VadeLab
DismissedFederal Court·

Federal Court Dismisses Privacy Complaint Against a Financial Institution

Case No. 2026 FC 863 · Justice D'Agostino

📌 In brief

The Federal Court dismissed an application under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) brought by a claimant against a financial institution regarding its policy on collecting Social Insurance Numbers for joint chequing accounts. The court found that the claimant did not provide enough evidence to prove that the collection of SINs was unnecessary or breached PIPEDA.

⚖️ Legal holding

A financial institution is not required by law to collect an individual's Social Insurance Number for the purpose of opening a joint chequing account, unless necessary for regulatory compliance or tax reporting purposes.

Topics

privacydata protection

Provisions

Personal Information Protection and Electronic Documents Act, s. 14(1)Personal Information Protection and Electronic Documents Act, Schedule 1, clause 4.3.3

📖 Technical summary

The claimant's application under PIPEDA was dismissed due to insufficient evidence of a breach.

📜 Headnote Official document

The claimant's application under PIPEDA, concerning a financial institution's policy requiring the Social Insurance Numbers of both accountholders for opening a joint chequing account, was dismissed. The Court found insufficient evidence to demonstrate that the collection of SINs was unnecessary or breached PIPEDA.

📚 Full judgment Official document

OUTCOME: Dismissed

Date: 20260624 Docket: T-4166-25 Citation: 2026 FC 863 Toronto, Ontario, June 24, 2026 PRESENT: The Honourable Justice D’[NAME]: [APPELLANT] Applicant and [RESPONDENT] Respondents

REASONS AND

JUDGMENT I. Overview [ 1 ] This is an application brought pursuant to subsection 14(1) of the Personal Information Protection and Electronic Documents Act , SC 2000, c 5 [PIPEDA], concerning the matter referred to in the Investigation Report of an investigator of the Office of the [NAME] of Canada [the [NAME]] dated July 21, 2025 [the [NAME]]. [ 2 ] The [NAME] addressed the Applicant’s complaint with the [NAME] regarding the [RESPONDENT]’s policy of requiring the Social Insurance Number [SIN] of both accountholders prior to opening a joint chequing account [the Complaint]. The [NAME] found that the Complaint was “not well founded” and concluded that [RESPONDENT] “has provided a fair and reasonable response.” [ 3 ] As explained in greater detail below, this application is dismissed. Based on a de novo review of the [RESPONDENT]’s conduct, the Applicant has not met his burden to demonstrate that the [RESPONDENT] breached PIPEDA within the scope of subsection 14(1).

