Canada’s Privacy Watchdog Seeks Answers Over Major Driver’s Licence Data Exposure
- By Tahani Elghazaly
- Published
Canada’s Office of the Privacy Commissioner is seeking more information about a major cyber incident that may have exposed driver’s licence and identity-document data belonging to Canadians and Americans. The office says it is engaging with the company involved to obtain more information, assess its obligations under Canada’s federal private-sector privacy law, PIPEDA, and determine next steps.
The move follows reports that a dark-web marketplace was offering access to a vast collection of digital driver’s licences and other identity documents from Canada and the United States. The reported dataset has been estimated at roughly 153 million identity records, but Canadian authorities have not confirmed that figure or established how many Canadians may be affected.
A search of the reported database for Canadian driver’s licences returned approximately 1.1 million results, according to reporting on the incident. That figure has not been independently verified by Canadian authorities, and federal and provincial agencies have not released an official national tally.
The FBI has confirmed that it is looking into the incident, while the RCMP says it is monitoring the situation and remains in contact with domestic and international law-enforcement and cybersecurity partners. Canadian authorities have not publicly confirmed the source of all the identity records involved.
Reports have linked the incident to U.S.-based identity-verification company IDScan.net. The company said it became aware around September 1 of data that may have been accessed without authorization and later determined that an unauthorized third party may have accessed or copied certain customer information stored in accounts on its cloud platform.
The potential exposure is particularly sensitive because driver’s licences can contain a person’s name, address, photograph, date of birth, gender, signature and unique licence number. Canada’s privacy commissioner has previously warned that the combination of personal information and the credibility of a government-issued document makes driver’s licences valuable to identity thieves.
Under PIPEDA, organizations must report breaches of security safeguards to the Privacy Commissioner when there are reasonable grounds to believe the incident creates a real risk of significant harm. Such harm can include identity theft, financial loss and damage to a person’s credit record.
The Privacy Commissioner’s office has not publicly announced a formal investigation at this stage, but says it is gathering information from the company and assessing what further action may be required.
You May Also Like
Authors
-
Tahani Elghazaly5002 Posts
Popular Posts
Newsletter
Subscribe to our mailing list to get the new updates!