When student data is hacked & stolen: Regulators’ lessons from the #PowerSchool data breach
A close look at the #PowerSchool #cybersecurity incident, perhaps the largest education-sector data breach ever investigated in Canada, and the findings issued by the Information and Privacy Commissioners of Ontario and Alberta. PowerSchool is widely used by Canadian school boards to manage student information, including enrollment, grades, contact details, and medical alerts. In late 2024, a threat actor gained access to PowerSchool’s systems using compromised credentials belonging to a support contractor, allowing them to exfiltrate sensitive student and educator data affecting millions of individuals across multiple provinces. This video explains: ► What PowerSchool is and how school boards rely on it ► How the cyberattack occurred and what data was accessed ► What Ontario and Alberta privacy regulators investigated ► Where the regulators’ findings align — and where they differ What this case teaches about outsourcing, vendor oversight, and accountability under Canadian privacy law Both regulators concluded that school boards remained legally responsible for protecting personal information, even though PowerSchool operated the systems. The investigations highlight failures in cybersecurity safeguards, contract management, data retention practices, and breach preparedness — and underscore the heightened sensitivity of children’s personal information. Relevant links: ► Ontario finding: https://www.ipc.on.ca/en/resources/po... ► Alberta finding: https://oipc.ab.ca/wp-content/uploads... ► Saskatchewan finding: https://oipc.sk.ca/assets/la-foip-inv... Where you can find me ► Privacylawyer blog: https://blog.privacylawyer.ca ► My law firm: https://www.mcinnescooper.com/people/... ► Twitter: / privacylawyer ► LinkedIn: / davidtsfraser Disclaimer: This is intended for education and information only and should not be taken as legal advice. If you need advice for your particular situation, you should seek out qualified counsel. All views expressed are solely those of the creator and should not be attributed to his firm or any of its clients.

PIPEDA: Canadian Privacy Law 101 - a primer on the privacy law that regulates businesses in Canada

World's Deadliest Computer Virus: WannaCry

"You’re Not Coming In": Immigration Officers Take a Stand

THESE Apps Are SPYING on You — Shut Them Off NOW!

Something is jamming GPS over Europe. Here's what we found

Canada's proposed new privacy law: Bill C-36, the Protecting Privacy and Consumer Data Act

Lawful Access is back: All about Bill C-22 (Spoiler alert: Part 2 is very troubling.)

LAWYER: How to Stop Cops From Using This NEW Tech to Spy on You

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

The World's Most Important Machine

Torturing This Smug Scammer Group With Their Photo

How to Disappear Online and Become Untraceable

Testimony at the SECU Committee by Professors Michael Geist & Robert Diab and David Fraser

The Deeply Problematic Part 2 of Bill C-22: The Supporting Authorized Access to Information Act.

Privacy, Online Fraud, and What You Can Do About It

The Hidden Backdoors Inside Millions of Smart Devices | WSJ

My Bill C-22 (Lawful Access) testimony to the Committee on Public Safety & National Security

I spent 7 days evading America’s 82 MILLION surveillance cameras

Why AI Agents are either the best or worst thing we’ve ever built

