← University
Defamation, Privacy, and Economic Torts
0 of 4

A regional catering and event services company in southern Ontario had employed a senior sales manager for 7 years before that manager resigned to establish a competing business in the same geographic market. The departure itself was unremarkable, governed by a standard employment contract that included a 12-month non-solicitation clause covering existing clients but no broader non-compete restriction. Within 3 months of the manager's departure, the original company began losing contracts with clients it had served for years, including 2 municipal governments and a regional hospital that together represented approximately $340,000 in annual revenue.

The owner of the original company suspected the former manager was actively soliciting clients covered by the non-solicitation agreement and began gathering information. Through a contact at one of the municipal clients, the owner obtained internal emails suggesting the former manager had reached out to procurement staff before leaving her position, discussing the possibility of future business arrangements. The owner also discovered that the former manager's new company was circulating marketing materials to prospective clients that included comparative statements about food safety practices, implying the original company had experienced health inspection issues that had never actually occurred.

The situation escalated when the original company's owner posted a detailed account on a regional business networking platform describing the former manager's conduct, including allegations about dishonesty during her employment and claims that she had accessed confidential client pricing information before her departure. The post named the former manager's new business and urged other business owners in the region to avoid working with her. Within 2 weeks, 3 suppliers who had been negotiating contracts with the new catering company withdrew from those discussions, citing concerns about the allegations.

The former manager responded by sending a letter to the original company's remaining clients, attaching what she described as evidence of workplace safety violations at the original company's food preparation facility, including photographs taken during her employment that showed kitchen conditions and identifiable staff members. The letter also included salary information for several current employees, presented as evidence that the original company underpaid its workers compared to industry standards.

Both parties retained counsel. The original company claimed damages exceeding $500,000 for lost contracts and reputational harm. The former manager counterclaimed for defamation and interference with her new business relationships, seeking $750,000 in damages. The underlying questions concern which statements and conduct by each party may attract liability, what defences may apply, and how the overlapping claims of reputational harm, privacy violation, and economic interference interact under Canadian tort law.

Privacy Torts: Intrusion Upon Seclusion and Publication of Private Facts

Privacy law in Canada has evolved significantly over the past two decades, responding to technological changes that have made it easier than ever to capture, store, and disseminate personal information. While defamation protects a person's reputation from false statements, privacy torts address a different kind of harm: the violation of a person's reasonable expectation to be left alone and to control information about their private lives. For business owners, non-profit operators, and professionals across Canada, understanding these emerging legal concepts is essential because the line between legitimate business activity and actionable invasion of privacy can be surprisingly thin.

The common law provinces have recognized two distinct privacy torts that operate independently of statutory privacy regimes: intrusion upon seclusion and publication of private facts. These torts emerged from judicial recognition that existing legal frameworks inadequately protected individuals from certain invasions of their personal sphere. Unlike defamation, which requires proof of reputational harm, privacy torts recognize that the very act of intrusion or unauthorized disclosure can constitute a compensable wrong. Quebec, operating under its civil law tradition, approaches privacy protection differently through the Civil Code of Quebec, which enshrines privacy as a fundamental personality right. The Civil Code explicitly protects the private life of every person, establishing a framework that accomplishes similar goals through different legal mechanisms. This distinction matters because businesses operating across provincial boundaries must appreciate that privacy protection exists everywhere in Canada, though the specific rules and remedies vary by jurisdiction.

Intrusion upon seclusion addresses situations where one party deliberately and substantially interferes with another's private affairs without lawful justification. The elements of this tort require intentional or reckless conduct, an invasion of private affairs or concerns, and circumstances where a reasonable person would regard the invasion as highly offensive and causing distress, humiliation, or anguish. The invasion does not require physical entry into someone's space; it can occur through surveillance, unauthorized access to personal information, or other means of prying into matters that a person has a reasonable expectation of keeping private. This tort recognizes that certain zones of personal life deserve legal protection from intrusion, regardless of whether any information is subsequently published or disclosed.

Publication of private facts operates on different principles. This tort applies when someone gives publicity to a matter concerning another person's private life, where the matter publicized would be highly offensive to a reasonable person and is not of legitimate concern to the public. The key distinction from intrusion upon seclusion is that publication of private facts requires dissemination of information, while intrusion upon seclusion can occur even if the intruder never shares what they learn. Both torts can apply to the same course of conduct, such as when someone secretly accesses private information and then shares it publicly, but they address different aspects of the privacy violation.

In practical terms, business owners encounter privacy considerations in numerous contexts that may not immediately seem legally significant. Employment relationships generate substantial privacy exposure because employers necessarily collect and maintain personal information about their workers. Customer relationships similarly involve the acquisition and use of personal data. Businesses operating physical premises must consider whether their security measures, such as video surveillance, appropriately balance legitimate security needs against privacy expectations. Organizations using social media for marketing must navigate the boundary between publicly available information and private matters that should not be exploited commercially. Non-profit operators face particular challenges when their missions involve serving vulnerable populations, as the very nature of their work may require collecting sensitive personal information while simultaneously creating obligations to protect it.

The statutory framework for privacy protection operates alongside these common law torts and creates additional obligations for organizations. The Personal Information Protection and Electronic Documents Act, a federal statute, applies to private sector organizations engaged in commercial activities across most of Canada, as of the date of authorship. British Columbia, Alberta, and Quebec have enacted substantially similar provincial legislation that applies to provincially regulated organizations within their borders. Saskatchewan, Ontario, and other provinces have general privacy statutes that create civil causes of action for violations of privacy, though these differ in scope and remedies from both the common law torts and the comprehensive data protection legislation. Understanding this layered framework matters because a single course of conduct might simultaneously violate common law privacy torts, statutory privacy protections, and sector-specific regulations applicable to particular industries.

The reasonable expectation of privacy serves as a cornerstone concept across these various legal mechanisms. What constitutes a reasonable expectation depends heavily on context. A person conducting business in a public marketplace has reduced privacy expectations regarding their commercial activities. That same person attending a medical appointment has heightened privacy expectations regarding the information disclosed to healthcare providers. Employees working in open office environments have different privacy expectations than those working from home offices. The assessment of reasonableness considers social norms, the nature of the information or space in question, and whether the individual took steps to preserve privacy. Business operators must develop the habit of asking whether their practices respect the privacy expectations that reasonable people would hold in similar circumstances.

Consider the situation facing a wellness centre operating in Halifax that offers massage therapy, physiotherapy, and counselling services. The centre serves approximately two hundred regular clients and employs twelve practitioners across its various service lines. The owner, seeking to improve customer service and reduce no-show appointments, decided to implement a sophisticated scheduling and reminder system. The new system collected comprehensive client information including not only contact details and appointment history but also notes about the nature of services received, practitioner preferences, and any special accommodations required. The system automatically sent appointment reminders by text message to clients' mobile phones, and these messages included details about the specific service booked. A reminder might read that the client had an upcoming appointment for trauma counselling on Thursday at 2:30 p.m. with a particular practitioner.

The owner also installed a security camera system throughout the premises, including cameras in waiting areas, hallways, and near treatment room doors. While no cameras were placed inside treatment rooms, they were positioned such that clients could be identified entering specific service areas. The footage was stored on a networked system accessible to administrative staff and was retained for ninety days before automatic deletion. The owner had not implemented any formal policy restricting staff access to this footage or governing its use.

Complicating matters, one of the administrative staff members became curious about whether her neighbour was among the centre's clients. She searched the client database and confirmed that the neighbour had been attending counselling appointments every Tuesday evening for the past several months. The staff member mentioned this to her spouse during a dinner conversation, noting that the neighbour seemed to be dealing with some issues and was seeing a therapist. The spouse, who worked with the neighbour, began treating her differently, and the neighbour eventually discovered the source of the changed behaviour.

The privacy implications of this scenario reveal multiple points of exposure for the wellness centre. The text message reminder system, while implemented with good intentions to improve service delivery, disclosed private health-related information in an insecure manner. Text messages might be visible on a phone screen to family members, coworkers, or anyone in proximity to the recipient's device. The mere fact that someone is attending trauma counselling constitutes sensitive private information that most reasonable people would expect to remain confidential. By including specific service details in unencrypted text messages, the centre created a mechanism for potential unauthorized disclosure of private facts even without any malicious intent.

The security camera placement, while perhaps defensible for legitimate security purposes, raised concerns about the extent to which visual records of clients entering particular service areas constituted intrusion into private affairs. While a waiting room in a commercial establishment is a semi-public space with reduced privacy expectations, the ability to track which specific services a client receives by observing which treatment areas they enter crosses a different threshold. The ninety-day retention period and unrestricted staff access magnified the risk by creating a repository of potentially sensitive information without adequate safeguards.

The staff member's unauthorized access to client records and subsequent disclosure to her spouse represents the clearest privacy violation, but the employer bears responsibility for creating the conditions that enabled this breach. The absence of formal access controls, training on confidentiality obligations, and policies governing appropriate use of client information meant that the organization had failed to implement reasonable safeguards. In privacy litigation, both the individual wrongdoer and the organization that negligently permitted the wrongdoing may face liability. Damages in privacy tort claims need not be tied to specific financial losses; courts can award damages for intangible harms such as humiliation, anxiety, and loss of dignity. Awards in Canadian privacy cases have ranged from modest sums of a few thousand dollars to significant amounts exceeding twenty thousand dollars depending on the nature and severity of the intrusion.

