BreachOfPrivacy

Canadian Privacy Decisions

The comprehensive archive of Canadian privacy decisions from federal, provincial, and territorial commissioners — with AI-summarized plain-language summaries for every decision.

950 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & resolved
Jan 8, 2018PIPEDA Report of Findings #2018-001· Indexed Apr 12, 2026

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

VTech Holdings Limited

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint following a global data breach at VTech Holdings Limited, which potentially compromised the personal information of over 316,000 Canadian children and 237,000 Canadian adults. The investigation found significant deficiencies in VTech's information security safeguards, including a lack of testing, inadequate access controls, cryptographic issues, and absence of security monitoring. Although VTech contravened PIPEDA Principle 4.7, the OPC concluded the matter was resolved because VTech implemented timely and comprehensive measures to address the breach and improve its security.

Quick View

Personal Information Protection and Electronic Documents ActWell-founded & resolved

PIPEDA Report of Findings #2018-001: Connected toy manufacturer improves safeguards to adequately protect children’s information

Jan 8, 2018PIPEDA Report of Findings #2018-001
Adjudicator: Daniel Therrien
Plain-Language Summary

The Office of the Privacy Commissioner of Canada (OPC) investigated a complaint following a global data breach at VTech Holdings Limited, which potentially compromised the personal information of over 316,000 Canadian children and 237,000 Canadian adults. The investigation found significant deficiencies in VTech's information security safeguards, including a lack of testing, inadequate access controls, cryptographic issues, and absence of security monitoring. Although VTech contravened PIPEDA Principle 4.7, the OPC concluded the matter was resolved because VTech implemented timely and comprehensive measures to address the breach and improve its security.

Key Issues
  • Adequacy of information security safeguards for children's data
  • Failure to test for and mitigate known vulnerabilities
  • Insufficient access controls and cryptographic protection
  • Lack of comprehensive security management program
Quebec
Subscribers only
Act respecting health and social services information

2018 QCCAI 1 — Centre intégré universitaire de santé et de services sociaux de la Mauricie-et-du-Centre-du-Québec

Subscribe to access Quebec decisions.

Flag of Prince Edward Island
Prince Edward Island
Subscribers only
Freedom of Information and Protection of Privacy Act

FI-18-001 — Public Schools Branch

Subscribe to access Prince Edward Island decisions.

Flag of Ontario
Ontario
Subscribers only
Municipal Freedom of Information and Protection of Privacy Act

Order MO-3548

Subscribe to access Ontario decisions.

Flag of Saskatchewan
Saskatchewan
Subscribers only
Local Authority Freedom of Information and Protection of Privacy Act

REVIEW REPORT 210-2017 — City of Saskatoon

Subscribe to access Saskatchewan decisions.