
Investigation into a privacy breach at a Canada Border Services Agency contractor
The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.
- 1Whether licence plate image files, including associated metadata (jurisdiction, characters, date, time, border crossing site, lane number), constitute personal information under Section 3 of the Privacy Act.
- 2Whether the unauthorized access and disclosure of these licence plate image files constituted an improper disclosure under Section 8 of the Privacy Act.
- 3Whether the Canada Border Services Agency (CBSA) had adequate security safeguards in place, particularly in its contractual arrangements with a third-party contractor, to protect personal information.
- 4Whether the data retention practices for licence plate image files by the CBSA and its contractor were appropriate and compliant with the Privacy Act.
- Personal information definition: Licence plate data deemed personal information
- Contractual safeguards: Contract lacked sufficient security and retention clauses
- Disclosure contravention: CBSA contravened disclosure provisions
- Recommendations: CBSA accepted OPC recommendations
- Complaint outcome: Complaint found well-founded and resolved
Complaint well-founded and resolved
The CBSA contravened the disclosure provisions of the Privacy Act due to inadequate safeguards and retention clauses in its contract with the third-party contractor, leading to unauthorized access and disclosure of personal information. The complaint was resolved because the CBSA accepted and committed to implementing the OPC's recommendations.
The OPC recommended that the CBSA fully review and update its contracts with the contractor to include clear language that licence plate image files constitute personal information, incorporate appropriate safeguards for storage, use, access, and destruction, seek guarantees of data destruction, and demonstrate compliance through an audit. The CBSA adopted these recommendations.
- s.3 Privacy Act
- s.8(1) Privacy Act
- s.8(2) Privacy Act
- s.29(3) Privacy Act
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro