The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

616 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Mar 6, 2006Settled Case summary #18Indexed Jun 30, 2026

Settled Case summary #18: Business learns that it must have a privacy policy available to the public (March 6, 2006)

A business

An individual complained that a business withheld some of his personal information and its privacy policy. The business initially claimed the individual was not entitled to information predating January 1, 2004, when PIPEDA became applicable to it. After the complainant challenged this, the business provided the remaining personal information but still did not provide a privacy policy. The OPC discovered the business did not have a privacy policy. At the OPC's request, the business drafted a privacy policy and provided it to the complainant. The complainant considered the matter settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #18: Business learns that it must have a privacy policy available to the public (March 6, 2006)

Mar 6, 2006Settled Case summary #18
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a business withheld some of his personal information and its privacy policy. The business initially claimed the individual was not entitled to information predating January 1, 2004, when PIPEDA became applicable to it. After the complainant challenged this, the business provided the remaining personal information but still did not provide a privacy policy. The OPC discovered the business did not have a privacy policy. At the OPC's request, the business drafted a privacy policy and provided it to the complainant. The complainant considered the matter settled.

Key Issues
  • Whether the business improperly withheld personal information requested by the individual
  • Whether the business failed to make its privacy policy publicly available as required by PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Feb 3, 2006Settled Case summary #19Indexed Jun 30, 2026

Settled Case summary #19: SIN not required when signing apartment lease (February 3, 2006)

A property management firm

A student complained that a property management firm required his Social Insurance Number (SIN) to rent an apartment. The firm stated it needed the SIN for identity verification, credit checks, and collections. The OPC noted that while no legislation prevents organizations from asking for SINs for identification, organizations subject to PIPEDA must inform individuals that providing a SIN for identification is optional and not a condition of service. As a result of the complaint, the property manager revised the lease agreement to only require a driver's license for identification and stopped requesting SINs from potential renters. The student and the OPC considered the matter settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #19: SIN not required when signing apartment lease (February 3, 2006)

Feb 3, 2006Settled Case summary #19
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A student complained that a property management firm required his Social Insurance Number (SIN) to rent an apartment. The firm stated it needed the SIN for identity verification, credit checks, and collections. The OPC noted that while no legislation prevents organizations from asking for SINs for identification, organizations subject to PIPEDA must inform individuals that providing a SIN for identification is optional and not a condition of service. As a result of the complaint, the property manager revised the lease agreement to only require a driver's license for identification and stopped requesting SINs from potential renters. The student and the OPC considered the matter settled.

Key Issues
  • Whether requiring a SIN for an apartment lease is permissible under PIPEDA
  • Whether organizations must inform individuals that providing a SIN for identification is optional
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jan 27, 2006Settled Case summary #25Indexed Jun 30, 2026

Settled case summary #25 — A restaurant

A restaurant

An individual complained that a restaurant's credit card receipts displayed her name, full credit card number, and expiry date, arguing this information should be masked. The restaurant used electronic processing equipment that did not mask this information. The OPC found that the personal information was collected, used, and stored in a manner consistent with PIPEDA principles, and there was no unauthorized disclosure. However, the OPC noted that technology for masking credit card information on receipts exists and that industry representatives indicated all equipment would mask this information by 2007. The complainant was satisfied with this information and the restaurant owner's awareness of privacy legislation. The matter was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #25 — A restaurant

Jan 27, 2006Settled Case summary #25
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a restaurant's credit card receipts displayed her name, full credit card number, and expiry date, arguing this information should be masked. The restaurant used electronic processing equipment that did not mask this information. The OPC found that the personal information was collected, used, and stored in a manner consistent with PIPEDA principles, and there was no unauthorized disclosure. However, the OPC noted that technology for masking credit card information on receipts exists and that industry representatives indicated all equipment would mask this information by 2007. The complainant was satisfied with this information and the restaurant owner's awareness of privacy legislation. The matter was settled during the investigation.

Key Issues
  • Whether the display of full credit card details on receipts constituted a contravention of PIPEDA
  • Whether the collection, use, and storage of personal information on credit card receipts was consistent with PIPEDA principles
  • Whether there was unauthorized disclosure of personal information
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Dec 16, 2005Settled Case summary #17Indexed Jun 30, 2026

Settled case summary #17 — A not-for-profit association

A not-for-profit association

A member of a not-for-profit association complained that the association required a second piece of identification, in addition to his membership card, to obtain member discounts. The complainant believed his membership card should be sufficient and that collecting further personal information was unwarranted. The association explained that it had legal agreements with vendors requiring it to sell discounted products only to current members. Due to some members loaning their cards to non-members, which caused legal and revenue issues, the association implemented the supplementary identification requirement to confirm identity and prevent misuse. The association also noted that members could choose their secondary identification and that this information was not recorded. The complainant was satisfied with this explanation, and the complaint was settled.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #17 — A not-for-profit association

Dec 16, 2005Settled Case summary #17
Adjudicator: Jennifer Stoddart
Plain-Language Summary

A member of a not-for-profit association complained that the association required a second piece of identification, in addition to his membership card, to obtain member discounts. The complainant believed his membership card should be sufficient and that collecting further personal information was unwarranted. The association explained that it had legal agreements with vendors requiring it to sell discounted products only to current members. Due to some members loaning their cards to non-members, which caused legal and revenue issues, the association implemented the supplementary identification requirement to confirm identity and prevent misuse. The association also noted that members could choose their secondary identification and that this information was not recorded. The complainant was satisfied with this explanation, and the complaint was settled.

Key Issues
  • Whether requiring supplementary identification for member discounts was an unwarranted collection of personal information
  • Whether the membership card alone was sufficient identification
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 21, 2005Settled Case summary #16Indexed Jun 30, 2026

Settled Case summary #16: Personal information on receipts removed, information collected when goods returned is limited (November 21, 2005)

A retail chain

An individual complained about a retail chain's practice of printing personal information on receipts and collecting excessive information for returns. The complainant was concerned that the printing of name, credit card number, and expiry date on receipts, and the recording of driver's license and credit card information for refunds, constituted unnecessary collection of personal information. During the investigation, the company updated its point-of-sale equipment to mask personal information on receipts. For returns, the company committed to continuing to collect name, address, and telephone number, but would no longer record identification information, only asking to see it. Credit card information would only be requested if a credit card was used for the original purchase. The company also committed to training its employees on these new procedures. Both the complainant and the OPC were satisfied with these changes.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary #16: Personal information on receipts removed, information collected when goods returned is limited (November 21, 2005)

Nov 21, 2005Settled Case summary #16
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained about a retail chain's practice of printing personal information on receipts and collecting excessive information for returns. The complainant was concerned that the printing of name, credit card number, and expiry date on receipts, and the recording of driver's license and credit card information for refunds, constituted unnecessary collection of personal information. During the investigation, the company updated its point-of-sale equipment to mask personal information on receipts. For returns, the company committed to continuing to collect name, address, and telephone number, but would no longer record identification information, only asking to see it. Credit card information would only be requested if a credit card was used for the original purchase. The company also committed to training its employees on these new procedures. Both the complainant and the OPC were satisfied with these changes.

Key Issues
  • Whether printing customer's name, credit card number, and expiry date on receipts constituted unnecessary collection of personal information under PIPEDA
  • Whether requiring and recording a driver's license and credit card for returns constituted unnecessary collection of personal information under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jul 29, 2005Settled Case summaryIndexed Jun 30, 2026

Settled Case summary: Disclosure of personal information to estranged spouse - July 29, 2005

A bank

An individual complained that a bank employee improperly disclosed her bank account balance to her estranged husband. The husband subsequently withheld a support payment, causing financial difficulty for the complainant. The bank apologized and acknowledged that its employee likely contravened Principle 4.3 of PIPEDA by disclosing personal information without consent. Although the employee denied the specific recollection, the bank found no evidence to suggest the allegations were false. The bank and the complainant reached a private settlement regarding compensation. The OPC concluded that there was no systemic problem, as the bank had adequate privacy policies and training in place.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary: Disclosure of personal information to estranged spouse - July 29, 2005

Jul 29, 2005Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a bank employee improperly disclosed her bank account balance to her estranged husband. The husband subsequently withheld a support payment, causing financial difficulty for the complainant. The bank apologized and acknowledged that its employee likely contravened Principle 4.3 of PIPEDA by disclosing personal information without consent. Although the employee denied the specific recollection, the bank found no evidence to suggest the allegations were false. The bank and the complainant reached a private settlement regarding compensation. The OPC concluded that there was no systemic problem, as the bank had adequate privacy policies and training in place.

Key Issues
  • Whether a bank employee disclosed personal information without consent
  • Whether the disclosure of a bank account balance to an estranged spouse contravened Principle 4.3 of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jun 24, 2005Settled Case summary #15Indexed Jun 30, 2026

Settled case summary #15 — A retail store and A financial institution

A retail store and A financial institution

An individual complained that a retail store inappropriately collected her personal information and disclosed it to a financial institution, and that the financial institution used and disclosed her information without consent. The complainant provided her information for a credit application but decided not to proceed, tearing up the contract. However, due to a salesperson's error, her information was entered into the system before her signature, leading to a credit card being issued. The financial institution apologized, removed inquiries from her credit file, and purged her information. The retail store implemented new procedures to ensure signatures are obtained before data entry. Both the complainant and the OPC were satisfied with the corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #15 — A retail store and A financial institution

Jun 24, 2005Settled Case summary #15
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a retail store inappropriately collected her personal information and disclosed it to a financial institution, and that the financial institution used and disclosed her information without consent. The complainant provided her information for a credit application but decided not to proceed, tearing up the contract. However, due to a salesperson's error, her information was entered into the system before her signature, leading to a credit card being issued. The financial institution apologized, removed inquiries from her credit file, and purged her information. The retail store implemented new procedures to ensure signatures are obtained before data entry. Both the complainant and the OPC were satisfied with the corrective actions.

Key Issues
  • Whether the retail store inappropriately collected and disclosed personal information without consent
  • Whether the financial institution used and disclosed personal information without consent
  • Whether the salesperson followed proper procedure for credit applications
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
May 17, 2005Settled Case summaryIndexed Jun 30, 2026

Settled case summary #13 — A company

A company

An individual complained that a company sent him an unsolicited commercial e-mail promoting its products. The company, which typically markets through a distributor network and commission sales agents, was unaware that one of its agents was using email for marketing. The company does not approve of this marketing technique. Upon learning of the issue, the company contacted the agent and instructed them to cease using email for marketing. The agent confirmed compliance and apologized to the complainant. The company, despite its small size, has a privacy policy and a designated privacy officer. The complainant was satisfied with the resolution.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #13 — A company

May 17, 2005Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a company sent him an unsolicited commercial e-mail promoting its products. The company, which typically markets through a distributor network and commission sales agents, was unaware that one of its agents was using email for marketing. The company does not approve of this marketing technique. Upon learning of the issue, the company contacted the agent and instructed them to cease using email for marketing. The agent confirmed compliance and apologized to the complainant. The company, despite its small size, has a privacy policy and a designated privacy officer. The complainant was satisfied with the resolution.

Key Issues
  • Whether sending unsolicited commercial email constitutes a contravention of PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 21, 2004Incident Summary #1Indexed Jun 30, 2026

Incident Summary #1: Misdirected faxes containing health information end up in apartment managers' hands

Dynacare and Viewpoint

This incident summary details two separate investigations into misdirected faxes containing personal health information. In both cases, faxes from Dynacare and Viewpoint were erroneously sent to apartment managers. The OPC found that both companies disclosed personal information without consent, contravening PIPEDA. Dynacare implemented an electronic auto-fax function and revised policies, while Viewpoint committed to retrieving misdirected faxes and verifying numbers. The Assistant Commissioner recommended both organizations implement OPC faxing guidelines, notify affected individuals, and annually update employee confidentiality agreements.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #1: Misdirected faxes containing health information end up in apartment managers' hands

Dec 21, 2004Incident Summary #1
Adjudicator: Jennifer Stoddart
Plain-Language Summary

This incident summary details two separate investigations into misdirected faxes containing personal health information. In both cases, faxes from Dynacare and Viewpoint were erroneously sent to apartment managers. The OPC found that both companies disclosed personal information without consent, contravening PIPEDA. Dynacare implemented an electronic auto-fax function and revised policies, while Viewpoint committed to retrieving misdirected faxes and verifying numbers. The Assistant Commissioner recommended both organizations implement OPC faxing guidelines, notify affected individuals, and annually update employee confidentiality agreements.

Key Issues
  • Whether Dynacare disclosed personal information without consent, contrary to PIPEDA
  • Whether Viewpoint disclosed personal information without consent, contrary to PIPEDA
  • Whether Dynacare's security safeguards were adequate to prevent misdirected faxes
  • Whether Viewpoint's security safeguards were adequate to prevent misdirected faxes
  • Whether Dynacare should notify the affected individual
  • Whether Viewpoint should notify the affected individual
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 16, 2004Settled Case summaryIndexed Jun 30, 2026

#12 — A department store

A department store

An individual complained that a department store disclosed his personal information to a third party, a credit monitoring service, after he had requested that his information not be shared. The complainant received a mail solicitation that appeared to be supported by the department store but sent by the third party. The investigation found that the department store had not disclosed the complainant's personal information; rather, the store conducted the mail-out on behalf of the third party. The store acknowledged that the mail-out should have been clearer about its role and apologized. The store also agreed to review its account application policies to allow new customers to opt out at enrolment and to improve its suppression mechanisms. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

#12 — A department store

Nov 16, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a department store disclosed his personal information to a third party, a credit monitoring service, after he had requested that his information not be shared. The complainant received a mail solicitation that appeared to be supported by the department store but sent by the third party. The investigation found that the department store had not disclosed the complainant's personal information; rather, the store conducted the mail-out on behalf of the third party. The store acknowledged that the mail-out should have been clearer about its role and apologized. The store also agreed to review its account application policies to allow new customers to opt out at enrolment and to improve its suppression mechanisms. The complaint was settled during the investigation.

Key Issues
  • Whether the department store disclosed personal information to a third party without consent
  • Whether the mail-out clearly indicated the department store's role
  • Whether the department store's opt-out mechanisms were adequate
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 15, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #10 — A collection agency

A collection agency

An individual complained to the OPC after a collection agency failed to correct inaccurate information in his credit file, despite his lawyer's repeated attempts. The complainant had paid off a debt years prior, but the collection agency had not reported this to credit bureaux, causing him difficulty in securing credit. The collection agency initially had no record of the lawyer's correspondence. However, after the OPC intervened and the lawyer sent another letter, the agency investigated and confirmed the debt was paid. Consequently, the agency updated the credit bureaux, and the complainant's credit files were amended. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #10 — A collection agency

Nov 15, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained to the OPC after a collection agency failed to correct inaccurate information in his credit file, despite his lawyer's repeated attempts. The complainant had paid off a debt years prior, but the collection agency had not reported this to credit bureaux, causing him difficulty in securing credit. The collection agency initially had no record of the lawyer's correspondence. However, after the OPC intervened and the lawyer sent another letter, the agency investigated and confirmed the debt was paid. Consequently, the agency updated the credit bureaux, and the complainant's credit files were amended. The complaint was settled during the investigation.

Key Issues
  • Whether the collection agency failed to ensure the accuracy of personal information it held
  • Whether the collection agency failed to correct inaccurate personal information upon request
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 5, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #4 — A federally regulated transportation company

A federally regulated transportation company

Several employees of a federally regulated transportation company complained that a list of employees receiving severance packages, including names, identification and seniority numbers, and Social Insurance Numbers (SINs), was disclosed to their union without their knowledge or consent. The company admitted that the SINs were included on an electronic spreadsheet provided to the union, though in a hidden column. The employer did not obtain employee consent for this disclosure. During the investigation, the company changed its severance application process to no longer require SINs. The company also agreed to amend its application form to include a consent statement for the release of personal information to the union. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #4 — A federally regulated transportation company

Nov 5, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

Several employees of a federally regulated transportation company complained that a list of employees receiving severance packages, including names, identification and seniority numbers, and Social Insurance Numbers (SINs), was disclosed to their union without their knowledge or consent. The company admitted that the SINs were included on an electronic spreadsheet provided to the union, though in a hidden column. The employer did not obtain employee consent for this disclosure. During the investigation, the company changed its severance application process to no longer require SINs. The company also agreed to amend its application form to include a consent statement for the release of personal information to the union. The complaint was settled during the investigation.

