N-1Letters of Comment - Redacted
15 passages
From: Painting-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: M12273 Administrative Demand for Structural Redress – NSUARB Oversight Failure and NS Power Identity Breach Date: May 23, 2025 10:11:33 AM Attachments: Administrative...
AI summary An administrative demand for structural redress is made regarding NSUARB oversight failures and an NS Power identity breach. The email, sent to Nova Scotia provincial officials, references attachments including NSERBT decisions and formal responses related to matters M11099 and M11411, highlighting concerns over regulatory compliance and contractual structures.
passive access as lawful consent - confirms that the regulatory system is enforcing what appears to be contracts of adhesion in direct contradiction to Canadian legal standards of equity and consent. 3. Identity Breach as Confirmation of A...
AI summary The text critiques NS Power's contractual practices as unfair and lacking informed consent, citing an identity breach as evidence of systemic failures. It accuses NSERBT of enforcing invalid contracts and demands regulatory review. The author claims residents are bound to a monopoly utility with no remedy, calling for accountability from the Executive Council overseeing NSERBT.
’s security breach, and according to the Personal Information Protection and Electronic Documents Act (PIPEDA), I have a legal right to know the full scope of My Personal Data Theft. • The NS Power letter provided no guidance on what steps...
AI summary The complainant alleges a major NS Power data breach affecting half of Nova Scotia's population, criticizing NS Power for failing to provide identity theft protection guidance and for recommending TransUnion (linked to NS Power's parent company Emera) as a paid service. The request includes disclosure of stolen data, explanation of the 23-day breach notification delay, and mandatory identity protection.
…/2 -2 - 3) Provide comprehensive identity protection through a credible provider; 4) Provide in writing, a clear acknowledgement that NS Power was the care holder of my Personal and Private information, as they had requested it from me, b...
AI summary The complainant alleges NS Power failed to protect personal data during a cyberattack, leading to the theft of 280,000 Nova Scotians' information. They demand identity protection, written acknowledgment of NS Power's data stewardship, and an explanation for restoring public trust, citing delayed breach disclosure and ongoing access barriers.
lf is a major breach of trust, during an ongoing security breach. Even now, NS Power will not provide the basic NS Power profile information to a customer calling in and requesting same. I was born in this province and have lived here most...
AI summary The text highlights a customer's complaint against NS Power for a security breach, lack of transparency, and risks to customers (e.g., credit theft, mortgage issues). It also criticizes NS Power's history of power outages, rate hikes, and poor customer service, urging government intervention.
ce of the Information and Privacy Commissioner for Nova Scotia Subject: Formal Privacy Complaint Regarding NS Power Data Breach and Insecure Remedial Platform (mytrueidentity.ca) Dear Commissioner, My name is YungYu Yeh, A victim of NS pow...
AI summary A privacy complaint is filed against NS Power regarding a data breach and the insecure remedial platform mytrueidentity.ca. The complainant highlights significant security flaws in the site, including unsafe headers, broken code, lack of HTTPS enforcement, and reliance on third-party scripts, which could expose sensitive data to attacks.
TransUnion credit monitoring services. When I called the number, I was connected with TransUnion. This limited response is not enough support for victims of a data breach of this size. In closing, I request that Nova Scotia Power immediate...
AI summary Melissa Marsh alleges a data breach by Nova Scotia Power (NSP) compromised her personal information, requesting detailed breach specifics, explanations for delayed notification, enhanced identity protection, and improved cybersecurity protocols. She criticizes NSP's current response as inadequate for protecting customer data and ensuring transparency.
arty. NSP was vague regarding any specifics of my personal information that was accessed. NSP, in the aforementioned correspondence, offered a two year account with credit reporting agency Transunion. I have specific concerns and questions...
