A Caisse populaire Desjardins sign is seen in Montreal on Tuesday, June 18, 2019. The federal privacy watchdog says a series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest in the Canadian financial services sector. THE CANADIAN PRESS/Paul Chiasson

A Caisse populaire Desjardins sign is seen in Montreal on Tuesday, June 18, 2019. The federal privacy watchdog says a series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest in the Canadian financial services sector. THE CANADIAN PRESS/Paul Chiasson

Series of gaps allowed massive Desjardins data breach, privacy watchdog says

The incident compromised the data of nearly 9.7 million Canadians

A series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest to date in the Canadian financial services sector, the federal privacy watchdog has found.

In a report today, privacy commissioner Daniel Therrien said Desjardins did not demonstrate the level of attention needed to protect the sensitive personal information entrusted to its care.

The incident compromised the data of nearly 9.7 million Canadians.

“Canadians expect banking information to have a high level of protection, given its sensitivity,” Therrien told a news conference today.

For at least 26 months, a malicious employee was siphoning sensitive personal information collected by Desjardins from customers who had purchased or received products through the organization, Therrien found.

This information was originally stored in two data warehouses to which the employee in question had limited access, the commissioner said.

However, other employees, in the course of fulfilling their work, would regularly copy that information onto a shared drive. As a result, employees who would not usually have the required clearance or the need to access some of the confidential data were able to do so, Therrien found.

The commissioner says the investigation into the breach sheds light on the risks of internal threats, whether they are intentional or not.

The investigation revealed that Desjardins failed to meet several of its obligations under the federal privacy law governing companies. Therrien found:

  • Desjardins did not ensure proper implementation of its policies and procedures for managing personal information, some of which were inadequate;
  • The access controls and data segregation of the company’s databases and directories were lacking;
  • Employee training and awareness were inadequate, considering the sensitive nature of the personal information;
  • Desjardins did not have proper procedures regarding the periodic destruction of personal information.

Desjardins agreed to a series of recommendations to improve information security and the protection of personal data, Therrien said.

The company has committed to provide progress reports every six months as well as hire external auditors to assess and certify its programs.

Therrien’s office and the Commission d’accès à l’information du Québec, which also published its report today, co-ordinated their respective probes.

Jim Bronskill, The Canadian Press

Like us on Facebook and follow us on Twitter.

Want to support local journalism? Make a donation here.

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Eli, left, Brent, Lindsay and Ava Wilson. (Photo courtesy of Lindsay Wilson)
West Shore families share experience in raising a child with autism

Two families reveal some parallels, but circumstances are different for everyone

Kit Thornton, chief aquarist at the Shaw Centre for the Salish Sea, plays with Wanda, the female Giant Pacific octopus currently residing at the centre. The centre will release Wanda back into the wild next month. (Wolf Depner/News Staff)
An octopus named Wanda will soon say goodbye to Sidney

Wanda’s personality is ‘complete opposite’ of previous octopus named after Dr. Bonnie Henry

Hamels Fabrics & Quilting is set to open on April 6 in Sooke. The shop is located at 2044 Otter Point Road. (Mark Martins/Pixabay)
Fabric and quilting store opens doors in Sooke

Shop is filled with all kinds of ‘bright, bold and cheery’ designs

Saanich Fire Department on the scene after a car crashed into the Walmart in Uptown. (Photo courtesy Dan Wood)
PHOTOS: Saanich firefighters free trapped workers at Uptown Walmart

Incident reported as explosion after driver rammed through wall

Tiny packets of carrots ready to be distributed in Victoria. (Submitted/Victoria Seed Share)
Free Victoria seed sharing collective bags work experience funding

Fully volunteer run Victoria Seed Share will get a boost from provincial grant

B.C. Health Minister Adrian Dix and Premier John Horgan describe vaccine rollout at the legislature, March 29, 2021. (B.C. government)
1,262 more COVID-19 infections in B.C. Friday, 9,574 active cases

Province’s mass vaccination reaches one million people

Chief Public Health Officer Theresa Tam speaks during a technical briefing on the COVID pandemic in Canada, Friday, January 15, 2021 in Ottawa. THE CANADIAN PRESS/Adrian Wyld
Canada’s ICUs see near-record of COVID-19 patients last week as variant cases double

Last week, Canadian hospitals treated an average of 2,500 patients with COVID-19, daily, up 7% from the previous week

University of Victoria rowing coach Barney Williams at the University of Victoria in Victoria, B.C. THE CANADIAN PRESS/Chad Hipolito
UVic, women’s rowing coach deny former athlete’s allegation of verbal abuse

Lily Copeland alleges coach Barney Williams would stand close to her and speak aggressively in the sauna

Buckingham Palace officials say Prince Philip, the husband of Queen Elizabeth II, has died. THE CANADIAN PRESS/AP/Alastair Grant
Flags drop, bells toll as Canadians remember special relationship with Prince Philip

‘He was often portrayed as a brisk or brusque, rough character… but it’s that other side of him, the caring individual who spent time with people and asked questions and showed compassion’

Librarian Katie Burns with the Fraser Valley Regional Libraries poses for a photo in Chilliwack on June 18, 2019. Monday, April 12, 2021 is Library Workers’ Day. (Jenna Hauck/ Chilliwack Progress file)
Unofficial holidays: Here’s what people are celebrating for the week of April 11 to 17

Library Workers Day, That Sucks! Day, and Wear Your Pyjamas to Work Day are all coming up this week

Nanaimo RCMP are asking for the public’s help in identifying the man suspected of being involved in a stabbing. (Photo submitted)
Nanaimo RCMP trying to identify stabbing suspect who wielded rusty knife

Stabbing followed argument between two men at Port Place Shopping Centre April 1

The inside of the Campbell River Community Centre gymnasium has been marked off in order to facilitate the public flowing through the clinic as they receive their COVID-19 vaccination. Photo by Alistair Taylor – Campbell river Mirror
Leftover vaccines go into arms, not down the drain: Island Health

Immunization plan comes with built-in options for any unused vaccines at the end of the day

A man wears a face mask past the emergency department of the Vancouver General Hospital. (THE CANADIAN PRESS/Jonathan Hayward)
Calls for stricter action in B.C. as COVID-19 variants projected to climb

Jens von Bergmann says the province has taken a ‘wait and see’ approach when early action is needed

Vancouver’s park board general manager issued a new order Friday restricting tents and other temporary structures from being set up in Strathcona Park after April 30, 2021. THE CANADIAN PRESS/Jonathan Hayward
Vancouver park board issues order to restrict tents in Strathcona Park

The order issued Friday restricted tents and other temporary structures from being set up after April 30

Most Read