
Commissioner’s Findings - PIPEDA Report of Findings # 2012-004 : Weak authentication allowed imposter to hijack customer’s cell phone account
An imposter gained access to the complainant's cell phone account by social engineering a customer service representative (CSR). The CSR disclosed personal information, including PIN, billing, and call history, and made changes to the account. The complainant also alleged inadequate response to an access request for call recordings and transcripts. The OPC found the disclosure of personal information to the imposter to be well-founded, as the company's authentication procedures were not followed, contravening Principle 4.3. The access complaint was found well-founded because the company initially failed to respond within the 30-day timeframe, but it was resolved as the company eventually provided the requested information. The OPC recommended the company review its privacy management programs, policies, and procedures.
- 1Whether the cellular service provider disclosed personal information without consent to an imposter, contravening Principle 4.3 PIPEDA
- 2Whether the cellular service provider adequately responded to the complainant's access request for personal information under Principle 4.9 PIPEDA
- 3Whether the cellular service provider responded to the access request within the 30-day timeframe as per s.8(3) PIPEDA
- 4Whether the redaction of the CSR's name from the transcript was permissible under s.9(1) PIPEDA
- 5Whether the company was required to provide an audio recording of the conversation in addition to a transcript under s.10 PIPEDA
- Disclosure of personal information: Complaint well-founded; company failed to follow authentication procedures
- Timeliness of access request: Complaint well-founded; company failed to respond within 30 days
- Resolution of access request: Resolved; company eventually provided information
- Privacy management program: Recommendation to review programs, policies, and procedures
Disclosure complaint well-founded; Access complaint well-founded and resolved
The disclosure complaint was well-founded because the company's CSR failed to follow established authentication procedures, leading to unauthorized disclosure. The access complaint was initially well-founded due to a delayed response but resolved when the company eventually provided the requested information.
The OPC recommended that the company review its privacy management programs, policies, and procedures, including those relating to safeguards and employee training, in light of the guidance document 'Getting Accountability Right with a Privacy Management Program'.
- Principle 4.3 PIPEDA
- Principle 4.9 PIPEDA
- s.10 PIPEDA
- s.2(1) PIPEDA
- s.8(3) PIPEDA
- s.8(4) PIPEDA
- s.8(5) PIPEDA
- s.9(1) PIPEDA
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro