The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,013 decisions matching
Northwest TerritoriesAccess to Information and Protection of Privacy Act
Northwest Territories flag

16-143 — Yellowknife Housing Authority

Subscribe to open Northwest Territories decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2016 QCCAI 58 — Régie de gestion des matières résiduelles de la Mauricie

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2016 QCCAI 60 — CHU de Québec - Université Laval

Subscribe to open Quebec decisions.

Unlock this jurisdiction
Newfoundland and LabradorAccess to Information and Protection of Privacy Act, 2015
Newfoundland and Labrador flag

A-2016-001 — Office of the Chief Information Officer

Subscribe to open Newfoundland and Labrador decisions.

Unlock this jurisdiction
British ColumbiaFreedom of Information and Protection of Privacy Act
British Columbia flag

F16-07 — BC OIPC order 1829

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
OntarioMunicipal Freedom of Information and Protection of Privacy Act
Ontario flag

Order MO-3289

Subscribe to open Ontario decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2016 QCCAI 46 — Commission scolaire Eastern Townships

Subscribe to open Quebec decisions.

Unlock this jurisdiction
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Feb 19, 2016PIPEDA Report of Findings #2016-002Indexed Jun 30, 2026

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

A property management company

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2016-002: Property management company agrees to scrap "bad tenant list"

Feb 19, 2016PIPEDA Report of Findings #2016-002
Adjudicator: Daniel Therrien
Plain-Language Summary

A complainant alleged that a property management company improperly collected, used, and disclosed tenants' personal information by maintaining a "bad tenant list" for a landlord association, leading to her rental application rejection. The company confirmed it held the list, arguing tenants consented via a rental application clause. The OPC found that the consent clause was not meaningful for this purpose and that the company was acting as an unlicensed credit reporting agency, making the purpose inappropriate under PIPEDA s.5(3). The OPC also found issues with the accuracy of the information and the lack of opportunity for individuals to challenge it. The company disagreed with being classified as a credit reporting agency but agreed to destroy the list and cease its collection, use, and disclosure. The matter was found to be well-founded and resolved.

Key Issues
  • Whether the collection, use, and disclosure of personal information for a "bad tenant list" was for purposes that a reasonable person would consider appropriate in the circumstances (s.5(3) PIPEDA)
  • Whether the property management company was acting as an unlicensed credit reporting agency under provincial legislation
  • Whether meaningful knowledge and consent of individuals were obtained for the collection, use, and disclosure of their personal information for the "bad tenant list" (Principle 4.3, 4.3.2 PIPEDA)
  • Whether the personal information on the "bad tenant list" was accurate, complete, and up-to-date (Principle 4.6, 4.6.1 PIPEDA)
  • Whether individuals had the ability to challenge the accuracy of information about them on the list (Principle 4.10 PIPEDA)
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 19, 2016Incident Summary #11Indexed Jun 30, 2026

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

A financial institution

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #11: Financial institution reacts quickly to mass-mailing error

Feb 19, 2016Incident Summary #11
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual received their RRSP tax contribution statement from a financial institution, but one copy contained the personal information of another individual, including their name, address, account number, RRSP contribution, and social insurance number. The financial institution reported the mass-mailing error to the OPC, explaining that a production error during automated printing caused a few hundred incorrect statements to be mailed. The OPC noted that the financial institution reacted quickly by assembling a breach response team, notifying affected clients, providing new statements, increasing account monitoring, and offering complimentary credit alert monitoring. The institution also asked clients to destroy incorrect statements and implemented new internal controls to prevent future errors. The OPC highlighted the importance of precautions in mass mail-outs and having systems to respond to errors.

Key Issues
  • Whether the financial institution adequately safeguarded personal information during mass mail-outs
  • Whether the financial institution responded appropriately to a privacy breach involving misdirected mail
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2016 QCCAI 47 — Municipalité de la paroisse des Saints-Martyrs-Canadiens

Subscribe to open Quebec decisions.

Unlock this jurisdiction
Prince Edward IslandFreedom of Information and Protection of Privacy Act
Prince Edward Island flag

FI-16-001 — Department of Economic Development and Tourism

Subscribe to open Prince Edward Island decisions.

Unlock this jurisdiction
British ColumbiaPersonal Information Protection Act
British Columbia flag

P16-01 — BC OIPC order 1828

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Federal (Canada) flag
Feb 18, 2016Incident Summary #13Indexed Jun 30, 2026

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

A Canadian financial institution

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Quick view

Personal Information Protection and Electronic Documents ActResolved

Incident Summary #13: Fraudster targets financial institution employees and then customers to obtain personal information

Feb 18, 2016Incident Summary #13
Adjudicator: Daniel Therrien
Plain-Language Summary

A Canadian financial institution reported a privacy breach where a fraudster used deceptive impersonation techniques to obtain contact information for approximately 100 customers from its customer service centre employees. The fraudster then contacted these customers directly to extract additional sensitive personal information, potentially exposing them to identity theft. Upon discovering the incident, the financial institution alerted the OPC, conducted an investigation, and notified all affected customers, offering them complimentary credit protection monitoring. The institution also advised customers on how to prevent fraud and implemented enhanced controls and additional staff training to mitigate recurrence. No reports of fraud related to credit or debit cards were received by the institution as a result of the incident.

Key Issues
  • Whether the financial institution adequately protected customer personal information from unauthorized disclosure by a fraudster
  • Whether the financial institution took appropriate steps to mitigate the impact of the breach and prevent recurrence
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2016 QCCAI 45 — Municipalité de Shannon

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2016 QCCAI 44 — La Capitale assurances et gestion du patrimoine inc.

Subscribe to open Quebec decisions.

Unlock this jurisdiction