← Back to catalogue/Federal (Canada)PIPEDA Findings #2021-003
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Organization: Bank of MontrealComplainant: Two BMO customers
Plain-language brief

The OPC investigated complaints from two Bank of Montreal (BMO) customers following a large-scale data breach. BMO's online banking software contained significant vulnerabilities, which allowed attackers to compromise approximately 113,154 customer accounts between June 2017 and January 2018. The compromised personal information included highly sensitive data such as Social Insurance Numbers, dates of birth, financial account numbers, and contact details. The OPC found that BMO failed to implement appropriate security safeguards commensurate with the sensitivity of the information, contravening PIPEDA Principle 4.7. Deficiencies were identified in developer security testing, vulnerability management, and oversight and monitoring. However, BMO implemented significant improvements to its security protocols, systems, and operations after the breach to address these shortcomings. Consequently, the OPC concluded the matter was well-founded and resolved.

Key issues
  1. 1Whether BMO implemented appropriate security safeguards to adequately protect personal information under its control, as required by PIPEDA Principle 4.7
  2. 2Adequacy of BMO's developer security testing and evaluation processes
  3. 3Adequacy of BMO's vulnerability management program, including identification, assessment, and remediation of vulnerabilities
  4. 4Adequacy of BMO's oversight and monitoring capabilities, specifically regarding bot management, cyberattack detection, and real-time alerts
  5. 5Adequacy of BMO's organizational policies and procedures for handling cyberattacks and incident response
Outcome breakdownFavours: Applicant / complainant
  • Security safeguards: BMO contravened PIPEDA Principle 4.7
  • Vulnerability management: Deficiencies identified
  • Developer security testing: Deficiencies identified
  • Oversight and monitoring: Deficiencies identified
  • Complaint resolution: Well-founded and resolved
Outcome

Complaint well-founded and resolved

Reasoning

The OPC found that BMO failed to implement appropriate safeguards, but BMO subsequently implemented significant improvements to address the identified deficiencies to the OPC's satisfaction.

AI-generated summary for reference only. Always verify against the official decision ↗
Decision notes
Statutes considered
  • Principle 4.7 PIPEDA
  • Principle 4.7.1 PIPEDA
  • Principle 4.7.3 PIPEDA

This summary is informational only and not legal advice.

Pro · AI

Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.

Pro
Coverage — 13 of 14 jurisdictions searchable

Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.

Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).

Coming soon: Nunavut — being re-processed for AI search.

Find decisions like this one — by meaning, not keywords.

Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.

Upgrade to Pro