AI summary A customer complains that NSP was vague about personal information accessed during a breach and provided inadequate customer service, including poor call handling and lack of contact options. The customer seeks clarification on what data was compromised and better support from NSP and the Government of NS.
and my questions and concerns are as follows: Precisely what personal information of mine was on file with you at the time your server was breached by an authorized third party? If I accept the Transunion account does that, from the perspe...
AI summary The customer raises concerns about a data breach at NS Power, inquiring about the personal information exposed, legal implications for class-action lawsuits, financial compensation for damages, and whether NS Power received data from third parties like solar providers.
and what information was received, and, if applicable, what specific information, including the entity from which the information was derived, did an unauthorized third party gain access? What level of accountability will NSP and/or the Go...
AI summary The complainant alleges unauthorized access to personal information by NSP, attributing the breach to inadequate safeguards and the government's sale of the power entity to NSP without ensuring data protection. They demand accountability from NSP and the government, criticizing the monopoly and lack of safeguards.
whether or not to pay the ransom. We obviously don't count. I appreciate your attention in this matter. Many thanks. Did they contact the utility? No How did the utility respond? Page 2 of 3 How do they want the Legal protection against id...
AI summary A customer lodges a formal complaint against Nova Scotia Power (NSP) for negligence in safeguarding data, leading to a data breach that resulted in identity theft and $30,000 in fraudulent losses. The complainant demands legal protection, compensation, transparency, and policy changes to prevent future incidents.
bers), hackers were able to directly contact my bank, , and use our personal information (from NS Power) to steal $30,000 by fraudulently transferring the money from . While I have received no response or communication from Nova Scotia Pow...
AI summary A customer alleges that Nova Scotia Power (NSP) failed to protect personal data, leading to a $30,000 fraud. The breach occurred in March 2025, but customers were notified only in May 2025. The complainant criticizes NSP's delayed response, lack of urgency in communication, and failure to address the breach promptly, holding NSP fully responsible for the theft.
appointed by the boards continuous approval of NSPowers requests for rate increases despite the cost of living in Nova Scotia already being at all time highs and wages not keeping pace with inflation. If the board continues to act as a rub...
AI summary The text contains two letters of complaint. The first criticizes the Nova Scotia Utility and Review Board for approving rate increases by NSP despite high living costs and stagnant wages. The second letter expresses concern over the collection of personal information, including SIN, and criticizes NSP's IT security practices.
From: Painting-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: FW: DRO 31 May re Sean Kelly re Data Breech Date: June 4, 2025 9:50:04 AM From: Sean Kelly Sent: June 3, 2025 10:27 PM To: [email protected] Cc: customer...
AI summary Sean Kelly criticizes the poor quality of regulations, arguing they favor the company and neglect customer privacy and data security. He questions the board's role in protecting Nova Scotians and highlights the lack of clarity on who is responsible for creating the regulations. He also references CMMC data security requirements and requests a meeting with the board.
Page 2 of 4 We are left unsure of what steps to take or what risks we truly face. 3. Inadequate Support NS Power offered 2 years of free credit monitoring via TransUnion of Canada Inc. While somewhat helpful, this offer falls short. Expert...
AI summary The customer expresses concerns about inadequate support following a data breach, questioning NS Power's data retention practices and requesting a meter inspection and billing review. They demand a full investigation into data security practices, compliance with privacy laws, and expanded protection for affected customers.
N-3Incident Report - Redacted
3 passages
..................................................... 14 10 4.2 Communications to Customers ......................................................................................... 18 11 4.3 Other Stakeholders ...............................
AI summary The document outlines a regulatory proceeding structure, including sections on stakeholder communication, personal information handling, impact analysis, and recommendations for enhancing cybersecurity, policy updates, and customer engagement. It references a specific direction (M12457) and emphasizes data privacy, security measures, and procedural improvements.
1 8.5 Collection and Retention of Personal Information 2 3 At the time of the Incident, NS Power had formally documented its approach to privacy compliance 4 through an established and robust suite of written privacy policies, procedures,...
AI summary NS Power has implemented privacy policies and procedures for the collection and retention of personal information. It no longer collects social insurance numbers (SINs) except for tax reporting purposes and is working to remove existing SINs from its systems. This change was made in 2018 and further actions were taken in 2024.
26 In limited circumstances, NS Power continued to collect SINs from customers where there was a 27 legal requirement to do so. SINs continued to be collected for tax reporting purposes where NS 17 Peter Gregg, President & CEO, Nova Scotia...
AI summary NS Power collected SINs for tax reporting in limited circumstances due to legal requirements. A cybersecurity incident report was filed in 2025, though the details are redacted. Peter Gregg, President & CEO of Nova Scotia Power, gave an opening statement to the Standing Committee on Natural Resources and Economic Development in November 2025.
N-5Refiled Incident Report - NSPI - Redacted
8 passages
1 8.5 Collection and Retention of Personal Information 2 3 At the time of the Incident, NS Power had formally documented its approach to privacy compliance 4 through an established and robust suite of written privacy policies, procedures,...
AI summary NS Power has implemented policies to collect, use, and retain personal information, including social insurance numbers (SINs), primarily for tax reporting. Prior to 2018, SINs were collected during account opening, but the practice was changed in 2018. Since 2019, efforts have been made to remove SINs from systems, with a goal to complete the removal by March 31.
1 Power was required to issue a T5 in connection with interest over $50 earned in a year on a 2 customer deposit. 3 4 In 2021, Nova Scotia Power initiated a customer energy management program called MyEnergy 5 Insights to better inform cus...
AI summary Nova Scotia Power implemented a customer energy management program called MyEnergy Insights in 2021, which involved exporting customer data to a cloud storage environment. This data was targeted by a threat actor, leading to the exposure of some customers' SINs. NS Power has since committed to permanently deleting SINs from its systems, with completion expected by March 31, 2026.
1 The OPC initiated an investigation into the Incident on May 28, 2025, and the Company is 2 actively and fully cooperating with the OPC to support the OPC’s investigative efforts. 3 The Company has also provided updates to the Nova Scotia...
AI summary The OPC initiated an investigation into an incident on May 28, 2025, and the Company is fully cooperating. The incident did not disrupt operations or impact customer service. The Company has taken a transparent approach, communicating through various channels to inform affected individuals and stakeholders.
tion in accessing its internal resources and external advisors, and assumes that any such external advisors will execute a confidentiality undertaking prior to their receipt of such confidential data. Similarly, NS Power is assuming that a...
AI summary NS Power outlines its approach to handling confidential data in the cybersecurity incident proceeding, including requiring confidentiality undertakings from external advisors and intervenors. It also confirms its commitment to providing timely responses to the Board's information requests and submitting the Incident Report by December 31, 2025.
ly 14, 2025), and will endeavour to complete and submit the report earlier, if possible. 2 Consistent with Rule 12 of the Board Regulatory Rules. REDACTED (CONFIDENTIAL INFORMATION REMOVED) Page 3 B. Request for Confidentiality Further to...
AI summary NS Power has submitted a request for confidentiality regarding its submission dated August 8, 2025, citing Rule 12 of the Board Regulatory Rules. The submission includes detailed reasons for confidentiality and consents to disclosure to intervenors with standing. The letter is signed by Adam Kardash of Osler and includes a statutory excerpt from PIPEDA.
Appendix “A” Statutory Excerpts Federal: Personal Information Protection and Electronic Documents Act (PIPEDA), SC 2000, c 5, ss. 20(1) -(1.1) Confidentiality 20 (1) Subject to subsections (2) to (7), 12(3), 12.2(3), 13(3), 19(1), 23(3) an...
AI summary This section outlines confidentiality provisions under federal and provincial legislation, including PIPEDA, PIPA BC, and PIPA Alberta, which restrict the disclosure of information obtained by commissioners and their staff while performing their duties.
or or under the direction of the Commissioner shall not disclose any information obtained in performing their duties, powers and functions under this Act, except as provided in subsections (2) to (4). REDACTED (CONFIDENTIAL INFORMATION REM...
AI summary The text outlines confidentiality obligations for the Commissioner and their staff, prohibiting the disclosure of information obtained during the performance of their duties, except under specific legal conditions. Similar provisions are mentioned in the Data Protection Act 2018 in the UK and the French Data Protection Act.
ybook (ITSM.00.099)” , at paragraph 3 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Page 7 In sum, there is a strong public interest in maintaining the confidentiality and limiting the distribution of certain details relating to the ransomwa...
AI summary The text discusses the importance of maintaining confidentiality regarding details of a ransomware attack, citing the need to protect sensitive information. It references Alison Wikoff's expertise in threat intelligence and its role in risk assessment and incident response.
98901Letter NSPI re: Application for Procedural Order and Request for Confidentiality
5 passages
Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, Ontario, Canada M5X 1B8 416.362.2111 MAIN 416.862.6666 FACSIMILE August 8, 2025 Adam Kardash Direct Dial: 416.862.4703 [email protected] Our Matter Number: 1268459 Sent...
AI summary NS Power seeks a procedural order and confidentiality for submissions related to a 2025 ransomware attack inquiry. The request emphasizes the sensitive nature of cybersecurity incident details, limiting access to panel members, the Clerk, and Board counsel.
further background facts are outlined in the Confidential Submissions. Page 2 B. Procedural Order Sought 4. Pursuant to Rules 5(2) and 5(3) of the Board Regulatory Rules, NS Power respectfully requests that the Board issue procedural order...
AI summary NS Power requests procedural orders to dispense with the Board's regulatory rules and adopt privacy regulator standards for a cybersecurity-related inquiry, citing public interest and collaboration needs. Confidential submissions detail the rationale, with emphasis on aligning with international privacy practices.
r seeking a determination. Rather, one or more individuals make a complaint to the regulator, and the regulator thereafter initiates a confidential investigative process. b. During the investigation, everything exchanged between the regula...
AI summary The process outlines how complaints are handled by the regulator through a confidential investigation. The regulator publishes a report detailing findings, company responses, and preventive measures, with the company allowed to comment on the draft. Complainants and intervenors are excluded from the inquiry process, with privacy regulations restricting their access to investigative records.
e Inquiry, the Clerk of the Board, and Board counsel. Submissions designated as “Board Confidential” will not be posted publicly nor made accessible to any other parties. e. To the extent that the Board intends to release a report on the i...
AI summary NS Power requests confidentiality for submissions to the Board, seeking review of draft reports and clarification on statutory provisions governing the Inquiry. The company emphasizes collaboration and transparency in the process, ensuring factual accuracy and protection of commercial information.
Rules, NS Power requests that the Confidential Submissions be held in confidence by the Board and be reviewed only to panel members involved in the Inquiry, the Clerk of the Board, and Board counsel. 16. The Confidential Submissions explai...
AI summary NS Power requests confidentiality for submissions related to a cybersecurity incident, arguing public disclosure would harm the public interest. The request is supported by Adam Kardash and NS Power executives, emphasizing the need to protect sensitive information.
98924Board letter re additional information required
4 passages
(and, if not, whether it has incurred or will incur expenses as a result that could be considered to have resulted from imprudence). Document: 323519 -2- Moreover, your client has a broadly stated mandate “to furnish service and facilities...
AI summary The Board raises concerns about NS Power's prudent investment in cybersecurity following a recent incident, questioning the adequacy of its operational technology protections and data handling practices. It challenges the confidentiality terms in the proposed procedural order, emphasizing the 'open courts' principle and referencing past proceedings (Matter M11181).
ower believes it is entitled to unilaterally designate information it may file as “Board Confidential” and expects that this claimed status will be accepted without review or question. • As the regulator, the Board must be able to access a...
