
PIPEDA Findings #2021-002: Investigation into CoreFour Inc.’s compliance with PIPEDA
The Office of the Privacy Commissioner of Canada (OPC) investigated CoreFour Inc.'s compliance with PIPEDA regarding its Edsby K-12 learning management system, following a complaint about safeguards, breach response, and accountability. Regarding safeguards, the OPC found that while CoreFour had many effective security practices, it had specific vulnerabilities, including weak password requirements for parental accounts, inadequate protection for student profile picture thumbnails, and a failure to scan for malware on third-party content uploads. The OPC concluded that CoreFour lacked a robust overarching information security framework, leading to a finding of "well-founded" for safeguards. On breach reporting and notification, the OPC determined that the password vulnerability occurred before mandatory reporting, and the student image vulnerability, while a breach, did not pose a "real risk of significant harm" as the only unauthorized access was by the complainant. Therefore, CoreFour was not required to report these incidents, and its breach reporting procedures were found to be compliant, leading to a "not well-founded" finding for this issue. For accountability, the OPC found CoreFour lacked a privacy management framework, appropriate written policies (e.g., complaint handling, data retention), adequate privacy training for staff, and its Privacy Policy was unclear in several respects, resulting in a "well-founded" finding. CoreFour committed to implementing all recommendations, including developing comprehensive information security and privacy management frameworks, updating its Privacy Policy, and providing a third-party report, leading to the "conditionally resolved" status for safeguards and accountability. The OPC will monitor CoreFour's progress to ensure full compliance with the Act.
- 1Whether CoreFour's security safeguards were appropriate to the sensitivity and volume of personal information under Principle 4.7 PIPEDA
- 2Whether CoreFour's weak password requirements for certain Edsby parental accounts constituted an inadequate safeguard
- 3Whether CoreFour's safeguards to protect against unauthorized access to thumbnail images of student profile pictures were adequate
- 4Whether Edsby's failure to scan for malware when uploading content from third-party applications constituted a safeguard weakness
- 5Whether CoreFour lacked a robust overarching information security framework, contravening Principle 4.1.4 and 4.7-4.7.3 PIPEDA
- 6Whether CoreFour had an adequate mechanism for handling and reporting privacy breaches under PIPEDA
- 7Whether CoreFour was required to report the password management vulnerability, given it occurred before mandatory breach reporting came into effect
- 8Whether the student image vulnerability created a "real risk of significant harm" requiring mandatory reporting and notification under s.10.1 PIPEDA
- 9Whether CoreFour maintained a breach register as required under s.10.3 PIPEDA
- 10Whether CoreFour lacked a privacy management framework, including appropriate written internal policies and practices (e.g., complaint handling, data retention), contravening Principle 4.1.4 PIPEDA
- 11Whether CoreFour provided adequate privacy training to its employees, consultants, contractors, and students
- 12Whether CoreFour's Privacy Policy was unclear regarding the characterization of personal information, its responsibility for security, and the sharing of user information
- Safeguards: Complaint well-founded due to vulnerabilities and lack of framework
- Breach reporting: Complaint not well-founded; no reporting required
- Accountability: Complaint well-founded due to lack of privacy management framework
- Resolution: Conditionally resolved based on commitments
Safeguards and accountability well-founded and conditionally resolved; breach reporting not well-founded
CoreFour had safeguard and accountability deficiencies but committed to implementing OPC recommendations, including developing frameworks and updating policies. Its breach reporting practices were found compliant as identified vulnerabilities did not meet mandatory reporting thresholds or were pre-mandatory reporting.
The Commissioner recommended CoreFour implement an information security management framework, ensure sufficient IT security resources, scan for malware on third-party uploads, train staff, develop a privacy management framework (including complaint handling and data retention policies), adopt a privacy training program, and clarify its Privacy Policy, with a commitment to provide a third-party report confirming implementation.
- Principle 4.7 PIPEDA
- Principle 4.7.1 PIPEDA
- Principle 4.7.2 PIPEDA
- Principle 4.7.3 PIPEDA
- Principle 4.1.4 PIPEDA
- s.10.1 PIPEDA
- s.10.2 PIPEDA
- s.10.3 PIPEDA
- s.7.2(1) PIPEDA
- s.7.2(2) PIPEDA
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro