Investigations into businesses
The Office of the Privacy Commissioner of Canada (OPC) conducts independent and impartial investigations into the personal information handling practices of businesses subject to the Personal Information Protection and Electronic Documents Act (PIPEDA).
The OPC publishes a selection of case summaries and findings from its investigations to provide concrete examples of how PIPEDA applies to the day-to-day management of personal information by businesses.
For each case, the Office indicates the outcome using a set of defined terms for findings and dispositions.
For more information about the complaint and investigation process, read How the OPC Enforces PIPEDA.
Note: Complainants are not named in the summaries or reports. The organizations are not identified unless the Privacy Commissioner of Canada has deemed it to be in the public interest to do so.
Disclaimer: Typographical errors have been corrected from the original version of the report of findings. They are indicated in [brackets].
Investigation into a swimming pool’s compliance with consent requirements under the Personal Information Protection and Electronic Documents Act
...allowing the organization to take and post images of their children in swim attire on public... the facility to take and post images of children on public platforms in order to enroll them in swimming... it necessary to accept that images of children can be taken and posted on public platforms for promotional...
Security deficiencies at BMO lead to large-scale breach
...of birth (“DOB”), address and/ or credit/debit card numbers - and publicly disclosed..., an unauthorized third party proceeded to publicly post the personal information of 3,190 BMO customers on various public websites . While BMO acted quickly to request that the information be removed...
Biron Health Group has ceased sending promotional emails to travellers arriving in Canada who undergo COVID-19 testing
...was required to undergo COVID-19 testing, conducted by Biron, in accordance with public health rules issued by the Public Health Agency of Canada. The complainant says he provided his email address to Biron... but to do business with Biron to comply with the rules issued by the Public Health Agency. In this...
Store stops practice of posting pictures of suspected shoplifters
...resolved case summary #2015-01 Lessons Learned Publicly displaying, without consent, photographs... constituted their personal information and could not be publicly disclosed in such a manner...
Insurance company collected and used credit score for inappropriate purpose during auto insurance claims assessment process
...government had made the public policy decision to allow credit reporting agencies to disclose..., which suggests that the general public may not be sufficiently informed about insurance companies... the public on the use of credit information. Brokers suggested that consumers are actively being harmed...
Investigation into Equifax Inc. and Equifax Canada Co.’s compliance with PIPEDA in light of the 2017 breach of personal information
...On September 7, 2017 Equifax Inc. publically announced that an attacker had accessed the personal... a publically known vulnerability in the Apache Strut software platform supporting Equifax Inc.’s online... handling, Equifax Canada has consistently represented, both to our office, and to the public...
Investigation into a telecommunications company’s response to an individual’s request for access to information about disclosures of her personal information to other parties
...her personal information to third parties, which also includes private and public sector entities not covered... 9(2.1) to 9(2.4), as well as other public sector third parties that are not covered by subsections 9..., had been disclosed to all other parties, including private and public sector organizations. The telco...
Investigation into authentication and transfer practices used during Loblaw gift card offering
...by publically clarifying the limited information it required from individuals submitting ID... its request for ID in subsequent messaging in the media. Loblaw advised publically... clarified publically, and through a revision to its notice to registrants, that it only needed to verify...
Investigation into the personal information retention practices of Loblaw for the PC Optimum Loyalty Program
...and public network IP address as well as frequency, duration and time of logins); Browsing behaviour... sufficient anonymization for the following reasons: First, Loblaw retains public IP address data... given that an individual’s public IP address can be used to approximate their physical location, which, when cross...
Hotel chain discovers breach of customer database following acquisition of a competitor
..., Marriott International, Inc. (“Marriott”) publicly announced that it had experienced a data... our Office gathered and analyzed from publicly available sources concerning the breach, including... having confirmed its compliance with PCI DSS in April 2016, public statements made by Starwood...
Showing items 31 through 40 of 70.
- Date modified: