The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,249 decisions matching
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2021 QCCAI 101 — Barreau du Québec

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2021 QCCAI 73 — Université du Québec à Montréal

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2021 QCCAI 79 — CISSS des Laurentides

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting the protection of personal information in the private sector
Quebec flag

2021 QCCAI 81 — Première générale Gatineau

Subscribe to open Quebec decisions.

Unlock this jurisdiction
Nova ScotiaFreedom of Information and Protection of Privacy Act
Nova Scotia flag

21-04 — Justice

Subscribe to open Nova Scotia decisions.

Unlock this jurisdiction
SaskatchewanFreedom of Information and Protection of Privacy Act
Saskatchewan flag

REVIEW REPORT 295-2019, 296-2019 — SaskBuilds Corporation and Ministry of SaskBuilds and Procurement

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
SaskatchewanFreedom of Information and Protection of Privacy Act
Saskatchewan flag

Review Report 297-2019 — Ministry of SaskBuilds and Procurement (formerly SaskBuilds Corporation)

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
OntarioFreedom of Information and Protection of Privacy Act
Ontario flag

Order PO-4134-R

Subscribe to open Ontario decisions.

Unlock this jurisdiction
OntarioFreedom of Information and Protection of Privacy Act
Ontario flag

Order PO-4132-R

Subscribe to open Ontario decisions.

Unlock this jurisdiction
OntarioFreedom of Information and Protection of Privacy Act
Ontario flag

Order PO-4130

Subscribe to open Ontario decisions.

Unlock this jurisdiction
OntarioFreedom of Information and Protection of Privacy Act
Ontario flag

Order PO-4133

Subscribe to open Ontario decisions.

Unlock this jurisdiction
OntarioMunicipal Freedom of Information and Protection of Privacy Act
Ontario flag

Order MO-4034

Subscribe to open Ontario decisions.

Unlock this jurisdiction
OntarioPersonal Health Information Protection Act
Ontario flag

PHIPA DECISION 143

Subscribe to open Ontario decisions.

Unlock this jurisdiction
OntarioFreedom of Information and Protection of Privacy Act
Ontario flag

Order PO-4131-R

Subscribe to open Ontario decisions.

Unlock this jurisdiction
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2021PIPEDA Findings #2021-004Indexed Jun 30, 2026

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Fido Solutions Inc. (a subsidiary of Rogers Communications Inc.)

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2021-004: Company’s employees bypassed authentication protocols allowing fraudsters to repeatedly access customer’s account

Mar 30, 2021PIPEDA Findings #2021-004
Adjudicator: Daniel Therrien
Plain-Language Summary

An individual complained that Fido failed to safeguard his personal information, allowing fraudsters to repeatedly access his account, and that Fido did not provide his access request in an understandable format. The OPC found that Fido's employees repeatedly bypassed authentication protocols, leading to unauthorized disclosures of the complainant's personal information, indicating a systemic safeguards issue. Fido committed to implementing recommendations to enhance its authentication protocols and staff training. Regarding the access request, the OPC found that while Fido could provide call recordings instead of transcripts, the poor quality and restrictive listening conditions made the access not generally understandable. Fido subsequently provided transcripts. The safeguards aspect of the complaint was found well-founded and conditionally resolved, while the access aspect was found well-founded and resolved.

Key Issues
  • Whether Fido adequately safeguarded the Complainant’s personal information under Principle 4.7
  • Whether Fido responded to the Complainant’s access request in a generally understandable format under Principle 4.9 and 4.9.4