The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

173 decisions matching
AlbertaFreedom of Information and Protection of Privacy Act
Alberta flag

F2005-006 — Appeals Commission for Alberta Workers' Compensation

Subscribe to open Alberta decisions.

Unlock this jurisdiction
Northwest TerritoriesAccess to Information and Protection of Privacy Act
Northwest Territories flag

Review Recommendation 06-057 — Department of Public Works

Subscribe to open Northwest Territories decisions.

Unlock this jurisdiction
British ColumbiaPersonal Information Protection Act
British Columbia flag

P06-06 — BC OIPC order 1342

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
AlbertaFreedom of Information and Protection of Privacy Act
Alberta flag

F2005-007 — Alberta Justice and Attorney General

Subscribe to open Alberta decisions.

Unlock this jurisdiction
AlbertaHealth Information Act
Alberta flag

H2003-002 — Calgary Health Region

Subscribe to open Alberta decisions.

Unlock this jurisdiction
British ColumbiaFreedom of Information and Protection of Privacy Act
British Columbia flag

F06-21 — BC OIPC order 835

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
SaskatchewanFreedom of Information and Protection of Privacy Act
Saskatchewan flag

REPORT F-2006-005 — Saskatchewan Government Insurance and Saskatchewan Health and Saskatchewan Power Corporation and Saskatchewan Energy Incorporated

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
British ColumbiaPersonal Information Protection Act
British Columbia flag

P06-05 — BC OIPC order 1341

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
Dec 14, 2006Settled Case summary #28Indexed Jun 30, 2026

Settled case summary #28 — A DVD-rental store

A DVD-rental store

An individual complained that a DVD-rental store required him to provide his driver's license details for entry into their database to become a member, which he believed was unnecessary. The store initially argued this was a business necessity for identity verification and recovering overdue rentals. However, the investigation revealed the store did not use driver's license data for tracing members, but rather publicly available information. Recognizing it was collecting unnecessary information, the store revised its membership process. Under the new process, customers must present two pieces of identification, one with a photo, but driver's license details are no longer entered into the database. The store committed to updating its procedures and training staff on the new process.

Quick view

Personal Information Protection and Electronic Documents ActSettled

Settled case summary #28 — A DVD-rental store

Dec 14, 2006Settled Case summary #28
Adjudicator: Jennifer Stoddart
Plain-Language Summary

An individual complained that a DVD-rental store required him to provide his driver's license details for entry into their database to become a member, which he believed was unnecessary. The store initially argued this was a business necessity for identity verification and recovering overdue rentals. However, the investigation revealed the store did not use driver's license data for tracing members, but rather publicly available information. Recognizing it was collecting unnecessary information, the store revised its membership process. Under the new process, customers must present two pieces of identification, one with a photo, but driver's license details are no longer entered into the database. The store committed to updating its procedures and training staff on the new process.

Key Issues
  • Whether collecting and recording driver's license details was necessary for the DVD-rental store's operations
  • Whether the store's collection practices aligned with the principle of limiting collection to necessary information
British ColumbiaFreedom of Information and Protection of Privacy Act
British Columbia flag

Decision F06-12

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
Nova ScotiaFreedom of Information and Protection of Privacy Act
Nova Scotia flag

2007 NSSC 178 — Nova Scotia Department of Education

Subscribe to open Nova Scotia decisions.

Unlock this jurisdiction
AlbertaHealth Information Act
Alberta flag

H2006-IR-002 — Calgary Health Region

Subscribe to open Alberta decisions.

Unlock this jurisdiction
AlbertaFreedom of Information and Protection of Privacy Act
Alberta flag

F2006-028 — Workers' Compensation Board and Columbia Rehabilitation Centre

Subscribe to open Alberta decisions.

Unlock this jurisdiction
New BrunswickRight to Information and Protection of Privacy Act
New Brunswick flag

E.F. c. Nouveau-Brunswick (Éducation)

Subscribe to open New Brunswick decisions.

Unlock this jurisdiction
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Dec 4, 2006Incident Summary #3Indexed Jun 30, 2026

Incident Summary #3: Misdirected faxes - December 4, 2006

Two Canadian banks

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

Incident Summary #3: Misdirected faxes - December 4, 2006

Dec 4, 2006Incident Summary #3
Adjudicator: Jennifer Stoddart
Plain-Language Summary

The OPC investigated two incidents involving misdirected faxes from two banks, which resulted in personal information being sent to unintended recipients over several years. In both cases, the recipients attempted to notify the banks, but the issues were not escalated or resolved until media reports brought them to public attention. The investigations found that the banks failed to adequately safeguard personal information and ensure their privacy policies were effectively implemented by employees. While the banks took corrective measures during the investigation, the OPC made further recommendations to improve internal communication of breaches, customer notification, fax transmission verification, and recovery of misdirected information. Both banks fully implemented these recommendations.

Key Issues
  • Whether organizations adequately safeguard personal information to prevent inappropriate disclosure (Principle 4.7 PIPEDA)
  • Whether organizations implement effective policies and procedures to give effect to fair information practices (Principle 4.1 PIPEDA)
  • Whether employees are attuned to privacy issues and can respond to problems when they arise
  • Whether organizations notify affected customers of privacy breaches
  • Whether organizations have processes for confirming correct fax transmission
  • Whether organizations have measures to recover erroneously transmitted customer information