Canadian regulator opens probe of IDScan for allegedly violating data privacy laws
Canadian regulators are investigating IDScan, a widely used identity verification service, following reports of a data breach exposing scans of over 153 million driver’s licenses. The probe will examine IDScan’s security practices and whether adequate notifications were provided to affected users, highlighting a significant risk to personal data and privacy.
Canadian regulators are investigating IDScan, a company providing identity verification services, due to a potential violation of data privacy laws. The Privacy Commissioner of Canada, Philippe Dufresne, initiated an investigation following reports that a malicious actor gained access to IDScan’s databases, resulting in the exposure of scans of over 153 million driver’s licenses.
IDScan’s technology is commonly used within the retail and hospitality sectors for verifying official identification documents. The company initially announced the breach on September 4th, stating that hackers had accessed their cloud platform, but did not specify the exact number of affected users at the time. Journalist Brian Krebs reported on September 1st that the stolen driver’s license scans were being sold on the dark web, further fueling concerns about the scope of the breach.
IDScan initially disclosed the breach to the public after receiving notification from Krebs. The investigation will focus on assessing IDScan’s security protocols and whether the company followed proper procedures for notifying affected individuals as mandated by Canada’s federal private-sector privacy law. The Privacy Commissioner intends to determine if IDScan adequately addressed the security vulnerabilities that led to the breach and whether sufficient notification was provided to those impacted.