II. Background A. The factual context [ 4 ] The Applicant is [APPELLANT], a [NAME]. The Respondents are: [RESPONDENT], a virtual [RESPONDENT]; [NAME] [RESPONDENT] [COMPANY], an Ontario credit [RESPONDENT]; and Coast Capital Saving Federal [RESPONDENT], a federal credit [RESPONDENT]. [ 5 ] On January 8, 2024, the Applicant attempted to open a joint chequing account with [RESPONDENT] [the Account]. The Applicant identified himself as the primary joint accountholder and declined to provide the SIN of the secondary joint accountholder [the [NAME]] required pursuant to the [RESPONDENT]’s policy [the Disputed Requirement]. Consequently, the Applicant was not permitted to open the Account. [ 6 ] The record before the Court is unclear on the identity of the [NAME]. [ 7 ] Through correspondence with representatives of [RESPONDENT] between January 8, 2024, and February 7, 2024, the Applicant requested to bypass the Disputed Requirement and open the Account. By email dated February 7, 2024, the Applicant escalated his request to a Member Concerns Officer [MCO] of [RESPONDENT]. [ 8 ] By letter dated March 1, 2024, the MCO informed the Applicant about the [RESPONDENT]’s policy requiring the disclosure of a [NAME]’s SIN prior to opening a joint chequing account [the Letter]. The MCO explained that an individual account must be opened before a joint account can be created, and that the collection of an accountholder’s SIN is required because the [RESPONDENT] exclusively offers interest bearing deposit products. The MCO assured the Applicant that [RESPONDENT] has robust controls in place to secure sensitive information like the requested SIN. [ 9 ] Subsequently, the Applicant filed the Complaint. In the Complaint, the Applicant articulated his concerns as follows: I am filing this complaint against [RESPONDENT] due to their practices surrounding the collection and handling of the Social Insurance Number (SIN). Specifically, I believe that [RESPONDENT] engaged in a coercive tactic to collect the SIN, which is not legally required for the product I intended to open, a joint chequing account as a secondary account holder. I am unhappy with their requirement to open an individual account, which mandates providing a SIN, as a condition to open a joint account. This practice appears to be a deliberate attempt to collect SIN information unnecessarily and contrary to the guidelines provided under the Personal Information Protection and Electronic Documents Act (PIPEDA). […] [RESPONDENT] refused to open a joint chequing account unless I first opened an individual account, which requires the provision of a SIN . My primary contention is that this requirement is a form of coercive tied selling, aimed at unnecessarily collecting personal information (SIN) under the pretense of regulatory compliance. B. The [NAME] [ 10 ] After an investigation, the [NAME] was issued on July 21, 2025. As explained below, the [NAME] determined that the Complaint was “not well-founded” and concluded that [RESPONDENT] “has provided a fair and reasonable response.” [ 11 ] The [NAME] explained that as a virtual [RESPONDENT], [RESPONDENT] identifies customers through their online profile without meeting them in person. The [NAME] justified the Disputed Requirement for two main reasons. First, [RESPONDENT] is required to report to tax authorities because all accounts offered are interest bearing. Second, the right of survivorship applies to joint [RESPONDENT] accounts. [ 12 ] The [NAME] recognized the need of [NAME] to collect SINs to comply with financial regulations and income reporting obligations and concluded that the [RESPONDENT]’s Disputed Requirement was reasonable. In relation to the right of survivorship, the [NAME] opined that it is ineffective to retroactively collect SINs in the event of a death. [ 13 ] The [NAME] found that the [RESPONDENT] established safeguards to protect SINs, including a robust cybersecurity framework and network segmentation practices, security awareness training, and a regular practice of audits and assessments to evaluate the effectiveness of its security controls. [ 14 ] On October 24, 2025, the Applicant filed a Notice of Application under subsection 14(1) of PIPEDA.

III. The Relevant Provisions [ 15 ] Subsection 14(1) and clause 4.3.3 of Schedule 1 of PIPEDA provide as follows: Application 14 (1) A complainant may, after receiving the Commissioner’s report or being notified under subsection 12.2(3) that the investigation of the complaint has been discontinued, apply to the Court for a hearing in respect of any matter in respect of which the complaint was made, or that is referred to in the Commissioner’s report, and that is referred to in clause 4.1.3, 4.2, 4.3.3, 4.4, 4.6, 4.7 or 4.8 of Schedule 1, in clause 4.3, 4.5 or 4.9 of that Schedule as modified or clarified by Division 1 or 1.1, in subsection 5(3) or 8(6) or (7), in section 10 or in Division 1.1 or 1.2. Demande 14 (1) Après avoir reçu le rapport du commissaire ou l’avis l’informant de la fin de l’examen de la plainte au titre du paragraphe 12.2(3), le plaignant peut demander que la [NAME] entende toute question qui a fait l’objet de la plainte — ou qui est mentionnée dans le rapport — et qui est visée aux articles 4.1.3, 4.2, 4.3.3, 4.4, 4.6, 4.7 ou 4.8 de l’annexe 1, aux articles 4.3, 4.5 ou 4.9 de cette annexe tels qu’ils sont modifiés ou clarifiés par les sections 1 ou 1.1, aux paragraphes 5(3) ou 8(6) ou (7), à l’article 10 ou aux sections 1.1 ou 1.2 […] […] 4.3.3 An organization shall not, as a condition of the supply of a product or service, require an individual to consent to the collection, use, or disclosure of information beyond that required to fulfil the explicitly specified, and legitimate purposes [Emphasis added] 4.3.3 Une organisation ne peut pas, pour le motif qu’elle fournit un bien ou un service, exiger d’une personne qu’elle consente à la collecte, à l’utilisation ou à la communication de renseignements autres que ceux qui sont nécessaires pour réaliser les fins légitimes et explicitement indiquées [Soulignement ajouté]