Quebec's approach under the Civil Code of Quebec provides instructive comparison. Article 35 of the Civil Code establishes that every person has a right to the respect of their reputation and privacy, and Article 36 enumerates specific acts that may be considered invasions of privacy. These include entering or taking anything in a person's dwelling, intentionally intercepting or using private communications, appropriating or using a person's image or voice while in private premises, keeping a person's private life under observation by any means, using a person's name, image, likeness, or voice for purposes other than legitimate information of the public, and using correspondence, manuscripts, or other personal documents. This explicit enumeration provides clearer guidance than the common law approach but covers substantially similar ground. A Quebec business operator must recognize that privacy protection is constitutionally and legislatively embedded in that province's legal framework in a manner that may result in different procedural mechanisms for enforcement even while protecting similar interests.

For business owners and non-profit operators seeking to manage privacy exposure, several practical measures warrant attention. Organizations should conduct a thorough inventory of the personal information they collect, examining each category of information to determine whether its collection is necessary for legitimate operational purposes. Information that serves no genuine business need should not be collected in the first place, as data that does not exist cannot be improperly accessed or disclosed. Where collection is necessary, organizations should implement technical and administrative controls proportionate to the sensitivity of the information involved. Access should be limited to personnel with legitimate need, and systems should log access to enable detection of unauthorized use.

Communication practices deserve careful review. Any system that transmits personal information should be assessed for the possibility of inadvertent disclosure to unintended recipients. Text messages, emails, and voicemails can all be intercepted, overheard, or viewed by third parties. Particularly sensitive information such as health matters, financial difficulties, or personal struggles should be communicated through channels that minimize disclosure risk. Organizations should obtain clear consent for their communication practices and provide clients with options to choose their preferred contact methods.

Physical surveillance through cameras or other monitoring technologies requires thoughtful implementation. Legitimate security purposes can often be achieved through camera placement that focuses on entry points, cash handling areas, and locations where assets are at risk without extending into spaces where heightened privacy expectations exist. Signage alerting visitors to surveillance should be clearly posted. Retention policies should limit footage storage to periods necessary for security review, and access controls should restrict who can view recorded material. Organizations should document their rationale for surveillance and be prepared to demonstrate that their practices represent proportionate responses to legitimate concerns.

Employee training represents a critical but frequently neglected safeguard. Staff members handling personal information must understand their confidentiality obligations and the consequences of unauthorized access or disclosure. Organizations should establish clear policies prohibiting curiosity-driven searches of client records and implement mechanisms to detect policy violations. The wellness centre scenario illustrates how a single employee's unauthorized conduct can create organizational liability, emphasizing the importance of preventive measures.

Contractual relationships with service providers who handle personal information warrant attention. Cloud-based software systems, payment processors, marketing platforms, and other third parties that access client data should be bound by confidentiality obligations appropriate to the information involved. Organizations remain responsible for safeguarding personal information even when outsourcing processing functions, and they should verify that service providers maintain adequate protections.

Documentation practices support both operational privacy management and legal defense should issues arise. Organizations should maintain records of their privacy policies, the training provided to staff, consent mechanisms used with clients, and the safeguards implemented to protect personal information. When privacy concerns are raised, whether through client complaints or internal discovery of potential issues, organizations should document their response and any remedial measures taken. This documentation can demonstrate good faith efforts to protect privacy even if human error or malicious conduct results in a breach.

Questions that business owners should ask themselves include whether each piece of personal information they collect serves a genuine operational purpose, whether access to personal information is appropriately restricted, whether communication methods adequately protect confidential information, whether surveillance practices are proportionate and disclosed, whether staff understand their confidentiality obligations, whether service providers are contractually bound to protect shared information, and whether documentation would support a defense of reasonable conduct if a privacy concern were raised. Regular review of these questions can identify emerging risks before they materialize into legal liability.

Privacy torts in Canada reflect an evolving societal consensus that individuals deserve legal protection for their personal sphere even when no financial harm or reputational injury can be demonstrated. The intrusion upon seclusion tort guards against prying into private matters, while publication of private facts addresses unauthorized disclosure of personal information. Business operators, non-profit leaders, and professionals who understand these principles can implement practices that respect client privacy while achieving their legitimate organizational objectives. In an era of pervasive data collection and digital communication, privacy consciousness is not merely a legal compliance matter but an aspect of ethical business operation that builds trust and protects both organizations and the individuals they serve.

Continue with University access

This lesson is part of a $79 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options