The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

22,101 decisions in the archive
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2020 QCCAI 164 — Impact Réadaptation

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2020 QCCAI 173 — Municipalité de La Pêche

Subscribe to open Quebec decisions.

Unlock this jurisdiction
Nova ScotiaFreedom of Information and Protection of Privacy Act
Nova Scotia flag

20-03 — Fisheries and Aquaculture

Subscribe to open Nova Scotia decisions.

Unlock this jurisdiction
OntarioMunicipal Freedom of Information and Protection of Privacy Act
Ontario flag

Order MO-3936

Subscribe to open Ontario decisions.

Unlock this jurisdiction
Federal (Canada)Privacy ActNot well-founded
Federal (Canada) flag
Jul 14, 2020Indexed Jun 30, 2026

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Canada Border Services Agency (CBSA)

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Quick view

Privacy ActNot well-founded

Privacy Act restrictions on use and disclosure do not apply to publicly available personal information

Jul 14, 2020
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) contravened the Privacy Act by disclosing his personal medical information to his bondsperson. The CBSA had carbon copied the bondsperson on a letter containing details about the complainant's health changes while in CBSA detention. The CBSA argued that the information was publicly available because the complainant had included the same medical information in court documents as part of his litigation. The OPC found that the medical information was indeed publicly available in court records, making section 8 of the Privacy Act inapplicable under subsection 69(2). Therefore, the complaint was found to be not well-founded. The OPC noted that had the information not been publicly available, the disclosure would likely have constituted a breach of the Act, as the CBSA's operational bulletin did not sufficiently authorize the disclosure.

Key Issues
  • Did the CBSA disclose the complainant’s personal information?
  • Was any disclosed information “publicly available”, such that subsection 69(2) of the Act excludes application of sections 7 and 8?
  • If not, was the disclosure permitted under subsection 8(2) of the Act?
SaskatchewanFreedom of Information and Protection of Privacy Act
Saskatchewan flag

REVIEW REPORT 289-2019 — SaskBuilds Corporation

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
British ColumbiaFreedom of Information and Protection of Privacy Act
British Columbia flag

F20-31 — BC OIPC order 2306

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
Northwest TerritoriesAccess to Information and Protection of Privacy Act
Northwest Territories flag

Review Report 20-235 — Workers' Safety and Compensation Commission

Subscribe to open Northwest Territories decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2020 QCCAI 166 — Ministère du Travail, de l’Emploi et de la Solidarité sociale

Subscribe to open Quebec decisions.

Unlock this jurisdiction
Newfoundland and LabradorAccess to Information and Protection of Privacy Act, 2015
Newfoundland and Labrador flag

A-2020-008 — Memorial University of Newfoundland

Subscribe to open Newfoundland and Labrador decisions.

Unlock this jurisdiction
OntarioMunicipal Freedom of Information and Protection of Privacy Act
Ontario flag

Order MO-3937

Subscribe to open Ontario decisions.

Unlock this jurisdiction
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2020 QCCAI 167 — Syndicat des agents de la paix en services correctionnels du Québec (SAPSCQ-CSN)

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2020 QCCAI 174 — Municipalité de Terrasse-Vaudreuil

Subscribe to open Quebec decisions.

Unlock this jurisdiction
OntarioPersonal Health Information Protection Act
Ontario flag

PHIPA DECISION 124

Subscribe to open Ontario decisions.

Unlock this jurisdiction
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jul 9, 2020PIPEDA Findings #2020-003Indexed Jun 30, 2026

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Dell Inc.

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation

Jul 9, 2020PIPEDA Findings #2020-003
Adjudicator: Daniel Therrien
Plain-Language Summary

Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.

Key Issues
  • Whether Dell adequately safeguarded personal information under its control while using a service provider (PIPEDA Principle 4.1.3 and 4.7).
  • Whether the personal information transferred to the service provider was sensitive enough to require a high degree of protection.
  • Whether Dell's access controls were sufficient to protect customer information.
  • Whether Dell's logging and monitoring practices were adequate to detect anomalous employee requests for customer information.
  • Whether Dell's technical measures, such as USB drive restrictions, were sufficient.
  • Whether Dell adequately investigated the circumstances and scope of the June 2017 breach.
  • Whether Dell adequately responded to customer complaints about potential privacy breaches (PIPEDA Principle 4.10.4).
  • Whether Dell remained responsible for personal information transferred to a third party for processing.