PogoWasRight.org

Menu
  • About
  • Privacy
Menu

BC’s Privacy Commissioner Releases Report on Government Privacy Breaches

Posted on January 28, 2015 by pogowasright.org

British Columbia’s Privacy Commissioner, Elizabeth Denham, has released a report on privacy breach management in government ministries.

The report, An Examination of BC Government’s Privacy Breach Management, examines the degree to which government is fulfilling its duty to respond to, and properly manage, its privacy breaches. From the executive summary of the report:

The examination revealed that government has a solid foundation in place for managing privacy breaches and that the majority of suspected breaches are reported to the OCIO within a day or two of discovering the incident, are contained, and are investigated within a reasonable timeframe. Ministries provided notifications to affected individuals when appropriate, and written notifications included all of the necessary information. The OCIO also provided advice on preventative measures in almost every investigation. 

There are, however, opportunities for improvement as gaps were found in relation to audits of security safeguards, analysis and public reporting of breaches, follow-up on implementation of preventative measures, timeliness of notifying individuals who may be impacted by a breach, internal processes for documenting and tracking breaches, and training participation rates. 

There is also a lack of clarity around when breaches should be reported to the Information and Privacy Commissioner.

For the period 2010-2013, there were 2,718 actual breaches involving personal information. Of those, 71.7% were due to “Administrative Error,” and 16.4% were due to “Disclosure.” All other categories of breach types accounted for less than 5% each. Mailing errors accounted for 50% of the administrative error breaches.

Over 50% of all breaches were reported by the Ministry of Social Development and Social Innovation (31.2%) and Ministry of Health (24.0%).

The report concludes with five recommendations.

Category: BreachesFeatured NewsGovtNon-U.S.

Post navigation

← Mexico says may sanction Google over data protection breach
Alberta’s Privacy Commissioner releases report on government information sharing →

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

RSS Recent Posts on DataBreaches.net

  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse
  • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy
  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
©2025 PogoWasRight.org. All rights reserved.