Skip to content

Regulatory Pulse

Canada privacy regulator seeks Federal Court order on search-result de-listing

The OPC has asked the Federal Court to enforce recommendations that Google de-list specified results from name searches in a limited, harm-based case. No court order has yet been made.

Canada
Search engines, de-listing and privacy rights
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Federal Court enforcement application following a privacy investigation · Reviewed 29 August 2026 · 8 min read

The 60-second summary

On 28 August 2026, the Office of the Privacy Commissioner of Canada announced that it had filed an application asking the Federal Court to implement recommendations from its 27 August 2025 Google search investigation. The OPC found that returning specified media articles when an individual’s name was searched contravened PIPEDA subsection 5(3) in the particular circumstances because serious harm to safety and dignity outweighed the limited public interest in name-linked retrieval. Google did not accept the recommendation. The filing is an enforcement step, not a judgment: no court order has yet been made, the underlying articles would remain online, and any de-listing would concern specified name-search results rather than removal of the source content.

Timeline that matters

  1. June 2017

    Original complaint received

    The complaint challenged specified articles appearing when the individual’s name was searched.

  2. July 2021

    Federal Court confirms PIPEDA applicability

    The court confirmed that the commercial search-engine service falls within PIPEDA in the circumstances.

  3. October 2023

    Federal Court of Appeal upholds jurisdiction result

    The appellate ruling allowed the OPC investigation to continue.

  4. 27 August 2025

    OPC publishes findings

    The regulator recommends de-listing specified articles from results for searches using the complainant’s name; Google does not accept the recommendation.

  5. 28 August 2026

    OPC announces Federal Court application

    The regulator seeks an order implementing its recommendations.

  6. Pending

    Court process and decision

    No hearing date, judgment or effective compliance deadline was identified in the official announcement reviewed on 29 August 2026.

What changed

The regulator has moved from a non-binding recommendation to court enforcement. Under the current PIPEDA structure, the Privacy Commissioner cannot issue a binding compliance order in this matter and must apply to the Federal Court. The 28 August 2026 filing seeks an order implementing the recommendations in the unresolved 2025 investigation. The regulator’s underlying position is limited and fact-specific: the complaint involved highly sensitive information, serious alleged harms, an individual who was not a public figure, old and incomplete reporting, and limited public interest in retrieving the articles through a name search. The Federal Court has not yet ruled on the enforcement application.

Who should pay attention?

Search and indexing providers

The case tests how privacy, serious harm and public interest may affect name-linked retrieval of personal information.

Privacy-rights operations

Teams need intake, verification, balancing, escalation and evidence processes for de-listing and related suppression requests.

Publishers and content platforms

De-listing does not automatically remove source content, but indexing controls and response coordination may become operationally relevant.

Trust, safety and legal teams

Requests may require documented assessment of sensitivity, elapsed time, public interest, completeness, harm and freedom of expression.

Technology and vendor teams

Search, identity-resolution and third-party request tooling should preserve scope, decisions, overrides and audit evidence.

What the guidance clarifies

The court has not yet decided the application
The OPC announced a filing seeking enforcement. It did not announce a judgment, injunction or binding de-listing order.
The development is procedural but material
The regulator has escalated an unresolved recommendation to the court within the statutory enforcement route available under the current law.
De-listing is not deletion of the source article
The regulator states that the content would remain online and could still be found at the publisher or through search terms other than the individual’s name.
The regulator’s position is limited and contextual
The 2025 findings balance significant harm against public interest and identify factors such as sensitivity, age, accuracy or completeness, public-figure status and the passage of time.
The accuracy allegation was not upheld
The OPC found no breach of PIPEDA’s accuracy requirements for the search results, but found the continued name-linked display inappropriate under subsection 5(3) in the circumstances.
Earlier courts confirmed jurisdiction, not the final de-listing remedy
The Federal Court and Federal Court of Appeal previously confirmed that PIPEDA applies to the commercial search-engine service; the present application concerns implementation of the later recommendation.

Global relevance — de-listing requires a defensible balancing process

Why this matters for global organisations

Search, profile discovery and identity-resolution systems can turn old or sensitive information into a persistent operational risk. A mature response process distinguishes source deletion from query-specific suppression, balances harm and public interest, protects freedom of expression, and records why a request was accepted, narrowed or refused.

  • Separate source removal, index removal and query-specific de-listing in policies and system controls.
  • Create a repeatable assessment for sensitivity, serious harm, public role, relevance, completeness and elapsed time.
  • Route high-impact or contested requests to qualified legal and specialist review.
  • Keep decision evidence, technical implementation proof and re-indexing tests.
  • Coordinate search, privacy, publishing, vendor and incident teams without implying that one jurisdiction’s outcome is universally controlling.

12 actions to start now

  1. Track the Federal Court docket and official OPC updates; do not treat the filing as a final judgment.
  2. Inventory products that return personal information in response to a person’s name, identifier or profile query.
  3. Define separate request types for deletion at source, search-index removal, query-specific de-listing, correction and suppression.
  4. Publish an intake route that captures identity, exact URLs or results, search terms, requested scope and claimed harm.
  5. Verify the requester proportionately while minimising additional collection of sensitive information.
  6. Build a documented balancing test covering sensitivity, seriousness and likelihood of harm, public-figure status, public debate, age, accuracy, completeness and passage of time.
  7. Require legal or specialist review for contested cases, journalism-related content, freedom-of-expression issues and cross-border conflicts.
  8. Record the geographic, service and query scope of every technical action.
  9. Test that accepted de-listing decisions work for the specified query without unintentionally removing the source content or unrelated results.
  10. Create vendor instructions, service levels and audit rights for outsourced search, identity-resolution or request tooling.
  11. Set review triggers for changed facts, new court decisions, republished content, re-indexing or renewed public interest.
  12. Prepare communications that accurately distinguish a regulator’s position, a court filing and a binding court order.

Evidence worth retaining

  • Regulatory watch record linking the 2025 findings, 2026 filing and later court events.
  • Search and identity-feature inventory with owners, data sources, query types and geographic availability.
  • Request intake form, identity-verification standard and data-minimisation rationale.
  • Case file showing the exact URLs, queries, screenshots and requested remedy.
  • Balancing assessment covering harm, sensitivity, public interest, relevance, completeness and elapsed time.
  • Legal or specialist review notes for contested and high-impact cases.
  • Decision notice showing scope, reasoning, appeal or reconsideration route and implementation owner.
  • Technical change ticket, query tests, screenshots and re-indexing verification.
  • Vendor instructions, confirmations, audit evidence and exception records.
  • Retention schedule and access controls for sensitive request evidence.
  • Metrics for volumes, outcomes, turnaround, reversals and implementation defects.
  • Change log for policy, system and precedent updates.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Which services and features are capable of returning personal information through a name or identity query?
  • Does the applicable law distinguish deletion, index removal and query-specific de-listing?
  • What evidence is necessary and proportionate to assess serious harm without over-collecting sensitive data?
  • How should public interest and freedom of expression be balanced in this case?
  • Is the person a public figure, and does the information contribute to a current matter of public debate?
  • Is the information accurate, complete, current and relevant to the query?
  • Would narrowing the query, territory, service or duration address the risk more proportionately?
  • Which entity controls the index, ranking, snippet, source content and technical suppression rule?
  • What notice, review and appeal process should be available to affected parties?
  • How will the organisation detect re-indexing, mirrored content or failed vendor implementation?
  • Do contractual roles and cross-border conflicts require separate specialist advice?
  • What court or regulator development would trigger an immediate policy reassessment?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.