• About
  • Offices
  • Careers
  • News
  • Students
  • Alumni
  • Payments
  • EN | FR
Background Image
Bennett Jones Logo
  • People
  • Expertise
  • Knowledge
  • Search
  • FR Menu
  • Search Mobile
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
View all
Practices
Corporate Litigation Regulatory Tax View all
Industries
Energy Infrastructure Mining Private Equity & Investment Funds View all
Advisory
Crisis & Risk Management Public Policy
View Client Work
International Experience
Insights News Events Subscribe
Arbitration Angle Artificial Intelligence Insights Business Law Talks Podcast Class Actions: Looking Forward Class Action Quick Takes
Economic Outlook New Energy Economy Series Quarterly Fintech Insights Quarterly M&A Insights Sustainability & the CIO
People
Offices
About
Practices
Industries
Advisory Services
Client Work
Insights
News
Events
Careers
Law Students
Alumni
Payments
Search
Subscribe

Stay informed on the latest business and legal insights and events.

LinkedIn LinkedIn Twitter Twitter Vimeo Vimeo
 
Blog

Cyber Breach at the Ontario Cannabis Store Impacts 4,500 Consumers

November 07, 2018

Written By Ruth Promislow and Katherine Rusk

The Toronto Sun reported this morning that the privacy of 4,500 consumers of recreational cannabis in Ontario has been compromised. The names and addresses of individuals purchasing cannabis through the Ontario Cannabis Store (OCS) website, and the names of the individuals who signed for the package delivery, was accessed by an unidentified individual through the Canada Post online tracking tool in late October or early November.

The OCS has notified the impacted consumers and has reported the breach to the Office of the Privacy Commissioner. Canada Post has announced that it has fixed the loophole and further unauthorized access has been prevented. During the ramp up to legalization and over the past few weeks, the OCS has consistently prioritized the privacy of its consumers. For example, its privacy policy reveals a focus on shipping, stating that "when we ship orders, we deliver in discreet, plain packaging, so the nature of your purchase is not revealed." Privacy has been noted as a major concern for many consumers of cannabis.

But even the most prepared corporation can be at risk when a third-party service provider is breached. Understanding the risk of a cyberattack on your third-party service providers is an integral part of any business arrangement.

Consumers of recreational cannabis in Ontario who are worried about their privacy do not have an alternative legal purchase option at the moment as they are required to purchase from the OCS's website and Canada Post is the only shipping provider.

Addresses and names of consumers are generally considered to be "personal information" under Canada's federal privacy Act, PIPEDA. The OCS breach highlights the risk of attacks and cybersecurity incidents occurring through third-party service providers. While some of the tasks surrounding consumer privacy can be contracted out, the ultimate responsibility for maintaining consumer privacy cannot be delegated.

Third-party vendors are a critical factor in cybersecurity. If you are an organization that engages third-party service providers to assist with processing personal information, you should protect yourself by ensuring that you have a recorded basis for selecting the third-party vendor. This should also ensure that you know the third party has the appropriate safeguards in place. Contractual provisions with third parties should identify items such as:

  • its obligation to safeguard the personal information;
  • its obligation to notify you about security incidents;
  • your ability to oversee and potentially audit its operations as it concerns the personal information it processes on your behalf;
  • who bears the burden of the costs associated with a data security incident; and
  • any requirement that it procure cybersecurity insurance to cover the costs associated with a breach.

The Bennett Jones Cybersecurity group can help review your cybersecurity and privacy preparations to ensure that your organization is ready for when a breach occurs.

Please note that this publication presents an overview of notable legal trends and related updates. It is intended for informational purposes and not as a replacement for detailed legal advice. If you need guidance tailored to your specific circumstances, please contact one of the authors to explore how we can help you navigate your legal needs.

For permission to republish this or any other publication, contact Amrita Kochhar at kochhara@bennettjones.com.

Download PDF

Author

  • Ruth E. Promislow Ruth E. Promislow, Partner

Related Links

  • Insights
  • Media
  • Subscribe

Recent Posts

Blog

BC Government Streamlines Renewable Energy Regulatory [...]

May 09, 2025
       

Blog

BBHIC 2025: Key Insights From Canada’s Leading Healthcare [...]

May 08, 2025
       

Blog

Upending the Ground Rules: Proposed Major Overhaul [...]

May 08, 2025
       

Blog

Government of Alberta Proposes Significant Changes [...]

May 06, 2025
       

Blog

What Does the SPAC IPO Rebound Mean for Cross-Border Deals?

May 05, 2025
       
Bennett Jones Centennial Footer
Bennett Jones Centennial Footer
About
  • Leadership
  • Diversity
  • Community
  • Innovation
  • Security
Offices
  • Calgary
  • Edmonton
  • Montréal
  • Ottawa
  • Toronto
  • Vancouver
  • New York
Connect
  • Insights
  • News
  • Events
  • Careers
  • Students
  • Alumni
Subscribe

Stay informed on the latest business and legal insights and events.

LinkedIn LinkedIn Twitter Twitter Vimeo Vimeo
© Bennett Jones LLP 2025. All rights reserved.
  • Privacy Policy
  • Disclaimer
  • Terms of Use
Logo Bennett Jones