The 60-second summary
On 21 September 2026, the Office of the Privacy Commissioner of Canada opened an investigation into a breach at IDScan.net after reports that an unauthorised third party accessed its database and stole personal information, including digital scans of driver’s licences and other identification. IDScan.net technology is used by hospitality, nightlife and other businesses to verify government-issued ID. The investigation will assess safeguards in place at the time of the breach and whether notifications to affected individuals were adequate under PIPEDA. This is an active investigation, not a finding of non-compliance. The OPC has not released the scale, attack method, affected data fields or notification timeline.
Timeline that matters
Earlier in September 2026
Public incident advisory
The company issued a public advisory, according to the regulator.
21 September 2026
Investigation announced
The OPC opened a formal investigation into safeguards and notification adequacy.
Investigation ongoing
No outcome yet
No compliance finding, order, penalty or final report has been issued.
24 December 2026
Next review
Check for findings, additional affected-data details and remedial commitments.
What changed
The regulator has moved from engagement following the company’s public advisory to a formal investigation focused on two operational questions: whether safeguards were appropriate for retained identification data and whether affected-person notifications were adequate. The case highlights the concentrated risk created when identity-verification providers retain reusable document images on behalf of many customer organisations.
Who should pay attention?
Identity-verification providers
Demonstrate minimisation, security, retention, tenant separation and incident notification controls.
Customer organisations
Establish whether submitted identification data was retained or affected and coordinate notices.
Security and incident-response teams
Preserve evidence, contain access and monitor identity-fraud risks.
Procurement and vendor-risk teams
Review data lifecycle, subprocessors, breach clauses and deletion evidence.
Privacy and legal teams
Assess notification triggers, controller roles, contracts and affected-person support.
What the guidance clarifies
- This is not an enforcement finding
- The OPC has opened an investigation and has not concluded that PIPEDA was breached.
- Identification images are in scope
- The official announcement identifies digital scans of driver’s licences and other identification among the stolen information.
- Safeguards and notification are the stated focus
- The investigation will examine security controls and the adequacy of notices to affected individuals.
- Customer organisations also need answers
- Businesses using the provider should determine what data was submitted, retained, accessed and notified.
- Key incident facts remain unavailable
- The regulator has not disclosed the number affected, attack vector, full data set or investigation outcome.
Document scans create durable identity-fraud risk across the vendor chain
Why this matters for global organisations
Identity documents combine high-value identifiers, images and verification attributes that may remain useful to attackers long after a password is changed. Organisations need to minimise collection, challenge routine image retention, isolate customer data, test deletion and coordinate incident evidence and notification across providers.
- Avoid retaining document images when verification results are sufficient.
- Know which provider, subprocessor and customer holds each copy.
- Contract for rapid evidence, deletion and notification support.
- Plan long-term protection for people exposed to identity misuse.
15 actions to start now
- Identify every service that scans, uploads, verifies or stores identity documents.
- Determine whether the provider retains full images, extracted fields, biometric templates or verification results.
- Map controller, processor and service-provider roles for each use case.
- Confirm which data, tenants, dates and users may be affected by the incident.
- Preserve contracts, assessments, transfer records, logs and provider communications.
- Challenge the necessity of retaining full document images after verification.
- Set short, purpose-specific retention periods with verifiable deletion.
- Separate customer tenants and restrict privileged access using least privilege.
- Encrypt document images and extracted data in transit and at rest.
- Monitor bulk exports, unusual administrative access and database queries.
- Require subprocessors and hosting providers to support investigation and evidence requests.
- Coordinate legal analysis and notification decisions across provider and customer organisations.
- Prepare affected-person guidance addressing identity theft, fraud and document replacement where appropriate.
- Review cyber-insurance, law-enforcement and credit-monitoring escalation routes.
- Track the investigation outcome before drawing conclusions about compliance.
Suggested next steps
- Ask every identity-verification provider for a written lifecycle map covering collection, extraction, image retention, subprocessors, deletion, breach evidence and customer-notification support, then reconcile it with the organisation’s own records.
Evidence worth retaining
- Identity-verification vendor inventory and accountable owners.
- Data-flow maps showing image, extracted-data and result storage.
- Necessity and proportionality assessments.
- Contracts, data-processing terms and subprocessor lists.
- Retention schedules and deletion certificates.
- Encryption, key-management and access-control evidence.
- Tenant-separation and privileged-access test results.
- Security assessments, penetration tests and remediation records.
- Incident timeline and evidence-preservation logs.
- Provider notifications, advisories and customer communications.
- Affected-data and affected-person reconciliation records.
- Notification decision logs and copies of notices.
- Identity-fraud support and complaint records.
- Board, risk and regulatory escalation records.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Was a full document image necessary, or would a verification result have met the purpose?
- Which party decided the purposes and retention period?
- What data was stored beyond the visible document image?
- Were customer tenants and administrative roles adequately separated?
- When did each party become aware of the breach?
- Which contractual clock governs provider-to-customer notification?
- Can affected records and recipients be reconciled accurately?
- What continuing identity-fraud risks remain after containment?
- Can deletion be proven across backups, logs and subprocessors?
- Which additional jurisdictions or sectoral notification rules may apply?
- What facts remain unknown because the investigation is ongoing?
Official sources
- Office of the Privacy Commissioner of Canada — investigation announcement, 21 September 2026
- Justice Laws Website — Personal Information Protection and Electronic Documents Act
- OPC — What you need to know about mandatory reporting of breaches of security safeguards
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.