As an Ombudsperson, the Commissioner’s primary role is to investigate and try to resolve privacy complaints against organizations. Her findings on a given issue may differ depending on the facts of each case and the position of the parties. Over time, findings on certain key issues have begun to crystallize into general principles that can serve as helpful guidance for organizations.
In an effort to summarize the general principles that have emerged from the Commissioner’s findings to date, the OPC has begun issuing Interpretations of certain key concepts in PIPEDA. These Interpretations are not binding legal interpretations, but rather, are intended only as a guide. As the Commissioner issues more findings, and the courts render more decisions, these Interpretations may evolve and be further refined over time.
Section 2(1) of the Personal Information Protection and Electronic Documents Act (2000, c. 5) (PIPEDA) states that “personal information” means “information about an identifiable individual, but does not include the name, title or business address or telephone number of an employee of an organization.”
Section 4(1) provides that PIPEDA applies to every organization in respect of personal information that the organization “collects, uses or discloses in the course of commercial activities” or “is about an employee of the organization and that the organization collects, uses or discloses in connection with the operation of a federal work, undertaking or business.”
1 This case arose under the Access to Information Act, R.S., 1985, c. A-1 that incorporates the definition of “personal information” from the Privacy Act, R.S.C. 1985, c. P-21, which is virtually identical to the definition of “personal information” in PIPEDA.
2 Personal Information Protection and Electronic Documents Act, Regulations Specifying Publicly Available Information (SOR/2001-7).
3 PIPEDA Case Summary #297 (December 1, 2004), Unsolicited e-mail for marketing purposes http://www.privcom.gc.ca/cf-dc/2005/297_050331_01_e.asp.
4PIPEDA Case Summary #372 -Disclosures to data brokers expose weaknesses in telecoms’ safeguards http://www.privcom.gc.ca/cf-dc/2007/372_20070709_e.asp.
5 PIPEDA Case Summary #181 (July 10, 2003), Alleged inappropriate disclosure of personal information to a third party - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_030710_05_e.asp.
6 PIPEDA Case Summary #14 - Selling of information on physicians’ prescribing patterns - http://www.privcom.gc.ca/cf-dc/2001/cf-dc_010921_e.asp; PIPEDA Case Summary #15 - Privacy Commissioner releases his finding on the prescribing patterns of doctors - http://www.privcom.gc.ca/media/an/wn_011002_e.asp.
7 PIPEDA Case Summary #220 - Telemarketer objects to employer sharing her sales results with other employees - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_030915_e.asp.
8 PIPEDA Case Summary #303 - Real estate broker publishes names of top five sales representatives in a city - http://www.privcom.gc.ca/cf-dc/2005/303_20050531_e.asp.
9 PIPEDA Case Summary #22 - Company asks for customer’s SIN as a matter of policy - http://www.privcom.gc.ca/cf-dc/2001/cf-dc_011105_02_e.asp; PIPEDA Case Summary #337 - Income tax preparation company mails personal information to wrong clients - http://www.privcom.gc.ca/cf-dc/2006/337_20060609_e.asp; PIPEDA Case Summary #317 - Fax from debt collector contained debtor’s personal information - http://www.privcom.gc.ca/cf-dc/2005/317_20051024_e.asp.
10 PIPEDA Case Summary # 277 - Mass mailout results in disclosure of contest entrants e-mail addresses - http://www.privcom.gc.ca/cf-dc/2004/cf-dc_040902_02_e.asp; PIPEDA Case Summary # 297 - Unsolicited e-mail for marketing purposes - http://www.privcom.gc.ca/cf-dc/2005/297_050331_01_e.asp.
11 PIPEDA Case Summary #296 - Language of consent and monitoring activity challenged - http://www.privcom.gc.ca/cf-dc/2005/296_050314_02_e.asp; PIPEDA Case Summary #300 - Company collecting consumer personal information without identifying purposes halts practice and implements privacy policies and practices - http://www.privcom.gc.ca/cf-dc/2005/300_050429_e.asp; PIPEDA Case Summary #366 - Auto body shop implements privacy policy and undertakes changes to privacy practices - http://www.privcom.gc.ca/cf-dc/2007/366_20070119_e.asp; PIPEDA Case Summary - Ticketmaster Canada Limited revised its policies and practices with respect to PIPEDA to protect customers’ personal information - http://www.privcom.gc.ca/cf-dc/2008/cf-dc_20080212_e.asp.
12 PIPEDA Case Summary #262 - Airline agrees to amend privacy policy - http://www.privcom.gc.ca/cf-dc/2004/cf-dc_040227_e.asp.
13 PIPEDA Case Summary #374 -Bank faxes credit card account statement to fraudster - http://www.privcom.gc.ca/cf-dc/2007/374_20070323_e.asp ; PIPEDA Case Summary #176 - Bank records customer call without consent; refuses to erase tape - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_030603_e.asp; PIPEDA Case Summary #72 - Telecommunications company improves its collection and disclosure practices - http://www.privcom.gc.ca/cf-dc/2002/cf-dc_021007_1_e.asp.
