Decision pursuant to 6.1, 2026 OIC 61

Date of decision: March 30, 2026

Summary

An institution made an application to the Information Commissioner for approval to decline to act on an access request under subsection 6.1(1) of the Access to Information Act. The institution submitted that the request constitutes an abuse of the right of access.

The Commissioner finds that the institution did not demonstrate that the access request is an abuse of the right to make a request.

The application is denied.

Application

Under subsection 6.1(1) of the Access to Information Act, the head of a government institution may seek the Information Commissioner’s written approval to decline to act on an access request if, in the head of the institution’s opinion, the request is one or more of the following:

  • Vexatious;
  • Made in bad faith;
  • An abuse of the right to make a request for access to records.

Institutions may not decline to act on access requests for the sole reason that the requested information was already proactively published under Part 2 of the Act (subsection 6.1(1.1)).

The institution bears the burden of establishing that the access request meets one or more of the requirements under subsection 6.1(1).

If the institution establishes that one or more of the requirements of subsection 6.1(1) apply, the Commissioner must exercise her discretionary power to either grant or refuse the application.

In exercising her discretion, the Commissioner will consider all relevant factors and circumstances, including:

  • The quasi-constitutional nature of the right of access;
  • The public interest in the records sought;
  • Whether the institution met its obligations under subsection 4(2.1) to make every reasonable effort to assist a requester in connection with their request.

Access request at issue

On November 3, 2025, the institution sought the Commissioner’s approval to decline to act on an access request it had received on October 2, 2025. The access request was for the following information:

[Translation]

  1. All text messages (texts) sent and received by [employee] on their work cell phone [...] from 2023 to 2025
  2. All contacts saved on the work cell phone of [employee] and on their professional Outlook email account as of August 6, 2025
  3. All appointments of [employee] scheduled on their work Outlook calendar from 2023 to 2025
  4. The list or record of all phone calls received and made by [employee] on their work cell phone from 2023 to 2025
  5. All photographs and image files saved on the work cell phone of [employee] (including but not limited to .jpeg, .gif, .png files) as of August 6, 2025
  6. All video files recorded on the work cell phone of [employee] dated August 6, 2025
  7. All files contained in the “Downloads” or “Téléchargements” folder on the work cell phone of [employee] as of August 6, 2025
  8. [Employee]’s browsing history from 2023 to present (across all browsers, including but not limited to Chrome and Edge)
  9. All files contained in the “Downloads” or “Téléchargements” folder on the work computer of [employee] as of August 6, 2025
  10. All organizational charts including [employee] from 2023 to 2025
  11. All personal emails or email not related to work to any email address ending in anything other than "gc.ca" or "canada.ca" from 2023 to 2025
  12. All timesheets completed and submitted by [employee] from 2023 to 2025
  13. All photo or image files exceeding 1 megabyte saved on the work computer’s hard drive of [employee] as of August 6, 2025 (including but not limited to .jpeg, .gif, .png files)
  14. All files contained in folders or subfolders of a network drive for which access is restricted exclusively to [employee] as of August 6, 2025
  15. All messages sent and received by [employee] on Microsoft Teams for the period of April to September 2025
  16. All content of the OneNote account of [employee] as of August 6, 2025

According to the institution, the access request is an abuse of the right to make an access request.

Is the request an abuse of the right to make a request to access records?

The Act provides requesters with a right to access information under a government institution’s control—a right that should not be abused.

The Commissioner considers an abuse to have occurred when an access request exceeds the limits of the legitimate exercise of that right. When determining whether a request is abusive, the Commissioner focusses on the scope, nature and cumulative effect of the request, including the following: 

  • Whether the request is repetitive or overly broad;
  • Whether the request was made with a purpose other than obtaining documents or information;
  • whether acting on the request would overburden the institution and/or obstruct the institution’s ability to respond to other access requests (and, therefore, affect other requesters’ right of access) or both.

She may also consider the institution’s efforts, if any, to help the requester determine what information they want and/or narrow the scope of their request. The Commissioner may also consider the requester’s responses to such efforts, including the extent to which they have demonstrated a willingness to work with the institution.

The institution argues that the request is an abuse of the right to access due to its objectives and because it would overburden the institution.

Purposes of the access request

In its application, the institution states that the access request aims at the following two related purposes:

  • obtain information that is not under the control of the institution
  • obtain another individual’s personal information

The institution claims that these purposes are most clearly demonstrated in its communications with the requester. The institution states that in its communications, the requester has never referred to the functions or work of the employee targeted by the access request, but rather emphasized the personal information of the employee.

According to the institution, these two objectives demonstrate that the access request does not seek legitimate access to government records under its control.

Whether the institution is overburdened

The institution states that in the absence of a specific theme or subject, and considering the two-year period, the access request remains excessively vague.

According to the institution, the access request should generate 33,000 records (or 20,000 pages) and it should take 202.5 hours, or 5 working weeks, for the collection, extraction and preparation of responsive records.

The institution also states that the request represents 24% of the total number of pages processed for all access to information requests it closed during the last fiscal year. In 2024-25, the institution processed more than 80,000 pages under the Access to Information Act.

In light of the above, the institution is of the opinion that processing the access request would overburden it, interfere with its departmental priorities, and hinder other individuals’ right to access.

Discussion

The Commissioner then assessed whether the institution established that the access request is an abuse of the right of access.

Purposes of the access request

  1. Is the request an illegitimate exercise of the right to make an access request because the information would not be under the control of the institution?

In its response to the institution's application, the requester denies that the purpose of their request is to obtain records that are not under the control of the institution; they maintain that the requested records, and in particular the emails in point 11 on which the institution’s argument is based, are under its control.

The Act provides requesters with a right to access records under the control of government institutions, subject to limited and specific exceptions. While the Act does not define “control,” the Supreme Court of Canada held that the term should be interpreted broadly and liberally to provide a meaningful right of access. (See Canada (Information Commissioner) v. Canada (National Defence Minister), 2011 CSC 25.) Whether a record is under the control of an institution depends on the facts specific to each case.

In certain circumstances, information of an entirely personal nature may not be under the control of the institution even if it is located on servers or devices that belong to it. For example, it was the case in Employment and Social Development Canada, 2021 OIC 13, where the Commissioner concluded, after examining all relevant factors, that emails of a purely personal nature were not under the control of the institution. It is the responsibility of the institution to answer this question as part of processing the access request, and not to rely on it to justify an application to decline to act on an access request.

Be that as it may, even if the access request were to involve the disclosure of records that are not under the control of the institution, that would not, in itself, constitute an illegitimate exercise of the right of access. The fact that information may ultimately not be under the control of an institution does not mean that the right of access has been exercised in a manner that is way that exceeds, diverts or is contrary to the purpose of the right of access. An institution could not submit an application under section 6.1 on the grounds that the requested records are not under its control rather than responding appropriately to a request, thereby avoiding any complaint that might otherwise arise.

  1. Does a request for an employee's personal information constitute an improper exercise of the right to make an access request?

In their response to the application, the requester also denied that the purpose of their request is to obtain personal information. They draw a distinction between the concept of "personal information" and that of "personal use." The requester gives the example of an institutional email containing the following sentences: "What would you like for lunch? I feel like ordering from McDonald's." According to them, the employee would be using their institutional email for personal purposes, but the information it contains is not personal information because it does not pertain to an individual.

The requester appears to misunderstand the applicable principles.

“Personal information” is defined at section 3 of the Privacy Act (PA) as “information about an identifiable individual that is recorded in any form.” This section also provides several examples illustrating the scope of this concept. The Supreme Court has also noted that the definition of "personal information" is “undeniably expansive” and essentially covers any information relating to an identifiable individual, subject to specific exceptions (Dagg v. Canada (Minister of Finance), [1997] 2 SCR 403 at para 68). For the purposes of the Act, however, information relating to the position or duties of an employee of a government institution does not constitute personal information (see paragraph 3(j) of the definition of “personal information” in the PA).

