Federal Court Rejects Claim Over SIN Requirement for Joint Chequing Accounts
📌 In brief
A claimant took a financial institution to the Federal Court over its requirement to collect the Social Insurance Number (SIN) of a secondary accountholder for a joint chequing account. The court dismissed the claim, finding that the claimant did not provide enough evidence to prove a breach of PIPEDA.
⚖️ Legal holding
A financial institution is not required to obtain the Social Insurance Number of a secondary accountholder for a joint chequing account.
📖 Technical summary
The court dismissed the claimant's application, finding insufficient evidence to prove a breach of PIPEDA.
📜 Headnote Official document
The Federal Court dismissed an application brought by a claimant alleging a breach of PIPEDA over a financial institution's requirement to collect the Social Insurance Number (SIN) of a secondary accountholder for a joint chequing account. The court found insufficient evidence to prove a breach of PIPEDA.
📚 Full judgment Official document
Date: 20260624 Docket: T-4166-25 Citation: 2026 FC 863 Toronto, Ontario, June 24, 2026 PRESENT: The Honourable Justice D’[NAME]: [NAME] Applicant and [COMPANY], COAST CAPITAL SAVINGS FEDERAL CREDIT UNION Respondents
REASONS AND
JUDGMENT I. Overview [ 1 ] This is an application brought pursuant to subsection 14(1) of the Personal Information Protection and Electronic Documents Act , SC 2000, c 5 [PIPEDA], concerning the matter referred to in the Investigation Report of an investigator of the Office of the Privacy Commissioner of Canada [the Privacy Commissioner] dated July 21, 2025 [the [NAME]]. [ 2 ] The [NAME] addressed the Applicant’s complaint with the Privacy Commissioner regarding the [COMPANY]’s policy of requiring the Social Insurance Number [SIN] of both accountholders prior to opening a joint chequing account [the Complaint]. The [NAME] found that the Complaint was “not well founded” and concluded that [COMPANY] “has provided a fair and reasonable response.” [ 3 ] As explained in greater detail below, this application is dismissed. Based on a de novo review of the [COMPANY]’s conduct, the Applicant has not met his burden to demonstrate that the [COMPANY] breached PIPEDA within the scope of subsection 14(1).
II. Background A. The factual context [ 4 ] The Applicant is [NAME], a self-represented litigant. The Respondents are: [COMPANY], a virtual bank; [COMPANY], an Ontario credit union; and Coast Capital Saving Federal Credit Union, a federal credit union. [ 5 ] On January 8, 2024, the Applicant attempted to open a joint chequing account with [COMPANY] [the Account]. The Applicant identified himself as the primary joint accountholder and declined to provide the SIN of the secondary joint accountholder [the Secondary Accountholder] required pursuant to the [COMPANY]’s policy [the Disputed Requirement]. Consequently, the Applicant was not permitted to open the Account. [ 6 ] The record before the Court is unclear on the identity of the Secondary Accountholder. [ 7 ] Through correspondence with representatives of [COMPANY] between January 8, 2024, and February 7, 2024, the Applicant requested to bypass the Disputed Requirement and open the Account. By email dated February 7, 2024, the Applicant escalated his request to a Member Concerns Officer [MCO] of [COMPANY]. [ 8 ] By letter dated March 1, 2024, the MCO informed the Applicant about the [COMPANY]’s policy requiring the disclosure of a Secondary Accountholder’s SIN prior to opening a joint chequing account [the Letter]. The MCO explained that an individual account must be opened before a joint account can be created, and that the collection of an accountholder’s SIN is required because the [COMPANY] exclusively offers interest bearing deposit products. The MCO assured the Applicant that [COMPANY] has robust controls in place to secure sensitive information like the requested SIN. [ 9 ] Subsequently, the Applicant filed the Complaint. In the Complaint, the Applicant articulated his concerns as follows: I am filing this complaint against [COMPANY] due to their practices surrounding the collection and handling of the Social Insurance Number (SIN). Specifically, I believe that [COMPANY] engaged in a coercive tactic to collect the SIN, which is not legally required for the product I intended to open, a joint chequing account as a secondary account holder. I am unhappy with their requirement to open an individual account, which mandates providing