
PIPEDA Findings #2020-005: Investigation into Desjardins’ compliance with PIPEDA following a breach of personal information between 2017 and 2019
The Office of the Privacy Commissioner of Canada (OPC) investigated a major data breach at Desjardins that affected close to 9.7 million individuals in Canada and abroad between 2017 and 2019. The breach was caused by a malicious employee who exfiltrated sensitive personal information, including names, dates of birth, social insurance numbers, and transaction histories. The OPC found that Desjardins contravened PIPEDA's principles regarding accountability, retention periods, and security safeguards. Specifically, Desjardins had inadequate organizational policies and procedures, critical gaps in employee training and awareness, ineffective access controls and data segregation, and insufficient oversight and monitoring. Additionally, Desjardins failed to handle personal information in accordance with retention and destruction requirements, retaining some inactive files for decades. While the complaints were found to be well-founded, Desjardins' mitigation measures offered to affected individuals were deemed adequate. Desjardins committed to implementing the OPC's recommendations to address the identified weaknesses.
Ontario
British Columbia
Alberta
Saskatchewan
Manitoba
Quebec
Nova Scotia
New Brunswick
Prince Edward Island
Newfoundland and Labrador
Yukon
Northwest Territories
Nunavut