Since the access request concerns records relating to the personal use of institutional resources by a specific employee, much of the information contained therein would likely be considered personal information under the Act. Indeed, the records targeted by the access request seek to deliberately obtain a wide range of information concerning an identified individual. Notably, the requested records could likely contain information related to the employee’s health status (e.g., medical appointments), their marital and family situation, personal relationships with other individuals, and potentially other elements of a similarly personal nature. Some or parts of the requested records may contain information that is not personal under the Act, because it would relate to the employee’s position or duties for example, or even a communication (e.g., a text message) related to work.

It is clear that the requester seeks access to records demonstrating the personal use by the employee of certain resources provided by their employer. Therefore, and with regard to the definition of “personal information” in the PA, the access request primarily aims to obtain personal information concerning another individual, namely the employee indicated in the request.

However, this does not in itself constitute an illegitimate exercise of the right of access. As the Commissioner found in decision 2023 OIC 48, requesting another individual’s personal information is not inherently abusive, inappropriate or contrary to the Access to Information Act. The Act actually allows the disclosure of this information in certain circumstances listed in subsection 19(2), including when the individual to whom it relates consents, when the information is publicly available or when the disclosure is in accordance with section 8 of the PA.

In certain circumstances, an access request primarily seeking an employee’s personal information may be considered a frivolous, in bad faith or an abuse of the right to make an access request. For example, this would be the case if the request was made with the purpose of harassing or harming the person. That being said, the institution has not raised such grounds in support of its application, and it is not possible to draw such a conclusion from the institution’s and the requester’s. representations.

Based on the above, the Commissioner concludes that the institution has not established that the purpose of the access request is contrary to the Act.

Burden

In response to the application, the requester argues that the institution’s estimate that the request should generate 33,000 records or 20,000 pages is not sufficiently justified, and cites decision 2025 OIC 8 in support.

The Commissioner agrees with the requester on these issues. The institution does not appear to have made a serious effort to evaluate the volume of records that the request will generate. In an email, the institution stated the following to the requester:

[Translation]

Based on our experience, any employee [of the institution] getting a request of this nature would likely have a high volume of relevant records (approximately 20,000 pages).

So the institution appears to rely on generalities to estimate the number of records. However, the use that a employee makes of their telephone, email address, or even work computer, can vary enormously depending on the type of task they perform and their personal preferences.

An application under paragraph 6.1(1) is a serious matter and must be based on clear and compelling evidence. The Commissioner finds that the evidence provided by the institution does not meet the standard.

Moreover, the Commissioner finds that the assessment of the potential impact of the access request on the Office of Primary Interest (OPI) and on the Access to Information and Privacy (ATIP) Office is not sufficiently justified. The institution states that it will take the OPI 202.5 hours to collect, extract and prepare the records, but does not explain on what this estimate is based. The institution also states that the request represents 24% of the total number of pages processed over a year, but does not explain why it lacks the capacity to process this quantity of pages.

Furthermore, the institution states that part of the requested records are not under its control. This assertion, even if we assume it to be founded, does not in itself demonstrate an illegitimate exercise of the right to make a request for access, as mentioned previously. Nonetheless, it remains relevant to the analysis of the burden that processing the access request would represent. Indeed, if the institution maintains that these records are not under its control, the workload associated with processing the request would necessarily be reduced. However, the institution does not appear to have taken this into account in its assessment.

For these reasons, the Commissioner concludes that the institution did demonstrate that the access request would overburden the institution.

Conclusion

The Commissioner finds that the institution did not establish that the access request is an abuse of the right to make a request.

Decision

The institution has not established that the access request meets one or more of the requirements of subsection 6.1(1).

Therefore, the application is denied.

Date modified:
Submit a complaint