BreachOfPrivacy

Canadian Privacy Decisions

The comprehensive archive of Canadian privacy decisions from federal, provincial, and territorial commissioners — with AI-summarized plain-language summaries for every decision.

1 decision matching
Federal (Canada)Personal Information Protection and Electronic Documents ActDiscontinued
Mar 25, 2026· Indexed May 6, 2026

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Nova Scotia Power

This compliance letter concerns a privacy breach at Nova Scotia Power that began around March 19, 2025. A malware attack allowed a threat actor to access and exfiltrate sensitive customer information, including names, contact details, financial information, and SINs, affecting approximately 375,000 current and 540,000 former customers. Nova Scotia Power has committed to specific actions, including deleting customer SINs and undergoing an external security assessment, to address the breach. Upon the Commissioner's satisfaction with these commitments, the investigation will be discontinued.

Quick View

Personal Information Protection and Electronic Documents ActDiscontinued

Compliance Letter to the Office of the Privacy Commissioner of Canada (“OPC”) By Nova Scotia Power

Mar 25, 2026
Adjudicator: Philippe Dufresne
Plain-Language Summary

This compliance letter concerns a privacy breach at Nova Scotia Power that began around March 19, 2025. A malware attack allowed a threat actor to access and exfiltrate sensitive customer information, including names, contact details, financial information, and SINs, affecting approximately 375,000 current and 540,000 former customers. Nova Scotia Power has committed to specific actions, including deleting customer SINs and undergoing an external security assessment, to address the breach. Upon the Commissioner's satisfaction with these commitments, the investigation will be discontinued.

Key Issues
  • Adequacy of security safeguards following a significant data breach.
  • Timeliness and method of notification to affected individuals.
  • Collection and retention of Social Insurance Numbers (SINs).
  • Breach response and remediation efforts.