Canada Opens PIPEDA Investigation Into IDScan.net Breach

Independently fact-checkedBy Recording Law Editorial Team21 min read

Independently fact-checked against primary sources (last audited September 24, 2026). · 7 primary sources cited on this page. How we verify our legal content

Canada Opens PIPEDA Investigation Into IDScan.net Breach

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. Office of the Privacy Commissioner of Canada, news release, 'Privacy Commissioner of Canada Launches Investigation Into Data Breach Involving Stolen Identification Details' (September 21, 2026)(priv.gc.ca).gov
  2. Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, s. 10.1 (breach reporting, individual notification, definition of significant harm and real-risk factors), current to 2026-09-03(laws-lois.justice.gc.ca).gov
  3. PIPEDA, Schedule 1, cl. 4.1.3 (accountability for information transferred to a processor) and cl. 4.7 to 4.7.5 (Principle 7, Safeguards), current to 2026-09-03(laws-lois.justice.gc.ca).gov
  4. Breach of Security Safeguards Regulations, SOR/2018-64, ss. 2 to 6 (report contents, notification contents, direct and indirect notification, 24-month record retention), current to 2026-09-03(laws-lois.justice.gc.ca).gov
  5. PIPEDA ss. 10.2, 10.3, 11, 12, 12.1, 13 and 14 (records, Commissioner-initiated complaints, investigative powers, report of findings within one year, Federal Court hearing), current to 2026-09-03(laws-lois.justice.gc.ca).gov
  6. PIPEDA s. 17.1 (compliance agreements), current to 2026-09-03(laws-lois.justice.gc.ca).gov
  7. Office of the Privacy Commissioner of Canada, 'What you need to know about mandatory reporting of breaches of security safeguards' (guidance on control, processors, fines and referral to the Attorney General of Canada)(priv.gc.ca).gov
Share: