The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

2 decisions matching
Federal (Canada)Privacy ActWell-founded
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Royal Canadian Mounted Police (RCMP)

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Quick view

Privacy ActWell-founded

Special report to Parliament: Investigation of the RCMP’s collection of open-source information under Project Wide Awake

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into the Royal Canadian Mounted Police's (RCMP) collection of open-source information under Project Wide Awake (PWA), triggered by a complaint from MP Charlie Angus. The investigation focused on the RCMP's use of third-party services, specifically Babel Street's Babel X, for collecting personal information from various online sources. The OPC found that the RCMP failed to conduct adequate due diligence to ensure that the personal information collected via Babel X and its data providers complied with Canadian privacy laws, particularly PIPEDA. Furthermore, the OPC determined that the RCMP did not meet its transparency obligations under Section 11 of the Privacy Act, as its Personal Information Bank (PIB) descriptions were inadequate in detailing the types and purposes of open-source information collected. The RCMP did not agree to implement the OPC's recommendations, including ceasing collection from problematic Babel X sources until a thorough review was completed and updating its PIB descriptions with sufficient granularity. Consequently, both issues were found to be well-founded and unresolved.

Key Issues
  • Whether the RCMP's collection of personal information via Social Studio complied with Section 4 of the Privacy Act.
  • Whether the RCMP's collection of personal information via Babel X complied with Section 4 of the Privacy Act.
  • Whether the RCMP conducted adequate due diligence on the lawfulness of collection practices of Babel X and its data providers.
  • Whether Section 4 of the Privacy Act permits the collection of personal information from a third-party agent that collected, used, or disclosed the information in contravention of a law that third party is subject to.
  • Whether the RCMP's publicly available descriptions of its open-source information gathering are granular enough to meet transparency obligations under Section 11 of the Privacy Act.
  • Whether the RCMP's published descriptions clarify limits on purposes for collection under Section 11 of the Privacy Act.
  • Whether the RCMP's descriptions of open-source information collection and related purposes are adequate under Section 11 of the Privacy Act.
Federal (Canada)Privacy ActWell-founded & conditionally resolved
Federal (Canada) flag
Feb 15, 2024Special report to ParliamentIndexed Jun 30, 2026

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Canada Revenue Agency and Employment and Social Development Canada

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Quick view

Privacy ActWell-founded & conditionally resolved

Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks

Feb 15, 2024Special report to Parliament
Adjudicator: Philippe Dufresne
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.

Key Issues
  • Whether Canada Revenue Agency (CRA) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether Employment and Social Development Canada (ESDC) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
  • Whether CRA contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether ESDC contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
  • Whether CRA and ESDC adequately assessed the level of identity authentication warranted for their online services.
  • Whether CRA and ESDC's identity assurance practices adequately protected against identity theft.
  • Whether CRA and ESDC's credential assurance practices adequately protected against credential stuffing.
  • Whether CRA and ESDC had adequately informed and accountable security decision-making processes.
  • Whether interdepartmental information sharing and accountability systems were adequate to protect personal information.
  • Whether CRA and ESDC conducted comprehensive vulnerability assessments and penetration testing.
  • Whether CRA and ESDC had effective monitoring to detect and promptly contain the ongoing breach.
  • Whether other federal departments using the GC Key service experienced fraudulent access or modification of personal information.