Accessibility Statement Skip Navigation
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • Data Privacy
  • Français
  • my CNW 
    • Login
    • Register
  • Client Login 
    • Online Member Centre
    • Next Gen Communications Cloud
    • Cision Communications Cloud®
  • Sign Up
  • Send a Release
Return to PR Newswire homepage
  • News
  • Products
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
Advanced Search
  • News in Focus
      • Browse News Releases

      • All News Releases
      • All Public Company
      • News Releases Overview

      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
      • Multimedia Gallery Overview

      • Trending Topics

      • All Trending Topics
  • Business
      • Auto & Transportation

      • All Automotive & Transportation
      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • Auto & Transportation Overview

      • View All Auto & Transportation

      • Business Technology

      • All Business Technology
      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • Business Technology Overview

      • View All Business Technology

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Financial Services & Investing

      • All Financial Services & Investing
      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • Financial Services & Investing Overview

      • View All Financial Services & Investing

      • General Business

      • All General Business
      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • General Business Overview

      • View All General Business

  • Science & Tech
      • Consumer Technology

      • All Consumer Technology
      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • Consumer Technology Overview

      • View All Consumer Technology

      • Energy & Natural Resources

      • All Energy
      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • Energy & Natural Resources Overview

      • View All Energy & Natural Resources

      • Environ­ment

      • All Environ­ment
      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • Environ­ment Overview

      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • All Heavy Industry & Manufacturing
      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • Heavy Industry & Manufacturing Overview

      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • All Telecomm­unications
      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • Telecomm­unications Overview

      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • All Consumer Products & Retail
      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • Consumer Products & Retail Overview

      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Health

      • All Health
      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • Health Overview

      • View All Health

      • Sports

      • All Sports
      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • Sports Overview

      • View All Sports

      • Travel

      • All Travel
      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • Travel Overview

      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • All Policy & Public Interest
      • Advocacy Group Opinion
      • Animal Welfare
      • Canadian Federal Government
      • Canadian Municipal Government
      • Canadian Provincial Government
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • Policy & Public Interest Overview

      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • All People & Culture
      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • People & Culture Overview

      • View All People & Culture

  • Advanced Search
  • Overview
  • Cision Communications Cloud®
  • Monitoring
  • Distribution
  • Multimedia
  • Guaranteed Paid Placement
  • AI Tools
  • IR
  • Become a Client
  • Request a Demo
  • Editorial Bureaus
  • Partnerships
  • General Enquiries
  • Media
  • Worldwide Offices
  • Hamburger menu
  • Cision Canada
  • Send a Release
  • FR
    • Phone

    • 877-269-7890 from 8 AM - 10 PM ET

    • ALL CONTACT INFO
    • Contact Cision

      877-269-7890
      from 8 AM - 10 PM ET

  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR
  • News in Focus
    • Browse All News
    • Multimedia Gallery
    • Trending Topics
  • Business
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
    • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR
  • Overview
  • Cision Communications Cloud®
  • Monitoring
  • Distribution
  • Multimedia
  • Guaranteed Paid Placement
  • AI Tools
  • IR
  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR
  • Become a Client
  • Request a Demo
  • Editorial Bureaus
  • Partnerships
  • General Enquiries
  • Media
  • Worldwide Offices
  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR

Privacy Commissioner finds Equifax safeguards "unacceptable" and will monitor company for six years following major data breach Français


News provided by

Office of the Privacy Commissioner of Canada

Apr 09, 2019, 12:51 ET

Share this article

Share toX

Share this article

Share toX

GATINEAU, QC, April 9, 2019 /CNW/ - An investigation into a global data breach has found that both Equifax Canada and its US-based parent company fell far short of their privacy obligations to Canadians.

Privacy concerns included poor security safeguards; retaining information too long; inadequate consent procedures; a lack of accountability for Canadians' information and limited protection measures offered to affected individuals after the breach.

These issues contributed to, and exacerbated the impact of the breach, which affected more than 143 million people worldwide, including 19,000 Canadians.

"Given the vast amounts of highly sensitive personal information Equifax holds, and its pivotal role in the financial sector as a credit reporting agency, it was completely unacceptable to find such significant shortcomings in the company's privacy and security practices," says Daniel Therrien, Privacy Commissioner of Canada.

"In the end, the company did agree to enter into a compliance agreement, which demonstrates its commitment to addressing many of our concerns, and making privacy a priority going forward."

Since the breach, Equifax Canada and Equifax Inc. have taken steps to improve their security, accountability and data destruction programs.

Given the seriousness of the issues identified, the OPC also sought and received a commitment from Equifax Canada to submit third-party audit reports on its own security and that of Equifax Inc. to the OPC every two years for the next six years. This will allow for ongoing monitoring of compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private sector privacy law, including assessing the steps taken by Equifax since the breach.

The breach occurred after hackers gained access to Equifax Inc.'s systems through a vulnerability the company had known about for more than two months, but had not fixed.

The personal information of Canadians became caught up in the breach at U.S.-based Equifax Inc. because they had obtained products, such as credit monitoring or fraud alerts, from Equifax Canada – transactions that were processed by its parent company. Once Canadians' information was in Equifax Inc.'s systems in the United States, critical gaps in its security program left the Canadian information inadequately protected.

While Equifax Canada ultimately agreed to offer free credit monitoring to breach victims for a minimum of four years , the company did not go so far as its parent company in regard to other post breach protections. During its investigation, the OPC expressed concern that affected Americans were offered a credit freeze allowing them to restrict access to their credit files, thus reducing the chance of fraudulent or unauthorized credit checks.

"Canadians affected by the breach face the same risks, and it is unfortunate that Equifax Canada refused to offer a credit freeze option to affected Canadians" Commissioner Therrien says.

Several complainants told the OPC they were surprised to learn their information had left Canada and was transferred to the U.S. 

The OPC found the transfer to be inconsistent with the organization's obligation under PIPEDA to obtain meaningful consent from individuals before disclosing their personal information to a third party. For consent to be valid, individuals must be provided with clear information about the disclosure, including when the third party is located in another country, and the associated risks.

Organizations must obtain express consent where individuals would not reasonably expect the transfer. This was the case here given Canadian customers interacted exclusively with Equifax Canada at the time and were not explicitly advised that their information would be processed in the U.S. Express consent is also required where the information is sensitive, as is generally the case with financial information.

The OPC recognizes this marks a departure from its previous position which has led to a re-examination of its guidance on cross-border data flows for businesses.

OPC launches consultation on cross-border transfers

As a first step, the OPC is launching a formal consultation with stakeholders with a view to soliciting feedback and updating its guidance on cross-border transfers of personal information. The OPC has issued a consultation document and is welcoming written submissions through June 4, 2019.

"We know there are advantages to transborder data flows, but individuals ought to and do, under the law, have a say in whether their personal information will be disclosed outside Canada," Commissioner Therrien says.

"Whether this affects their decision to enter into a business relationship with an organization or to forego a product or service should be left to the discretion of the individual."

Following the consultation, the OPC will clarify the rules so that organizations understand their obligations around obtaining valid consent and remain accountable for protecting the information in their control.

International Collaboration

It is also worth noting that the OPC benefited from collaboration with the U.S. Federal Trade Commission (FTC) and the UK Information Commissioner's Office (ICO) over the course of its investigation.

"We would like to express our appreciation for the FTC and ICO's assistance," Commissioner Therrien says.

About the Privacy Commissioner of Canada

The Privacy Commissioner of Canada is mandated by Parliament to act as a guardian of privacy in Canada. The Commissioner enforces two laws for the protection of personal information: the Privacy Act, which applies to the federal public sector; and the Personal Information Protection and Electronic Documents Act, Canada's federal private sector privacy law.

See also:

Report of Findings

Compliance agreement

Consultation on consent for cross-border transfers of personal information

NOTE: To help us respond more quickly, journalists are asked to please send requests for interviews or further information via e-mail.

SOURCE Office of the Privacy Commissioner of Canada

[email protected], 819-994-5689

Related Links

https://www.priv.gc.ca

Modal title

Organization Profile

Office of the Privacy Commissioner of Canada

Contact Cision

  • 866-245-2317
    from 8 AM - 10 PM ET
  • Become a Client
  • Request a Demo
  • Editorial Bureaus
  • Partnerships
  • General Enquiries
  • Media

Products

  • Cision Communications Cloud®
  • Media Monitoring
  • Content Distribution
  • Multimedia Distribution
  • Measurement & Analytics
  • Investor Relations

About

  • About Cision Canada
  • About Cision
  • Media Partners
  • Careers
  • Accessibility Statement
  • APAC
  • APAC - Simplified Chinese
  • APAC - Traditional Chinese
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Indonesia
  • Israel
  • Japan
  • Korea
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United States
  • Vietnam

My Services

  • All News Releases
  • Online Member Centre
  • Next Gen Communications Cloud
  • Cision Communications Cloud®
  • my CNW

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Online Member Centre
  • Next Gen Communications Cloud
  • Cision Communications Cloud
  • my CNW
877-269-7890
from 8 AM - 10 PM ET
  • Terms of Use
  • Information Security Policy
  • Site Map
  • Cookie Settings
  • Accessibility Statement
Copyright © 2025 CNW Group Ltd. All Rights Reserved. A Cision company.