Privacy Commissioner of Canada (Office of the)
agent of Parliament; only homepage fetched; endpoints/strategy not attempted before session-wide WebFetch rate limit
Current this library's internal records: Office of the Privacy Commissioner of Canada's 2026-27 Departmental Plan (2027)
Completeness
- Document shelf: 29 rows (29 archived · 0 staged · 0 pending · 0 missing)
- Backgrounder: on file
- Strategy-evolution brief: on file
- Custody audit: 29 of 29 row(s) audited, all clean
- Last verified: 2026-08-04 · this org has NOT had a full discovery-verification pass (our discovery-verification log)
Endpoints
- Website
- Open data: checked — none found
- API: checked — none found
- RSS
- Newsroom: checked — none found
- FOI / access requests: checked — none found
Document shelf (29 rows)
Backgrounder
Source: this library's internal records — a mechanical research draft, not independently reviewed for publication; reproduced as-is.
Privacy Commissioner of Canada (Office of the) - backgrounder
Backgrounder / 2026-07-30 / registry row: fed-privacy-commissioner-canada (this library's government-document registry) / lens file for this org's series briefs
Mandate & statutory basis
The Office of the Privacy Commissioner of Canada (OPC) is established under the Privacy Act, R.S.C. 1985, c. P-21, consolidated at laws-lois.justice.gc.ca (https://laws-lois.justice.gc.ca/eng/acts/P-21/, fetched and verified directly). Sections 53-61 create the Office of the Privacy Commissioner and an Assistant Privacy Commissioner with supporting staff, empowered to investigate complaints, conduct special studies, and oversee federal-institution compliance with privacy protections (same source). The OPC also administers the Personal Information Protection and Electronic Documents Act (PIPEDA) governing private-sector personal information ⚠️ still being checked (PIPEDA citation not independently re-fetched this review).
Roles, responsibilities & scope
Per its 2026-27 Departmental Plan, the OPC's core responsibility is "Protection and Promotion of Privacy Rights"; 2026-27 priorities include strengthening compliance with federal privacy laws, resolving privacy complaints and reported breaches, addressing the privacy implications of AI/generative AI, and advancing children's-privacy protections (https://www.priv.gc.ca/en/about-the-opc/opc-operational-reports/planned-opc-spending/dp-index/2026-2027/dp-2026-27/, fetched directly).
Governance & reporting line
The Privacy Commissioner is an Agent of Parliament; the registry notes it as such (registry row registry id: fed-privacy-commissioner-canada), consistent with the Privacy Act's structuring of the Office as independent of the government departments it oversees (https://laws-lois.justice.gc.ca/eng/acts/P-21/). The Office's Departmental Plan is issued under copyright of "the Minister of Justice and Attorney General of Canada," reflecting the Justice portfolio's administrative tabling role rather than direction of the Commissioner's investigative work ⚠️ still being checked (precise reporting mechanics to Parliament not independently re-verified this review beyond the Act's establishment provisions).
Budget scale
~$37.6 million total planned spending for 2026-27 (including internal services), with 231 planned full-time-equivalent staff (2026-27 Departmental Plan, https://www.priv.gc.ca/en/about-the-opc/opc-operational-reports/planned-opc-spending/dp-index/2026-2027/dp-2026-27/, document id per doc-shelf: annual-report/departmental-plan). The Office proactively reduced executive positions by 10% as part of a 2025 reorganization (same source).
Institutional history
Established under the Privacy Act (Office of the Privacy Commissioner provisions at ss. 53-61, R.S.C. 1985, c. P-21); exact founding/coming-into-force year ⚠️ still being checked - not re-confirmed via primary source this review.
Strategy evolution brief
Source: this library's internal records — a mechanical research draft, not independently reviewed for publication; reproduced as-is.
Office of the Privacy Commissioner of Canada - strategy evolution
2026-08-02 / registry: fed-privacy-commissioner-canada / grounded in archived copies (cited document id + sha256) / read through our research file for that body
TL;DR: The biggest priority addition across the readable record is a formal, named strategic-priorities architecture that has now been rebuilt twice: four "strategic privacy priorities" announced in May 2015 (Economics of Personal Information, Government Surveillance, Reputation and Privacy, The Body as Information) for 2015-2020, superseded by an entirely different three-priority Strategic Plan launched January 2024 (protecting/promoting privacy with maximum impact; addressing AI/generative AI; championing children's privacy). The most consequential quiet drop is the entire 2015 four-priority framework itself — it is not renewed, extended, or explicitly retired anywhere in the readable series; the Office simply operates without a named priority architecture from roughly 2020 to January 2024. The most load-bearing number is that federal-institution data-breach reports to the Office rose from 26 in 2008-09 to 341 in 2019-20 (ar-2020, 2b76372aeda3) under a shift from voluntary to mandatory reporting in 2014-15 — a scale change the Office itself repeatedly cautions cannot be read as a pure severity trend. The central open question, live in the most recent archived document: whether Bill C-27 (private-sector reform) and Privacy Act modernization survive into the 45th Parliament after C-27 died on the order paper at prorogation in January 2025.
Backgrounder summary
Per the backgrounder, the OPC is established under the Privacy Act, R.S.C. 1985, c. P-21 (ss. 53-61), and also administers PIPEDA governing private-sector personal information (⚠️ still being checked in backgrounder — PIPEDA citation not independently re-fetched by the backgrounder pass). The Commissioner is an Agent of Parliament, independent of the departments it oversees. The 2026-27 Departmental Plan cites ~$37.6M total planned spending and 231 planned FTEs, with a 2025 reorganization proactively cutting executive positions by 10% (backgrounder, priv.gc.ca dp-2026-27). Core responsibility per that plan: "Protection and Promotion of Privacy Rights," with 2026-27 priorities including federal-law compliance, complaint/breach resolution, AI privacy implications, and children's-privacy protections — continuous with the priorities this brief traces emerging in the archived annual reports through 2025.
Series inventory
_index.json: 14 ok / 4 stub-suspected / 0 extract-failed.
Registry (our document registry) carries 26 rows for this org spanning 2001-2025; 18 are archived and appear below, 8 are staged and 0 are missing — those 8 staged years (2005, 2006, 2007, 2008, 2009, 2010, 2011, 2017) are not analyzable from the archive and are treated as gaps, not as disclosure choices.
| document id | year | type | archive ref sha256-12 | content read? |
|---|---|---|---|---|
| fed-privacy-commissioner-canada-ar-2001 | 2001 | annual-report | fa547f2f5194 | stub-suspected (LAC "Information Archived on the Web" interstitial, 804 chars — confirmed by reading) |
| fed-privacy-commissioner-canada-ar-2002 | 2002 | annual-report | 7f3633d28c9b | stub-suspected (same interstitial — confirmed) |
| fed-privacy-commissioner-canada-ar-2003 | 2003 | annual-report | c93f955cc98c | stub-suspected (same interstitial — confirmed) |
| fed-privacy-commissioner-canada-ar-2004 | 2004 | annual-report | cfcecf3ceaf7 | stub-suspected (same interstitial — confirmed) |
| fed-privacy-commissioner-canada-ar-2012 | 2012 | annual-report | 86d6a27b8041 | yes |
| fed-privacy-commissioner-canada-ar-2013 | 2013 | annual-report | 60d2a8db0018 | yes |
| fed-privacy-commissioner-canada-ar-2014 | 2014 | annual-report | 18ecfc830164 | yes |
| fed-privacy-commissioner-canada-ar-2015 | 2015 | annual-report | 06359f29fa54 | yes |
| fed-privacy-commissioner-canada-ar-2016 | 2016 | annual-report | 5c7bb74cd5a9 | yes |
| fed-privacy-commissioner-canada-ar-2018 | 2018 | annual-report | a5b78bceb060 | yes |
| fed-privacy-commissioner-canada-ar-2019 | 2019 | annual-report | f683af870ee4 | yes |
| fed-privacy-commissioner-canada-ar-2020 | 2020 | annual-report | 2b76372aeda3 | yes |
| fed-privacy-commissioner-canada-ar-2021 | 2021 | annual-report | 11b7657e11e0 | yes |
| fed-privacy-commissioner-canada-ar-2022 | 2022 | annual-report | 38590469b94f | yes |
| fed-privacy-commissioner-canada-ar-2023 | 2023 | annual-report | 6214e3ffacd0 | yes |
| fed-privacy-commissioner-canada-ar-2024 | 2024 | annual-report | 6b0ead366c13 | yes |
| fed-privacy-commissioner-canada-ar-2025 | 2025 | annual-report | 6b8a756f7169 | yes |
| fed-privacy-commissioner-canada-oth-2021 | 2021 | other (PIPEDA finding) | 62e45d469a23 | yes |
Note: no archived document exists for 2017 despite the registry showing it as staged rather than missing; this is a continuous gap between ar-2016 and ar-2018, not an extraction failure of a captured file.
Priority evolution
2011-12 and 2012-13 (ar-2012, 86d6a27b8041; ar-2013, 60d2a8db0018): No named strategic-priority framework yet exists. The Office (Commissioner Jennifer Stoddart, then in her final year) frames its work around the Privacy Act's 30th anniversary, an ombudsman model with no order-making power, and four narrative "trends" driving public concern: IT vulnerability/data breaches, inappropriate government employee access, response-time delays, and national-security-driven surveillance expansion (ar-2012). The 2012-13 report is dominated by the Correctional Service of Canada, Canada Revenue Agency, and FINTRAC as the Office's highest-complaint/audit targets, and by the "lawful access" legislative fight (Bill C-30) (60d2a8db0018).
2013-14 (ar-2014, 18ecfc830164): New Commissioner Daniel Therrien's first report. States explicitly that a prior Stoddart-era "strategic priority areas" exercise had served the Office "for several years" and that a fresh priority-setting exercise is beginning — the first documented instance of the Office formally re-deriving its own priorities rather than simply reporting activity (18ecfc830164, lines ~140-142). Dominant substantive theme: the Snowden/CSEC surveillance revelations and the R. v. Spencer Supreme Court ruling on subscriber-information privacy.
2014-15 (ar-2015, 06359f29fa54): The priority-setting exercise concludes. In May 2015 the Office announces four named "strategic privacy priorities" for 2015-2020, published as The OPC Privacy Priorities 2015-2020: Mapping a course for greater protection: Economics of Personal Information, The Body as Information, Reputation and Privacy, and Government Surveillance (06359f29fa54, lines 116-159). This is the first appearance of a formally named, multi-year priority architecture in the readable series. Government Surveillance is explicitly tied to Bill C-51 (the Anti-Terrorism Act, 2015) and its Security of Canada Information Sharing Act.
2015-16 (ar-2016, 5c7bb74cd5a9): First full-year report under the four 2015-2020 priorities; each gets a dedicated update. New parallel theme launched here and continued every year after: Privacy Act reform, with the Commissioner's first detailed 16-recommendation submission to the ETHI parliamentary committee on modernizing the 1983 Act (technological change, transparency, legislative modernization) (5c7bb74cd5a9).
2017-18 (ar-2018, a5b78bceb060): The Facebook/Cambridge Analytica investigation and a wave of breaches (Equifax, Uber, Nissan Canada Finance) dominate. The Office restructures its own operating model into two program areas — Promotion (moving organizations toward compliance) and Compliance (addressing existing violations) — and launches its first proactive, Commissioner-initiated investigation (into data/list brokers) (a5b78bceb060, lines ~240-263). Sustained, escalating push for order-making powers and administrative monetary penalties begins here.
2018-19 (ar-2019, f683af870ee4): Commissioner's message pivots to a comprehensive rights-based reform framework — arguing privacy should be defined and legislated as a fundamental human right, not merely a data-protection statute, with four pillars: enduring/technology-neutral drafting, an end to private-sector self-regulation, necessity/proportionality for public-sector collection, and effective enforcement (order-making, fines) (f683af870ee4). This becomes the Office's standing legislative-reform ask for every subsequent report.
2019-20 (ar-2020, 2b76372aeda3): COVID-19 dominates. The Office issues an April 2020 framework for assessing pandemic privacy-impactful initiatives and a joint federal/provincial/territorial statement on contact-tracing apps, explicitly rejecting a "privacy vs. public health" framing. No named strategic-priority renewal appears for the 2020-2025 period at this point — the 2015-2020 four-priority framework's five-year window closes without a stated successor.
2020-21 (ar-2021, 11b7657e11e0): Therrien's final full year. Bill C-11 (private-sector law reform) is tabled in November 2020 and dies on the order paper at the August 2021 election call. The report names "the newest frontier of surveillance capitalism" as artificial intelligence for the first time in the readable series (11b7657e11e0, line 119), though not yet as a named standing priority.
2021-22 (ar-2022, 38590469b94f): Philippe Dufresne becomes Commissioner mid-report-year (June 2022), succeeding Therrien after 8 years. Dufresne states his personal three-pillar vision (privacy as a fundamental right; privacy supporting innovation/competitiveness; privacy as a trust accelerator) — not yet a formal strategic plan, but the seed of one. Bill C-27 (successor to C-11) is tabled June 2022. Facial-recognition-technology guidance (post Clearview AI and RCMP use) and the Tim Hortons location-tracking finding are the year's major enforcement actions (38590469b94f).
2022-23 (ar-2023, 6214e3ffacd0): First full Dufresne-year report. His three pillars now explicitly generate named strategic priorities for the first time under his tenure: (1) AI/generative AI, (2) children's privacy, (3) preparing for Bill C-27 (6214e3ffacd0, lines 121-134) — informal precursors to the eventual January 2024 Strategic Plan. The ChatGPT/OpenAI joint investigation (with Quebec, BC, Alberta) launches in this period.
2023-24 (ar-2024, 6b0ead366c13): The Office formally launches a Strategic Plan in January 2024, A roadmap for trust, innovation and protecting the fundamental right to privacy in the digital age, running through 2027, with three named priorities: (1) Protecting and promoting privacy with maximum impact; (2) Addressing and advocating for privacy in this time of technological change (AI/generative AI); (3) Championing children's privacy rights (6b0ead366c13, lines 126-141, 491-501). This is the second full restructuring of the Office's named-priority architecture in the readable record, and it explicitly narrows the four 2015 priorities down to three, dropping "Economics of Personal Information" and "The Body as Information" as standalone named categories and folding government-surveillance-style concerns into the general AI/technological-change priority. The Aylo/Pornhub investigation (non-consensual intimate-image sharing) is a major 2023-24 enforcement finding, publicly released as Bill C-27 and the Online Harms Act were both before Parliament.
2024-25 (ar-2025, 6b8a756f7169): Bill C-27 dies on the order paper at prorogation, January 2025 (6b8a756f7169, lines 181-185). Dufresne (at the midpoint of a seven-year mandate) launches a January 2025 internal transformation plan reframing compliance as a continuum (advisory-to-investigation) rather than a Promotion/Compliance binary, citing federal fiscal constraint. The three January 2024 strategic priorities are retained unchanged and continue to organize the report; children's-privacy work is deepened via a parent/teacher survey and enforcement-lens application (6b8a756f7169).
Priorities added, dropped, renamed
- Added — the 2015-2020 four "strategic privacy priorities" (Economics of Personal Information, Government Surveillance, Reputation and Privacy, The Body as Information): announced May 2015 following a stakeholder priority-setting exercise; absent from every report before ar-2015 (06359f29fa54); first named there.
- Added — Privacy Act legislative-reform advocacy as a standing annual theme: first substantial form in ar-2016 (5c7bb74cd5a9, 16-recommendation ETHI submission); continues in every subsequent report through ar-2025, evolving from Privacy Act-only (2016) to a joint PIPEDA+Privacy Act "rights-based" ask (2019 onward, f683af870ee4).
- Added — Promotion/Compliance program split as the Office's internal operating structure: first appears ar-2018 (a5b78bceb060); superseded by the "compliance continuum" model in ar-2025 (6b8a756f7169).
- Added — artificial intelligence as a named strategic priority: first informal mention as a surveillance-adjacent concern in ar-2021 (11b7657e11e0, "newest frontier of surveillance capitalism"); named as one of three informal Dufresne priorities in ar-2023 (6214e3ffacd0); formalized as Strategic Priority 2 in the January 2024 Strategic Plan (ar-2024, 6b0ead366c13).
- Added — children's privacy as a named strategic priority: first appears as one of Dufresne's three informal priorities in ar-2023 (6214e3ffacd0, "protecting children's privacy"); formalized as Strategic Priority 3 in January 2024 (6b0ead366c13); deepened via parent/teacher survey work in ar-2025 (6b8a756f7169).
- Quietly dropped — the entire 2015-2020 four-priority framework: present and actively updated ar-2015 through at least ar-2018/ar-2019 in diminishing form; no report in the readable series explicitly retires it, extends it past 2020, or announces its replacement until the wholly different three-priority Strategic Plan of January 2024 — a roughly four-year gap (2020-2024) with no stated standing priority architecture at all, spanning the COVID-19 pandemic response.
- Renamed/restructured — the underlying "surveillance" concern: framed as a discrete "Government Surveillance" priority tied to Bill C-51 in 2015-2018 (5c7bb74cd5a9 et seq.), then absorbed into the general "technological change"/AI priority from 2021 onward with no discrete surveillance-specific priority named again (11b7657e11e0 onward).
- Renamed — private-sector reform bill lineage: Bill C-11 (tabled Nov 2020, died Aug 2021 election call) → Bill C-27 (tabled June 2022, died at January 2025 prorogation) — same underlying legislative objective (PIPEDA replacement/Digital Charter Implementation Act), carried across three Commissioners' reports (11b7657e11e0; 38590469b94f; 6b0ead366c13; 6b8a756f7169) without ever becoming law within the archived series.
Budget & mandate inflection points
- 2001-2004 (ar-2001 through ar-2004, all stub-suspected) — unreadable; see Residuals.
- May 2015 — four strategic privacy priorities announced for 2015-2020 (06359f29fa54).
- 2014-15 fiscal year — first year of mandatory (rather than voluntary) federal-institution data-breach reporting under a Treasury Board directive; breach reports to the Office rose accordingly (06359f29fa54).
- June 2015 / August 2015 — Bill C-51 (Anti-Terrorism Act, 2015) receives Royal Assent and comes into force, adding the Security of Canada Information Sharing Act to the Office's surveillance-oversight file (5c7bb74cd5a9).
- 2018 (calendar) — Facebook/Cambridge Analytica scandal and Equifax/Uber/Nissan Canada Finance breaches; Office restructures into Promotion/Compliance programs and requests (modest) increased permanent funding (a5b78bceb060).
- November 2020 — Bill C-11 tabled; dies on the order paper, election call August 2021 (11b7657e11e0).
- June 2022 — Philippe Dufresne appointed Commissioner, succeeding Daniel Therrien after 8 years; Bill C-27 tabled the same month (38590469b94f).
- January 2024 — Strategic Plan 2024-2027 launched, three named priorities, replacing the lapsed 2015-2020 framework with no explicit continuity statement (6b0ead366c13).
- February 2024 — Aylo/Pornhub investigation findings released, alongside Parliamentary debate on the Online Harms Act (6b0ead366c13).
- January 2025 — Bill C-27 dies on the order paper at prorogation; outcome ⚠️ still being checked beyond the archived series (6b8a756f7169).
- January 2025 — internal transformation plan launched, reframing Compliance/Promotion into a single "compliance continuum," citing federal fiscal constraint (6b8a756f7169).
- Budget scale — the backgrounder's 2026-27 figure of ~$37.6M / 231 FTEs and a 2025 10% executive-position reduction post-date the archived annual-report series' last document (ar-2025 covers fiscal 2024-25) and are relayed here as the backgrounder's figures, not independently verified against an archived document in this series (per a recorded standing decision).
Ontario/Toronto relevance
The OPC is a federal Agent of Parliament headquartered in Ottawa with a nationwide mandate; the archived series does not establish any dedicated Ontario or Toronto office or site presence. Relevance to Ontario/Toronto in this series is indirect and topical rather than physical: the Office's 2018 advisory engagement with Sidewalk Toronto (the Waterfront Toronto/Sidewalk Labs smart-city project on Toronto's eastern waterfront) is the one instance of direct, named engagement with a Toronto-specific initiative, where OPC staff met with Sidewalk Toronto and Office of the Information and Privacy Commissioner of Ontario colleagues on data-collection and privacy-by-design questions (a5b78bceb060). Toronto also appears as an event/speaking-engagement venue (e.g., Commissioner Dufresne at the IAPP Canada Privacy Symposium, Toronto, per ar-2023, 6214e3ffacd0) and as an auditor's-office/incidental-reference city in earlier reports — neither constitutes operational footprint. Beyond Sidewalk Toronto, the Office's relevance to Ontario/Toronto residents runs through its general federal PIPEDA/Privacy Act jurisdiction over organizations and federal institutions operating there, exercised identically nation-wide.
Residuals & gaps
- Registry gap, 2005-2011 (7 years) and 2017 (1 year), 8 years total: these registry rows are
staged(queued/failed capture), notarchived; they are not analyzable from the archive and are treated here as capture gaps, not as evidence the Office changed its disclosure practices in those years. This leaves the transition years between the Stoddart-era priority framework mentioned retrospectively in ar-2014 and the 2012-13 report unreadable, and creates a one-year blind spot immediately after the four-priority framework's first full-year report (ar-2016) before ar-2018. - ar-2001 through ar-2004 (4 docs, all stub-suspected): the detector call is confirmed correct by direct reading — all four are identical ~800-character publications.gc.ca/Library and Archives Canada "Information Archived on the Web" interstitial pages, not report content. No detector disagreement to report.
- Sampling method for this brief: given 14 usable documents plus one PIPEDA finding, all 14 annual reports and the PIPEDA finding were read (Commissioner's message, priority/strategic-plan sections, and "Privacy by the numbers" sections in full for every year; case-study and investigation-detail chapters read in full for ar-2012 and ar-2013 to establish house style, then targeted via section search for the remaining years to locate priority-defining and mandate-reform language). No document in the usable set was left entirely unopened.
- Superlative check performed per the standing rule: the "all-time high" data-breach claims made in ar-2012 (80 breaches) and ar-2013 (109 breaches, "yet another record") are each superseded by later-year figures (256 in ar-2015, 298 in ar-2016, 341 in ar-2020 under the Privacy Act alone) — none of these are restated in this brief as a series-wide peak; each is bound to its own publication year in the Budget & mandate inflection points section above, and no unbounded "record" claim from any single report is carried forward as a standing fact.
- ⚠️ Still being checked: the exact fate of Bill C-27 and Privacy Act modernization in the 45th Parliament — ar-2025 (the last archived document) states C-27 died on the order paper at January 2025 prorogation and expresses hope for reintroduction, but no later document exists in this series to confirm.
- ⚠️ Still being checked: whether the 2015-2020 four-priority framework was ever explicitly, formally retired in a document this brief did not fully capture in linear detail (ar-2017 is an unarchived registry gap and could theoretically contain a retirement statement not visible elsewhere in the series).
- ⚠️ Still being checked: precise PIPEDA statutory citation and the Privacy Act's exact coming-into-force date, both flagged as unconfirmed in the backgrounder itself and not independently re-verified in this review.
- No detector disagreements found in either direction: the 4 stub-suspected calls were all confirmed as genuine interstitials by direct reading, and all 14 "ok" documents contained substantive, readable report content consistent with their stated status.