The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

22,101 decisions in the archive
ManitobaThe Freedom of Information and Protection of Privacy Act
Manitoba flag

2015-0233 — City of Winnipeg – Assessment and Taxation Department

Subscribe to open Manitoba decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2017 QCCAI 151 — Ville de Saguenay

Subscribe to open Quebec decisions.

Unlock this jurisdiction
Newfoundland and LabradorAccess to Information and Protection of Privacy Act, 2015
Newfoundland and Labrador flag

A-2017-015 — Department of Natural Resources

Subscribe to open Newfoundland and Labrador decisions.

Unlock this jurisdiction
AlbertaFreedom of Information and Protection of Privacy Act
Alberta flag

F2017-52 — Alberta Labour

Subscribe to open Alberta decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2017 QCCAI 138 — Ville de Gatineau

Subscribe to open Quebec decisions.

Unlock this jurisdiction
SaskatchewanFreedom of Information and Protection of Privacy Act
Saskatchewan flag

Review Report 308-2016 and 309-2016 — Global Transportation Hub Authority

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
SaskatchewanHealth Information Protection Act
Saskatchewan flag

Investigation Report 066-2017 — MD Ambulance

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
Nova ScotiaMunicipal Government Act — Part XX (Information Access and Protection of Privacy)
Nova Scotia flag

17-05 — Halifax Regional Municipality

Subscribe to open Nova Scotia decisions.

Unlock this jurisdiction
OntarioMunicipal Freedom of Information and Protection of Privacy Act
Ontario flag

Order MO-3456

Subscribe to open Ontario decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2017 QCCAI 148 — Centre hospitalier de l'Université de Montréal

Subscribe to open Quebec decisions.

Unlock this jurisdiction
OntarioPersonal Health Information Protection Act
Ontario flag

HA16-21 — Dr. Nili Kaplan-Myrth

Subscribe to open Ontario decisions.

Unlock this jurisdiction
Newfoundland and LabradorAccess to Information and Protection of Privacy Act, 2015
Newfoundland and Labrador flag

P-2017-002 — Town of Gander

Subscribe to open Newfoundland and Labrador decisions.

Unlock this jurisdiction
SaskatchewanFreedom of Information and Protection of Privacy Act
Saskatchewan flag

Review Report 305-2016 — Executive Council

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
SaskatchewanFreedom of Information and Protection of Privacy Act
Saskatchewan flag

REVIEW REPORT 026-2017 — Ministry of Highways and Infrastructure

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Jun 8, 2017Indexed Jun 30, 2026

Phoenix pay system compromised Public Servants’ privacy

Public Services and Procurement Canada

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Quick view

Privacy ActWell-founded

Phoenix pay system compromised Public Servants’ privacy

Jun 8, 2017
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner (OPC) investigated three complaints concerning Public Services and Procurement Canada's (PSPC) Phoenix Pay System. Complainants alleged improper disclosure of federal public service employees' personal information, with PSPC being aware of privacy issues before the system's launch. The OPC's investigation revealed at least 11 breaches, more extensive than initially reported by PSPC, involving employee names, Personal Record Identifiers (PRIs), and salary information, with government-wide vulnerabilities. These breaches stemmed from inadequate testing, coding errors, and insufficient system controls. The OPC found that PSPC failed to adequately monitor access to personal information, provide timely and sufficient notification to affected individuals, and fully address known vulnerabilities. Consequently, the OPC found the complaints to be well-founded and issued six recommendations to PSPC, some of which PSPC's proposed actions were deemed inconsistent or insufficient by the OPC.

Key Issues
  • Whether personal information was at issue in the reported incidents
  • Whether the personal information at issue was improperly disclosed
  • What was the scope of the improper disclosure
  • Whether the personal information that was improperly disclosed was misused
  • Whether PSPC was aware of potential privacy issues with Phoenix before the launch
  • What kind of harm could result from the unauthorized disclosure of the personal information at issue
  • Whether PSPC resolved all of the vulnerabilities within Phoenix
  • Whether PSPC provided individuals with timely information regarding the breaches and vulnerabilities
  • Whether PSPC developed and implemented controls to monitor and document access to personal information held in Phoenix (Recommendation 1)
  • Whether PSPC developed more robust testing and response procedures (Recommendation 2)
  • Whether PSPC conducted necessary assessments to identify potential risks and vulnerabilities in Phoenix (Recommendation 3)
  • Whether PSPC took measures to mitigate the increased vulnerability of information used by employees in call centres (Recommendation 4)
  • Whether PSPC reviewed its breach notification practices and provided notification of the extent of the Phoenix breaches (Recommendation 5)
  • Whether PSPC completed the review of pages with row-level security (Recommendation 6)