{"id":18056,"date":"2024-09-19T09:46:51","date_gmt":"2024-09-19T13:46:51","guid":{"rendered":"https:\/\/www.millerthomson.com\/?post_type=insights&#038;p=224463"},"modified":"2026-04-01T16:45:28","modified_gmt":"2026-04-01T20:45:28","slug":"federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures","status":"publish","type":"post","link":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/","title":{"rendered":"Facebook failed to obtain consent and safeguard personal data: Federal Court Appeal clarifies PIPEDA compliance"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Introduction<\/h2>\n\n\n\n<p>On September 9, 2024, the Federal Court of Appeal (the \u201c<strong>FCA<\/strong>\u201d) issued its decision in <a href=\"https:\/\/decisions.fca-caf.gc.ca\/fca-caf\/decisions\/en\/item\/521452\/index.do\" target=\"_blank\" rel=\"noopener\"><em>Privacy Commissioner of Canada v Facebook Inc., <\/em>2024 FCA 140<\/a>,<a href=\"#_edn1\" name=\"_ednref1\">[i]<\/a> overturning the Federal Court\u2019s decision<a href=\"#_edn2\" name=\"_ednref2\">[ii]<\/a> and declaring that Facebook, Inc. (now Meta Platforms Inc.) had violated the <a href=\"https:\/\/www.canlii.org\/en\/ca\/laws\/stat\/sc-2000-c-5\/latest\/sc-2000-c-5.html\" target=\"_blank\" rel=\"noopener\"><em>Personal Information Protection and Electronic Documents Act<\/em><\/a> (\u201c<strong>PIPEDA<\/strong>\u201d) by improperly sharing users&#8217; personal information with third-party applications (&#8220;<strong>apps<\/strong>&#8220;) on its platform.<a href=\"#_edn3\" name=\"_ednref3\">[iii]<\/a> Specifically, Facebook breached the requirements for obtaining meaningful consent<a href=\"#_edn4\" name=\"_ednref4\">[iv]<\/a> and did not adequately safeguard user data.<a href=\"#_edn5\" name=\"_ednref5\">[v]<\/a><\/p>\n\n\n\n<p>The FCA\u2019s decision serves as a helpful reminder that PIPEDA is designed to strike a balance between the privacy <em>rights<\/em> of individuals and the legitimate <em>needs<\/em> of organizations to collect and use personal information. The FCA\u2019s analysis of meaningful consent emphasizes the need for organizations to be specific and transparent regarding the uses and disclosures of personal data, especially in the context of third-party apps and other digital ecosystems. An organization cannot contract out of its statutory duty to safeguard personal information, and the impracticalities of monitoring compliance do not justify limiting the scope of safeguarding obligations \u2013 especially when those challenges are created by the organization itself.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Background<\/h2>\n\n\n\n<p>This case stemmed from the Office of the Privacy Commissioner of Canada\u2019s (\u201c<strong>OPC<\/strong>\u201d) investigation into the scraping and selling of Facebook user data by the app \u201cthisisyourdigitallife\u201d (\u201c<strong>TYDL<\/strong>\u201d) which was sold and used to generate user profiles to facilitate targeted political advertising. The alleged PIPEDA violations occurred from TYDL\u2019s launch in November 2013 until its removal from Facebook in December 2015. During this period, Facebook had three layers of consent policies and practices in place:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><em>Platform-wide policies<\/em>: When signing up for Facebook, users had to agree to the Terms of Service (4,500 words), which set out users\u2019 rights and responsibilities, including how users could control their information. Facebook\u2019s Data Policy (9,100 words) was incorporated by reference into the Terms of Service, such that users accepting the Terms of Service were deemed to have consented to the Data Policy. The Terms of Service broadly explained how user data could be shared, including with third-party apps, and stated that the agreement between the user and the app would govern how the app uses, stores, or transfers information. The Data Policy broadly described the user information shared with third-party apps \u2013 including through the use of such third-party apps by users\u2019 friends.<\/li>\n\n\n\n<li><em>User controls<\/em>: Users could adjust their data sharing preferences through permissions, the App Settings page, and the Privacy Settings page (e.g., selecting the default audience for their posts and restricting apps\u2019 access to their information).<\/li>\n\n\n\n<li><em>Educational resources<\/em>: Facebook provided resources for users to learn about Facebook\u2019s privacy policies and practices, including explanations of what information is shared when friends use third-party apps and how to control that information.<\/li>\n<\/ol>\n\n\n\n<p>Facebook required third-party apps to agree to its Platform Policy and Terms of Service (\u201c<strong>Platform Policy<\/strong>\u201d), which included specific &nbsp;terms regarding the collection, use, and disclosure of user information. This included the requirement for apps to have a privacy policy and a prohibition against selling or purchasing data obtained from Facebook.<\/p>\n\n\n\n<p>Despite the requirements of the Platform Policy, Facebook did not review or verify third-party compliance with this policy. When TYDL requested expanded access to user data, Facebook identified this as a &#8220;red flag&#8221; but took no action beyond denying the request.<\/p>\n\n\n\n<p>After identifying that TYDL had breached the Platform Policy, Facebook removed TYDL in 2015 and asked it to delete the data it had obtained. However, Facebook did not notify affected users, nor did it remove Dr. Kogan or Cambridge Analytica from its platform until 2018, after media reports surfaced that they had not deleted the data as requested.<\/p>\n\n\n\n<p>The OPC investigated Facebook<a href=\"#_edn6\" name=\"_ednref6\">[vi]<\/a> and concluded that it failed to obtain valid and meaningful consent for its disclosures to third-party apps<a href=\"#_edn7\" name=\"_ednref7\">[vii]<\/a> and failed to safeguard user data.<a href=\"#_edn8\" name=\"_ednref8\">[viii]<\/a> These conclusions formed the basis of the OPC\u2019s application pursuant to s. 15(a) of PIPEDA.<\/p>\n\n\n\n<p>The Federal Court considered two central issues: 1) whether Facebook failed to obtain meaningful consent from users and their friends when sharing personal information with third-party apps, and 2) whether Facebook failed to adequately safeguard user data. The Federal Court dismissed the OPC\u2019s application, finding that the OPC\u2019s burden of proof for either allegation was unmet, particularly due to the absence of expert and subjective evidence.<a href=\"#_edn9\" name=\"_ednref9\">[ix]<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Federal Court of Appeal&#8217;s Key Findings<\/h2>\n\n\n\n<p>A unanimous panel of three judges at the FCA partially granted the OPC&#8217;s appeal, finding that the Federal Court made two main errors:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>relying too heavily on the lack of expert and subjective evidence in its analysis; and<\/li>\n\n\n\n<li>failing to assess the consent given by friends of users who downloaded third-party apps, separate from the consent of the installing users.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Failure to Obtain Meaningful Consent<\/h3>\n\n\n\n<p>The FCA held that Facebook did not obtain meaningful consent for sharing user data, applying the objective &#8220;reasonable person&#8221; standard under PIPEDA. This standard does not require subjective or expert evidence; instead, it considers whether a reasonable person would understand the nature, purpose, and consequences of the disclosure of their information.<\/p>\n\n\n\n<p>Key findings by the FCA include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em>Reasonable Efforts vs. Manner of Consent:<\/em> Consent must be both reasonable in form and clearly understood by users. Facebook\u2019s methods fell short because users could not fully understand what they were consenting to. An organization\u2019s reasonable efforts do not override the manner of consent, as valid consent requires individuals to understand what they are consenting to.<\/li>\n\n\n\n<li><em>Users Friends&#8217; Data<\/em>: Friends of users were unable to review app privacy policies before their data was shared, violating clause 4.3.2 of PIPEDA. Broad statements in the Data Policy about sharing data with apps used by friends were too vague to form meaningful consent. Even if consent could somehow be derived from the Data Policy, the data use exceeded what could reasonably have been contemplated by users\u2019 friends.<\/li>\n\n\n\n<li><em>Users&#8217; Consent<\/em>: Based on deficiencies in its Terms of Service and Data Policy, Facebook also failed to obtain valid consent from the downloading users. Simply incorporating the Data Policy into the Terms of Service was insufficient under PIPEDA, as the manner and substance of these policies did not facilitate users\u2019 understanding of the nature, purpose, and consequences of the disclosure of their information.<\/li>\n\n\n\n<li><em>Lack of Warnings<\/em>: Facebook did not adequately inform users that third-party apps could misuse their data or sell it to others, which a reasonable user would expect safeguards against.<\/li>\n\n\n\n<li><em>Overall Deficiencies<\/em>: Facebook\u2019s privacy policies were too long and unclear. Its reliance on default privacy settings that allowed data sharing without active consent violated the principle that consent must be an affirmative choice.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Inadequate Safeguards for User Data<\/h3>\n\n\n\n<p>Facebook breached its safeguarding obligations by failing to properly monitor third-party apps or review their privacy policies. Key findings by the Court include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em>Failure to Act on Red Flags:<\/em> Facebook ignored TYDL\u2019s &#8220;red flag&#8221; request for excessive data, breaching its safeguarding obligations.<\/li>\n\n\n\n<li><em>Platform Overload:<\/em> Although Facebook claimed it would be practically impossible to review the privacy policies of all third-party apps, the Court noted this issue was of Facebook\u2019s own making. Facebook could not avoid its statutory responsibilities by claiming it had too many apps to manage, nor by contracting out of its statutory obligations under s. 6.1 and Principle 3 of PIPEDA.<br><em>Breach of Safeguarding Duty<\/em>: Facebook&#8217;s lack of oversight of third-party apps\u2019 privacy practices violated its obligation to protect user data under PIPEDA.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Key Takeaways<\/h2>\n\n\n\n<p><em>Proactive Steps for PIPEDA Compliance:<\/em> Organizations should view this decision as a call to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>conduct regular privacy audits and update consent processes;<\/li>\n\n\n\n<li>simplify privacy policies and make them accessible;<\/li>\n\n\n\n<li>implement rigorous third-party oversight mechanisms; and<\/li>\n\n\n\n<li>avoid default settings that assume consent.<\/li>\n<\/ul>\n\n\n\n<p>By focusing on these areas, organizations can not only avoid legal risks but also build trust with their users, ensuring that privacy compliance becomes a competitive advantage. Other noteworthy points for privacy lawyers and private sector organizations include:<\/p>\n\n\n\n<p><em>Reaffirmation of the Reasonable Person Standard for Consent<\/em>: &#8220;Meaningful&#8221; consent is not merely about complying with formal consent mechanisms like terms of service or privacy policies. Consent must be understood from the perspective of a reasonable person, taking into account the specific context in which data is collected and shared. Users must be clearly informed about the nature, purpose, and risks of sharing their information. Organizations should review their privacy policies and consent processes to ensure they are clear, accessible, and easy to understand for the average user, and suitable for the circumstances and sensitivity of the information involved.<\/p>\n\n\n\n<p><em>Vague or Overly Complex Policies Will Not Suffice<\/em>: Lengthy, complicated, or obscured privacy policies are inadequate. Consent obtained through complex, broad, or indirect language is unlikely to meet PIPEDA&#8217;s consent requirements.<\/p>\n\n\n\n<p><em>Friends\u2019 Data Requires Explicit Consent<\/em>: Facebook failed to obtain valid consent from the friends of users whose data was shared through third-party apps. Organizations cannot assume implied consent for sharing secondary data (such as friends\u2019 information). Businesses that facilitate social media interactions or rely on data-sharing ecosystems should re-examine how they handle secondary data and ensure explicit consent mechanisms are in place.<\/p>\n\n\n\n<p><em>Enhanced Safeguarding Measures Are Essential<\/em>: Facebook failed to safeguard user data by not monitoring third-party apps. PIPEDA&#8217;s safeguarding provisions require proactive oversight of how third parties access and use personal data. Organizations should implement comprehensive measures to audit and monitor supply chain and third-party data practices. Privacy lawyers can guide businesses in setting up these audit and oversight frameworks.<\/p>\n\n\n\n<p><em>Address the Risks of Default Privacy Settings<\/em>: The FCA\u2019s remarks about Facebook\u2019s default privacy settings reinforces that consent under PIPEDA must be an &#8220;active&#8221; process, not obtained by default. Organizations should avoid default settings that assume consent for data sharing and instead create opt-in mechanisms that require affirmative user action.<\/p>\n\n\n\n<p>If you have any questions or would like guidance on how this decision impacts your organization, please contact a member of the Miller Thomson LLP <a href=\"https:\/\/www.millerthomson.com\/en\/expertise\/business\/technology-ip-and-privacy\/\">Technology, IP and Privacy<\/a> Group.<\/p>\n\n\n\n<p><a href=\"#_ednref1\" name=\"_edn1\">[i]<\/a> 2024 FCA 140.<\/p>\n\n\n\n<p><a href=\"#_ednref2\" name=\"_edn2\">[ii]<\/a> <em>Canada (Privacy Commissioner) v Facebook, Inc.<\/em>, 2023 FC 533.<\/p>\n\n\n\n<p><a href=\"#_ednref3\" name=\"_edn3\">[iii]<\/a> <em>Personal Information Protection and Electronic Documents Act,<\/em> SC 2000, c 5.<\/p>\n\n\n\n<p><a href=\"#_ednref4\" name=\"_edn4\">[iv]<\/a> <em>ibid<\/em>, clause 4.3, and s. 6.1.<\/p>\n\n\n\n<p><a href=\"#_ednref5\" name=\"_edn5\">[v]<\/a> <em>ibid<\/em>, clause 4.7.<\/p>\n\n\n\n<p><a href=\"#_ednref6\" name=\"_edn6\">[vi]<\/a> PIPEDA Report of Findings #2019-002, April 25, 2019, https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/investigations\/investigations-into-businesses\/2019\/pipeda-2019-002\/.<\/p>\n\n\n\n<p><a href=\"#_ednref7\" name=\"_edn7\">[vii]<\/a> <em>Personal Information Protection and Electronic Documents Act,<\/em> SC 2000, c 5., clause 4.3 of Schedule 1.<\/p>\n\n\n\n<p><a href=\"#_ednref8\" name=\"_edn8\">[viii]<\/a> <em>ibid<\/em>, clause 4.7 of Schedule 1.<\/p>\n\n\n\n<p><a href=\"#_ednref9\" name=\"_edn9\">[ix]<\/a> <em>Privacy Commissioner of Canada v Facebook, Inc.,<\/em> 2023 FC 533 at para 71.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction On September 9, 2024, the Federal Court of Appeal (the \u201cFCA\u201d) issued its decision in Privacy Commissioner of Canada v Facebook Inc., 2024 FCA 140,[i] overturning the Federal Court\u2019s decision[ii] and declaring that Facebook, Inc. (now Meta Platforms Inc.) had violated the Personal Information Protection and Electronic Documents Act (\u201cPIPEDA\u201d) by improperly sharing users&#8217; [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":14393,"parent":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[557],"insight-format":[416],"class_list":["post-18056","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology-ip-and-privacy"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.1.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>PIPEDA compliance clarified: Meaningful consent and safeguarding of personal data<\/title>\n<meta name=\"description\" content=\"Understand the key takeaways from the Federal Court of Appeal decision against Facebook.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PIPEDA compliance clarified: Meaningful consent and safeguarding of personal data\" \/>\n<meta property=\"og:description\" content=\"Understand the key takeaways from the Federal Court of Appeal decision against Facebook.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/\" \/>\n<meta property=\"og:site_name\" content=\"Miller Thomson\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/MillerThomsonLaw\/\" \/>\n<meta property=\"article:published_time\" content=\"2024-09-19T13:46:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-01T20:45:28+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@millerthomson\" \/>\n<meta name=\"twitter:site\" content=\"@millerthomson\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/www.millerthomson.com\/en\/#\/schema\/person\/3f9143e8aec04617923b89fecf6886ea\"},\"headline\":\"Facebook failed to obtain consent and safeguard personal data: Federal Court Appeal clarifies PIPEDA compliance\",\"datePublished\":\"2024-09-19T13:46:51+00:00\",\"dateModified\":\"2026-04-01T20:45:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/\"},\"wordCount\":1739,\"publisher\":{\"@id\":\"https:\/\/www.millerthomson.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/Insights_Technology-IP-and-Privacy_Post-Image.jpg\",\"articleSection\":[\"Technology, IP and Privacy\"],\"inLanguage\":\"en-US\"},{\"@type\":[\"WebPage\",\"ItemPage\"],\"@id\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/\",\"url\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/\",\"name\":\"PIPEDA compliance clarified: Meaningful consent and safeguarding of personal data\",\"isPartOf\":{\"@id\":\"https:\/\/www.millerthomson.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/Insights_Technology-IP-and-Privacy_Post-Image.jpg\",\"datePublished\":\"2024-09-19T13:46:51+00:00\",\"dateModified\":\"2026-04-01T20:45:28+00:00\",\"description\":\"Understand the key takeaways from the Federal Court of Appeal decision against Facebook.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#primaryimage\",\"url\":\"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/Insights_Technology-IP-and-Privacy_Post-Image.jpg\",\"contentUrl\":\"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/Insights_Technology-IP-and-Privacy_Post-Image.jpg\",\"width\":1776,\"height\":994},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.millerthomson.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Facebook failed to obtain consent and safeguard personal data: Federal Court Appeal clarifies PIPEDA compliance\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.millerthomson.com\/en\/#website\",\"url\":\"https:\/\/www.millerthomson.com\/en\/\",\"name\":\"Miller Thomson\",\"description\":\"National law firm providing business law expertise and litigation and disputes services for businesses across Canada since 1957.\",\"publisher\":{\"@id\":\"https:\/\/www.millerthomson.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.millerthomson.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.millerthomson.com\/en\/#organization\",\"name\":\"Miller Thomson\",\"url\":\"https:\/\/www.millerthomson.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.millerthomson.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/miller-thomson.svg\",\"contentUrl\":\"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/miller-thomson.svg\",\"width\":380,\"height\":50,\"caption\":\"Miller Thomson\"},\"image\":{\"@id\":\"https:\/\/www.millerthomson.com\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/MillerThomsonLaw\/\",\"https:\/\/x.com\/millerthomson\",\"https:\/\/www.linkedin.com\/company\/miller-thomson-llp\/\",\"https:\/\/www.youtube.com\/@millerthomson\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.millerthomson.com\/en\/#\/schema\/person\/3f9143e8aec04617923b89fecf6886ea\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.millerthomson.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/2fb85dacd7d0cf6d162ec9c30c25b90c6e69a82dbe5ebe52991d2ec0d73e4890?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/2fb85dacd7d0cf6d162ec9c30c25b90c6e69a82dbe5ebe52991d2ec0d73e4890?s=96&d=mm&r=g\",\"caption\":\"admin\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PIPEDA compliance clarified: Meaningful consent and safeguarding of personal data","description":"Understand the key takeaways from the Federal Court of Appeal decision against Facebook.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/","og_locale":"en_US","og_type":"article","og_title":"PIPEDA compliance clarified: Meaningful consent and safeguarding of personal data","og_description":"Understand the key takeaways from the Federal Court of Appeal decision against Facebook.","og_url":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/","og_site_name":"Miller Thomson","article_publisher":"https:\/\/www.facebook.com\/MillerThomsonLaw\/","article_published_time":"2024-09-19T13:46:51+00:00","article_modified_time":"2026-04-01T20:45:28+00:00","author":"admin","twitter_card":"summary_large_image","twitter_creator":"@millerthomson","twitter_site":"@millerthomson","twitter_misc":{"Written by":"admin","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#article","isPartOf":{"@id":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/"},"author":{"name":"admin","@id":"https:\/\/www.millerthomson.com\/en\/#\/schema\/person\/3f9143e8aec04617923b89fecf6886ea"},"headline":"Facebook failed to obtain consent and safeguard personal data: Federal Court Appeal clarifies PIPEDA compliance","datePublished":"2024-09-19T13:46:51+00:00","dateModified":"2026-04-01T20:45:28+00:00","mainEntityOfPage":{"@id":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/"},"wordCount":1739,"publisher":{"@id":"https:\/\/www.millerthomson.com\/en\/#organization"},"image":{"@id":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#primaryimage"},"thumbnailUrl":"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/Insights_Technology-IP-and-Privacy_Post-Image.jpg","articleSection":["Technology, IP and Privacy"],"inLanguage":"en-US"},{"@type":["WebPage","ItemPage"],"@id":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/","url":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/","name":"PIPEDA compliance clarified: Meaningful consent and safeguarding of personal data","isPartOf":{"@id":"https:\/\/www.millerthomson.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#primaryimage"},"image":{"@id":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#primaryimage"},"thumbnailUrl":"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/Insights_Technology-IP-and-Privacy_Post-Image.jpg","datePublished":"2024-09-19T13:46:51+00:00","dateModified":"2026-04-01T20:45:28+00:00","description":"Understand the key takeaways from the Federal Court of Appeal decision against Facebook.","breadcrumb":{"@id":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#primaryimage","url":"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/Insights_Technology-IP-and-Privacy_Post-Image.jpg","contentUrl":"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/Insights_Technology-IP-and-Privacy_Post-Image.jpg","width":1776,"height":994},{"@type":"BreadcrumbList","@id":"https:\/\/www.millerthomson.com\/en\/insights\/technology-ip-and-privacy\/federal-court-of-appeal-pipeda-compliance-lessons-facebook-consent-failures\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.millerthomson.com\/en\/"},{"@type":"ListItem","position":2,"name":"Facebook failed to obtain consent and safeguard personal data: Federal Court Appeal clarifies PIPEDA compliance"}]},{"@type":"WebSite","@id":"https:\/\/www.millerthomson.com\/en\/#website","url":"https:\/\/www.millerthomson.com\/en\/","name":"Miller Thomson","description":"National law firm providing business law expertise and litigation and disputes services for businesses across Canada since 1957.","publisher":{"@id":"https:\/\/www.millerthomson.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.millerthomson.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.millerthomson.com\/en\/#organization","name":"Miller Thomson","url":"https:\/\/www.millerthomson.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.millerthomson.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/miller-thomson.svg","contentUrl":"https:\/\/www.millerthomson.com\/wp-content\/uploads\/2024\/10\/miller-thomson.svg","width":380,"height":50,"caption":"Miller Thomson"},"image":{"@id":"https:\/\/www.millerthomson.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/MillerThomsonLaw\/","https:\/\/x.com\/millerthomson","https:\/\/www.linkedin.com\/company\/miller-thomson-llp\/","https:\/\/www.youtube.com\/@millerthomson"]},{"@type":"Person","@id":"https:\/\/www.millerthomson.com\/en\/#\/schema\/person\/3f9143e8aec04617923b89fecf6886ea","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.millerthomson.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/2fb85dacd7d0cf6d162ec9c30c25b90c6e69a82dbe5ebe52991d2ec0d73e4890?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2fb85dacd7d0cf6d162ec9c30c25b90c6e69a82dbe5ebe52991d2ec0d73e4890?s=96&d=mm&r=g","caption":"admin"}}]}},"_links":{"self":[{"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/posts\/18056","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/comments?post=18056"}],"version-history":[{"count":1,"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/posts\/18056\/revisions"}],"predecessor-version":[{"id":48873,"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/posts\/18056\/revisions\/48873"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/media\/14393"}],"wp:attachment":[{"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/media?parent=18056"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/categories?post=18056"},{"taxonomy":"insight-format","embeddable":true,"href":"https:\/\/www.millerthomson.com\/en\/wp-json\/wp\/v2\/insight-format?post=18056"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}