The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,324 decisions matching
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01406Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01406

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 25, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01406

May 20, 20225820-01406

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 25, 2022.

Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 20, 20225820-01403Indexed Apr 21, 2026

Environment and Climate Change Canada, 5820-01403

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 23, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Environment and Climate Change Canada, 5820-01403

May 20, 20225820-01403

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 23, 2022.

Federal (Canada)Privacy ActWell-founded & resolved
Federal (Canada) flag
May 20, 2022Indexed Jun 30, 2026

Investigation into a privacy breach at a Canada Border Services Agency contractor

Canada Border Services Agency

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Quick view

Privacy ActWell-founded & resolved

Investigation into a privacy breach at a Canada Border Services Agency contractor

May 20, 2022
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Key Issues
  • Whether licence plate image files, including associated metadata (jurisdiction, characters, date, time, border crossing site, lane number), constitute personal information under Section 3 of the Privacy Act.
  • Whether the unauthorized access and disclosure of these licence plate image files constituted an improper disclosure under Section 8 of the Privacy Act.
  • Whether the Canada Border Services Agency (CBSA) had adequate security safeguards in place, particularly in its contractual arrangements with a third-party contractor, to protect personal information.
  • Whether the data retention practices for licence plate image files by the CBSA and its contractor were appropriate and compliant with the Privacy Act.
Newfoundland and LabradorAccess to Information and Protection of Privacy Act, 2015
Newfoundland and Labrador flag

A-2022-005 — City of St. John's

Subscribe to open Newfoundland and Labrador decisions.

Unlock this jurisdiction
Newfoundland and LabradorAccess to Information and Protection of Privacy Act, 2015
Newfoundland and Labrador flag

A-2022-006 — Department of Industry, Energy and Technology

Subscribe to open Newfoundland and Labrador decisions.

Unlock this jurisdiction
British ColumbiaFreedom of Information and Protection of Privacy Act
British Columbia flag

F22-25 — BC OIPC order 2523

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
Federal (Canada)Access to Information ActOIC Order (ATIA s.36.1, binding)
Federal (Canada) flag
May 19, 20225821-01019Indexed Apr 21, 2026

Communications Security Establishment Canada, 5821-01019

The Information Commissioner ordered Communications Security Establishment Canada to provide a final response to the access request no later than July 24, 2022.

Quick view

Access to Information ActOIC Order (ATIA s.36.1, binding)

Communications Security Establishment Canada, 5821-01019

May 19, 20225821-01019

The Information Commissioner ordered Communications Security Establishment Canada to provide a final response to the access request no later than July 24, 2022.

Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2022PIPEDA Findings #2022-004Indexed Jun 30, 2026

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

MGM Resorts International

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

May 19, 2022PIPEDA Findings #2022-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Key Issues
  • Whether MGM had the obligation to report the breach to the OPC and notify affected Canadians
  • Whether the MGM breach met the RROSH reporting and notification threshold
  • Whether the personal information involved was sensitive
  • Whether there was a high probability of misuse of the personal information
  • Whether MGM notified the OPC and affected Canadians as soon as feasible
Northwest TerritoriesHealth Information Act
Northwest Territories flag

2022 NTIPC 9 — Northwest Territories Health and Social Services Authority

Subscribe to open Northwest Territories decisions.

Unlock this jurisdiction
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2022 QCCAI 145 — Trans Union of Canada Inc.

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2022 QCCAI 146 — Équifax Canada Co.

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2022 QCCAI 147 — Trans Union of Canada Inc.

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2022 QCCAI 152 — Laurentian Bank of Canada

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2022 QCCAI 166 — Ministère de la Sécurité publique (Sûreté du Québec)

Subscribe to open Quebec decisions.

Unlock this jurisdiction
SaskatchewanLocal Authority Freedom of Information and Protection of Privacy Act
Saskatchewan flag

Review Report 359-2021 — Village of Neudorf

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction