There is a growing double standard in Canadian privacy litigation, and organizations should understand it before they misread their risk.
On one side, appellate courts have narrowed intrusion-upon-seclusion claims arising from third-party cyberattacks. Del Giudice v Thompson is the clean statement of that limit: being hacked does not automatically make the database holder the tortious intruder. Negligence and damages proof become the harder path.
On the other side, courts remain willing to let privacy class actions move forward where the organization itself is alleged to have used personal information in intrusive, unauthorized, or deceptive ways. The Trueman v Rogers style fact pattern—repeated soft credit checks without meaningful consent—illustrates the point. When the defendant’s own commercial process is the privacy event, certification dynamics change.
External breach versus internal misuse
I use a simple teaching contrast with business stakeholders.
External hack: criminal outsider forces entry. The company may still face regulatory scrutiny, contract claims, and negligence theories. But intentional privacy tort theories aimed at the company often fit poorly.
Internal misuse: the company runs a process that touches credit files, account graphs, location history, or health-adjacent data for a purpose people did not reasonably expect. Here, intention, control, and commercial motive are easier to allege. Statutory breach, intrusion, breach of confidence, and consumer-protection theories can travel together.
That contrast is not moral hair-splitting. It is litigation architecture.
Why “soft” processes create hard risk
Soft credit checks and similar quiet inquiries feel operationally harmless inside a company. No hard hit. No obvious customer complaint in week one. Maybe even a fraud or collections rationale layered on later.
From the outside, the pattern can look like industrial-scale probing of sensitive financial reputation data. If consent was buried, stale, or never obtained for that purpose, plaintiffs will call it what it feels like: unauthorized watching.
I have reviewed “temporary” growth tests that became permanent pipelines. Nobody wrote a privacy assessment because the data was already in-house. That is exactly how internal misuse risk accumulates—through normalization, not cartoon villainy.
What privacy programs should monitor
Secondary use registries beat slogans. Every new purpose for existing personal information should pass a documented gate: legal basis, notice quality, retention, access controls, and opt-out or withdrawal where required.
High-risk internal uses deserve extra friction:
- Credit, financial capacity, and insurance-style inferences
- Location trails and device graphs
- Employee monitoring beyond narrow security needs
- Training machine-learning models on customer content
- Data enrichment purchased and joined to profiles without clear notice
If a use would sound ugly on the front page, do not hide it in a footnote. Federal commercial programs should still ground their baseline in PIPEDA’s purpose and consent expectations. Quebec operations should treat Law 25 as a stricter design constraint on secondary use and governance.
Governance lessons from the certification split
First, stop telling boards that Del Giudice means “privacy class actions are over.” It means one pathway is harder in pure third-party hack cases.
Second, invest in purpose limitation with the same seriousness you give perimeter security. Many organizations spend millions on firewalls and almost nothing on preventing quiet internal repurposing.
Third, align marketing, risk, and collections teams to the same consent inventory. Fragmented teams create fragmented purposes—and fragmented stories in discovery.
Fourth, preserve decision records. If you believed you had authority for soft checks or secondary analytics, you will need the policy, the legal opinion, and the customer-facing language. Memory is not evidence.
The human voice I use with product owners
I do not start with tort elements. I start with respect. People hand over data for a service. Using that intimacy for an unannounced commercial side channel burns trust faster than most outages. Courts are simply catching up to that intuition when the actor is the company itself.
Security failures are often tragedies plus control gaps. Internal misuse looks like a choice. Juries, judges, and regulators read choices differently from tragedies.
There is a measurement angle I push hard. Track new secondary uses approved and rejected each quarter. If everything is approved in a day with no paper trail, you have a rubber stamp. Mature programs offer redesign paths: better notice, narrower fields, shorter retention, or a true opt-in.
A working control set for internal use
When I help teams reduce intentional-misuse risk, we usually install five habits:
- Purpose register with a named business owner for every processing activity that touches customer or employee personal information.
- Change control so new joins, models, and credit-style checks cannot go live from a Slack message alone.
- Notice parity so the customer-facing story matches the actual pipeline.
- Access minimization so growth and collections teams do not get production-wide exports “for analysis.”
- Kill switches so a challenged process can be paused without rewriting the whole stack.
Reform conversations after Bill C-27 died still point toward stronger individual rights and civil exposure over time. You do not need royal assent to stop treating internal data as a playground. Current law, current regulators, and current certification trends are already enough.
Actionable takeaway
Run a 30-day internal-use audit focused on credit checks, enrichment joins, and any “silent” profiling feeds. For each, capture purpose, legal basis, notice location, volume, and owner. Kill or redesign any process that depends on hope rather than documented authority. Report the top three residual risks to an executive forum with a go/no-go decision—not a note to file. Keep Del Giudice in the board appendix so leadership understands why internal misuse, not only external hacks, should dominate the civil-risk conversation.