14 PIPEDA Case Summary #292 - Former employer changed account information of Air Canada frequent flyer member - http://www.privcom.gc.ca/cf-dc/2005/292_050406_e.asp and PIPEDA Case Summary #241 - Bank complies with consent principles - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_031204_04_e.asp.
15 PIPEDA Case Summary #370 - Airline broadens interpretation of personal information and improves handling of personal information access requests - http://www.privcom.gc.ca/cf-dc/2007/370_20070112_e.asp.
16 PIPEDA, section 4(1)(b).
17 PIPEDA Case Summary #198 - Employer accused of wrongful disclosure - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_030801_03_e.asp.
18 PIPEDA Case Summary #73 - Telecommunications company asked to adopt consistent retention practices - http://www.privcom.gc.ca/cf-dc/2002/cf-dc_021007_2_e.asp.
19 PIPEDA Case Summary #233 - An individual challenged the requirement to provide the medical diagnosis on her doctor’s certificate for sick leave - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_031003_e.asp; PIPEDA Case Summary #257 - Employees objected to corporation’s requirement http://www.privcom.gc.ca/cf-dc/2003/cf-dc_031009_01_e.asp; PIPEDA Case Summary #235 - Individual challenges employer’s refusal to grant sick leave - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_031107_03_e.asp; PIPEDA Case Summary #287 - Request for medical information deemed reasonable, but consent procedures not properly followed - http://www.privcom.gc.ca/cf-dc/2005/287_050105_e.asp; Case Summary #284 - Use and disclosure of health information considered appropriate, but access request was mishandled - http://www.privcom.gc.ca/cf-dc/2004/cf-dc_041130_e.asp; PIPEDA Case Summary #226 - Company's collection of medical information unnecessary; safeguards are inappropriate - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_031031_e.asp.
20 L’Ecuyer v. Aéroports de Montréal 2003 FCT 573 - http://decisions.fct-cf.gc.ca/en/2003/2003fct573/2003fct573.html, affirmed by [2004] F.C.A. 237 - http://decisions.fca-caf.gc.ca/en/2004/2004fca237/2004fca237.html.
21 PIPEDA Case Summary #149 - Individual denied access to personal information - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_030409_2_e.asp.and PIPEDA Case Summary #360 - Bank erroneously e-mails employees’ personal information to client - http://www.privcom.gc.ca/cf-dc/2006/360_20061114_e.asp.
22 PIPEDA Case Summary #149 - Individual denied access to personal information - http://www.privcom.gc.ca/cfdc/2003/cf-dc_030409_2_e.asp.
23 PIPEDA Case Summary #264 - Video cameras and swipe cards in the workplace - http://www.privcom.gc.ca/cf-dc/2004/cf-dc_040219_01_e.asp; PIPEDA Case Summary #290 -Video surveillance cameras at food processing plant questioned - http://www.privcom.gc.ca/cf-dc/2005/290_050127_e.asp; PIPEDA Case Summary #279 - Surveillance of employees at work - http://www.privcom.gc.ca/cf-dc/2004/cf-dc_040726_e.asp; PIPEDA Case Summary #114 - Employee objects to company’s use of digital video surveillance cameras - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_030123_e.asp; Eastmond v. Canadian Pacific Railway, 2004 FC 852 (CanLII), (2004), 16 Admin. L.R.(4th) 275 - http://www.canlii.org/en/ca/fct/doc/2004/2004fc852/2004fc852.html.
24 PIPEDA Case Summary #360 - Bank erroneously e-mails employees’ personal information to client - http://www.privcom.gc.ca/cf-dc/2006/360_20061114_e.asp.
25 PIPEDA Case Summary #201 - Former employee encounters delays in accessing personal information - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_030801_06_e.asp.
28 PIPEDA Case Summary #2009-018 – Psychologist’s anonymized peer review notes are the personal information of the patient - http://www.priv.gc.ca/cf-dc/2009/2009_018_0223_e.cfm
29 PIPEDA Case Summary #348 - Disclosure of diagnosis was inappropriate, but insurance company considered to be open about its privacy policies and practices - http://www.privcom.gc.ca/cf-dc/2006/348_20060814_e.asp.
30 PIPEDA Case Summary #368 - Insurance adjusters’ consent form considered overly broad - http://www.privcom.gc.ca/cf-dc/2007/368_20070111_e.asp
31 PIPEDA Case Summary #362 -Insurance adjuster readjusts its collection practices - http://www.privcom.gc.ca/cf-dc/2006/362_20061214_e.asp.
33 PIPEDA Case Summary 325- Personal information practices considered in sale of dental practice - http://www.privcom.gc.ca/cf-dc/2006/325_20060118_e.asp; PIPEDA Case Summary 328 - Medical records storage company revises its access policy - http://www.privcom.gc.ca/cf-dc/2006/328_20060609_e.asp.
