← Back to catalogue/Federal (Canada)PIPEDA Report of Findings #2018-001
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

Organization: VTech Holdings LimitedComplainant: Anonymous applicant
Plain-language brief

VTech Holdings Limited, a connected toy manufacturer, experienced a global data breach affecting over 316,000 Canadian children and 237,000 Canadian adults. The OPC launched an investigation after receiving a complaint from an affected Canadian. The investigation revealed significant safeguard deficiencies, including a lack of testing, inadequate access controls, cryptographic weaknesses, and no comprehensive security management program. These deficiencies were not commensurate with the sensitivity of the information, especially that of children. However, VTech implemented timely and comprehensive measures to contain the breach, mitigate risks to affected individuals, and address safeguard concerns during the investigation. The OPC concluded that the matter was well-founded and resolved due to these corrective actions.

Key issues
  1. 1Whether VTech Holdings Limited failed to adequately safeguard personal information under Principle 4.7 PIPEDA
  2. 2Whether VTech's security safeguards were appropriate to the sensitivity of the information (Principle 4.7 PIPEDA)
  3. 3Whether VTech's safeguards protected against unauthorized access, disclosure, copying, use, or modification (Principle 4.7.1 PIPEDA)
  4. 4Whether the nature of VTech's safeguards varied depending on the sensitivity, amount, distribution, format, and storage method of the information (Principle 4.7.2 PIPEDA)
  5. 5Whether VTech's methods of protection included physical, organizational, and technological measures (Principle 4.7.3 PIPEDA)
  6. 6Whether VTech had adequate testing and maintenance protocols to identify and mitigate vulnerabilities
  7. 7Whether VTech had adequate administrative access controls
  8. 8Whether VTech had adequate cryptographic protection for personal information
  9. 9Whether VTech had sufficient security monitoring and logging to detect threats
  10. 10Whether VTech had a comprehensive security management program
Outcome breakdownFavours: Both, in part
  • Safeguards: Deficiencies found
  • Corrective actions: Timely and comprehensive measures taken
  • Investigation outcome: Well-founded and resolved
Outcome

Complaint well-founded and resolved

Reasoning

The OPC found that VTech contravened Principle 4.7 of PIPEDA due to inadequate safeguards. However, VTech implemented sufficient and timely measures to address the deficiencies during the investigation, leading to a 'resolved' outcome.

AI-generated summary for reference only. Always verify against the official decision ↗
Decision notes
Recommended action / remedy

VTech implemented a regular, multifaceted testing protocol, an update/patch management program, limited administrative access, enhanced cryptography, increased logging and monitoring, and a new comprehensive data security policy.

Statutes considered
  • Principle 4.7 PIPEDA
  • Principle 4.7.1 PIPEDA
  • Principle 4.7.2 PIPEDA
  • Principle 4.7.3 PIPEDA

This summary is informational only and not legal advice.

Pro · AI

Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.

Pro
Coverage — 13 of 14 jurisdictions searchable

Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.

Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).

Coming soon: Nunavut — being re-processed for AI search.

Find decisions like this one — by meaning, not keywords.

Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.

Upgrade to Pro