Key Issues
  • Whether the disclosure of employee names, identification numbers, seniority numbers, and Social Insurance Numbers to a union without consent contravened PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Nov 1, 2004Settled Case summaryIndexed Jun 30, 2026

Settled Case summary: Credit check to open a personal deposit account - November 2004

A bank

An individual complained that a bank inappropriately required a credit check and other personal information, including length of employment and Social Insurance Number (SIN), to open a no-fee personal deposit account online. The complainant also found the language regarding information exchange with credit bureaus unclear. The bank agreed to modify its online application forms to clarify that credit checks are optional for deposit accounts if applied for in person. It also agreed to only request length of employment for credit applications and make SIN provision optional. The bank committed to reviewing the language concerning credit bureau information exchange. The OPC confirmed the complainant's credit rating was unaffected. Both the complainant and the OPC were satisfied with the bank's actions.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary: Credit check to open a personal deposit account - November 2004

Nov 1, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a bank inappropriately required a credit check and other personal information, including length of employment and Social Insurance Number (SIN), to open a no-fee personal deposit account online. The complainant also found the language regarding information exchange with credit bureaus unclear. The bank agreed to modify its online application forms to clarify that credit checks are optional for deposit accounts if applied for in person. It also agreed to only request length of employment for credit applications and make SIN provision optional. The bank committed to reviewing the language concerning credit bureau information exchange. The OPC confirmed the complainant's credit rating was unaffected. Both the complainant and the OPC were satisfied with the bank's actions.

Key Issues
  • Whether a credit check was appropriately required for a no-fee personal deposit account
  • Whether length of employment was appropriately required for a no-fee personal deposit account
  • Whether the Social Insurance Number (SIN) was appropriately required for a no-fee personal deposit account
  • Whether the language describing information exchange with credit bureaus was clear
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Oct 26, 2004Settled Case summaryIndexed Jun 30, 2026

Settled case summary #2 — A chain of pharmacies

A chain of pharmacies

An individual complained that a pharmacy chain required him to sign an overly broad consent form for medication, fearing his personal information would be used for marketing. The complainant was concerned he would be denied medication if he refused consent. The OPC clarified with the pharmacy that it did not disclose personal information for secondary marketing purposes. The pharmacy, having received similar complaints, revised its consent form to be simpler and clearer. It also introduced a new policy allowing customers to verbally consent to privacy practices if they were uncomfortable signing the form. The complainant was satisfied with these changes.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #2 — A chain of pharmacies

Oct 26, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a pharmacy chain required him to sign an overly broad consent form for medication, fearing his personal information would be used for marketing. The complainant was concerned he would be denied medication if he refused consent. The OPC clarified with the pharmacy that it did not disclose personal information for secondary marketing purposes. The pharmacy, having received similar complaints, revised its consent form to be simpler and clearer. It also introduced a new policy allowing customers to verbally consent to privacy practices if they were uncomfortable signing the form. The complainant was satisfied with these changes.

Key Issues
  • Whether the pharmacy's consent form authorized overly broad disclosure practices
  • Whether personal information was being disclosed for marketing purposes
  • Whether the pharmacy's consent process was appropriate under PIPEDA
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Jul 6, 2004Settled Case summaryIndexed Jun 30, 2026

Settled Case summary: Windows reveal too much information - July and October 2004

Two financial institutions

The OPC received two separate complaints against two different banks concerning the improper disclosure of personal information through envelope windows. In the first case, a complainant received RRSP transfer documents where Social Insurance Numbers (SINs) were visible through the envelope window. The bank acknowledged the issue and implemented a new process to ensure SINs and account numbers are not visible. In the second case, a complainant received a dormant account notice where the word "Bankrupt" and a date were visible through the envelope window below his name. The bank modified its process for client profile notations to prevent such information from appearing in the address field. Both complaints were settled during the course of the investigations, with the banks taking satisfactory corrective actions.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled Case summary: Windows reveal too much information - July and October 2004

Jul 6, 2004Settled Case summary
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC received two separate complaints against two different banks concerning the improper disclosure of personal information through envelope windows. In the first case, a complainant received RRSP transfer documents where Social Insurance Numbers (SINs) were visible through the envelope window. The bank acknowledged the issue and implemented a new process to ensure SINs and account numbers are not visible. In the second case, a complainant received a dormant account notice where the word "Bankrupt" and a date were visible through the envelope window below his name. The bank modified its process for client profile notations to prevent such information from appearing in the address field. Both complaints were settled during the course of the investigations, with the banks taking satisfactory corrective actions.

Key Issues
  • Whether Social Insurance Numbers visible through an envelope window constituted inadequate protection of personal information under PIPEDA
  • Whether a bankruptcy notation visible through an envelope window constituted improper disclosure of personal information under PIPEDA
  • Whether the banks' practices for handling and displaying personal information on mailings met PIPEDA's protection requirements