Updated daily · 21,367 recordsSign in
The catalogue

Canadian privacy & access decisions

The comprehensive archive of federal, provincial, and territorial commissioner decisions — each with a plain-language summary.

1,563 decisions matching
British ColumbiaFreedom of Information and Protection of Privacy Act
British Columbia flag

F25-49 — BC OIPC order 2983

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
British ColumbiaFreedom of Information and Protection of Privacy Act
British Columbia flag

F25-50 — BC OIPC order 2984

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2025 QCCAI 186 — City of Salaberry-de-Valleyfield

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2025 QCCAI 204 — Ministère de l’Enseignement supérieur

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2025 QCCAI 244 — Hydro-Québec

Subscribe to open Quebec decisions.

Unlock this jurisdiction
SaskatchewanLocal Authority Freedom of Information and Protection of Privacy Act
Saskatchewan flag

Review Report 057-2025 — Village of Hawarden

Subscribe to open Saskatchewan decisions.

Unlock this jurisdiction
OntarioMunicipal Freedom of Information and Protection of Privacy Act
Ontario flag

Order MO-4670

Subscribe to open Ontario decisions.

Unlock this jurisdiction
OntarioPersonal Health Information Protection Act
Ontario flag

PHIPA DECISION 285 - 2025-06-20

Subscribe to open Ontario decisions.

Unlock this jurisdiction
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Federal (Canada) flag
Jun 20, 2025PIPEDA Findings #2025-001

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

23andMe Inc.

This joint investigation by the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) examined a significant data breach at 23andMe, which affected nearly 7 million customers globally. The investigation found that 23andMe failed to implement appropriate safeguards to protect sensitive personal information, including genetic data, from a credential stuffing attack. Furthermore, the company's notifications to both regulatory bodies and affected individuals were found to be inadequate in content and, in some cases, timeliness. Although contraventions were found, the issues were deemed resolved due to significant security improvements made by 23andMe.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner

Jun 20, 2025PIPEDA Findings #2025-001
Adjudicator: Philippe Dufresne
Plain-Language Summary

This joint investigation by the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) examined a significant data breach at 23andMe, which affected nearly 7 million customers globally. The investigation found that 23andMe failed to implement appropriate safeguards to protect sensitive personal information, including genetic data, from a credential stuffing attack. Furthermore, the company's notifications to both regulatory bodies and affected individuals were found to be inadequate in content and, in some cases, timeliness. Although contraventions were found, the issues were deemed resolved due to significant security improvements made by 23andMe.

Key Issues
  • Adequacy of safeguards to protect personal information, particularly genetic data, from credential stuffing attacks.
  • Timeliness and completeness of breach notifications to regulators and affected individuals.
  • Risk of harm to individuals due to the sensitive nature of compromised personal information.
  • 23andMe's assessment of and response to the identified security deficiencies.
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2025 QCCAI 179 — Ville de Montréal (SPVM) and Dynamique Humaine Inc.

Subscribe to open Quebec decisions.

Unlock this jurisdiction
QuebecAct respecting access to documents held by public bodies and the protection of personal information
Quebec flag

2025 QCCAI 185 — Retraite Québec and Gestion Isabelle Parent inc.

Subscribe to open Quebec decisions.

Unlock this jurisdiction
British ColumbiaFreedom of Information and Protection of Privacy Act
British Columbia flag

F25-48 — BC OIPC order 2977

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
British ColumbiaFreedom of Information and Protection of Privacy Act
British Columbia flag

F25-47 — BC OIPC order 2976

Subscribe to open British Columbia decisions.

Unlock this jurisdiction
OntarioMunicipal Freedom of Information and Protection of Privacy Act
Ontario flag

Order MO-4668

Subscribe to open Ontario decisions.

Unlock this jurisdiction
OntarioMunicipal Freedom of Information and Protection of Privacy Act
Ontario flag

Order MO-4669

Subscribe to open Ontario decisions.

Unlock this jurisdiction