a SIN, as a condition to open a joint account. This practice appears to be a deliberate attempt to collect SIN information unnecessarily and contrary to the guidelines provided under the Personal Information Protection and Electronic Documents Act (PIPEDA). […] [COMPANY] refused to open a joint chequing account unless I first opened an individual account, which requires the provision of a SIN . My primary contention is that this requirement is a form of coercive tied selling, aimed at unnecessarily collecting personal information (SIN) under the pretense of regulatory compliance. B. The [NAME] [ 10 ] After an investigation, the [NAME] was issued on July 21, 2025. As explained below, the [NAME] determined that the Complaint was “not well-founded” and concluded that [COMPANY] “has provided a fair and reasonable response.” [ 11 ] The [NAME] explained that as a virtual bank, [COMPANY] identifies customers through their online profile without meeting them in person. The [NAME] justified the Disputed Requirement for two main reasons. First, [COMPANY] is required to report to tax authorities because all accounts offered are interest bearing. Second, the right of survivorship applies to joint bank accounts. [ 12 ] The [NAME] recognized the need of financial institutions to collect SINs to comply with financial regulations and income reporting obligations and concluded that the [COMPANY]’s Disputed Requirement was reasonable. In relation to the right of survivorship, the [NAME] opined that it is ineffective to retroactively collect SINs in the event of a death. [ 13 ] The [NAME] found that the [COMPANY] established safeguards to protect SINs, including a robust cybersecurity framework and network segmentation practices, security awareness training, and a regular practice of audits and assessments to evaluate the effectiveness of its security controls. [ 14 ] On October 24, 2025, the Applicant filed a Notice of Application under subsection 14(1) of PIPEDA.
III. The Relevant Provisions [ 15 ] Subsection 14(1) and clause 4.3.3 of Schedule 1 of PIPEDA provide as follows: Application 14 (1) A complainant may, after receiving the Commissioner’s report or being notified under subsection 12.2(3) that the investigation of the complaint has been discontinued, apply to the Court for a hearing in respect of any matter in respect of which the complaint was made, or that is referred to in the Commissioner’s report, and that is referred to in clause 4.1.3, 4.2, 4.3.3, 4.4, 4.6, 4.7 or 4.8 of Schedule 1, in clause 4.3, 4.5 or 4.9 of that Schedule as modified or clarified by Division 1 or 1.1, in subsection 5(3) or 8(6) or (7), in section 10 or in Division 1.1 or 1.2. Demande 14 (1) Après avoir reçu le rapport du commissaire ou l’avis l’informant de la fin de l’examen de la plainte au titre du paragraphe 12.2(3), le plaignant peut demander que la [NAME] entende toute question qui a fait l’objet de la plainte — ou qui est mentionnée dans le rapport — et qui est visée aux articles 4.1.3, 4.2, 4.3.3, 4.4, 4.6, 4.7 ou 4.8 de l’annexe 1, aux articles 4.3, 4.5 ou 4.9 de cette annexe tels qu’ils sont modifiés ou clarifiés par les sections 1 ou 1.1, aux paragraphes 5(3) ou 8(6) ou (7), à l’article 10 ou aux sections 1.1 ou 1.2 […] […] 4.3.3 An organization shall not, as a condition of the supply of a product or service, require an individual to consent to the collection, use, or disclosure of information beyond that required to fulfil the explicitly specified, and legitimate purposes [Emphasis added] 4.3.3 Une organisation ne peut pas, pour le motif qu’elle fournit un bien ou un service, exiger d’une personne qu’elle consente à la collecte, à l’utilisation ou à la communication de renseignements autres que ceux qui sont nécessaires pour réaliser les fins légitimes et explicitement indiquées [Soulignement ajouté]
IV. Preliminary Issues [ 16 ] [ADDRESS] will disregard what I consider to be argumentative portions of the Affidavit of [NAME] submitted by the Respondents, which are of no moment to this matter: paragraphs 4, 5, 9, 10-23, 25, 28, 29, 31-78, 80-87, and 90-98 ( Federal Courts Rules, SOR/98-106, r 81(1); Canada (Attorney General) v [NAME] , 2010 FCA 47 at para 18; Tsleil-[NAME] v Canada (Attorney General), 2017 FCA 116 at para 37). [ 17 ] While the Respondents advance arguments on mootness, the Court will not address these arguments based on my following conclusion, explained in more detail below, that the Respondents did not breach PIPEDA.
V. Issues and Standard of Review [ 18 ] The issues for the Court’s determination in this application are as follows: Has the Applicant shown a breach of PIPEDA? If so, has the Applicant shown his entitlement to any remedies? A. Standard of Review [ 19 ] [ADDRESS] in such proceedings must undertake a de novo review of the conduct of the party against whom the complaint was made when determining an application pursuant to subsection 14(1) of PIPEDA ( [NAME] v [COMPANY] , 2004 FCA 387 [ [NAME] ] at paras 47-48; [NAME] v [COMPANY]. , 2026 FC 666 [ [NAME] ] at para 8; Canada (Privacy Commissioner) v Facebook, Inc. , 2024 FCA 140 [ Facebook FCA ] at para 133, leave to appeal to SCC granted 41538; [NAME] v [COMPANY] , 2018 FC 525 [ [NAME] ] at para 21). Therefore, an application under subsection 14(1) is not a judicial review and no deference is owed to the Privacy Commissioner’s report ( [NAME] at para 8; Facebook FCA at para 133). [ 20 ] If the Court finds that the party against whom the complaint was made is in breach of its obligations under PIPEDA, then the Court considers the remedies available to the applicant under section 16 of the PIPEDA ( [NAME] v [COMPANY] , 2018 FC 1155; at para 21; [NAME], at para 21).
VI. Analysis A. Has the Applicant shown a breach of PIPEDA? [ 21 ] The burden lies on the Applicant to show, on a balance of probabilities, a breach of PIPEDA through evidence that is sufficiently “clear, convincing and cogent” ( [NAME] v [NAME].com.ca, Inc. , 2023 FC 166 [ [NAME] ], at para 4, aff’d [NAME] v [NAME].com.ca, Inc , 2023 FCA 189; [NAME] at para 21; [NAME] v [COMPANY]. , 2025 FC 1679, at para 59). While the Court may provide allowances to a self-represented litigant, the self-represented litigant must still put forward their case ( [NAME] at para 21; [NAME] at para 30). [ 22 ] As the [COMPANY] disputes the Court’s jurisdiction over the application, I will first address the scope of the Court’s de novo review of [COMPANY]’s conduct. Afterwards, I will assess whether the Applicant has met his burden of demonstrating that [COMPANY]’s conduct breached PIPEDA. [ 23 ] As will be explained below, the Court concludes that it does have jurisdiction but that the Applicant has not demonstrated through sufficient evidence that [COMPANY] breached PIPEDA ( [NAME] at para 4). (1) The scope of the alleged breach [ 24 ] Contrary to the Respondents’ submissions, the Court has jurisdiction over this application because the matters raised “fall within the four corners of section 14” of PIPEDA ( [NAME] at para 31). The two limitations to the Court’s jurisdiction when engaging in a de novo review under subsection 14(1) of PIPEDA are not applicable in this matter ( [NAME], at paras 14-16). [ 25 ] First, an application must be brought with respect to “any matter in respect of which the complaint was made, or that is referred to in the Privacy Commissioner’s Report” (PIPEDA, s 14(1); [NAME] at para 15). [ 26 ] Second, the application must address an alleged breach in relation to Schedule 1 of PIPEDA, and the additional clauses listed in subsection 14(1) ( [NAME] at para 16). [ 27 ] Once the Privacy Commissioner’s report is completed, an individual becomes a complainant under subsection 14(1) of PIPEDA, regardless of whether the individual’s own information is at stake ( Facebook, Inc v Canada (Privacy Commissioner) , 2023 FC 534 at para 74, rev’g Facebook FCA but not on this point, leave to appeal to SCC granted 41538; [NAME] at para 50; see also [NAME] v Canada (Attorney General) , 2023 FC 236 at para 19). As the [NAME] was completed without dispute, the Applicant is a complainant under subsection 14(1) PIPEDA. (2) Evidence of the alleged breach [ 28 ] The Applicant submits that it is the Disputed Requirement to collect the Secondary Accountholder’s SIN, and not the collection itself, that constitutes a breach of PIPEDA’s obligations. [ 29 ] The Applicant states that the collection of the Secondary Accountholder’s SIN is not required by law, and that this collection is therefore not “necessary to fulfil the purposes identified” , within the meaning of clause 4.4.3 of Schedule 1 of PIPEDA. According to the Applicant, [COMPANY]’s refusal to open the Account without first collecting each accountholder’s SIN is thus a breach of PIPEDA. [ 30 ] The Respondents submit that the collection of the Secondary Accountholder’s SIN was necessary to fulfill their fiscal obligations to be compliant with the authorities. The Respondents also submit there was no direct communication with the Secondary Accountholder. [ 31 ] The Applicant lacks sufficient evidence to establish the alleged breach. I am not satisfied that the Applicant has met the standard of proof as espoused in the jurisprudence ( [NAME] at para 4; [NAME] at para 21). The Applicant states that the Disputed