
PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment
The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.
- 1Whether MGM had the obligation to report the breach to the OPC and notify affected Canadians
- 2Whether the MGM breach met the RROSH reporting and notification threshold
- 3Whether the personal information involved was sensitive
- 4Whether there was a high probability of misuse of the personal information
- 5Whether MGM notified the OPC and affected Canadians as soon as feasible
- Breach reporting: Contravention found for failure to assess RROSH and report promptly
- Individual notification: Contravention found for failure to notify individuals promptly
- Breach response framework: MGM committed to amending framework
- Complaint outcome: Well-founded and conditionally resolved
Complaint well-founded and conditionally resolved
MGM failed to promptly assess the real risk of significant harm to Canadians and did not report the breach or notify affected individuals as soon as feasible. However, MGM committed to implementing corrective measures to its breach response framework.
MGM committed to amending its privacy breach response framework by June 30, 2022, to ensure prompt RROSH assessments, timely reporting to the OPC, and notification to affected individuals for future breaches involving Canadian residents.
- s.10.1 PIPEDA
- s.10.1(1) PIPEDA
- s.10.1(2) PIPEDA
- s.10.1(3) PIPEDA
- s.10.1(6) PIPEDA
- s.10.1(8) PIPEDA
- Principle 4.3.4 PIPEDA
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro