Condita Research

Canadian Privacy Decisions

The comprehensive archive of Canadian privacy decisions from federal, provincial, and territorial commissioners — with AI-summarized plain-language summaries for every decision.

1,266 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
May 19, 2022PIPEDA Findings #2022-004· Indexed Apr 12, 2026

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

MGM Resorts International

This investigation concerned MGM Resorts International's handling of a 2019 data breach that affected millions of guests, including nearly two million Canadians. The OPC initiated a complaint after media reports indicated a breach and MGM had not reported it. The investigation found that MGM failed to promptly assess the risk of significant harm (RROSH) posed by the breach and did not report it to the OPC or notify affected Canadians as soon as feasible. MGM has committed to updating its privacy breach response framework to ensure timely RROSH assessments and reporting.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

May 19, 2022PIPEDA Findings #2022-004
Adjudicator: Daniel Therrien
Plain-Language Summary

This investigation concerned MGM Resorts International's handling of a 2019 data breach that affected millions of guests, including nearly two million Canadians. The OPC initiated a complaint after media reports indicated a breach and MGM had not reported it. The investigation found that MGM failed to promptly assess the risk of significant harm (RROSH) posed by the breach and did not report it to the OPC or notify affected Canadians as soon as feasible. MGM has committed to updating its privacy breach response framework to ensure timely RROSH assessments and reporting.

Key Issues
  • Whether the personal information involved in the breach posed a real risk of significant harm (RROSH) to affected Canadians.
  • Whether MGM adequately assessed the RROSH.
  • Whether MGM reported the breach to the OPC and notified affected Canadians as soon as feasible.
  • Whether MGM's delay in assessing the breach and notifying Canadians contravened PIPEDA's mandatory breach reporting obligations.
Quebec
Subscribers only
Act respecting the protection of personal information in the private sector

2022 QCCAI 145 — Trans Union of Canada Inc.

Subscribe to access Quebec decisions.

Quebec
Subscribers only
Act respecting the protection of personal information in the private sector

2022 QCCAI 146 — Équifax Canada Co.

Subscribe to access Quebec decisions.

Quebec
Subscribers only
Act respecting the protection of personal information in the private sector

2022 QCCAI 147 — Trans Union of Canada Inc.

Subscribe to access Quebec decisions.

Quebec
Subscribers only
Act respecting the protection of personal information in the private sector

2022 QCCAI 152 — Laurentian Bank of Canada

Subscribe to access Quebec decisions.

Quebec
Subscribers only
Act respecting access to documents held by public bodies and the protection of personal information

2022 QCCAI 166 — Ministère de la Sécurité publique (Sûreté du Québec)

Subscribe to access Quebec decisions.

Flag of Saskatchewan
Saskatchewan
Subscribers only
Local Authority Freedom of Information and Protection of Privacy Act

Review Report 359-2021 — Village of Neudorf

Subscribe to access Saskatchewan decisions.

Flag of Saskatchewan
Saskatchewan
Subscribers only
Local Authority Freedom of Information and Protection of Privacy Act

Review Report 361-2021 — Village of Neudorf

Subscribe to access Saskatchewan decisions.

Flag of British Columbia
British Columbia
Subscribers only
Freedom of Information and Protection of Privacy Act

F22-24 — BC OIPC order 2522

Subscribe to access British Columbia decisions.

Flag of Ontario
Ontario
Subscribers only
Municipal Freedom of Information and Protection of Privacy Act

Order MO-4200-I

Subscribe to access Ontario decisions.

Quebec
Subscribers only
Act respecting access to documents held by public bodies and the protection of personal information

2022 QCCAI 138 — Municipalité de St-Dominique

Subscribe to access Quebec decisions.

Flag of Nova Scotia
Nova Scotia
Subscribers only
Municipal Government Act — Part XX (Information Access and Protection of Privacy)

22-11 — Halifax Regional Police

Subscribe to access Nova Scotia decisions.

Flag of Ontario
Ontario
Subscribers only
Municipal Freedom of Information and Protection of Privacy Act

Order MO-4199

Subscribe to access Ontario decisions.

Quebec
Subscribers only
Act respecting access to documents held by public bodies and the protection of personal information

2022 QCCAI 123 — Revenu Québec

Subscribe to access Quebec decisions.

Quebec
Subscribers only
Act respecting access to documents held by public bodies and the protection of personal information

2022 QCCAI 127 — CIUSSS du Centre-Sud-de-l'Île-de-Montréal and CISSS de Laval

Subscribe to access Quebec decisions.