
PIPEDA Findings #2020-003: Dell improves security and complaint handling practices following breaches and OPC Investigation
Two Dell customers complained to the OPC after receiving "tech support scam" calls where fraudsters possessed their personal Dell product information, alleging insufficient security safeguards and inadequate complaint handling by Dell. The OPC's investigation revealed that two employees of Dell's service provider in India had sold customer data lists in June and November 2017, affecting at least 7,883 Canadians. The OPC found Dell responsible for the personal information, concluding that its safeguards related to access controls, logging, monitoring, and technical measures were insufficient given the data's sensitivity and the high-risk environment. Dell also failed to adequately investigate the June 2017 breach and respond to customer complaints. Following the OPC's recommendations, Dell implemented numerous enhancements, including changing service providers, improving security protocols, and revising complaint handling procedures. Consequently, the OPC deemed the matter well-founded and resolved.
- 1Whether Dell adequately safeguarded personal information under its control while using a service provider (PIPEDA Principle 4.1.3 and 4.7).
- 2Whether the personal information transferred to the service provider was sensitive enough to require a high degree of protection.
- 3Whether Dell's access controls were sufficient to protect customer information.
- 4Whether Dell's logging and monitoring practices were adequate to detect anomalous employee requests for customer information.
- 5Whether Dell's technical measures, such as USB drive restrictions, were sufficient.
- 6Whether Dell adequately investigated the circumstances and scope of the June 2017 breach.
- 7Whether Dell adequately responded to customer complaints about potential privacy breaches (PIPEDA Principle 4.10.4).
- 8Whether Dell remained responsible for personal information transferred to a third party for processing.
- Safeguards: Insufficient safeguards found
- Breach investigation: Inadequate investigation of breach
- Complaint handling: Inadequate complaint handling
- Corrective actions: Corrective actions implemented by institution
- Overall finding: Matter well-founded and resolved
Complaint well-founded and resolved
The OPC found that Dell's security safeguards and complaint handling were inadequate, but Dell implemented satisfactory corrective measures in response to the OPC's recommendations.
Dell implemented procedures for thorough investigation of complaints and breaches, trained staff on privacy obligations, strengthened access controls (e.g., two-factor authentication, masking information), improved monitoring and logging capabilities, and disabled USB functionality.
- Principle 4.1.3 PIPEDA
- Principle 4.7 PIPEDA
- Principle 4.10.4 PIPEDA
This summary is for informational purposes only and does not constitute legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro