27, 2009Report of FindingsIndexed Jun 30, 2026

Report of Findings: Complaint under PIPEDA against Accusearch Inc., doing business as Abika.com

Accusearch Inc., doing business as Abika.com

CIPPIC complained that Abika.com, a U.S. company, collected, used, and disclosed Canadians' personal information without consent, compiled and disclosed inaccurate personal information through its "psychological profile" service, and used personal information for inappropriate purposes. The OPC initially declined jurisdiction, but the Federal Court ordered the investigation to proceed. The OPC found that Abika collected and disclosed personal information, including telephone records, of Canadians without their knowledge or consent, often for inappropriate purposes such as investigating partners. While the OPC found the accuracy complaint not well-founded due to lack of verifiable evidence, it concluded that Abika contravened PIPEDA Principles 4.3 and subsection 5(3). Abika failed to respond adequately to the OPC's recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Report of Findings: Complaint under PIPEDA against Accusearch Inc., doing business as Abika.com

Jul 27, 2009Report of Findings
Adjudicator: Jennifer Stoddart
Plain-Language Summary

CIPPIC complained that Abika.com, a U.S. company, collected, used, and disclosed Canadians' personal information without consent, compiled and disclosed inaccurate personal information through its "psychological profile" service, and used personal information for inappropriate purposes. The OPC initially declined jurisdiction, but the Federal Court ordered the investigation to proceed. The OPC found that Abika collected and disclosed personal information, including telephone records, of Canadians without their knowledge or consent, often for inappropriate purposes such as investigating partners. While the OPC found the accuracy complaint not well-founded due to lack of verifiable evidence, it concluded that Abika contravened PIPEDA Principles 4.3 and subsection 5(3). Abika failed to respond adequately to the OPC's recommendations.

Key Issues
  • Whether Abika collected, used, and disclosed personal information of individuals living in Canada without their knowledge and consent, in contravention of Principle 4.3
  • Whether Abika compiled and disclosed inaccurate personal information through its "psychological profile" service, in contravention of Principle 4.6
  • Whether Abika collected, used, and disclosed personal information about Canadians for inappropriate purposes, in contravention of subsection 5(3)
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jan 29, 2009Indexed Jun 30, 2026

Investigation finds no evidence that Canadian Human Rights Commission accessed individual's Internet connection

Canadian Human Rights Commission (CHRC)

An individual complained that the Canadian Human Rights Commission (CHRC) improperly collected and used her personal information by accessing her wireless internet connection to post messages on a white supremacist website. The OPC investigated whether the CHRC contravened sections 4 to 8 of the Privacy Act. The investigation first determined that the complainant's IP address, when linked to her identity via a subpoena, constituted personal information under section 3 of the Act. However, the OPC found no evidence that the CHRC ever collected or had knowledge of the complainant's personal information prior to the allegations. Technological experts suggested the association of the complainant's IP address with the CHRC was likely a third-party mismatch. Consequently, the Assistant Privacy Commissioner concluded there was no contravention of the Privacy Act.

Quick view

Privacy ActNot well-founded

Investigation finds no evidence that Canadian Human Rights Commission accessed individual's Internet connection

Jan 29, 2009
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that the Canadian Human Rights Commission (CHRC) improperly collected and used her personal information by accessing her wireless internet connection to post messages on a white supremacist website. The OPC investigated whether the CHRC contravened sections 4 to 8 of the Privacy Act. The investigation first determined that the complainant's IP address, when linked to her identity via a subpoena, constituted personal information under section 3 of the Act. However, the OPC found no evidence that the CHRC ever collected or had knowledge of the complainant's personal information prior to the allegations. Technological experts suggested the association of the complainant's IP address with the CHRC was likely a third-party mismatch. Consequently, the Assistant Privacy Commissioner concluded there was no contravention of the Privacy Act.

