
Environment and Climate Change Canada, 5820-01406
The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 25, 2022.
The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by May 25, 2022.

The Information Commissioner ordered Environment and Climate Change Canada to provide a response to the request by June 23, 2022.

The Office of the Privacy Commissioner of Canada (OPC) investigated a ransomware attack on a Canada Border Services Agency (CBSA) contractor that resulted in the compromise of licence plate image files. Malicious actors accessed and copied approximately 1.4 million CBSA licence plate images, with about 11,000 confirmed to have been posted on the Dark Web. The CBSA initially contended that licence plate information was not personal information and that its contract with the third-party contractor was adequate. However, the OPC determined that licence plate image files, when combined with metadata revealing border crossing time and location, constitute personal information under the Privacy Act. The investigation found that the CBSA's contract with the contractor lacked sufficient clauses for security safeguards and appropriate data retention. Consequently, the OPC found the complaint to be well-founded, concluding that the CBSA contravened the disclosure provisions of the Act. The CBSA accepted the OPC's recommendations to update its contracts with clear privacy clauses, ensure proper safeguards and retention limits, and verify compliance, leading to the complaint being resolved.

Subscribe to open Newfoundland and Labrador decisions.

Subscribe to open Newfoundland and Labrador decisions.

Subscribe to open British Columbia decisions.

The Information Commissioner ordered Communications Security Establishment Canada to provide a final response to the access request no later than July 24, 2022.

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Subscribe to open Northwest Territories decisions.

Subscribe to open Quebec decisions.

Subscribe to open Quebec decisions.

Subscribe to open Quebec decisions.

Subscribe to open Quebec decisions.

Subscribe to open Quebec decisions.

Subscribe to open Saskatchewan decisions.