Canada Opens PIPEDA Investigation Into IDScan.net Breach
Independently fact-checked against primary sources (last audited September 24, 2026). · 7 primary sources cited on this page. How we verify our legal content

Canada's Privacy Commissioner opened a formal investigation into ID-verification vendor IDScan.net on September 21, 2026, after reports that an unauthorized third party stole digital driver's licence scans. The probe tests compliance with PIPEDA's safeguards and breach-notification duties. No findings have been made.
Information last verified on September 24, 2026. This is a developing story; we update it as the record changes.
Status: The OPC opened its investigation on September 21, 2026. No findings have been made and no finding of non-compliance has been issued as of September 24, 2026.
Jurisdiction scope: This article covers Canadian federal law. The investigation is being run by the Office of the Privacy Commissioner of Canada under the Personal Information Protection and Electronic Documents Act, the federal private-sector privacy statute. It does not address provincial private-sector privacy statutes, and it does not address any United States federal or state law.
What Happened
The Office of the Privacy Commissioner of Canada (OPC) published a news release from Gatineau, Quebec on September 21, 2026 announcing that Privacy Commissioner Philippe Dufresne "has opened an investigation into a data breach at IDScan.net following reports that an unauthorized third party gained access to the company database and stole personal information, including digital scans of driver's licences and other types of identification (ID)."
The release describes the company's role in plain terms: "IDScan.net's technology is used by businesses such as hospitality and nightlife establishments, among others, to verify customers' government-issued identification."
The scope of the file is set out in a single sentence, and it is worth reading closely because it defines the two questions on the table:
The investigation will examine the security safeguards that IDScan.net had in place at the time of the breach, as well as the adequacy of its notifications to affected individuals, to determine its compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law.
The OPC added that IDScan.net "issued a public advisory about the incident earlier this month," and that since then the office "has been actively engaging with IDScan.net, and will continue to do so, to ensure that the organization is taking the necessary steps to address the incident and mitigate any risks to Canadians." The release closes by stating that "As the matter involves an active investigation, the OPC is not in a position to provide further details at this time."
What the release does not say
The OPC's announcement does not give a date or a date range for the breach. It does not quantify how many people were affected. It does not say whether IDScan.net filed a breach report with the Commissioner, and it does not state any conclusion about the company's conduct.
Those omissions are not incidental. The day or period of the breach and the number of individuals affected are two of the seven items an organization must put in its own breach report to the Commissioner under section 2(1) of the Breach of Security Safeguards Regulations. Until the OPC publishes findings, the Canadian public record on this file consists of the September 21 release plus whatever the company itself has chosen to disclose.
What the Law Actually Says
The safeguards standard (Canada, federal)
PIPEDA's security obligation is Principle 7 in Schedule 1 of the Act, clause 4.7, and it is stated in one line: "Personal information shall be protected by security safeguards appropriate to the sensitivity of the information." (PIPEDA, S.C. 2000, c. 5, Schedule 1, cl. 4.7; Canada, federal.)
The sub-clauses define the shape of that duty. Clause 4.7.1 requires that the safeguards "protect personal information against loss or theft, as well as unauthorized access, disclosure, copying, use, or modification," and adds that "Organizations shall protect personal information regardless of the format in which it is held." Clause 4.7.2 makes the standard proportionate rather than fixed: the nature of the safeguards varies with "the sensitivity of the information that has been collected, the amount, distribution, and format of the information, and the method of storage," and "More sensitive information should be safeguarded by a higher level of protection." Clause 4.7.3 lists the categories of protection, including technological measures, "for example, the use of passwords and encryption."
There is no prescribed control list in the statute. That is why a safeguards investigation is fact-specific: the question is not whether a named technology was deployed but whether what was deployed was appropriate to the sensitivity of what was held.
Reporting a breach to the Commissioner (Canada, federal)
Section 10.1(1) sets the trigger: "An organization shall report to the Commissioner any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual." The report must be in the prescribed form "as soon as feasible after the organization determines that the breach has occurred" (s. 10.1(2)).
Section 10.1(7) defines the threshold term. Significant harm "includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record and damage to or loss of property." Section 10.1(8) lists the factors relevant to whether the risk is real: the sensitivity of the information involved, the probability that it "has been, is being or will be misused," and any other prescribed factor.
Section 2(1) of the Breach of Security Safeguards Regulations, SOR/2018-64, prescribes the contents of the report to the Commissioner: the circumstances and, if known, the cause; the day or period of the breach; a description of the personal information involved; the number of individuals affected; the steps taken to reduce or mitigate the risk of harm; the steps taken or planned to notify affected individuals; and a contact person who can answer the Commissioner's questions.
