Baseline Controls News Resources Glossary About

Stolen ID Scans Canada: OPC Opens PIPEDA Investigation into IDScan.net Breach

Stolen ID Scans Canada: OPC Opens PIPEDA Investigation into IDScan.net Breach

The Privacy Commissioner of Canada opened a formal PIPEDA investigation on September 21, 2026 into a data breach at IDScan.net, a company whose technology is used by Canadian bars, hotels, and retailers to verify customer identification. The investigation follows reports that an unauthorized third party gained access to the company's database and stole personal information, including digital scans of driver's licences and other government ID collected from businesses across Canada.

For Canadian businesses that scan customer ID at the door or the counter, this investigation raises immediate questions: what data was exposed, what went wrong, and what obligations apply when a third-party vendor suffers a breach involving your customers' most sensitive documents?

What the Privacy Commissioner Announced

According to the OPC's September 21, 2026 news release, Commissioner Philippe Dufresne has opened an investigation into the breach after reports that an unauthorized third party gained access to IDScan.net's database. The stolen data includes digital scans of driver's licences and other types of government-issued identification.

IDScan.net's technology is used by businesses in the hospitality and nightlife sectors, among others, to verify customers' government-issued ID. The company issued a public advisory about the incident earlier in September. The OPC states it has been actively engaging with IDScan.net to ensure the company is taking the necessary steps to address the incident and mitigate risks to Canadians.

The investigation will examine two things:

  1. The security safeguards IDScan.net had in place at the time of the breach
  2. The adequacy of its notifications to affected individuals

Both areas are core PIPEDA compliance requirements.

Why Government ID Scans Are High-Value Targets

Driver's licences and government ID documents are among the most sensitive categories of personal information. Unlike a leaked email address or password, a compromised ID scan cannot be easily changed. The information on these documents (full legal name, date of birth, address, photo, licence number, and in some cases signature) is precisely what criminals need for:

  • Identity fraud: Opening accounts, applying for credit, or filing false tax returns in someone else's name
  • Document forgery: Creating convincing fake IDs using real data
  • Social engineering: Impersonating individuals to bypass verification at banks, government services, or employers
  • Account takeover: Answering security questions or passing identity verification checks

When businesses scan customer ID, they become custodians of this information. If that data is then entrusted to a third-party service, the risk extends to that vendor's security practices.

What PIPEDA Requires When You Collect ID Scans

PIPEDA requires organizations to protect personal information with security safeguards appropriate to its sensitivity. Government-issued ID scans sit at the high end of the sensitivity scale.

Under PIPEDA, organizations that collect ID scans must:

  • Limit collection: Collect only the information necessary for the identified purpose. If you need to verify that someone is 19 or older, you may not need to retain a full image of their licence.
  • Implement adequate safeguards: Technical, physical, and organizational measures must protect the information from unauthorized access, disclosure, copying, use, or modification.
  • Report qualifying breaches: If a breach creates a "real risk of significant harm" to individuals, you must report it to the Office of the Privacy Commissioner as soon as feasible, notify affected individuals, and keep records of all breaches for at least two years.
  • Be accountable for vendors: If you share personal information with a third-party service provider, you remain accountable for how that provider handles the data.

The last point is critical for businesses using ID verification services. Outsourcing the technology does not outsource the privacy obligation.

Vendor Risk and the Accountability Principle

The IDScan.net investigation highlights a recurring theme in privacy breaches: the gap between who holds the data and who bears responsibility for protecting it.

Under PIPEDA's accountability principle, the organization that collects personal information is responsible for its protection, even when it transfers that information to a third party for processing. This means:

  • If your nightclub uses a third-party ID scanner that stores customer data in the cloud, you share accountability for how that data is secured
  • Your contracts with vendors should include clear security requirements, breach notification terms, and audit rights
  • You should understand where the data goes, how long it is retained, and what happens if the vendor is compromised

Many small businesses assume that using a vendor's "off-the-shelf" solution transfers the privacy risk. It does not. The OPC has consistently held that organizations cannot contract out of their privacy obligations.

For a deeper look at this issue, see our guide on vendor and third-party risk.

What Businesses That Scan ID Should Do Now

If your business scans customer identification (whether you operate a bar, hotel, cannabis retailer, or any establishment that verifies age or identity), the IDScan.net investigation is a prompt to review your own practices.

1. Understand What Data Your Vendor Holds

Contact your ID verification provider and confirm:

  • What data is captured (image, parsed fields, or both)
  • Where it is stored (on-device, in the cloud, or both)
  • How long it is retained
  • What security measures protect it
  • What their breach notification process is

If you cannot get clear answers, that is a red flag.

2. Review Your Data Minimization Practices

Do you need to retain a full ID scan, or would a pass/fail age verification result suffice? PIPEDA's limiting collection principle requires you to collect only what is necessary. Storing less sensitive data reduces your exposure if a breach occurs.

3. Check Your Vendor Contracts

Your contract with an ID verification provider should address:

  • Security standards the vendor must meet
  • Breach notification requirements (how quickly will they tell you?)
  • Data retention and deletion policies
  • Your right to audit or request evidence of compliance

If these terms are absent or vague, consider renegotiating or finding a provider that takes privacy seriously.

4. Confirm Your Breach Response Plan

If your vendor suffers a breach involving your customers' data, you need a plan. Under PIPEDA, you may have reporting obligations even if the breach happened at a third party's system. Your incident response plan should cover this scenario.

5. Train Staff on Privacy Basics

Employees who handle ID verification should understand why the data is sensitive and how to handle it properly. This overlaps with your broader security awareness training program.

Stolen ID Scans Canada: The Broader Pattern

The IDScan.net breach is part of a broader pattern of incidents involving ID verification data. As more businesses digitize identity checks, the attack surface expands. Criminal groups have recognized that ID scan databases are high-value targets, and the hospitality and retail sectors are increasingly in the crosshairs.

Canadian privacy regulators have signalled that enforcement is intensifying. The OPC's recent enforcement actions show a clear focus on organizations that fail to meet basic safeguard requirements, including situations where third-party vendors are involved.

For businesses that collect sensitive identification documents, the message is clear: the convenience of digital ID verification comes with real privacy obligations. If you cannot demonstrate that you are meeting those obligations (through data minimization, vendor due diligence, and incident response planning) you are exposed.

How This Connects to the Baseline Controls

PIPEDA requires appropriate safeguards but does not prescribe specific technical measures. The Canadian Centre for Cyber Security's Baseline Controls provide a practical framework for implementing those safeguards. Several control areas are directly relevant:

Next Steps

The OPC investigation into IDScan.net will take time to conclude, but the practical lessons are available now. If your business scans customer identification, use this incident as a prompt to:

  • Audit your ID verification practices and vendor relationships
  • Confirm your compliance with PIPEDA's safeguard and breach notification requirements
  • Strengthen the controls that protect your customers' most sensitive documents

Our free cybersecurity assessment evaluates your organization across all 13 Baseline Control areas, including access control, vendor risk, and incident response planning. It gives you a clear picture of where your security posture needs attention, without collecting your data or requiring a sales call.

When a vendor breach exposes your customers' driver's licences, the investigation may focus on the vendor, but the reputational damage lands on your business. The time to address that risk is before the next headline.

Free Assessment

How prepared is your business?

Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.

Check Your Score

Cite This Page

Suggested citation:

Cybersecurity Canada (2026). Stolen ID Scans Canada: OPC Opens PIPEDA Investigation into IDScan.net Breach. Retrieved from https://cybersecuritycanada.ca/news/posts/idscan-data-breach-stolen-id-scans-canada-opc-investigation/

Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.

Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.

How does your organization measure up?

Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.

Take the Free Assessment