
Report of Findings: Privacy Commissioner of Canada v. SWIFT
The Privacy Commissioner of Canada initiated a complaint against SWIFT SCRL (Society for Worldwide Interbank Financial Telecommunication) for allegedly disclosing personal information originating from or transferred to Canadian financial institutions to the US Department of the Treasury (UST) in response to administrative subpoenas. SWIFT, a global financial messaging service, argued it was legally compelled to comply with valid US subpoenas and had negotiated privacy protections with the UST. The OPC first determined that the Personal Information Protection and Electronic Documents Act (PIPEDA) applied to SWIFT due to its significant presence and commercial activities in Canada. The key issue was whether SWIFT's disclosure without consent complied with PIPEDA, specifically the exception for subpoenas under paragraph 7(3)(c) and the appropriateness of the disclosure under subsection 5(3). The Commissioner concluded that paragraph 7(3)(c) allows for compliance with valid foreign subpoenas when an organization operates in multiple jurisdictions and legitimately stores data abroad, and that the disclosure was appropriate given the legal compulsion and privacy safeguards SWIFT negotiated. Consequently, the complaint was found not well-founded, as SWIFT's actions did not contravene PIPEDA. The Commissioner, however, recommended that the Canadian government engage with US counterparts to encourage the use of existing information-sharing mechanisms with built-in privacy protections, and noted SWIFT's efforts to explore enhanced privacy solutions.
Ontario
British Columbia
Alberta
Saskatchewan
Manitoba
Quebec
Nova Scotia
New Brunswick
Prince Edward Island
Newfoundland and Labrador
Yukon
Northwest Territories
Nunavut