Expert Analysis

The password was shared; the privacy was not: The legal perils of spousal snooping

By Hodine Williams ·

Law360 Canada (August 7, 2026, 2:49 PM EDT) --
Hodine Williams
Hodine Williams

“My Face ID is registered on your phone.”

It sounds like the ultimate modern romantic gesture, doesn’t it? Right up there with sharing your Netflix password or letting them see you in your most un-Instagrammable sweatpants. But let’s be clear: sharing a biometric key is not a blanket invitation to conduct a forensic audit of your partner’s digital life.

Handing over the biometric keys to your smartphone feels like the ultimate expression of confidence. But there is a dangerous, almost seductive assumption hiding beneath that convenience: that access equals permission. I dare say — it does not! In the eyes of the law, trust is not a password, and having the keys to the kingdom doesn’t mean you’re allowed to rifle through every drawer in the castle.

Scrolling on phone_image_350W

fadfebrian: ISTOCKPHOTO.COM

As any barrister will tell you, a fingerprint is not a search warrant, and a shared life does not create a shared right to ransack every private corner of a partner’s digital existence. The smartphone has quietly become the most intimate object we own — a digital diary, a filing cabinet and a reflection of identity all rolled into one. It carries the weight of conversations with friends, medical records and legal advice.

That is why the question of whether a spouse can search a partner’s phone is not merely a technical one; it is a fundamental question of autonomy and the boundaries that must persist even within the most intimate of unions.

The ‘one-key’ fallacy and the biographical core

One of the greatest misconceptions in our hyper-connected age is the belief that if you can access information, you have the legal right to do so. Imagine giving a neighbour a key to your home to water the plants while you’re away. That key provides entry, but it doesn’t grant them a licence to rifle through your bedside drawers or read your personal journals. The physical key provides access; it does not provide unlimited authority.

The same principle applies to the glass-and-silicon vaults in our pockets. A spouse may know a passcode or have their Face ID registered, but these facts do not establish permanent, unrestricted consent. It doesn’t mean they have “lawful justification” to monitor your location, read private messages or install spyware. What used to be “checking the mileage on the car” has evolved into real-time GPS tracking, and the law is catching up to these new forms of digital intrusion.

This distinction was brought into sharp focus by the Supreme Court of Canada in R. v. Spencer, 2014 SCC 43, where the Supreme Court ruled that basic subscriber information linked to an IP address touches the biographical core of personal information, establishing a high reasonable expectation of privacy under s. 8 of the Charter. The information details reveal who they are, their lifestyle and their personal choices. It follows that if the state typically requires a warrant to peer into this core, a suspicious spouse certainly doesn’t receive a free pass simply by virtue of a marriage certificate.

The ‘it was already open’ defence

The most common justification for digital snooping is as old as the hills: “I didn’t hack anything; the phone was already unlocked.” But an unlocked device is not an open invitation. The fact that a door is left ajar does not mean the public is welcome to wander in and start reading the mail. In the digital realm, boundaries are often invisible — there is no locked filing cabinet to signal “keep out.” Yet, the absence of a physical barrier does not equate to the absence of a legal one.

In Ontario, the law has long recognized that privacy and secrecy are not synonyms. Privacy is the ability to maintain personal autonomy; secrecy is the intentional hiding of information that affects another. The law protects the former because individuality does not evaporate when two people build a life together. When you pick up that phone sitting on the kitchen counter, you aren’t just looking for “the truth” — you are stepping over a legal line that has been drawn with increasing clarity by the courts.

From jealousy to surveillance: The rise of coercive control

What we once dismissed as mere jealousy is now being recognized for what it often is: technology-facilitated intimate partner abuse. We have seen where digital tools are increasingly used to extend patterns of abuse beyond the physical home in a phenomenon known as “technology-facilitated abuse.” The modern abuser doesn’t need to follow their partner; a location-sharing app or a hidden AirTag does the job with chilling efficiency.

This form of coercive control — monitoring messages, accessing cloud backups or installing spyware — can be more damaging than physical violence because it leaves no bruises while creating a sense of psychological confinement. Technology has made surveillance effortless, but it has not made it harmless. In fact, it has turned the domestic sphere into a potential legal minefield.

The legal revolution: Intrusion upon seclusion

For much of legal history, privacy was a social value, not an enforceable right. That changed with the landmark Ontario Court of Appeal decision in Jones v. Tsige, 2012 ONCA 32. The court recognized a new civil cause of action: “intrusion upon seclusion.” The case involved a defendant who repeatedly accessed a plaintiff’s private banking records without authorization. The court’s message was clear: privacy is not a courtesy; it is an interest worthy of legal protection.

To succeed in such a claim, the conduct must be intentional or reckless, the intrusion must involve private affairs without lawful justification, and crucially, it must be “highly offensive” to a reasonable person. The question for the would-be digital detective is no longer “Could I get in?” but rather “Was I entitled to enter?” As we will explore in part two, those who go looking for a “smoking gun” often find themselves becoming the ones under investigation.

This is part one of a two-part series. Part two: The password was shared; the privacy was not: The legal perils of spousal snooping.

Hodine Williams has over 20 years of experience in law, corporate governance and regulatory compliance across the legal, financial, hospitality and engineering sectors. Hodine is a partner at Augustine Williams Law Professional Corporation. He is a former prosecutor and expert in digital forensics, financial crimes and cyber law, and has advised corporations in Jamaica, Canada and the United Kingdom. Holding a master of laws in international business law from Osgoode Hall Law School, along with degrees in management and economics and law, Hodine is also an educator, philanthropist and is a youth and human rights advocate. You can reach him at hodine.williams@gmail.com.

The opinions expressed are those of the author(s) and do not necessarily reflect the views of the author’s firm, its clients, Law360 Canada, LexisNexis Canada or any of its or their respective affiliates. This article is for general information purposes and is not intended to be and should not be taken as legal advice.

Interested in writing for us? To learn more about how you can add your voice to Law360 Canada, contact Analysis Editor Yvette Trancoso at Yvette.Trancoso-barrett@lexisnexis.ca or call 905-415-5811.

LexisNexis® Research Solutions