AI summary NS Power claims unilateral authority to designate information as 'Board Confidential' without review. The Board counters that it must access internal/external resources, including technical advisors, which NS Power's restrictions would hinder, citing s. 15 of the Energy and Regulatory Boards Act.
• It may be appropriate for NS Power to review some filings in this proceeding for confidentiality, such as evidence filed by the parties (including Board Counsel consultants). The need for this may depend on the nature of the information...
AI summary The Board acknowledges NS Power's role in reviewing filings for confidentiality but emphasizes transparency in proceedings. It requests clarification on procedures related to utility investigations and information security, while balancing the need to protect sensitive data. The Board reaffirms its commitment to public disclosure where possible, despite security constraints.
and transparently as possible. The “Board Confidential” letter that you sent on August 8, 2025, does not sufficiently recognize that the Board’s regulatory processes are based on the “open courts” principle and does not reflect the Board’s...
AI summary The Board criticizes a 'Board Confidential' letter for insufficient justification of confidentiality claims, emphasizing transparency and public disclosure requirements. It demands detailed submissions for each paragraph, with a deadline of August 20, 2025, and requires explanations for why information cannot be shared with intervenors under confidentiality undertakings.
99040Letter on behalf of NS Power re confidentiality - Redacted
7 passages
Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, Ontario, Canada M5X 1B8 416.362.2111 MAIN 416.862.6666 FACSIMILE August 20, 2025 Adam Kardash Direct Dial: 416.862.4703 [email protected] Our Matter Number: 1268459 Sent...
AI summary Osler, Hoskin & Harcourt LLP responds to the Nova Scotia Energy Board's inquiry into a cybersecurity incident involving Nova Scotia Power (NS Power), reiterating NS Power's commitment to cooperation while emphasizing the need for confidentiality protections due to the sensitive nature of the information involved.
changed in this matter will be quite sensitive and require particularly strict confidentiality protection, and may warrant that it be provided only to the Board and no other parties in the proceeding. Investigations into cybersecurity inci...
AI summary The text emphasizes the need for strict confidentiality in the proceeding, citing cybersecurity investigations as a justification. It references Sherman Estate v. Donovan and highlights NS Power's expectation that the Board will scrutinize confidentiality claims, with a request for an oral hearing involving cybersecurity experts.
ity to further explain to the Board why it is necessary to hold the designated information in confidence, including, if necessary, through an oral hearing with the assistance of cybersecurity experts. NS Power appreciates the Board will wo...
AI summary NS Power emphasizes the need for confidentiality in cybersecurity-related information shared with the Board, requesting justification for strict confidentiality measures and assurances on data protection. It acknowledges the Board's extension for responding to information requests and intends to prioritize early responses. NS Power assumes advisors and intervenors will comply with confidentiality undertakings.
t 15, 2025, permitting the responses to be delivered on or before September 5, 2025. NS Power will endeavor to prioritize its efforts to respond to the IRs earlier than September 5, 2025, if possible. NS Power also confirms that it will pr...
AI summary NS Power commits to submitting an Incident Report by December 31, 2025, and providing monthly updates. It also requests confidentiality for a submission under Rule 12 of the Board Regulatory Rules.
eiterate NS Power’s commitment to working cooperatively and collaboratively with the Board throughout the Inquiry. Sincerely, Adam Kardash Partner and Co-Chair, Privacy and Data Management, Osler c. W. David Rankin, Osler Judith Ferguson,...
AI summary NS Power reaffirms its commitment to collaboration with the Board during the Inquiry. The document includes statutory excerpts from PIPEDA and PIPA BC, emphasizing confidentiality restrictions on information obtained by commissioners and staff. Key individuals involved include Adam Kardash (Osler) and Judith Ferguson (NS Power).
rection of the commissioner must not disclose any information obtained in performing their duties or exercising their powers and functions under this Act, except as provided in subsections (2) to (6). Alberta: Personal Information Protecti...