IV. Preliminary Issues [ 16 ] [ADDRESS] will disregard what I consider to be argumentative portions of the Affidavit of [NAME] submitted by the Respondents, which are of no moment to this matter: paragraphs 4, 5, 9, 10-23, 25, 28, 29, 31-78, 80-87, and 90-98 ( Federal Courts Rules, SOR/98-106, r 81(1); Canada (Attorney General) v [NAME] , 2010 FCA 47 at para 18; Tsleil-[NAME] v Canada (Attorney General), 2017 FCA 116 at para 37). [ 17 ] While the Respondents advance arguments on mootness, the Court will not address these arguments based on my following conclusion, explained in more detail below, that the Respondents did not breach PIPEDA.

V. Issues and Standard of Review [ 18 ] The issues for the Court’s determination in this application are as follows: Has the Applicant shown a breach of PIPEDA? If so, has the Applicant shown his entitlement to any remedies? A. Standard of Review [ 19 ] [ADDRESS] in such proceedings must undertake a de novo  review of the conduct of the party against whom the complaint was made when determining an application pursuant to subsection 14(1) of PIPEDA ( Englander v [COMPANY] , 2004 FCA 387 [ Englander ] at paras 47-48; [NAME] v [COMPANY]. , 2026 FC 666 [ [NAME] ] at para 8; Canada ([NAME]) v [COMPANY]. , 2024 FCA 140 [ Facebook FCA ] at para 133, leave to appeal to SCC granted 41538; [NAME] v [NAME] [RESPONDENT] of Canada , 2018 FC 525 [ [RESPONDENT] ] at para 21). Therefore, an application under subsection 14(1) is not a judicial review and no deference is owed to the [NAME]’s report ( [NAME] at para 8; Facebook FCA at para 133). [ 20 ] If the Court finds that the party against whom the complaint was made is in breach of its obligations under PIPEDA, then the Court considers the remedies available to the applicant under section 16 of the PIPEDA ( [NAME] v [NAME] [RESPONDENT] of Canada , 2018 FC 1155; at para 21; [APPELLANT], at para 21).

VI. Analysis A. Has the Applicant shown a breach of PIPEDA? [ 21 ] The burden lies on the Applicant to show, on a balance of probabilities, a breach of PIPEDA through evidence that is sufficiently “clear, convincing and cogent” ( [NAME] v [NAME].ca, [COMPANY]. , 2023 FC 166 [ [NAME] ], at para 4, aff’d [NAME] v [NAME].[COMPANY] , 2023 FCA 189; [NAME] at para 21; [NAME] v [NAME] [RESPONDENT] [COMPANY]. , 2025 FC 1679, at para 59). While the Court may provide allowances to a [NAME], the [NAME] must still put forward their case ( [NAME] at para 21; [RESPONDENT] at para 30). [ 22 ] As the [RESPONDENT] disputes the Court’s jurisdiction over the application, I will first address the scope of the Court’s de novo review of [RESPONDENT]’s conduct. Afterwards, I will assess whether the Applicant has met his burden of demonstrating that [RESPONDENT]’s conduct breached PIPEDA. [ 23 ] As will be explained below, the Court concludes that it does have jurisdiction but that the Applicant has not demonstrated through sufficient evidence that [RESPONDENT] breached PIPEDA ( [RESPONDENT] at para 4). (1) The scope of the alleged breach [ 24 ] Contrary to the Respondents’ submissions, the Court has jurisdiction over this application because the matters raised “fall within the four corners of section 14” of PIPEDA ( [NAME] at para 31). The two limitations to the Court’s jurisdiction when engaging in a de novo review under subsection 14(1) of PIPEDA are not applicable in this matter ( [NAME], at paras 14-16). [ 25 ] First, an application must be brought with respect to “any matter in respect of which the complaint was made, or that is referred to in the [NAME]’s Report” (PIPEDA, s 14(1); [NAME] at para 15). [ 26 ] Second, the application must address an alleged breach in relation to Schedule 1 of PIPEDA, and the additional clauses listed in subsection 14(1) ( [NAME] at para 16). [ 27 ] Once the [NAME]’s report is completed, an individual becomes a complainant under subsection 14(1) of PIPEDA, regardless of whether the individual’s own information is at stake ( [COMPANY] v Canada ([NAME]) , 2023 FC 534 at para 74, rev’g Facebook FCA but not on this point, leave to appeal to SCC granted 41538; Englander at para 50; see also [NAME] v Canada (Attorney General) , 2023 FC 236 at para 19). As the [NAME] was completed without dispute, the Applicant is a complainant under subsection 14(1) PIPEDA. (2) Evidence of the alleged breach [ 28 ] The Applicant submits that it is the Disputed Requirement to collect the [NAME]’s SIN, and not the collection itself, that constitutes a breach of PIPEDA’s obligations. [ 29 ] The Applicant states that the collection of the [NAME]’s SIN is not required by law, and that this collection is therefore not “necessary to fulfil the purposes identified” , within the meaning of clause 4.4.3 of Schedule 1 of PIPEDA. According to the Applicant, [RESPONDENT]’s refusal to open the Account without first collecting each accountholder’s SIN is thus a breach of PIPEDA. [ 30 ] The Respondents submit that the collection of the [NAME]’s SIN was necessary to fulfill their fiscal obligations to be compliant with the authorities. The Respondents also submit there was no direct communication with the [NAME]. [ 31 ] The Applicant lacks sufficient evidence to establish the alleged breach. I am not satisfied that the Applicant has met the standard of proof as espoused in the jurisprudence ( [APPELLANT] at para 4; [APPELLANT] at para 21). The Applicant states that the Disputed Requirement contravenes PIPEDA. However, he provides no compelling evidence that the Disputed Requirement is unnecessary, and that the Respondents failed to explain the need for the Disputed Requirement. As stated previously, while the Court recognizes that the Applicant is [NAME]-[NAME], this does not relax or alter the burden of proof ( [RESPONDENT] at para 30; [RESPONDENT] at para 21). [ 32 ] [RESPONDENT]’s “Privacy & Security Notice” is contained in Exhibit A of the Affidavit of [NAME] submitted by the Respondents [the Privacy Policy]. The Privacy Policy provides that the SINs are used for “tax reporting purposes when requesting interest generating products or other investment income generating products or to verify and report credit or other information with the credit bureaus and credit reporting agencies.” Further, the Privacy Policy explains that SINs are used to confirm the identity of customers. The Privacy Policy explicitly states, “[y]ou may refuse to consent to the use of your SIN or its disclosure, except for purposes required by law, such as tax reporting,” and summarizes [RESPONDENT]’s obligations under Canadian privacy laws including accountability, consent, safeguards, and limiting collection, use and retention of personal information. [ 33 ] The applicant has failed to prove that [RESPONDENT]’s conduct of enforcing its Disputed Requirement breached its obligations under PIPEDA. While the Applicant has provided extensive communications with the Respondents regarding his disagreement with the Disputed Requirement, these communications do not substantiate the alleged breach by [RESPONDENT]. [ 34 ] As the Applicant has not demonstrated a breach of PIPEDA, I will not address remedies.

