Language selection

Search

Highlights from the Privacy Commissioner of Canada’s 2025-2026 Annual Report

June 4 2026

Privacy Act Bulletins are intended to offer lessons learned, best practices and other important privacy news, trends and information related to privacy protection in the federal government. We encourage you to share this information with employees across your organization, including teams involved in technology, communications and program-delivery.


The Privacy Commissioner of Canada’s 2025-2026 Annual Report to Parliament was tabled today.

The report, entitled Championing privacy in the age of AI, highlights Privacy Commissioner of Canada Philippe Dufresne’s efforts to promote children’s privacy and provide leadership in support of Canadians and Canadian organizations in a world of rapidly developing technologies such as artificial intelligence.

The report also describes key initiatives to address the impact of the fast-moving pace of technological advancements at a critical moment in time for privacy.

Privacy and data protection are more relevant today than ever, especially at a time where federal institutions are increasingly leveraging technologies and collecting data to better serve Canadians. By prioritizing privacy in programs and processes and promoting privacy by design and responsible innovation, federal institutions will nurture a culture of privacy and “future proof” themselves for success.

Here are some highlights from the report:

Support to federal institutions

The Office of the Privacy Commissioner of Canada (OPC) held information events on a variety of privacy topics with many federal institutions, including the Treasury Board of Canada Secretariat (TBS), the Privy Council Office, and other organizations. Information sessions for federal public servants addressed topics such as privacy obligations, strategies to prevent and respond to breaches, conducting privacy impact assessments (PIAs), as well as privacy in the context of public-sector human resources. These events allowed the OPC to connect with more than 3,600 public servants.

The OPC offers advice to federal government institutions that are considering the development or implementation of new or amended programs that will have an impact on privacy. In 2025-2026, the OPC opened 58 new advisory consultations with federal government institutions.

The OPC also reviews PIAs and provides advice and recommendations where high-risk issues are identified. In 2025-2026, the OPC reviewed 181 PIAs, a 31% increase compared to the previous year.

Privacy Act breaches

With a threat environment that is constantly evolving, data breaches continue to be a significant concern. The volume of personal information that federal government institutions hold about employees and others makes them a valuable target for cybercriminals and other bad actors.

In 2025-2026, the OPC received 451 breach reports from federal government institutions affecting 48,159 Canadians. Of those reported to the OPC, 94% of Privacy Act breaches were assessed as likely to cause a real risk of significant harm.

Mishandling of information (e.g., data entry error, misdirected correspondence, labelling error) was the cause of 368 breaches reported under the Privacy Act, followed by cyber incidents (39), employee snooping (22), and security vulnerabilities (19).

The report includes summaries of some of the breach investigations that the OPC closed in 2025-2026.

Privacy Act investigations

In 2025-2026, the OPC received 3,146 complaints under the Privacy Act, a 62% increase over the previous year.

The OPC saw a 121% increase in time limit complaints, where a federal government institution has not responded to a personal information request within the time period set out in the legislation.

The OPC also saw a 105% increase in complaints related to Privacy Act Extension Order, No.3, which allows individuals outside Canada, including foreign nationals, to request information that Canadian federal government institutions hold about them.

The report includes summaries of some of the investigations that were completed in the 2025-2026 fiscal year.

OPC advice related to Direction on prescribed presence in the workplace

The Government of Canada Direction on prescribed presence in the workplace issued by TBS has raised questions about how federal government institutions can monitor and report on-site attendance of their employees and comply with the hybrid work model.

This led to both an OPC investigation into the Direction and requests from departments for advice.

While the Direction has not changed managers’ pre-existing authority to ensure that employees are abiding by the terms and conditions of their employment, on-site presence monitoring requires managers to adopt a more nuanced approach that balances operational compliance with employee privacy rights to avoid intrusive tracking and unintentional misuse of data.

To mitigate such risks, the OPC recommends that federal government institutions ensure that the least privacy-invasive means of verifying compliance are used. More generally, the OPC recommends making sure that the principles of necessity and proportionality are adhered to. In other words, the information must be demonstrably necessary for the activity, and the loss of privacy must be outweighed by operational need.

While verifying and reporting on compliance with the Direction is an operational activity, institutions can rely on personal information that they already collect to report on organizational compliance. For example, how many employees or what percentage of employees are coming into the office based on turnstile data, existing attendance reports and/or internet protocol login data to collect aggregated departmental information.

Under the current framework, compliance reporting must only be used for statistical purposes and not to make administrative decisions that affect individual employees.

Further reading


Sign up for future Privacy Act Bulletins by subscribing to our RSS feed.

Date modified: