BreachOfPrivacy

Canadian Privacy Decisions

The comprehensive archive of Canadian privacy decisions from federal, provincial, and territorial commissioners — with AI-summarized plain-language summaries for every decision.

944 decisions matching
Quebec
Subscribers only
Act respecting the protection of personal information in the private sector

2018 QCCAI 310 — Syndicat des travailleurs et travailleuses unis de l'alimentation et du commerce, section locale 500

Subscribe to access Quebec decisions.

Flag of Ontario
Ontario
Subscribers only
Personal Health Information Protection Act

PHIPA DECISION 65

Subscribe to access Ontario decisions.

Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Jan 9, 2018PIPEDA findings #2018-007· Indexed Apr 12, 2026

PIPEDA findings #2018-007: Online marketplace needs consent from members before contacting them to join advocacy network

An online marketplace

The OPC investigated a complaint against an online marketplace that sent an email to members inviting them to sign a petition without their explicit consent. The OPC found that the marketplace retained information appropriately but failed to obtain adequate consent for sending the petition email, which was beyond the scope of their services. The OPC also found that the marketplace did not handle the complainant's privacy concerns effectively. The matter was conditionally resolved when the marketplace committed to implementing recommendations, including obtaining opt-in consent for such emails and improving complaint handling. The issue was later resolved upon evidence of implementation.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA findings #2018-007: Online marketplace needs consent from members before contacting them to join advocacy network

Jan 9, 2018PIPEDA findings #2018-007
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC investigated a complaint against an online marketplace that sent an email to members inviting them to sign a petition without their explicit consent. The OPC found that the marketplace retained information appropriately but failed to obtain adequate consent for sending the petition email, which was beyond the scope of their services. The OPC also found that the marketplace did not handle the complainant's privacy concerns effectively. The matter was conditionally resolved when the marketplace committed to implementing recommendations, including obtaining opt-in consent for such emails and improving complaint handling. The issue was later resolved upon evidence of implementation.

Key Issues
  • Adequacy of consent for using personal information for advocacy emails.
  • Proper handling and escalation of customer privacy complaints.
  • Appropriate retention of personal information.
  • Clarity of purposes stated in the privacy policy.
Quebec
Subscribers only
Act respecting access to documents held by public bodies and the protection of personal information

2018 QCCAI 21 — Ville de Montréal (Arrondissement Côte-des-Neiges/N.-D.-de-Grâce)

Subscribe to access Quebec decisions.

Quebec
Subscribers only
Act respecting access to documents held by public bodies and the protection of personal information

2018 QCCAI 31 — Protecteur du citoyen

Subscribe to access Quebec decisions.

Quebec
Subscribers only
Act respecting the protection of personal information in the private sector

2018 QCCAI 36 — Desjardins General Insurance Inc.

Subscribe to access Quebec decisions.

Quebec
Subscribers only
Act respecting access to documents held by public bodies and the protection of personal information

2018 QCCAI 4 — Services animaliers de la Vallée-du-Richelieu

Subscribe to access Quebec decisions.

Quebec
Subscribers only
Act respecting access to documents held by public bodies and the protection of personal information

2018 QCCAI 8 — Société de l'assurance automobile du Québec

Subscribe to access Quebec decisions.

Flag of Ontario
Ontario
Subscribers only
Freedom of Information and Protection of Privacy Act

Order PO-3802

Subscribe to access Ontario decisions.

Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Jan 8, 2018PIPEDA Report of Findings #2018-001· Indexed Apr 12, 2026

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

VTech Holdings Limited

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint following a global data breach at VTech Holdings Limited, which potentially compromised the personal information of over 316,000 Canadian children and 237,000 Canadian adults. The investigation found significant deficiencies in VTech's information security safeguards, including a lack of testing, inadequate access controls, cryptographic issues, and absence of security monitoring. Although VTech contravened PIPEDA Principle 4.7, the OPC concluded the matter was resolved because VTech implemented timely and comprehensive measures to address the breach and improve its security.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

Jan 8, 2018PIPEDA Report of Findings #2018-001
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint following a global data breach at VTech Holdings Limited, which potentially compromised the personal information of over 316,000 Canadian children and 237,000 Canadian adults. The investigation found significant deficiencies in VTech's information security safeguards, including a lack of testing, inadequate access controls, cryptographic issues, and absence of security monitoring. Although VTech contravened PIPEDA Principle 4.7, the OPC concluded the matter was resolved because VTech implemented timely and comprehensive measures to address the breach and improve its security.

Key Issues
  • Adequacy of information security safeguards for children's data
  • Failure to test for and mitigate known vulnerabilities
  • Insufficient access controls and cryptographic protection
  • Lack of comprehensive security management program
Quebec
Subscribers only
Act respecting health and social services information

2018 QCCAI 1 — Centre intégré universitaire de santé et de services sociaux de la Mauricie-et-du-Centre-du-Québec

Subscribe to access Quebec decisions.

Flag of Prince Edward Island
Prince Edward Island
Subscribers only
Freedom of Information and Protection of Privacy Act

FI-18-001 — Public Schools Branch

Subscribe to access Prince Edward Island decisions.

Flag of Ontario
Ontario
Subscribers only
Municipal Freedom of Information and Protection of Privacy Act

Order MO-3548

Subscribe to access Ontario decisions.

Flag of Saskatchewan
Saskatchewan
Subscribers only
Local Authority Freedom of Information and Protection of Privacy Act

REVIEW REPORT 210-2017 — City of Saskatoon

Subscribe to access Saskatchewan decisions.