Notifying the individuals (Canada, federal)
The notification duty in section 10.1(3) runs on the same real-risk-of-significant-harm trigger, and it is owed to the individual: "Unless otherwise prohibited by law, an organization shall notify an individual of any breach of security safeguards involving the individual's personal information under the organization's control" where that threshold is met.
Section 10.1(4) sets the quality of the notice. It "shall contain sufficient information to allow the individual to understand the significance to them of the breach and to take steps, if any are possible, to reduce the risk of harm that could result from it or to mitigate that harm." Section 10.1(5) adds that the notification "shall be conspicuous," and section 10.1(6) requires it "as soon as feasible after the organization determines that the breach has occurred."
Section 3 of SOR/2018-64 fills in the mandatory contents: the circumstances of the breach; the day or period it occurred; a description of the personal information involved; the steps the organization has taken to reduce the risk of harm; "a description of the steps that affected individuals could take to reduce the risk of harm that could result from the breach or to mitigate that harm"; and contact information for further details. Section 4 permits direct notification "in person, by telephone, mail, email or any other form of communication that a reasonable person would consider appropriate in the circumstances." Section 5 requires indirect notification, by public communication or a similar measure that could reasonably be expected to reach the affected individuals, where direct notice would likely cause further harm to the individual or undue hardship to the organization, or where the organization does not have contact information for the individual.
That structure is the reason the OPC's second question (the adequacy of notifications) is a free-standing compliance issue. An organization can be found to have notified late, incompletely, or through the wrong channel regardless of how the safeguards question resolves.
Records (Canada, federal)
Section 10.3(1) requires an organization to keep a record of every breach of security safeguards involving personal information under its control, and section 10.3(2) requires it to give the Commissioner access to or a copy of that record on request. Section 6(1) of SOR/2018-64 fixes the retention period at 24 months after the day the organization determines the breach occurred, and section 6(2) requires the record to contain any information enabling the Commissioner to verify compliance with the reporting and notification duties. Note the scope difference: the report and notification duties apply only above the real-risk threshold, but the record-keeping duty applies to every breach.
Who owes the duty when the breached company is a vendor
IDScan.net's customers are venues that scan patrons' ID. That raises the question of who is the organization "in control" of the information for PIPEDA purposes. The OPC's breach-reporting guidance addresses it directly. The guidance states that where a principal organization has transferred personal information to a third party for processing, "we find it reasonable to interpret the principal organization as having control of the personal information and therefore responsibility for breach reporting in respect of a breach that occurs with the third party processor," and that the principal "will need to ensure there are sufficient contractual arrangements in place with the processor."
Crucially, that does not empty the processor's own obligations. The same guidance states that "an organization that processes personal information on behalf of another organization still has obligations under the Act in respect of the personal information in its possession or custody, as an organization that collects, uses or discloses personal information in the course of commercial activities." The guidance also stresses that control "needs to be assessed on a case-by-case basis."
The backstop is Schedule 1, clause 4.1.3, which provides that an organization "is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing," and "shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party." Our explainer on how PIPEDA works walks through the ten Schedule 1 principles in more detail.
What an OPC investigation actually produces
The Commissioner does not need a member of the public to complain. Section 11(2) provides that "If the Commissioner is satisfied that there are reasonable grounds to investigate a matter under this Part, the Commissioner may initiate a complaint in respect of the matter." Section 12.1(1) gives the Commissioner investigative powers that include summoning and compelling witnesses and the production of records "in the same manner and to the same extent as a superior court of record," administering oaths, and entering premises other than a dwelling-house.
The output is a report, not an order. Section 13(1) requires the Commissioner, "within one year after the day on which a complaint is filed or is initiated by the Commissioner," to prepare a report containing findings and recommendations, any settlement reached, if appropriate a request that the organization report back on action taken, and the recourse available under section 14. Section 13(3) requires the report to go to the parties without delay.
Enforcement then runs through two other channels. Section 14(1) lets a complainant apply to the Federal Court for a hearing on matters covered by the complaint or the report, including clause 4.7 (safeguards) and Division 1.1 (the breach provisions), within one year of the report under section 14(2). Section 17.1 lets the Commissioner enter into a compliance agreement with an organization on terms the Commissioner considers necessary, which suspends the Commissioner's own court applications on the covered matters but does not stop an individual's section 14 application or a prosecution.
On penalties, the OPC's guidance is explicit that knowingly contravening the breach reporting, notification and record-keeping requirements is an offence that could lead to fines, but that "The OPC does not prosecute offences under PIPEDA or issue fines." What it can do is refer information about a possible offence to the Attorney General of Canada. For the wider picture of how these pieces fit together, see our guide to Canada's data privacy framework.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
Two features of this file are worth flagging, and neither depends on guessing how it ends.
The first is the sensitivity dial built into clause 4.7.2. PIPEDA's safeguards standard is proportionate by design, so the legal question in a licence-scan case is not the same question as in a mailing-list case, even if the technical failure looks identical. An image of a government identity document carries a face, a name, a date of birth, an address and a document number in one object. Clause 4.7.2 directs that more sensitive information "should be safeguarded by a higher level of protection," and clause 4.7.1 extends the duty to information in any format. An investigation applying that text is measuring controls against the sensitivity of what was actually held, which is why an outcome here would say little about a case involving less sensitive records.
The second is that the OPC put two questions in its sentence, not one. The adequacy of notifications is governed by its own provisions: section 10.1(3) to (6) and sections 3 to 5 of SOR/2018-64, which prescribe the contents, the form and the narrow circumstances in which indirect public notice is permitted instead of direct notice. Those requirements do not read on whether the underlying safeguards were adequate. A regulator can reach different conclusions on the two limbs, and the OPC's phrasing keeps both live.
There is also a structural point that outlasts this particular company. The information at issue was collected by venues and handled by a vendor, and the OPC's own guidance treats accountability as something that does not transfer with the data: the principal organization is generally treated as being in control for reporting purposes, the processor retains obligations for information in its possession or custody, and clause 4.1.3 requires contractual or other means providing a comparable level of protection. Any business that has outsourced identity checks is looking at its own contracts this week, not just at the vendor's incident page.
Finally, on timing and remedy, section 13(1) gives an outer bound of one year from initiation for the Commissioner's report, and that report contains findings and recommendations rather than a penalty. We take no position on what the OPC will find. As of September 24, 2026 the office has stated only that it has opened the investigation and that it cannot provide further details while the matter is active.
How This Affects You
This section is general information about how the Canadian federal regime operates. It is not advice about any particular person's situation.
If you are told your identity document was involved. PIPEDA sets a floor for what a breach notice has to tell you. Under section 10.1(4) it must contain enough information for you to understand the significance of the breach to you and to take steps to reduce or mitigate the risk of harm, and section 3 of SOR/2018-64 requires it to describe the circumstances, the timing, the categories of information involved, what the organization has done, what you can do, and where to get more information. A notice that omits those elements is a gap you can raise with the organization or with the OPC. Section 10.1(7) is also worth knowing, because it puts identity theft and negative effects on the credit record inside the statutory definition of significant harm, which is the same concept the organization was supposed to assess before deciding whether to notify anyone at all.
One practical difference between identity-document exposure and password exposure is that a licence number is not something a person can rotate. Readers who want to understand the standard credit-file tools available in the United States can start with our comparison of freezing your credit file versus placing a fraud alert; Canadian credit bureaus operate their own separate processes.
If you run a business that scans ID. The obligations described above attach to organizations, not only to technology vendors. The record-keeping duty in section 10.3(1) and section 6(1) of SOR/2018-64 applies to every breach of security safeguards, not only reportable ones, and the record has to be good enough for the Commissioner to verify your reporting and notification decisions. Clause 4.1.3 puts the contractual obligation on you when you hand personal information to a processor. Whether you or your vendor carries the reporting duty in a given incident is, per the OPC's guidance, a case-by-case question about control.
If you are considering legal action. Section 14 gives a complainant a route to the Federal Court after the Commissioner's report or a notice of discontinuance, within the time limit in section 14(2). Whether that route is available to any individual, and whether it is worth using, depends on facts this article cannot assess. That is a question for a lawyer licensed in the relevant jurisdiction.
Disclaimer: This article is general legal information, not legal advice. It describes Canadian federal law under the Personal Information Protection and Electronic Documents Act and does not address provincial private-sector privacy statutes or any United States federal or state law. It does not create a solicitor-client relationship, and it does not describe the merits of any person's situation. The investigation discussed here is active and no findings have been made. Information was last verified against primary sources on September 24, 2026. For advice on your own circumstances, consult a lawyer licensed in your jurisdiction.
Related articles
- How PIPEDA works, principle by principle
- Our hub for Canadian privacy law
- Canada's data privacy framework in context
- Quebec's Law 25, explained
- Credit freezes compared with fraud alerts
Last updated: 2026-09-24. This is a developing story; details verified as of 2026-09-24.
Frequently Asked Questions
Has the OPC decided that IDScan.net broke Canadian privacy law?
No. As of September 24, 2026 the OPC has announced only that it opened an investigation on September 21, 2026. Under PIPEDA s. 13(1) the Commissioner's findings and recommendations come in a report prepared within one year after the complaint is filed or initiated, and no such report has been issued on this matter. The OPC's release states that because the matter involves an active investigation, the office is not in a position to provide further details.
What specifically is the OPC investigating?
Two things, in the OPC's own words: the security safeguards that IDScan.net had in place at the time of the breach, and the adequacy of its notifications to affected individuals, in order to determine compliance with PIPEDA. The first engages Schedule 1, clause 4.7 of the Act; the second engages s. 10.1(3) to (6) and ss. 3 to 5 of the Breach of Security Safeguards Regulations, SOR/2018-64.
What is PIPEDA?
The Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, is Canada's federal private-sector privacy law. It governs how organizations collect, use and disclose personal information in the course of commercial activity, and Schedule 1 sets out ten principles, including Principle 7 on safeguards. Division 1.1 of Part 1 (ss. 10.1 to 10.3) contains the mandatory breach reporting, notification and record-keeping duties that came into force on November 1, 2018.
Can the Privacy Commissioner fine a company under PIPEDA?
No. The OPC's breach-reporting guidance states plainly that the OPC does not prosecute offences under PIPEDA or issue fines. Knowingly contravening the breach reporting, notification and record-keeping requirements is an offence that can lead to fines, but the OPC's role is to refer information about a possible offence to the Attorney General of Canada, which could lead to a prosecution by the Director of Public Prosecutions. Separately, s. 17.1 allows the Commissioner to enter into a compliance agreement with an organization.
How long does an OPC investigation take?
PIPEDA s. 13(1) requires the Commissioner to prepare the report of findings and recommendations within one year after the day the complaint is filed or is initiated by the Commissioner. That is the statutory outer bound for the report, not a prediction about this file. An investigation can also be discontinued under s. 12.2, in which case the complainant is notified and given reasons.
When does a company have to tell me my data was breached?
Under PIPEDA s. 10.1(3), an organization must notify an individual of a breach involving that individual's personal information under the organization's control where it is reasonable in the circumstances to believe the breach creates a real risk of significant harm to that individual, unless otherwise prohibited by law. Section 10.1(6) requires notification as soon as feasible after the organization determines that the breach occurred, and s. 10.1(5) requires it to be conspicuous.
What counts as a real risk of significant harm?
Section 10.1(7) of PIPEDA says significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record and damage to or loss of property. Section 10.1(8) says the factors relevant to whether the risk is real include the sensitivity of the personal information involved and the probability that the information has been, is being or will be misused.
If a vendor is breached, is my bar or my vendor responsible for reporting it?
The duty in s. 10.1(1) attaches to the organization that has the personal information under its control. The OPC's guidance interprets the principal organization as generally having control, and therefore the reporting responsibility, where it transferred the information to a third party for processing, while stressing that control is assessed case by case. The processor is not off the hook: the guidance says a processor still has obligations under the Act for information in its possession or custody, and Schedule 1, cl. 4.1.3 requires the principal to use contractual or other means to provide a comparable level of protection.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Office of the Privacy Commissioner of Canada, news release, 'Privacy Commissioner of Canada Launches Investigation Into Data Breach Involving Stolen Identification Details' (September 21, 2026)(priv.gc.ca).gov
- Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, s. 10.1 (breach reporting, individual notification, definition of significant harm and real-risk factors), current to 2026-09-03(laws-lois.justice.gc.ca).gov
- PIPEDA, Schedule 1, cl. 4.1.3 (accountability for information transferred to a processor) and cl. 4.7 to 4.7.5 (Principle 7, Safeguards), current to 2026-09-03(laws-lois.justice.gc.ca).gov
- Breach of Security Safeguards Regulations, SOR/2018-64, ss. 2 to 6 (report contents, notification contents, direct and indirect notification, 24-month record retention), current to 2026-09-03(laws-lois.justice.gc.ca).gov
- PIPEDA ss. 10.2, 10.3, 11, 12, 12.1, 13 and 14 (records, Commissioner-initiated complaints, investigative powers, report of findings within one year, Federal Court hearing), current to 2026-09-03(laws-lois.justice.gc.ca).gov
- PIPEDA s. 17.1 (compliance agreements), current to 2026-09-03(laws-lois.justice.gc.ca).gov
- Office of the Privacy Commissioner of Canada, 'What you need to know about mandatory reporting of breaches of security safeguards' (guidance on control, processors, fines and referral to the Attorney General of Canada)(priv.gc.ca).gov