Requirement contravenes PIPEDA. However, he provides no compelling evidence that the Disputed Requirement is unnecessary, and that the Respondents failed to explain the need for the Disputed Requirement. As stated previously, while the Court recognizes that the Applicant is self-represented, this does not relax or alter the burden of proof ( [NAME] at para 30; [NAME] at para 21). [ 32 ] [COMPANY]’s “Privacy & Security Notice” is contained in Exhibit A of the Affidavit of [NAME] submitted by the Respondents [the Privacy Policy]. The Privacy Policy provides that the SINs are used for “tax reporting purposes when requesting interest generating products or other investment income generating products or to verify and report credit or other information with the credit bureaus and credit reporting agencies.” Further, the Privacy Policy explains that SINs are used to confirm the identity of customers. The Privacy Policy explicitly states, “[y]ou may refuse to consent to the use of your SIN or its disclosure, except for purposes required by law, such as tax reporting,” and summarizes [COMPANY]’s obligations under Canadian privacy laws including accountability, consent, safeguards, and limiting collection, use and retention of personal information. [ 33 ] The applicant has failed to prove that [COMPANY]’s conduct of enforcing its Disputed Requirement breached its obligations under PIPEDA. While the Applicant has provided extensive communications with the Respondents regarding his disagreement with the Disputed Requirement, these communications do not substantiate the alleged breach by [COMPANY]. [ 34 ] As the Applicant has not demonstrated a breach of PIPEDA, I will not address remedies.
VII. Conclusion [ 35 ] Based on the reasons in the de novo review above, the application is dismissed. The Applicant did not meet the burden of proof, in a subsection 14(1) application, to show that the [COMPANY]’s conduct breached a principle of PIPEDA. [ 36 ] No costs shall be awarded on the application.
JUDGMENT in T-4166-25 THIS COURT’S
JUDGMENT is that : The application is dismissed. There is no order as to costs. “[NAME]” Judge FEDERAL COURT SOLICITORS OF RECORD DOCKET: T-4166-25 STYLE OF CAUSE: [NAME] v [COMPANY] et AL. PLACE OF HEARING:
HELD BY VIDEOCONFERENCE DATE OF HEARING: JUNE 16, 2026
REASONS and judgment: D’[NAME] J. DATED: JUNE 24, 2026 APPEARANCES : [NAME] FOR THE APPLICANT (Self-represented) [NAME] For The RespondentS SOLICITORS OF RECORD : [NAME]. Barristers and Solicitors Mississauga, Ontario For The RespondentS
⚖️ What tends to weigh in cases like this
✅ Tends to be accepted
- The financial institution's requirement to collect the Social Insurance Number (SIN) of accountholders is necessary for tax reporting purposes.
- The financial institution has implemented robust cybersecurity measures to protect sensitive information like SINs.
- The financial institution's policy aligns with legal requirements for financial institutions to comply with tax authorities.
❌ Tends to be rejected
- The applicant failed to provide sufficient evidence that the financial institution's requirement to collect SINs was unnecessary.
- The applicant's claim that the requirement to collect SINs is a form of coercive tied selling was not supported by compelling evidence.
- The applicant did not meet the burden of proof to demonstrate that the financial institution's conduct breached PIPEDA.
Patterns observed in similar cases in this collection — every case is unique.
❓ Frequently asked questions
What did this decision decide?
The Federal Court dismissed the claimant's application, finding insufficient evidence to prove a breach of PIPEDA.
What was the dispute about?
The dispute was over a financial institution's requirement to collect the Social Insurance Number (SIN) of a secondary accountholder for a joint chequing account.
How did the court decide, and why?
The court decided that the claimant had not met the burden of proof to show that the financial institution's requirement breached PIPEDA.
Which laws or rules were applied?
The Personal Information Protection and Electronic Documents Act (PIPEDA), specifically subsection 14(1) and clause 4.3.3 of Schedule 1 were applied.
What was the argument that mattered most?
The claimant argued that the requirement to collect the SIN was unnecessary and violated PIPEDA, but the court found the evidence insufficient.
Was the decision for or against the person who brought the case?
The decision was against the person who brought the case.
What does this mean for someone in a similar situation?
Someone in a similar situation should ensure they have strong evidence to support their claim before bringing an application to court.
What evidence or documents mattered?
The judgment does not specify the exact evidence or documents that mattered.
