Skip to content

Regulatory Pulse

OPC investigates IDScan.net breach involving stolen identity-document scans

Canada’s privacy regulator is investigating safeguards and notification after a breach reportedly exposed digital scans of driver’s licences and other identification.

Canada
Data breach, identity verification, vendor risk and incident notification
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Active regulatory investigation · Reviewed 24 September 2026 · 6 min read

The 60-second summary

On 21 September 2026, the Office of the Privacy Commissioner of Canada opened an investigation into a breach at IDScan.net after reports that an unauthorised third party accessed its database and stole personal information, including digital scans of driver’s licences and other identification. IDScan.net technology is used by hospitality, nightlife and other businesses to verify government-issued ID. The investigation will assess safeguards in place at the time of the breach and whether notifications to affected individuals were adequate under PIPEDA. This is an active investigation, not a finding of non-compliance. The OPC has not released the scale, attack method, affected data fields or notification timeline.

Timeline that matters

  1. Earlier in September 2026

    Public incident advisory

    The company issued a public advisory, according to the regulator.

  2. 21 September 2026

    Investigation announced

    The OPC opened a formal investigation into safeguards and notification adequacy.

  3. Investigation ongoing

    No outcome yet

    No compliance finding, order, penalty or final report has been issued.

  4. 24 December 2026

    Next review

    Check for findings, additional affected-data details and remedial commitments.

What changed

The regulator has moved from engagement following the company’s public advisory to a formal investigation focused on two operational questions: whether safeguards were appropriate for retained identification data and whether affected-person notifications were adequate. The case highlights the concentrated risk created when identity-verification providers retain reusable document images on behalf of many customer organisations.

Who should pay attention?

Identity-verification providers

Demonstrate minimisation, security, retention, tenant separation and incident notification controls.

Customer organisations

Establish whether submitted identification data was retained or affected and coordinate notices.

Security and incident-response teams

Preserve evidence, contain access and monitor identity-fraud risks.

Procurement and vendor-risk teams

Review data lifecycle, subprocessors, breach clauses and deletion evidence.

Privacy and legal teams

Assess notification triggers, controller roles, contracts and affected-person support.

What the guidance clarifies

This is not an enforcement finding
The OPC has opened an investigation and has not concluded that PIPEDA was breached.
Identification images are in scope
The official announcement identifies digital scans of driver’s licences and other identification among the stolen information.
Safeguards and notification are the stated focus
The investigation will examine security controls and the adequacy of notices to affected individuals.
Customer organisations also need answers
Businesses using the provider should determine what data was submitted, retained, accessed and notified.
Key incident facts remain unavailable
The regulator has not disclosed the number affected, attack vector, full data set or investigation outcome.

Document scans create durable identity-fraud risk across the vendor chain

Why this matters for global organisations

Identity documents combine high-value identifiers, images and verification attributes that may remain useful to attackers long after a password is changed. Organisations need to minimise collection, challenge routine image retention, isolate customer data, test deletion and coordinate incident evidence and notification across providers.

  • Avoid retaining document images when verification results are sufficient.
  • Know which provider, subprocessor and customer holds each copy.
  • Contract for rapid evidence, deletion and notification support.
  • Plan long-term protection for people exposed to identity misuse.

15 actions to start now

  1. Identify every service that scans, uploads, verifies or stores identity documents.
  2. Determine whether the provider retains full images, extracted fields, biometric templates or verification results.
  3. Map controller, processor and service-provider roles for each use case.
  4. Confirm which data, tenants, dates and users may be affected by the incident.
  5. Preserve contracts, assessments, transfer records, logs and provider communications.
  6. Challenge the necessity of retaining full document images after verification.
  7. Set short, purpose-specific retention periods with verifiable deletion.
  8. Separate customer tenants and restrict privileged access using least privilege.
  9. Encrypt document images and extracted data in transit and at rest.
  10. Monitor bulk exports, unusual administrative access and database queries.
  11. Require subprocessors and hosting providers to support investigation and evidence requests.
  12. Coordinate legal analysis and notification decisions across provider and customer organisations.
  13. Prepare affected-person guidance addressing identity theft, fraud and document replacement where appropriate.
  14. Review cyber-insurance, law-enforcement and credit-monitoring escalation routes.
  15. Track the investigation outcome before drawing conclusions about compliance.

Suggested next steps

  • Ask every identity-verification provider for a written lifecycle map covering collection, extraction, image retention, subprocessors, deletion, breach evidence and customer-notification support, then reconcile it with the organisation’s own records.

Evidence worth retaining

  • Identity-verification vendor inventory and accountable owners.
  • Data-flow maps showing image, extracted-data and result storage.
  • Necessity and proportionality assessments.
  • Contracts, data-processing terms and subprocessor lists.
  • Retention schedules and deletion certificates.
  • Encryption, key-management and access-control evidence.
  • Tenant-separation and privileged-access test results.
  • Security assessments, penetration tests and remediation records.
  • Incident timeline and evidence-preservation logs.
  • Provider notifications, advisories and customer communications.
  • Affected-data and affected-person reconciliation records.
  • Notification decision logs and copies of notices.
  • Identity-fraud support and complaint records.
  • Board, risk and regulatory escalation records.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Was a full document image necessary, or would a verification result have met the purpose?
  • Which party decided the purposes and retention period?
  • What data was stored beyond the visible document image?
  • Were customer tenants and administrative roles adequately separated?
  • When did each party become aware of the breach?
  • Which contractual clock governs provider-to-customer notification?
  • Can affected records and recipients be reconciled accurately?
  • What continuing identity-fraud risks remain after containment?
  • Can deletion be proven across backups, logs and subprocessors?
  • Which additional jurisdictions or sectoral notification rules may apply?
  • What facts remain unknown because the investigation is ongoing?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.