Key Issues
  • Whether the complainant's IP address constituted personal information under section 3 of the Privacy Act
  • Whether the CHRC collected the complainant's personal information
  • Whether the CHRC improperly used, disclosed, or retained the complainant's personal information in contravention of sections 4 to 8 of the Privacy Act
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
May 29, 2008Executive SummaryIndexed Jun 30, 2026

Executive Summary: Law School Admission Council Investigation

Law School Admission Council (LSAC)

A complainant objected to the Law School Admission Council's (LSAC) requirement for Canadian students to provide fingerprints to write the Law School Admission Test (LSAT). LSAC, a US-based non-profit, argued it was outside PIPEDA's jurisdiction and its activities were educational. The Assistant Privacy Commissioner found sufficient links to Canada for PIPEDA to apply and determined LSAC's activities were administrative, not educational. Applying a four-part test, the Assistant Commissioner found fingerprinting was not demonstrably necessary, effective, or proportional, and less privacy-invasive alternatives existed. LSAC agreed to cease fingerprint collection but reserved the right to reinstate it, proposing photographic evidence instead. The Assistant Commissioner found the complaint well-founded due to the disproportionate nature of fingerprint collection and LSAC's reservation to reinstate the policy.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Executive Summary: Law School Admission Council Investigation

May 29, 2008Executive Summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant objected to the Law School Admission Council's (LSAC) requirement for Canadian students to provide fingerprints to write the Law School Admission Test (LSAT). LSAC, a US-based non-profit, argued it was outside PIPEDA's jurisdiction and its activities were educational. The Assistant Privacy Commissioner found sufficient links to Canada for PIPEDA to apply and determined LSAC's activities were administrative, not educational. Applying a four-part test, the Assistant Commissioner found fingerprinting was not demonstrably necessary, effective, or proportional, and less privacy-invasive alternatives existed. LSAC agreed to cease fingerprint collection but reserved the right to reinstate it, proposing photographic evidence instead. The Assistant Commissioner found the complaint well-founded due to the disproportionate nature of fingerprint collection and LSAC's reservation to reinstate the policy.

Key Issues
  • Whether LSAC's activities fall within the scope of PIPEDA despite its non-profit status and US location
  • Whether LSAC's activities are educational in nature or serve administrative needs
  • Whether the collection of thumbprints is demonstrably necessary to meet a specific need
  • Whether the collection of thumbprints is likely to be effective in meeting that need
  • Whether the loss of privacy from thumbprint collection is proportional to the benefit gained
  • Whether there is a less privacy-invasive way of achieving the same end as thumbprint collection
  • Whether the collection of photographs as an alternative is acceptable under PIPEDA
  • Whether LSAC's reservation of the right to reinstate its fingerprint policy is compliant with PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded
Federal (Canada) flag
Feb 12, 2008BackgrounderIndexed Jun 30, 2026

Backgrounder: Ticketmaster Investigation

Ticketmaster Canada Limited

The OPC investigated Ticketmaster Canada Limited (TM) following a complaint that its practices for collecting, disclosing, and using customer personal information for marketing purposes did not comply with PIPEDA. The complainant alleged that customers were not properly informed or given a viable alternative to sharing their information for marketing. The Assistant Privacy Commissioner found that TM failed to uphold the principles of openness and consent. TM subsequently revised its privacy policy and online notifications to explicitly communicate information sharing practices and provide clear opt-in options for marketing. The investigation concluded that the issues were resolved satisfactorily, but the Assistant Commissioner expressed concern about the well-founded violations several years after PIPEDA's enactment.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded

Backgrounder: Ticketmaster Investigation

Feb 12, 2008Backgrounder
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated Ticketmaster Canada Limited (TM) following a complaint that its practices for collecting, disclosing, and using customer personal information for marketing purposes did not comply with PIPEDA. The complainant alleged that customers were not properly informed or given a viable alternative to sharing their information for marketing. The Assistant Privacy Commissioner found that TM failed to uphold the principles of openness and consent. TM subsequently revised its privacy policy and online notifications to explicitly communicate information sharing practices and provide clear opt-in options for marketing. The investigation concluded that the issues were resolved satisfactorily, but the Assistant Commissioner expressed concern about the well-founded violations several years after PIPEDA's enactment.

Key Issues
  • Whether Ticketmaster's privacy policy met the openness principle of PIPEDA
  • Whether Ticketmaster obtained valid consent for the use of personal information for marketing purposes
  • Whether customers were properly informed about the use of their personal information for marketing
  • Whether customers were provided a viable opt-in/opt-out option for marketing without penalty
  • Whether Ticketmaster's agreements with event providers ensured compliance with customer preferences
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 15, 2007Settled Case summary #30Indexed Jun 30, 2026

Settled Case summary #30: Solicitor’s lien insufficient grounds to deny access to personal information (November 15, 2007)

A law firm

A client sought access to her personal information from her former lawyer. The lawyer refused access, citing outstanding fees and asserting a solicitor's lien on the client's file, believing that providing access could jeopardize payment. The OPC noted that PIPEDA's subsection 9(3) provides an exhaustive list of reasons for refusing access, which does not include a solicitor's lien. Therefore, lawyers must grant access to personal information even if a valid lien exists. The OPC suggested that allowing the individual to view, but not copy, the information could balance the right to access with the lien. The lawyer subsequently provided a complete copy of the file, and the complaint was settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #30: Solicitor’s lien insufficient grounds to deny access to personal information (November 15, 2007)

Nov 15, 2007Settled Case summary #30
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A client sought access to her personal information from her former lawyer. The lawyer refused access, citing outstanding fees and asserting a solicitor's lien on the client's file, believing that providing access could jeopardize payment. The OPC noted that PIPEDA's subsection 9(3) provides an exhaustive list of reasons for refusing access, which does not include a solicitor's lien. Therefore, lawyers must grant access to personal information even if a valid lien exists. The OPC suggested that allowing the individual to view, but not copy, the information could balance the right to access with the lien. The lawyer subsequently provided a complete copy of the file, and the complaint was settled.

Key Issues
  • Whether a solicitor's lien is a valid ground to refuse access to personal information under PIPEDA
  • Whether subsection 9(3) of PIPEDA provides an exhaustive list of circumstances for refusing access
Federal (Canada)Personal Information Protection and Electronic Documents ActNot well-founded
Federal (Canada) flag
Apr 2, 2007Executive SummaryIndexed Jun 30, 2026

Executive Summary: Privacy Commissioner of Canada v. SWIFT

SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication)

The Privacy Commissioner of Canada launched an investigation into SWIFT SCRL following allegations that it disclosed personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) via administrative subpoenas. SWIFT provides messaging services to financial institutions globally, and some messages contain personal information. The Commissioner determined that SWIFT was subject to PIPEDA due to its operations and significant presence in Canada. While acknowledging SWIFT's compliance with US laws, the Commissioner found that SWIFT had not contravened PIPEDA, as the Act allows for disclosure without consent in response to a subpoena from a body with jurisdiction to compel information. The Commissioner emphasized that organizations operating in Canada must still abide by PIPEDA, even when subject to foreign laws. She also recommended that US authorities use existing information-sharing mechanisms with built-in privacy protections rather than subpoenas for Canadian-related financial information.

Quick view

Personal Information Protection and Electronic Documents ActNot well-founded

Executive Summary: Privacy Commissioner of Canada v. SWIFT

Apr 2, 2007Executive Summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The Privacy Commissioner of Canada launched an investigation into SWIFT SCRL following allegations that it disclosed personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) via administrative subpoenas. SWIFT provides messaging services to financial institutions globally, and some messages contain personal information. The Commissioner determined that SWIFT was subject to PIPEDA due to its operations and significant presence in Canada. While acknowledging SWIFT's compliance with US laws, the Commissioner found that SWIFT had not contravened PIPEDA, as the Act allows for disclosure without consent in response to a subpoena from a body with jurisdiction to compel information. The Commissioner emphasized that organizations operating in Canada must still abide by PIPEDA, even when subject to foreign laws. She also recommended that US authorities use existing information-sharing mechanisms with built-in privacy protections rather than subpoenas for Canadian-related financial information.

Key Issues
  • Whether SWIFT is subject to PIPEDA
  • Whether SWIFT contravened PIPEDA by disclosing personal information to the US Department of the Treasury
  • Whether the exception to consent for disclosures in response to a subpoena applies
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Feb 5, 2007Settled Case summary #29Indexed Jun 30, 2026

Settled case summary #29 — A department store

A department store

An individual complained that a department store's method of collecting tax exemption information allowed other customers to view her personal data and the data of previous customers. The store used a petition-style form where customers wrote their names, shopping dates, and tax exemption numbers, making this information visible to subsequent customers. The complainant was concerned about the lack of privacy for her personal information. In response to the complaint, the department store first implemented a temporary measure of using a new form where only one customer's information appeared per page. Subsequently, the store reconfigured its cash registers to electronically print a receipt-style form for tax exemptions, which was then completed by the customer and securely stored in the register. This new electronic system prevented customers from viewing each other's personal information. The complainant was satisfied with these changes, and the matter was considered settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #29 — A department store