VII. Conclusion [ 35 ] Based on the reasons in the de novo review above, the application is dismissed. The Applicant did not meet the burden of proof, in a subsection 14(1) application, to show that the [RESPONDENT]’s conduct breached a principle of PIPEDA. [ 36 ] No costs shall be awarded on the application.

JUDGMENT in T-4166-25 THIS COURT’S

JUDGMENT is that : The application is dismissed. There is no order as to costs. “[NAME]” Judge FEDERAL COURT SOLICITORS OF RECORD DOCKET: T-4166-25 STYLE OF CAUSE: [APPELLANT] v [RESPONDENT] [RESPONDENT] [COMPANY] et AL. PLACE OF HEARING:

HELD BY VIDEOCONFERENCE DATE OF HEARING: JUNE 16, 2026

REASONS and judgment: [APPELLANT] J. DATED: JUNE 24, 2026 APPEARANCES : [APPELLANT] FOR THE APPLICANT ([NAME]-[NAME]) [APPELLANT]. [APPELLANT] [NAME] [NAME] SOLICITORS OF RECORD : [NAME]. Barristers and Solicitors Mississauga, [NAME]

📊 How courts decide similar cases

Among 12 similar decisions in this collection:

A snapshot of this collection — not a prediction of your case's outcome.

⚖️ What tends to weigh in cases like this

✅ Tends to be accepted

  • The financial institution's policy of requiring a SIN for joint accounts was justified because all accounts offered are interest-bearing, requiring tax reporting.
  • The financial institution needed to collect SINs to comply with financial regulations and income reporting obligations.
  • The financial institution had robust controls in place to secure sensitive information like SINs.
  • The financial institution's privacy policy explicitly stated that SINs are used for tax reporting purposes for interest-generating products.
  • The financial institution's privacy policy explained that SINs are used to confirm customer identity.

❌ Tends to be rejected

  • The applicant failed to provide compelling evidence that the requirement to collect the secondary accountholder's SIN was unnecessary.
  • The applicant did not demonstrate that the financial institution failed to explain the need for the SIN requirement.

Patterns observed in similar cases in this collection — every case is unique.

❓ Frequently asked questions

What did this decision decide?

The Federal Court dismissed an application under PIPEDA brought by a claimant against a financial institution regarding its policy on collecting Social Insurance Numbers for joint chequing accounts.

Who was involved?

A a person and three a person were involved in the case.

How did the address decide, and why?

the address decided that the claimant failed to meet their burden of proof to show a breach of PIPEDA by the financial institution.

Which laws or rules were applied?

PIPEDA was primarily applied in this case.

What was the argument that mattered most?

The claimant argued that collecting SINs for joint chequing accounts is unnecessary and breaches PIPEDA, but failed to provide sufficient evidence to support their claims.

Was the decision for or against the person who brought the case?

The decision was against the person who brought the case.

What does this mean for someone in a similar situation?

Someone in a similar situation should ensure they provide sufficient evidence to support their claims under PIPEDA when challenging a financial institution's policy.

What evidence or documents mattered?

The claimant’s communications with the financial institution and the a person’s report were key pieces of evidence.

Can a decision like this be appealed?

Yes, decisions from the Federal Court can often be appealed to the Federal Court of Appeal.

Is it worth getting a lawyer for a case like this?

It is highly recommended to consult with a qualified lawyer when dealing with complex legal issues such as those under PIPEDA.

Official source: Federal Court headnote and full judgment reproduced from the court's public records. View on the official source ↗Summary, holding, technical summary and questions: produced by Artificial Intelligence based on the official headnote and judgment. These are VadeLab’s own material and are not the work of the Court.This decision was issued by the Federal Court. It is a reproduction of an official work published by the Government of Canada, and the reproduction has not been produced in affiliation with, or with the endorsement of, the Government of Canada. It is not an official version.