Canada's federal privacy regulator announced an investigation into IDScan.net on September 21, 2026, following reports that an unauthorized party accessed a database containing identification documents. The Office of the Privacy Commissioner said it would examine both the company's safeguards and its notification of affected individuals. An investigation has begun; the announcement does not establish that the company violated the law. The regulator's announcement identifies the questions, rather than answering them.
That distinction matters when reading a breach headline. A failure to prevent access and a failure to communicate after access are different propositions. Evidence relevant to one may say little about the other. A notice can describe a serious incident accurately without resolving whether earlier protections were adequate. Conversely, a technical explanation cannot by itself demonstrate that affected people received usable information.
The OPC describes IDScan.net as supplying identity-verification technology used by businesses, including hospitality and nightlife operators. It says the company issued a public advisory earlier in September and that the office had been engaging with it. The announcement does not provide a verified affected-person count or a final explanation of the intrusion. Those omissions are boundaries on the public record, not grounds to supply estimates.
Two timelines, different evidence
Consider a hypothetical investigation with two timelines. The first records when information entered a system, who could access it, and what protections existed. The second records when the organization learned of a problem, assessed it, and communicated. The same incident can occupy both timelines, but each timeline would need its own supporting records. This example describes an analytical distinction, not findings about IDScan.net.
The OPC's general breach-reporting guidance explains that organizations subject to PIPEDA must report and notify breaches presenting a real risk of significant harm, while maintaining records of all breaches. Its risk assessment considers information sensitivity and the probability of misuse. Notification is therefore not simply a function of how many records appear in a headline.
In the hypothetical case, a small set of highly sensitive records and a large set of less revealing records would not become equivalent merely because both were accessed. Nor would an absence of publicly documented misuse establish that misuse was impossible. These are reasons to keep the type of information, access circumstances and known consequences separate when interpreting later evidence.
There is also a difference between an announcement being available and an affected person receiving an informative notice. The general guidance describes notification as helping individuals understand the significance of a breach and possible measures to reduce harm. It does not settle whether the communications in this investigation met the applicable requirements.
The two cited records come from the same regulator: one opens a specific inquiry, and the other supplies general regulatory context. They do not constitute independent corroboration of the reported intrusion. A later investigation report or court record could support conclusions unavailable in the September 21 announcement. Until then, the accurate account is that safeguards and notification are under examination, with neither result presumed.