Feb 5, 2007Settled Case summary #29
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a department store's method of collecting tax exemption information allowed other customers to view her personal data and the data of previous customers. The store used a petition-style form where customers wrote their names, shopping dates, and tax exemption numbers, making this information visible to subsequent customers. The complainant was concerned about the lack of privacy for her personal information. In response to the complaint, the department store first implemented a temporary measure of using a new form where only one customer's information appeared per page. Subsequently, the store reconfigured its cash registers to electronically print a receipt-style form for tax exemptions, which was then completed by the customer and securely stored in the register. This new electronic system prevented customers from viewing each other's personal information. The complainant was satisfied with these changes, and the matter was considered settled.

Key Issues
  • Whether the department store's method of collecting tax exemption information allowed unauthorized disclosure of personal information to other customers
  • Whether the department store adequately safeguarded customers' personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Dec 14, 2006Settled Case summary #28Indexed Jun 30, 2026

Settled case summary #28 — A DVD-rental store

A DVD-rental store

An individual complained that a DVD-rental store required him to provide his driver's license details for entry into their database to become a member, which he believed was unnecessary. The store initially argued this was a business necessity for identity verification and recovering overdue rentals. However, the investigation revealed the store did not use driver's license data for tracing members, but rather publicly available information. Recognizing it was collecting unnecessary information, the store revised its membership process. Under the new process, customers must present two pieces of identification, one with a photo, but driver's license details are no longer entered into the database. The store committed to updating its procedures and training staff on the new process.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #28 — A DVD-rental store

Dec 14, 2006Settled Case summary #28
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a DVD-rental store required him to provide his driver's license details for entry into their database to become a member, which he believed was unnecessary. The store initially argued this was a business necessity for identity verification and recovering overdue rentals. However, the investigation revealed the store did not use driver's license data for tracing members, but rather publicly available information. Recognizing it was collecting unnecessary information, the store revised its membership process. Under the new process, customers must present two pieces of identification, one with a photo, but driver's license details are no longer entered into the database. The store committed to updating its procedures and training staff on the new process.

Key Issues
  • Whether collecting and recording driver's license details was necessary for the DVD-rental store's operations
  • Whether the store's collection practices aligned with the principle of limiting collection to necessary information
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Oct 2, 2006Settled Case summary #22Indexed Jun 30, 2026

Settled case summary #22 — A counselling firm and An emergency services organization

A counselling firm and an emergency services organization

A complainant alleged that a counselling firm, part of her employer's Employee Assistance Program (EAP), improperly disclosed sensitive personal information to her employer and others. The firm revealed she was using counselling services and believed she was a danger to herself, which the complainant disputed as a misinterpretation. The OPC's investigation found that a miscommunication occurred during a phone call between the complainant and her counsellor regarding the meaning of "having a plan." The counsellor, believing the complainant was suicidal, contacted emergency services, including the complainant's workplace. The police later concluded the complainant posed no danger. The counselling firm and the complainant reached a private settlement with the OPC's involvement. The firm subsequently revised its policies on disclosing personal information, emphasizing detailed case notes and limiting information shared with emergency services.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #22 — A counselling firm and An emergency services organization

Oct 2, 2006Settled Case summary #22
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A complainant alleged that a counselling firm, part of her employer's Employee Assistance Program (EAP), improperly disclosed sensitive personal information to her employer and others. The firm revealed she was using counselling services and believed she was a danger to herself, which the complainant disputed as a misinterpretation. The OPC's investigation found that a miscommunication occurred during a phone call between the complainant and her counsellor regarding the meaning of "having a plan." The counsellor, believing the complainant was suicidal, contacted emergency services, including the complainant's workplace. The police later concluded the complainant posed no danger. The counselling firm and the complainant reached a private settlement with the OPC's involvement. The firm subsequently revised its policies on disclosing personal information, emphasizing detailed case notes and limiting information shared with emergency services.

Key Issues
  • Whether the counselling firm improperly disclosed personal information about the complainant to her employer and others
  • Whether the information disclosed by the counselling firm was inaccurate
  • Whether the counsellor misconstrued the complainant's statements during a telephone conversation
  • Whether the counselling firm's disclosure of personal information was justified under circumstances of perceived imminent danger
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jul 24, 2006Settled Case summary #21Indexed Jun 30, 2026

Settled case summary #21 — A loyalty program

A loyalty program

An individual complained that a loyalty program shared his children's names and addresses with partner credit card companies, resulting in marketing materials being sent to the minors. The loyalty program stated it does not market to minors or share their information with partners. However, due to telephone account openings where birth dates were not mandatory, the children were not identified as minors in their profiles. This led to their information being shared for marketing purposes. The program acknowledged an overly long delay in correcting the issue, partly due to marketing lists being generated weeks in advance. The loyalty program sent an apology letter, and the mailings to the children ceased. The complaint was considered settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #21 — A loyalty program

Jul 24, 2006Settled Case summary #21
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a loyalty program shared his children's names and addresses with partner credit card companies, resulting in marketing materials being sent to the minors. The loyalty program stated it does not market to minors or share their information with partners. However, due to telephone account openings where birth dates were not mandatory, the children were not identified as minors in their profiles. This led to their information being shared for marketing purposes. The program acknowledged an overly long delay in correcting the issue, partly due to marketing lists being generated weeks in advance. The loyalty program sent an apology letter, and the mailings to the children ceased. The complaint was considered settled.

Key Issues
  • Whether the loyalty program inappropriately disclosed personal information of minors to partner companies for marketing purposes
  • Whether the loyalty program adequately protected the personal information of minor members
  • Whether the loyalty program took appropriate and timely steps to resolve the complaint
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jul 21, 2006Settled Case summary #24Indexed Jun 30, 2026

Settled case summary #24 — A web-based company

A web-based company

An individual complained that a web-based company retained his personal information for too long after he cancelled his free trial membership. He also alleged that the company lacked accountability under PIPEDA, as it did not fully answer his privacy questions and had no designated privacy officer. The company explained that it retained personal information, including credit card details, to process rental requests, ship items, and prevent fraud, particularly to track individuals attempting to obtain multiple free trials. As a result of the complaint, the company revised its privacy policy to clarify retention purposes and periods for different types of information. It also trained its customer service staff and designated a privacy officer. The complainant was satisfied with these changes.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #24 — A web-based company

Jul 21, 2006Settled Case summary #24
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a web-based company retained his personal information for too long after he cancelled his free trial membership. He also alleged that the company lacked accountability under PIPEDA, as it did not fully answer his privacy questions and had no designated privacy officer. The company explained that it retained personal information, including credit card details, to process rental requests, ship items, and prevent fraud, particularly to track individuals attempting to obtain multiple free trials. As a result of the complaint, the company revised its privacy policy to clarify retention purposes and periods for different types of information. It also trained its customer service staff and designated a privacy officer. The complainant was satisfied with these changes.

Key Issues
  • Whether the web-based company retained personal information for too long after a free trial cancellation
  • Whether the web-based company was fully accountable under PIPEDA
  • Whether the web-based company adequately answered privacy-related questions
  • Whether the web-based company had a designated person responsible for handling privacy issues
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jun 12, 2006Settled Case summary #23Indexed Jun 30, 2026

Settled case summary #23 — A building management firm

A building management firm

A tenant complained that the caretaker of his apartment building disclosed to other tenants that his rent cheque had bounced. The building management firm initially did not take the issue seriously, prompting the tenant to complain to the OPC. While the caretaker and his wife denied the disclosure, another tenant confirmed that the caretaker's wife had indeed shared this information, along with other tenants' rent details. The complainant sought a letter of apology from the building management firm. The firm provided the apology and also reminded the caretaker and his wife about their obligation not to discuss tenants' personal information. The OPC further advised the firm to create a privacy policy in compliance with PIPEDA. The matter was ultimately settled to the satisfaction of both the OPC and the complainant.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #23 — A building management firm

Jun 12, 2006Settled Case summary #23
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A tenant complained that the caretaker of his apartment building disclosed to other tenants that his rent cheque had bounced. The building management firm initially did not take the issue seriously, prompting the tenant to complain to the OPC. While the caretaker and his wife denied the disclosure, another tenant confirmed that the caretaker's wife had indeed shared this information, along with other tenants' rent details. The complainant sought a letter of apology from the building management firm. The firm provided the apology and also reminded the caretaker and his wife about their obligation not to discuss tenants' personal information. The OPC further advised the firm to create a privacy policy in compliance with PIPEDA. The matter was ultimately settled to the satisfaction of both the OPC and the complainant.

Key Issues
  • Whether a building caretaker disclosed a tenant's personal information without consent
  • Whether the building management firm adequately protected personal information
  • Whether the building management firm had appropriate privacy policies in place
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
May 16, 2006Settled Case summary #27Indexed Jun 30, 2026

Settled case summary #27 — A dental clinic

A dental clinic

An individual complained that her dental clinic disclosed information about her overdue account to the person who had referred her to the clinic. The complainant had been in hospital and respite care, missing invoices. The clinic, seeking her whereabouts, disclosed to the referrer that her bill was overdue, the amount owing, and that it would go to collections. The clinic acknowledged this violated its privacy policy, stating it should have only requested contact information. During the investigation, the clinic and complainant reached a monetary settlement, including an apology letter. The OPC and complainant agreed the matter was settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #27 — A dental clinic

May 16, 2006Settled Case summary #27
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that her dental clinic disclosed information about her overdue account to the person who had referred her to the clinic. The complainant had been in hospital and respite care, missing invoices. The clinic, seeking her whereabouts, disclosed to the referrer that her bill was overdue, the amount owing, and that it would go to collections. The clinic acknowledged this violated its privacy policy, stating it should have only requested contact information. During the investigation, the clinic and complainant reached a monetary settlement, including an apology letter. The OPC and complainant agreed the matter was settled.

Key Issues
  • Whether the dental clinic disclosed personal information without consent
  • Whether the disclosure of overdue bill details, amount owing, and collection threat to a third party was appropriate
  • Whether the clinic's actions violated its own privacy policy
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Mar 28, 2006Settled Case summary #26Indexed Jun 30, 2026

Settled Case summary #26: Department store's credit card application form appropriate (March 28, 2006)

A department store

An individual complained after receiving promotional material and telemarketing calls following her application for a department store credit card, believing she had not consented to the use of her contact information for marketing. The department store asserted that her signature on the application form indicated agreement to its terms and conditions, which included marketing. The OPC found that the application form adequately explained how personal information would be used and provided an opt-out mechanism below the signature line. The OPC informed the complainant that this type of opt-out was permissible under PIPEDA. The complainant was satisfied with this explanation and requested removal from marketing lists, which the store completed. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #26: Department store's credit card application form appropriate (March 28, 2006)

Mar 28, 2006Settled Case summary #26
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained after receiving promotional material and telemarketing calls following her application for a department store credit card, believing she had not consented to the use of her contact information for marketing. The department store asserted that her signature on the application form indicated agreement to its terms and conditions, which included marketing. The OPC found that the application form adequately explained how personal information would be used and provided an opt-out mechanism below the signature line. The OPC informed the complainant that this type of opt-out was permissible under PIPEDA. The complainant was satisfied with this explanation and requested removal from marketing lists, which the store completed. The complaint was settled during the investigation.

Key Issues
  • Whether the department store obtained valid consent for using personal information for marketing purposes
  • Whether the opt-out mechanism provided by the department store was compliant with PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Mar 6, 2006Settled Case summary #20Indexed Jun 30, 2026

Settled case summary #20 — A condominium corporation

A condominium corporation

An individual complained that a condominium corporation disclosed personal information about her dispute with the corporation to all condominium owners. The corporation sent a letter detailing the alleged by-law contravention to all owners, posted it on a bulletin board, and included it in Board meeting minutes. The corporation initially believed only contact information, which it considered publicly available, was disclosed. However, the OPC clarified that the personal information at issue was the fact of the dispute itself. The corporation had disclosed this information without the complainant's consent. The matter was resolved when the condominium corporation sent the complainant a letter of apology.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #20 — A condominium corporation

Mar 6, 2006Settled Case summary #20
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a condominium corporation disclosed personal information about her dispute with the corporation to all condominium owners. The corporation sent a letter detailing the alleged by-law contravention to all owners, posted it on a bulletin board, and included it in Board meeting minutes. The corporation initially believed only contact information, which it considered publicly available, was disclosed. However, the OPC clarified that the personal information at issue was the fact of the dispute itself. The corporation had disclosed this information without the complainant's consent. The matter was resolved when the condominium corporation sent the complainant a letter of apology.

Key Issues
  • Whether the fact of an individual's dispute with a condominium corporation constitutes personal information under PIPEDA
  • Whether the condominium corporation disclosed personal information without consent
  • Whether the personal information was publicly available