The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,626 decisions matching
Federal (Canada)Privacy ActWell-founded & unresolved
Federal (Canada) flag
Mar 11, 2025Indexed Jun 30, 2026

Investigation of the loss of an unencrypted Universal Serial Bus (USB) storage device by the Royal Canadian Mounted Police

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP) following the loss of an unencrypted USB storage device containing sensitive personal information of 1,741 individuals. The investigation focused on whether the RCMP contravened section 8 of the Privacy Act regarding disclosure, the appropriateness of its breach response, and the sufficiency of its safeguards for USB devices. The OPC found that the RCMP contravened section 8 due to unauthorized disclosure, as the device was lost, unencrypted, and its contents were copied and offered for sale. While the RCMP's notification to affected individuals and mitigation steps were generally appropriate after discovery, the initial reporting of the loss was significantly delayed. Furthermore, the RCMP failed to implement adequate safeguards, as its own policies for procurement, inventory, and encryption of USB devices were not followed, and security awareness training was insufficient. Despite the RCMP accepting the OPC's recommendations to strengthen safeguards, audit procedures, and awareness programs, it refused to commit to specific timelines for implementation. Consequently, the complaint was found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded & unresolved

Investigation of the loss of an unencrypted Universal Serial Bus (USB) storage device by the Royal Canadian Mounted Police

Mar 11, 2025
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated the Royal Canadian Mounted Police (RCMP) following the loss of an unencrypted USB storage device containing sensitive personal information of 1,741 individuals. The investigation focused on whether the RCMP contravened section 8 of the Privacy Act regarding disclosure, the appropriateness of its breach response, and the sufficiency of its safeguards for USB devices. The OPC found that the RCMP contravened section 8 due to unauthorized disclosure, as the device was lost, unencrypted, and its contents were copied and offered for sale. While the RCMP's notification to affected individuals and mitigation steps were generally appropriate after discovery, the initial reporting of the loss was significantly delayed. Furthermore, the RCMP failed to implement adequate safeguards, as its own policies for procurement, inventory, and encryption of USB devices were not followed, and security awareness training was insufficient. Despite the RCMP accepting the OPC's recommendations to strengthen safeguards, audit procedures, and awareness programs, it refused to commit to specific timelines for implementation. Consequently, the complaint was found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP disclosed personal information in contravention of section 8 of the Privacy Act
  • Whether the RCMP's response to the privacy breach was appropriate in the circumstances
  • Whether the RCMP's measures to protect personal information contained on USB storage devices were sufficient
  • Whether RCMP personnel failed to report the loss of the USB storage device to authorities in a timely manner
  • Whether the RCMP's policies and procedures for procurement, inventory, and encryption of USB devices were followed and enforced
  • Whether the RCMP's security and privacy awareness training for members was effective and sufficient
  • Whether the RCMP's policy compliance monitoring for USB device use was adequate
Northwest TerritoriesAccess to Information and Protection of Privacy Act
Northwest Territories flag

2025 NTIPC 96 — Department of Finance

Subscribe to open Northwest Territories decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2025 QCCAI 85 — Ministère de l'Emploi et de la Solidarité sociale

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2025 QCCAI 93 — Ministère des Transports et de la Mobilité durable

Subscribe to open Quebec decisions.

Unlock this jurisdiction
SaskatchewanLocal Authority Freedom of Information and Protection of Privacy Act
Saskatchewan flag

Review Report 176-2024 — Regina Police Service

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
OntarioMunicipal Freedom of Information and Protection of Privacy Act
Ontario flag

Order MO-4634

Subscribe to open Ontario decisions.

Unlock this jurisdiction
OntarioFreedom of Information and Protection of Privacy Act
Ontario flag

Order PO-4619

Subscribe to open Ontario decisions.

Unlock this jurisdiction
OntarioFreedom of Information and Protection of Privacy Act
Ontario flag

Order PO-4618

Subscribe to open Ontario decisions.

Unlock this jurisdiction
Federal (Canada)Access to Information ActWell-founded
Federal (Canada) flag
Mar 10, 20255822-05416Indexed Jun 30, 2026

5822-05416 — Canada Border Services Agency

Canada Border Services Agency

The complainant alleged that the Canada Border Services Agency (CBSA) improperly withheld information related to cybersecurity and data breach risk assessments of the ArriveCAN application under subsection 16(2) and paragraph 20(1)(d) of the Access to Information Act. During the investigation, CBSA initially disclosed some records but continued to withhold others under subsection 16(2) and additionally claimed subsection 19(1). The Commissioner found that while some information met the requirements of subsection 16(2) (facilitating an offence), other portions did not. Furthermore, the Commissioner concluded that CBSA failed to properly exercise its discretion under subsection 19(2) regarding personal information, as it did not demonstrate efforts to seek consent or consider public availability. The complaint was found to be well founded. Although the Commissioner issued an initial report with orders, CBSA subsequently made further disclosures, and the complainant indicated satisfaction, making a formal order unnecessary.

Quick view

Access to Information ActWell-founded

5822-05416 — Canada Border Services Agency

Mar 10, 20255822-05416
Adjudicator: Caroline Maynard
Plain-Language Summary

The complainant alleged that the Canada Border Services Agency (CBSA) improperly withheld information related to cybersecurity and data breach risk assessments of the ArriveCAN application under subsection 16(2) and paragraph 20(1)(d) of the Access to Information Act. During the investigation, CBSA initially disclosed some records but continued to withhold others under subsection 16(2) and additionally claimed subsection 19(1). The Commissioner found that while some information met the requirements of subsection 16(2) (facilitating an offence), other portions did not. Furthermore, the Commissioner concluded that CBSA failed to properly exercise its discretion under subsection 19(2) regarding personal information, as it did not demonstrate efforts to seek consent or consider public availability. The complaint was found to be well founded. Although the Commissioner issued an initial report with orders, CBSA subsequently made further disclosures, and the complainant indicated satisfaction, making a formal order unnecessary.

Key Issues
  • Whether s.16(2) ATIA (facilitating the commission of an offence) was properly applied to cybersecurity review information, including intranet/internal network addresses and specific vulnerabilities
  • Whether s.16(2) ATIA was properly applied to statements related to asset identification and valuation, lists of components, summaries of changes, names of reference documents, and executive overviews
  • Whether CBSA reasonably exercised its discretion under s.16(2) ATIA for information that met the exemption's requirements
  • Whether s.19(1) ATIA (personal information) was properly applied to pictures and contact information of KPMG employees
  • Whether CBSA made reasonable efforts to seek consent for disclosure of personal information under s.19(2)(a) ATIA
  • Whether CBSA considered if personal information was publicly available under s.19(2)(b) ATIA
  • Whether CBSA properly exercised its discretion under s.19(2) ATIA
SaskatchewanFreedom of Information and Protection of Privacy Act
Saskatchewan flag

Review Report 263-2024 — Saskatchewan Workers' Compensation Board

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
OntarioFreedom of Information and Protection of Privacy Act
Ontario flag

Order PO-4617

Subscribe to open Ontario decisions.

Unlock this jurisdiction
Northwest TerritoriesAccess to Information and Protection of Privacy Act
Northwest Territories flag

2025 NTIPC 94 — Department of Finance

Subscribe to open Northwest Territories decisions.

Unlock this jurisdiction
Northwest TerritoriesAccess to Information and Protection of Privacy Act
Northwest Territories flag

25-025-4 — Department of Finance

Subscribe to open Northwest Territories decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2025 QCCAI 72 — Ville de Trois-Rivières

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2025 QCCAI 73 — Curateur public

Subscribe to open Quebec decisions.

Unlock this jurisdiction