Updated daily · 21,367 recordsSign in
The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,266 decisions matching
OntarioMunicipal Freedom of Information and Protection of Privacy Act
Ontario flag

Order MO-4224-R

Subscribe to open Ontario decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2022 QCCAI 180 — Ministère de la Sécurité publique

Subscribe to open Quebec decisions.

Unlock this jurisdiction
SaskatchewanHealth Information Protection Act
Saskatchewan flag

Investigation Report 084-2021 — Saskatchewan Health Authority

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
SaskatchewanLocal Authority Freedom of Information and Protection of Privacy Act
Saskatchewan flag

Review Report 038-2021 — Village of Albertville

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 15, 2022PIPEDA Findings #2022-005

PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor

Marriott International, Inc.

Following a data breach involving the Starwood hotel database, the Office of the Privacy Commissioner of Canada (OPC) investigated Marriott International, Inc. The investigation found that Marriott's security safeguards, accountability measures, and information retention practices were inadequate at the time of the breach, leading to unauthorized access to personal information. While Marriott has taken remedial actions and the complaint is conditionally resolved, the OPC highlighted failures in access controls, antivirus software, logging and monitoring, and information storage. The OPC also found Marriott contravened accountability principles by not adequately assessing security risks during its acquisition of Starwood and retaining personal information longer than necessary.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor

Jul 15, 2022PIPEDA Findings #2022-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

Following a data breach involving the Starwood hotel database, the Office of the Privacy Commissioner of Canada (OPC) investigated Marriott International, Inc. The investigation found that Marriott's security safeguards, accountability measures, and information retention practices were inadequate at the time of the breach, leading to unauthorized access to personal information. While Marriott has taken remedial actions and the complaint is conditionally resolved, the OPC highlighted failures in access controls, antivirus software, logging and monitoring, and information storage. The OPC also found Marriott contravened accountability principles by not adequately assessing security risks during its acquisition of Starwood and retaining personal information longer than necessary.

Key Issues
  • Adequacy of security safeguards for personal information
  • Marriott's accountability and due diligence during the acquisition of Starwood
  • Timeliness of information retention and deletion practices
  • Adequacy of notification and mitigation measures for affected individuals
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2022 QCCAI 181 — Ministère de la Sécurité publique

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2022 QCCAI 187 — Syndicat des copropriétaires du 1628 Henri-Bourassa Est and Condovision Gestion Immobilière inc.

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2022 QCCAI 192 — Milton-Park Housing Cooperative

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2022 QCCAI 193 — La Capitale General Insurance Inc.

Subscribe to open Quebec decisions.

Unlock this jurisdiction
Nova ScotiaMunicipal Government Act — Part XX (Information Access and Protection of Privacy)
Nova Scotia flag

22-12 — Halifax Regional Police

Subscribe to open Nova Scotia decisions.

Unlock this jurisdiction
SaskatchewanFreedom of Information and Protection of Privacy Act
Saskatchewan flag

Investigation Report 027-2022 — Ministry of SaskBuilds and Procurement

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
British ColumbiaFreedom of Information and Protection of Privacy Act
British Columbia flag

F22-34 — BC OIPC order 2529

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
OntarioFreedom of Information and Protection of Privacy Act
Ontario flag

Order PO-4278

Subscribe to open Ontario decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2022 QCCAI 156 — Société québécoise d'information juridique (SOQUIJ)

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2022 QCCAI 159 — Autorité des marchés publics

Subscribe to open Quebec decisions.

Unlock this jurisdiction