34 PIPEDA Incident Summary #2 -CIBC's privacy practices failed in cases of misdirected faxes - http://www.privcom.gc.ca/incidents/2005/050418_01_e.asp; PIPEDA Case Summary #335 - Customer receives banking information of other clients - http://www.privcom.gc.ca/cf-dc/2006/335_20060627_e.asp; PIPEDA Case Summary #332 - Bank issues new guidelines and educates employees after customer information is faxed to the wrong individual - http://www.privcom.gc.ca/cf-dc/2006/332_20060412_e.asp.
35 PIPEDA Case summary #356 - Customer’s banking personal information found in a recycling bin - http://www.privcom.gc.ca/cf-dc/2006/356_20061023_e.asp.
36 PIPEDA Case Summary #317 - Fax from debt collector contained debtor’s personal information - http://www.privcom.gc.ca/cf-dc/2005/317_20051024_e.asp; PIPEDA Case Summary #200 - Bank disclosure results in cancelled wedding - http://www.privcom.gc.ca/cfdc/2003/cf-dc_030806_01_e.asp.
37 PIPEDA Case Summary #154 - Couple dismayed at receiving unsealed envelope from bank - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_030415_1_e.asp; PIPEDA Case Summary # 336 - Disclosure of mortgage information required by law; collection of information by bankruptcy trustee also allowed - http://www.privcom.gc.ca/cf-dc/2006/336_20060621_e.asp.
38 PIPEDA Case Summary #340 - Law firms collected credit reports without consent - http://www.privcom.gc.ca/cf-dc/2006/340_20060502_e.asp.
39 PIPEDA Case Summary #63 - Bank refuses customer access to internal credit score - http://www.privcom.gc.ca/cf-dc/2002/cf-dc_020722_2_e.asp; PIPEDA Case Summary #39 - Privacy Commissioner releases finding on a bank's refusal to release credit score - http://www.privcom.gc.ca/media/an/wn_020227_e.asp.
40 PIPEDA Case Summary #344 - Couple’s safety deposit box opened in error – http://www.privcom.gc.ca/cf-dc/2006/344_20060717_e.asp.
41 PIPEDA Case Summary - Residential Property Appraisal Documents are Owners’ Personal Information - http://www.privcom.gc.ca/cf-dc/2008/cf-dc_20080507_e.asp.
42 PIPEDA Case Summary #130 - Disclosure of personal information in the collection of a debt - http://www.privcom.gc.ca/cf-dc/2003/cf-dc_030304_4_e.asp; PIPEDA Case Summary #267 - Bank discloses customer's personal information to employer - http://www.privcom.gc.ca/cf-dc/2004/cf-dc_040430_e.asp.
43 Privacy Commissioner’s Report of Findings – Law School Admission Council Investigation – May 29, 2008 - http://www.privcom.gc.ca/cf-dc/2008/cf-dc_rep_080529_e.asp
44 Wansink v. TELUS Communications Inc. (F.C.A.), 2007 FCA 21 - http://decisions.fca-caf.gc.ca/en/2007/2007fca21/2007fca21.html.
45 See note 43, above.
46 PIPEDA Case Summary #349 - Photographing of tenants’ apartments without consent for insurance purposes - http://www.privcom.gc.ca/cf-dc/2006/349_20060824_e.asp.
47 See note 23, above.
48 PIPEDA Case Summary #1 - Video surveillance activities in a public place - http://www.privcom.gc.ca/cf-dc/2001/cf-dc_010615_e.asp.
49 PIPEDA Case Summary #351 - Use of personal information collected by Global Positioning System considered - http://www.privcom.gc.ca/cf-dc/2006/351_20061109_e.asp.
50 Radio Frequency Identification (RFID) in the Workplace: Recommendations for Good Practices: A Consultation Paper, March 2008 http://www.privcom.gc.ca/information/pub/rfid_e.pdf.
51 PIPEDA Case Summary #25 - A broadcaster accused of collecting personal information via Web site - http://www.privcom.gc.ca/cf-dc/2001/cf-dc_011120_e.asp; PIPEDA Case Summary #315 - Web-centered company’s safeguards and handling of access request and privacy complaint questioned - http://www.privcom.gc.ca/cfdc/2005/315_20050809_03_e.asp; PIPEDA Case Summary #319 - ISP’s anti-spam measures questioned - http://www.privcom.gc.ca/cf-dc/2005/319_20051103_e.asp; PIPEDA Case Summary #2009-010 – Assistant Commissioner recommends Bell Canada inform customers about Deep Packet Inspection - http://www.priv.gc.ca/cf-dc/2009/2009_010_rep_0813_e.cfm; See also Submission of the Office of the Privacy Commissioner of Canada to the Canadian Radio-television and Telecommunications Commissioner (CRTC) – February 2009 - http://www.priv.gc.ca/information/pub/sub_crtc_090218_e.cfm ; Final reply of the Office of the Privacy Commissioner of Canada to the Canadian Radio-television and Telecommunication Commissioner (CRTC) – July 2009 - http://www.priv.gc.ca/information/pub/sub_crtc_090728_e.cfm ; and Canadian Radio and Telecommunications Commission Telecom Regulatory Policy CRTC 2009-657 –http://www.crtc.gc.ca/eng/archive/2009/2009-657.htm. at paras 96-105