DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Ca: Federal Privacy Commissioner’s Office loses backup drive with personal information

Posted on April 24, 2014 by Dissent

Ouch.

Howard Solomon reports:

Mistakes can happen in any organization, but when the office of the federal privacy commissioner loses an unencrypted hard drive with personal information it must sting.

But that’s what happened on Feb 14 during the agency’s move to Gatineau, Que. from its home across the river in Ottawa.

The Toronto Star revealed the loss in the print edition of the paper this morning, and it was confirmed in an ITWorldCanada.com interview with interim commissioner Chantal Bernier.

Read more on ITWorldCanada.com.

On April 17,  Ms. Bernier sent a letter to John Sims, Privacy Commissioner, Ad Hoc, informing him of the loss. The letter, a copy of which was provided to DataBreaches.net by the Privacy Commissioner’s Office, says that they believe that the backup drive was lost during the move of headquarters from Kent Street in Ottawa to Victoria in Gatineau on February 14, and

On April 9, 2014, staff became aware that the drive contained a backup of the Performance Budgeting for Human Capital (PBHC) system, dating back to 2002; our Office shares the system with the Office of the Information Commissioner of Canada. This is the financial system used to manage and forecast employee salaries and it houses the personal information of employees. Specifically, it includes name, salaries, personal record identifiers (employee numbers) and payment descriptions (e.g., acting pay, arrears, and lump sums). Additionally, information which would normally be reflected on an organization chart, such as classification and position numbers, was also present on the drive.

Approximately 800 current and former employees of both their Office and the OIC are potentially affected by the incident.

Although the data were not encrypted. they were in a format that “would render it difficult to retrieve by anyone without technical expertise.”

In an update of April 22, the Office notes that the drive, a LaCie drive with no label on it indicating its purpose, was discovered missing in mid-March. The drive had been attached to one of the servers:

The drive had been used in the reconstruction of a server. It remained attached to the server infrastructure after the reconstruction of the server was complete. It was located in our secure data centre at 112 Kent. 

Later in the summer of 2013, the drive was used to back up our Performance Budgeting for Human Capital system. As it was connected to the server, it did not appear to be an external drive when saving the data to the system.

The Office candidly acknowledged that data had been retained for too long. In an FAQ on the breach including in the April 22 update, they write:

This information dates back to 2002 – should you have been keeping it that long?
No. The retention period for this information is seven years. It should not have been kept for so long. This is one of the issues we are examining.

Both external and internal reviews are ongoing at this time, and current and former employees are in the process of being notified.

Category: Government SectorLost or MissingNon-U.S.

Post navigation

← Port Jefferson Union Free School District IT assets not adequately secured – audit
D.C. physicians swept up in tax ID theft scam →

3 thoughts on “Ca: Federal Privacy Commissioner’s Office loses backup drive with personal information”

  1. Damon Greer says:
    April 24, 2014 at 4:29 pm

    The adage, “people in glass houses shouldn’t throw stones” is relevant here. The OPC should have its own house in order before enforcing privacy rules on others. Set the example.

    1. Dissent says:
      April 24, 2014 at 5:02 pm

      Yep, but if you look at how transparent they’re being about what happened, and what kind of info was involved, etc., I think they’re setting a good example on that. Should it have taken 3+ weeks to figure out that PII was on the drive? Probably not, but I’ve seen a lot worse.

  2. J says:
    April 29, 2014 at 9:51 pm

    Inform customers of data breach or pay $100,000 per case: new privacy bill
    http://www.itbusiness.ca/news/businesses-could-face-fines-of-100000-per-individual-digital-privacy-act/47931
    Businesses and organizations will be formally required to tell individual customers and the Privacy Commissioner of Canada if they’ve suffered a data breach – or pay up to $100,000 in fines for every individual not told, according to the new Digital Privacy Act, or Bill S-4, tabled in the Senate today.

    Released today, the act was touted as an update to the Personal Information Protection and Electronic Documents Act. It requires organizations to tell individuals if they’ve lost any personal information, and if they could be targeted for risks like identity theft. They will also have to give individuals advice on next steps in protecting themselves, and they will have to inform the federal privacy commissioner about the data breach.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines
  • Call for Public Input: Essential Cybersecurity Protections for K-12 Schools (2025-26 SY)
  • Cyberattack puts healthcare on hold for hundreds in St. Louis metro
  • Europol: DDoS-for-hire empire brought down: Poland arrests 4 administrators, US seizes 9 domains

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants
  • DOGE aims to pool federal data, putting personal information at risk
  • Privacy concerns swirl around HHS plan to build Medicare, Medicaid database on autism

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.