AI summary The text outlines confidentiality obligations for commissioners and their staff under Alberta's PIPA, the UK's Data Protection Act 2018, and France's 1978 Data Protection Act. These provisions restrict disclosure of information obtained during official duties, except as permitted by subsections in each jurisdiction's legislation.
France: Loi n° 78-17 du 6 janvier 1978 relative à l’informatique, aux fichiers et aux libertés (French Data Protection Act), Chapter II, Article 11 Art. II Les agents de la commission sont astreints au secret pour les faits, actes ou rense...
AI summary The French Data Protection Act (Loi n° 78-17) imposes strict confidentiality obligations on commission agents, requiring them to maintain secrecy regarding information obtained through their roles, with penalties under the Penal Code for breaches.
99375Board Letter re: Response to Monthly Update #1 and confidentiality
6 passages
ed on September 5, 2025, and are being reviewed by the Board. Those matters will be addressed under separate correspondence. Document: 324221 -5- Confidentiality NS Power has raised confidentiality issues relating to the filings in this ma...
AI summary NS Power requested confidentiality for submissions related to a procedural order in the proceeding, restricting access to Board panel members, the Clerk, and Board counsel. The Board acknowledged security concerns but emphasized the need for public transparency, stating some information cannot be disclosed due to stolen personal/confidential data.
tion that was stolen. However, the Board emphasized [in a letter dated July 14, 2025] that it was important that this proceeding be conducted as publicly and transparently as possible. The “Board Confidential” letter that you sent on Augus...
AI summary The Board criticizes a 'Board Confidential' letter for insufficient transparency, emphasizing regulatory processes must be publicly open. It demands detailed justifications for confidentiality claims, arguing much of the letter's content is non-sensitive and should be publicly disclosed. Submissions are due August 20, 2025, with confidentiality claims requiring full rationale.
tification must address not only the basis for the claim, but also why the information cannot be disclosed to intervenors under a confidentiality undertaking or with other protections. [Board Letter, August 12, 2025, p. 3] NS Power replied...
AI summary NS Power argues that privacy investigations by regulatory authorities provide useful models for the Board's confidentiality procedures. It emphasizes that such investigations typically occur confidentially, with limited disclosure, and acknowledges the Board's right to share 'Board Confidential' information with advisors who execute confidentiality undertakings.
any external Document: 324221 -6- advisors will execute a confidentiality undertaking prior to their receipt of such confidential data. It added: Similarly, NS Power is assuming that all Intervenors in the Inquiry will execute a confidenti...
AI summary NS Power emphasizes the need for confidentiality undertakings by advisors and intervenors due to the sensitive nature of data related to a cybersecurity incident. It requests the Board to maintain strict confidentiality for certain information and seek assurances on data protection measures, while consenting to share Appendix B with Formal Intervenors under standard processes.
ever, NS Power consented to the Board disclosing Appendix B and the Confidential Submission to the Formal Intervenors in this matter, under the Board’s normal process for confidentiality undertakings. As the Board has previously stated in...
AI summary NS Power agreed to the Board disclosing Appendix B and a Confidential Submission to formal intervenors. The Board clarified it is an economic regulator, not a privacy authority, and emphasized its 'open courts' principle. It noted it typically does not require confidentiality undertakings for external advisors like MNP Digital, though such advisors generally maintain confidentiality.
However, the Board’s engagement of advisors and consultants generally includes obligations to maintain and safeguard the confidentiality of information received in the performance of their engagement. That said, NS Power’s acknowledgement...
AI summary The Board emphasizes confidentiality obligations for advisors and consultants while allowing intervenors with formal standing to review confidential materials under a confidentiality undertaking. NS Power is directed to submit a draft undertaking, and the Board acknowledges the sensitivity of its confidential submissions, permitting objections to redactions.