Commissioner calls for privacy training, audits and updated breach protocols
A City of Toronto employee inappropriately accessed the personal information of 14 individuals through client profiles on the Social Assistance Management System (SAMS), prompting Ontario’s Information and Privacy Commissioner to recommend measures to prevent similar breaches.
The Information and Privacy Commissioner of Ontario (IPC), in a letter to the City of Toronto, said the measures should include stronger privacy training, annual confidentiality agreements, auditing protocols and updated breach-response procedures. New privacy safeguards and mandatory breach-notification requirements under the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA) take effect January 1, 2027.
The IPC opened its review after receiving a report in August 2024 alleging that a Toronto Employment and Social Services employee had accessed client files involving people the employee knew personally or suspected of receiving social assistance. The source also alleged the employee disclosed information to others who may know the clients to shame them.
The city’s investigation found the employee made 160 unauthorized accesses involving 14 individuals between April 4, 2023, and Sept. 22, 2024. Individual SAMS profiles were accessed between one and 36 times.
The affected individuals received services from Region of Peel Social Services rather than Toronto, leading the city to conclude the employee had no work-related reason to access their information. The city determined the individuals were known to the employee through shared surnames, maiden names or addresses, or connections to the employee’s former spouse or children.
Information potentially viewable through the accessed SAMS pages included names, birth dates, address histories, rental obligations, income and asset information, status in Canada, caseworker notes, social assistance applications and copies of government-issued identification. The city could not confirm whether information had been improperly shared, printed or otherwise disclosed.
The IPC identified gaps in the city’s existing privacy safeguards, noting it did not conduct annual privacy training, require annual confidentiality agreements for Social Services employees or audit employees’ use of SAMS.
Among its recommendations, the IPC called for annual privacy training and confidentiality agreements for staff with access to personal information, a documented privacy breach response plan and a formal policy or audit protocol for electronic files.
The IPC also assessed the breach using the real risk of significant harm (RROSH) framework. It found the information involved was sensitive and noted that the accesses were intentional. The IPC also concluded that further unauthorized disclosure was likely because the incident came to its attention through a member of the public who reported being aware that the employee accessed and disclosed information.
The commissioner ultimately found the incidents posed a real risk of significant harm and recommended that the city notify all individuals whose information was accessed without authorization.
The IPC closed the file on the condition that Toronto give its recommendations due consideration as it prepares for the new MFIPPA breach-notification regime. It said it could reopen the matter if additional information warrants further inquiry.