Investigations into businesses
The Office of the Privacy Commissioner of Canada (OPC) conducts independent and impartial investigations into the personal information handling practices of businesses subject to the Personal Information Protection and Electronic Documents Act (PIPEDA).
The OPC publishes a selection of case summaries and findings from its investigations to provide concrete examples of how PIPEDA applies to the day-to-day management of personal information by businesses.
For each case, the Office indicates the outcome using a set of defined terms for findings and dispositions.
For more information about the complaint and investigation process, read How the OPC Enforces PIPEDA.
Note: Complainants are not named in the summaries or reports. The organizations are not identified unless the Privacy Commissioner of Canada has deemed it to be in the public interest to do so.
Disclaimer: Typographical errors have been corrected from the original version of the report of findings. They are indicated in [brackets].
Overview of the Joint Investigation of OpenAI OpCo, LLC
...that violated its policies – from the raw public data to reduce the processing of personal information... by analyzing vast amounts of tokenized text data (i.e., words or parts of words converted to numerical... of developing and deploying GPT-3.5 and 4, OpenAI stated that it removed certain data – limited...
Joint Investigation of OpenAI OpCo, LLC
...that violates its policies) and (ii) data licensed from third parties. In response to our Preliminary... of OpenAI’s notification about accuracy, using OpenAI’s export data tool, gaining... data and may be updated as the LLM is subject to further training. To train the GPT-3.5 and GPT-4...
Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner
...Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner PIPEDA Findings #2025-001: Joint investigation into a data breach... into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner...
Investigation into Brinks Home
..., under section 10.1, for organizations that experience a data breach (referred to in PIPEDA as a “breach... whether the breach presented a real risk of significant harm (“RROSH”) and whether Brinks complied with its breach notification requirements under the Act. While we concluded that the personal information...
Investigation into Agronomy’s privacy practices related to safeguards, accountability valid consent for the collection and use of personal information
...to Agronomy’s breach prevention and response. Certain of these gaps contributed directly to the occurrence and severity of the breach in question. Specifically: (i) Agronomy did not employ multifactor... mitigating the exfiltration of customer data. We also identified further safeguard gaps...
Hotel chain discovers breach of customer database following acquisition of a competitor
...at the time of the breach, along with the security gaps that were highlighted by the breach... and receive data about potential threats at minimum. At the time of the breach, Marriott... individual, or increase the risk and exposure of potential data breaches, the organization...
Investigation into MGM breach highlights how to assess risk, and need for timely assessment
...regarding a large-scale data breach MGM suffered in 2019. Not having received a breach report... credentials (which had been compromised in a previous data breach, not associated with MGM... of, and receive consistent information about, data breaches that pose a real risk of significant harm...
Security deficiencies at BMO lead to large-scale breach
...turned its mind to this assessment, it was able to quickly ascertain the scope of the data breach... 2017 breach altogether. Furthermore, there were important gaps in BMO’s intrusion detection... of technical documents and raw data. Analysis Details of the breach Description of the affected system BMO’s...
Investigation into CoreFour Inc.’s compliance with PIPEDA
...to this complaint, our Office investigated CoreFour’s compliance with its safeguards, breach response... and reporting privacy breaches, and that it failed to notify parents, and our Office, of the vulnerabilities he had identified. We found that the respondent was in compliance with its breach-related...
Joint investigation of Clearview AI, Inc. by the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Information and Privacy Commissioner for British Columbia, and the Information Privacy Commissioner of Alberta
...associated with misidentification or exposure to potential data breaches), where the vast majority... sequential steps - Clearview: “scrapes” images of faces and associated data from publicly accessible online..., in almost all circumstances, and facial recognition data is particularly sensitive. Furthermore, individuals...
Showing items 1 through 10 of 27.
- Date modified: