Condita Research

Canadian Privacy Decisions

The comprehensive archive of Canadian privacy decisions from federal, provincial, and territorial commissioners — with AI-summarized plain-language summaries for every decision.

1,016 decisions matching
Flag of British Columbia
British Columbia
Subscribers only
Freedom of Information and Protection of Privacy Act

F17-20 — BC OIPC order 1937

Subscribe to access British Columbia decisions.

Flag of British Columbia
British Columbia
Subscribers only
Freedom of Information and Protection of Privacy Act

F17-19 — BC OIPC order 1936

Subscribe to access British Columbia decisions.

Flag of Ontario
Ontario
Subscribers only
Freedom of Information and Protection of Privacy Act

Order PO-3723

Subscribe to access Ontario decisions.

Flag of Ontario
Ontario
Subscribers only
Municipal Freedom of Information and Protection of Privacy Act

Order MO-3429

Subscribe to access Ontario decisions.

Federal (Canada)Personal Information Protection and Electronic Documents ActResolved
Apr 26, 2017Incident case summary #2017-001· Indexed Apr 12, 2026

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Office of the Privacy Commissioner of Canada

This report details three incidents in 2017 where Canadian organizations experienced data breaches due to password reuse by their customers. In each case, attackers used login credentials obtained from unrelated breaches to access customer accounts. The Office of the Privacy Commissioner of Canada found the organizations' responses to be appropriate, including actions like password resets, enhanced security measures, and customer notifications, and encouraged other organizations to adopt similar preventative strategies.

Quick View

Personal Information Protection and Electronic Documents ActResolved

Incident case summary #2017-001: Multiple breach incidents as a result of password reuse

Apr 26, 2017Incident case summary #2017-001
Adjudicator: Daniel Therrien
Plain-Language Summary

This report details three incidents in 2017 where Canadian organizations experienced data breaches due to password reuse by their customers. In each case, attackers used login credentials obtained from unrelated breaches to access customer accounts. The Office of the Privacy Commissioner of Canada found the organizations' responses to be appropriate, including actions like password resets, enhanced security measures, and customer notifications, and encouraged other organizations to adopt similar preventative strategies.

Key Issues
  • Impact of password reuse on personal information security
  • Adequacy of organizational responses to data breaches
  • Effectiveness of safeguards against unauthorized access
  • Communication and notification obligations to individuals
Flag of Newfoundland and Labrador
Newfoundland and Labrador
Subscribers only
Access to Information and Protection of Privacy Act, 2015

A-2017-011 — Royal Newfoundland Constabulary

Subscribe to access Newfoundland and Labrador decisions.

Flag of Prince Edward Island
Prince Edward Island
Subscribers only
Freedom of Information and Protection of Privacy Act

FI-17-006 — Department of Family and Human Services

Subscribe to access Prince Edward Island decisions.

Flag of Ontario
Ontario
Subscribers only
Personal Health Information Protection Act

PHIPA DECISION 44

Subscribe to access Ontario decisions.

Flag of Saskatchewan
Saskatchewan
Subscribers only
Local Authority Freedom of Information and Protection of Privacy Act

Review Report 014-2017 — Town of Kindersley

Subscribe to access Saskatchewan decisions.

Flag of Saskatchewan
Saskatchewan
Subscribers only
Local Authority Freedom of Information and Protection of Privacy Act

Review Report 011-2017 — Town of Kindersley

Subscribe to access Saskatchewan decisions.

Flag of Saskatchewan
Saskatchewan
Subscribers only
Local Authority Freedom of Information and Protection of Privacy Act

Review Report 010-2017 — Town of Kindersley

Subscribe to access Saskatchewan decisions.

Flag of Saskatchewan
Saskatchewan
Subscribers only
Local Authority Freedom of Information and Protection of Privacy Act

Review Report 012-2017 — Town of Kindersley

Subscribe to access Saskatchewan decisions.

Flag of Saskatchewan
Saskatchewan
Subscribers only
Local Authority Freedom of Information and Protection of Privacy Act

Review Report 013-2017 — Town of Kindersley

Subscribe to access Saskatchewan decisions.

Flag of Alberta
Alberta
Subscribers only
Freedom of Information and Protection of Privacy Act

F2017-41 — Treasury Board and Finance

Subscribe to access Alberta decisions.

Flag of Ontario
Ontario
Subscribers only
Municipal Freedom of Information and Protection of Privacy Act

Order MO-3428

Subscribe to access Ontario decisions.