N-1LOCs Redacted (N-1 from M12273)
10 passages
3. Identity Breach as Confirmation of Administrative Failure I am in possession of an identity breach notification issued by NS Power to a customer whose relationship with the company is governed by the same presumed contract structure I c...
AI summary The text discusses an identity breach by NS Power, highlighting administrative failures in the contracting frameworks approved by NSERBT. It argues that these frameworks fail to protect residents and lack legal authority to handle sensitive personal information without valid contracts.
Sent Via Email Premier Tim Houston Office of the NS Privacy Officer I am writing to formally complain about Nova Scotia Power's handling of its recent security breach. I am deeply concerned about both the theft of my personal information a...
AI summary The letter from the Premier Tim Houston Office of the NS Privacy Officer expresses concern over Nova Scotia Power's delayed and inadequate response to a security breach that occurred in March 2025, with notification only given in May 2025.
5. Indications of Neglect: - Outdated copyright (2019). - Use of deprecated security practices (e.g., X-XSS-Protection). - No evidence of recent updates or audits. Given these findings, I strongly believe that this "remedial" service may f...
AI summary The document highlights cybersecurity concerns related to an outdated service used by NS Power, noting outdated copyright and deprecated security practices. It requests an investigation into due diligence and alignment with privacy laws, emphasizing potential risks to Nova Scotians.
A TransUnion® Information Solution FAQs Terms and Conditions Privacy Policy Accessibility Security Analysis by Meng Cheng From: Painting-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: FW: Nova Scotia Power Privacy Date: May 26,...
AI summary This email discusses a privacy-related matter involving Nova Scotia Power, with Melissa Marsh contacting the privacy officer and various stakeholders, including the NSUARB and the Premier, regarding privacy concerns.
ay 23, 2025. While your letter acknowledged that my personal data had been stolen by an unauthorized third party, it didn't meet acceptable standards for breach notification in several important ways: - 1. Lack of Specific Information: The...
AI summary The letter criticizes Nova Scotia Power for inadequate breach notification following a data theft, citing lack of specific information, no guidance on next steps, and minimal support. It requests detailed disclosure, explanation of the delay, enhanced identity protection, clear guidance, and improved cybersecurity protocols.
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...
AI summary Nova Scotia Power has informed customers of a cyber incident where unauthorized access occurred on March 19, 2025, leading to the potential exposure of personal information. The company has engaged cybersecurity experts and notified authorities. As a precaution, customers are being offered free credit monitoring through TransUnion.
ds for breach notification in several important ways: Lack of Specific Information: The letter mentioned broad categories of compromised data but didn't specify what particular information was stolen. As a victim of the company's security...
AI summary The text discusses a data breach notification by Nova Scotia Power, which was criticized for being vague and lacking specific information about the compromised data. The notification failed to clearly state that the SIN was breached and provided minimal guidance or support to affected individuals.
n where granular technical specifics are filed confidentially. A confidentiality claim over implementation detail should not be permitted to withhold the basic fact of where Nova Scotians' data lives. Question 1 — Vendor and processor inve...
AI summary The text outlines two questions related to data privacy and transparency, focusing on the inventory of third-party vendors and the locations where customer personal information is stored and processed by Nova Scotia Power. It emphasizes the need for full disclosure of data handling practices.
ower customer personal information is (a) stored at rest, (b) processed, and (c) backed up or replicated. Where a single entity uses multiple regions, identify each and the data category held in each. Question 3 — Bidgely Inc., specificall...
AI summary The document outlines several questions regarding the handling of customer personal information by NS Power, focusing on data storage, processing, and transfer. It specifically addresses data residency, subprocessors, and safeguards for cross-border data transfers involving Bidgely Inc. and other vendors.
nt, and the Customer Information System replacement store or process customer personal information. For each, provide the storage and processing location per Question 2 and the vendor per Question 1. Question 10 — Customer-facing disclosur...
AI summary The text outlines several questions regarding NS Power's handling of customer data, including storage locations, vendor processing, and disclosure practices. It also raises concerns about affordability analytics and data confidentiality. The author requests transparency on jurisdictional data storage and processing and limits confidentiality claims to genuine security details.
N-9NSPI (INQ Law) RIRs 1-7
6 passages
1 Request IR-1: 2 3 With respect to privacy policies and procedures, please provide the following documentation. 4 If any of the documents are not available, please provide the reasons for each request. 5 6 (a) Privacy training policy and...
AI summary The document outlines a request for information regarding privacy policies and procedures, including training programs, staff completion rates, and breach response plans. NS Power provides details on their ongoing privacy training, with 96% of assigned modules completed in 2024.
1 Request IR-2: 2 3 With respect to governance and risk management processes addressing privacy risks, please 4 provide the following documentation or information, as applicable. If any of the documents 5 or information is not available, p...
AI summary The document requests information on Nova Scotia Power's privacy governance and risk management processes, including policies, procedures, and audit plans related to data collection, consent management, and privacy officers. A response indicates that relevant materials have been provided as confidential attachments.
1 As noted in the Incident Report (Section 5, and 8.4), NS Power has been working to 2 enhance its overall privacy governance framework and build on its existing privacy 3 program (policy, procedures and standards). The updated framework i...
AI summary NS Power has been enhancing its privacy governance framework, informed by the AICPA's Privacy Management Framework. They have provided their privacy policy and related procedures, and have a designated privacy officer with contact information available on their website.
ntial Attachments 1 and 2 to NS Power's response to NSEB IR-9 set 26 out its practices relating to data minimization. NS Power manages customer consent for 27 the collection, use and disclosure through its privacy policy, and in alignment...
AI summary NS Power outlines its data minimization practices and privacy governance framework in response to NSEB IR-9, emphasizing customer consent and alignment with its privacy policy.
30 1 (g) NS Power did not conduct a formal audit of access to personal data of customers in the 2 14 or Critical Customer Communication Program. The impacted information related 15 to these programs consists of personal information that in...
AI summary NS Power did not conduct a formal audit of access to personal data of customers in the Critical Customer Communication Program. The impacted information includes customer account history, power consumption data, service requests, and payment and billing history stored on affected servers.
(a) NS Power's "Access to Personal Information Procedure" has been provided as Confidential Attachment 4 to NSEB IR-9 . (b-d) NS Power employs an established access request response procedure which is designed to ensure a standard response...
AI summary NS Power faced a surge in access requests and privacy complaints following a cybersecurity incident, which required significant resource allocation. NS Power could not respond to all requests within 30 days but addressed them within 60 days. Privacy complaints were often tied to access requests and were handled similarly due to resource constraints.
N-10NSPI (NSEB) RIRs 1-25 - Redacted
4 passages
CONFIDENTIAL (Attachment Only) 1 set out as Confidential Attachment 12. A sample of those materials have been provided as 2 Confidential Attachments 14-18. 3 4 Sample Privacy Training Materials: 5 6 Attachment Policy/Procedure/Guidelines 7...
AI summary This document outlines NS Power's efforts to enhance its privacy governance framework following a privacy incident. It discusses the implementation of an enhanced privacy program aligned with internal policies and applicable laws, informed by the AICPA's Privacy Management Framework. NS Power's Privacy Policy details information retention standards for customers.
CONFIDENTIAL (Attachment Only) 1 More specifically, NS Power maintains internal records-management retention standards 2 (see Confidential Attachments 9 and 10), which establish the length of time records 3 are retained to meet customer se...
AI summary This document discusses NS Power's internal records-management retention standards, which are maintained to meet customer service, operational, legal, and regulatory requirements. It also mentions the retention of customer data beyond standard time frames and NS Power's efforts to enhance its privacy governance framework following an incident.
Customer Privacy Policy Nova Scotia Power Incorporated (NSPI) recognizes the importance of protecting our customers' privacy. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs how we collect, use and...
AI summary Nova Scotia Power Incorporated (NSPI) outlines its commitment to protecting customer privacy under the federal PIPEDA. The policy applies to personal information about individuals and not to information about organizations or businesses.
Privacy Statement Protecting the privacy and security of customer information has always been a part of how Nova Scotia Power serves its customers. Today, our Privacy Policy and procedures are consistent with the Federal requirements set o...
AI summary Nova Scotia Power outlines its commitment to protecting customer information in accordance with PIPEDA, emphasizing privacy and security in data collection, use, and storage practices.
N-13Evidence - InterGroup, on behalf of CA - Redacted
5 passages
history, payment and billing information and in some cases Social Insurance Numbers.[4](#page-5-7) Since the event was discovered, the Utility has taken the following steps[:](#page-5-9) 5 - 1) Mitigation and Restoration – containment, era...
AI summary This section outlines the steps taken by the Utility following a data breach, including mitigation efforts, customer communication, stakeholder notification, and response analysis. The breach affected over 375,000 accounts, and customer billing was non-functional until June. The Utility believes its response was sufficient, though some areas for improvement were identified.
5.0 COLLECTION AND RETENTION OF CUSTOMER INFORMATION NS Power's cybersecurity incident investigations showed that certain personal customer information for both current and former customers was exfiltrated from the system. Depending on the...
AI summary NS Power experienced a cybersecurity incident resulting in the exfiltration of personal customer information. The document discusses NS Power's data collection and retention practices, referencing PIPEDA and noting issues revealed by the incident. InterGroup highlights the requirement for clear purposes in data collection and consent for new uses.
s Retention Schedule[31](#page-12-9) maintained by Emera but no further specific information was provided. InterGroup's review of NSP's customer data retention process indicates a number of concerns: - 1. Lack of transparency in NSP's inte...
AI summary The document highlights concerns about the lack of transparency in Nova Scotia Power's (NSP) customer data retention policies. NSP relies on its parent company Emera's records management standards, but no specific documentation was provided to support its 'Records Retention Schedule'. This lack of clarity raises concerns about how long customer data is retained.
osure. As noted in the letters of comments, impacted customers are interested in knowing exactly which specific information of theirs was compromised. Excerpts of customers complaints are shown below: "I want more detailed information abou...
AI summary Customers are requesting detailed information about the data breach, including what specific personal information was compromised. NS Power acknowledges that the impacted data varied by customer but cannot determine precisely what information was affected for each individual. InterGroup recommends a further review to specify the nature of the breach for each customer category and notify customers once completed.
6.3 COMMUNICATION TO FORMER CUSTOMERS NS Power determined that personal information of former customers was also impacted by the breach and provided a public notification on June 25, 2025.[59](#page-18-1) With respect to communication to i...
AI summary NS Power notified the public about a data breach affecting former customers but did not directly contact them due to lack of updated contact information. A recommendation is made for NSP to explore ways to reach former customers who may have relocated outside the province.
N-14Evidence & Appendix A Resume - Tricia Ralph INQ Law/Consulting - BCC
9 passages
- 1. In my opinion, the following met best practice, and were reasonable in terms of expectations for customer service and limiting the impacts of the cybersecurity attack on customers: - Aside from issues related to the personal informati...
AI summary The text evaluates Nova Scotia Power Incorporated's (NSPI) response to a cybersecurity attack, finding some actions reasonable and others unreasonable. Key points include the reasonableness of customer notification timelines and communication efforts, while the use of a PI inventory, retention of SINs, and insufficient customer notices were deemed unreasonable.
B. Introduction - 1. I have been retained by Counsel for the Nova Scotia Energy Board ("NSEB") to carry out a review of NSPI's privacy related practices in relation to the cybersecurity incident NSPI identified on April 25, 2025 (the "Inci...
AI summary This report outlines a review of NSPI's privacy practices following a cybersecurity incident identified on April 25, 2025. The reviewer was retained by the Nova Scotia Energy Board to assess the reasonableness of NSPI's actions in delivering services to its customers.
D. Methodology 5. In order to come to my opinions, I reviewed the 2025 Nova Scotia Power's Cybersecurity Incident Report (the "Incident Report") and responses to my Information Request ("IR") to NSPI, as well as relevant information in oth...
AI summary The methodology section outlines the review of NSPI's 2025 Cybersecurity Incident Report and responses to an information request, using PIPEDA principles as a benchmark for evaluating the reasonableness of NSPI's actions without interpreting PIPEDA itself.
Audits 31. A commonly expected practice in terms of privacy management governance practices is to periodically audit internal access to PI to ensure that access to PI is only done for legitimate business needs. In its response to my IR-2,...
AI summary The document discusses the importance of conducting periodic audits of internal access to personal information (PI) as part of privacy management governance. NSPI did not conduct such audits in the two years before the Incident, but it is unlikely this lack contributed to the Incident. The document recommends that NSPI should implement these audits to ensure proper access to PI.
- 50. In its notification letters, NSPI explained that the impacted data would have varied by customer, and depended, in part, on the information a customer would have provided NSPI. The types of PI that customers were notified as having p...
AI summary NSPI informed customers of a data breach affecting personal information, including names, addresses, SINs, and account details. Customers were concerned about the lack of specific information on impacted data and the difficulty in taking protective measures. NSPI could not definitively identify the data impacted on an individual basis.
Issue 4 – Collection and Retention of Customer Information - 58. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions in delivering services to its customers concerning collection and retention of custo...
AI summary The document discusses the reasonableness of NSPI's collection and retention of customer information under PIPEDA, focusing on principles such as limiting collection and retention periods. The Board counsel requests an opinion on NSPI's actions related to customer data handling.
Reasonableness of Type of PI Collected - 62. In response to NSPI (INQ Law) IR-4, NSPI noted that as disclosed in its publicly available Customer Privacy Policy (Attachment 13 to NS Power's response to NSEB IR-9), the types of information w...
AI summary NSPI explained the types of personal information collected from customers, including contact details, identifying information, payment details, and demographic data, in response to a query regarding the reasonableness of the information collected.
NSPI's Retention and Destruction Policies, Procedures and Implementation - 70. An organization with a robust privacy program should both have and follow comprehensive retention and destruction policies and procedures. - 71. As set out NSPI...
AI summary The document discusses NSPI's retention and destruction policies and procedures, noting that while they were generally comprehensive and aligned with best practices, they lacked a records retention schedule. Additionally, NSPI did not maintain records of destruction activities, which is considered unreasonable given the volume of records it manages.
Reasonableness of length of Time PI was Retained - 76. As NSPI's record retention schedule was not provided, it is not possible for me to opine on whether the periods of time that NSPI established by information/record type were reasonable...
AI summary The review found that NSPI did not adhere to its own internal record retention standards for personal information, leading to unreasonable retention periods. This lack of compliance negatively impacted customer services by allowing threat actors to exfiltrate data that should have been deleted.
N-16NSPI Refiled Formal Incident Report - Redacted (filed in M12273 as N-5 on April 27, 2026)
8 passages
1 3.2 Data & Personal Information 2 3 . The process to 4 identify the customers who were directly impacted has been extremely complex, and has been 5 completed. As set out in the notices sent to impacted customers, the impacted data would...
AI summary The document discusses the complexity of identifying customers impacted by a data breach involving NS Power. It outlines the types of personal information accessed, including names, contact details, account history, and sensitive identifiers like SIN and bank account numbers. Two versions of notification letters were issued depending on whether a customer's SIN was affected.
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...
AI summary Nova Scotia Power informed customers of a cyber incident on April 25, 2025, where unauthorized access occurred to parts of its Canadian network. Customer information, including personal and account details, was accessed. The company is offering free credit monitoring and advising customers to be cautious of unsolicited communications.
A. Clarification of the Procedural Order Sought NS Power understands that the Board applies the "open courts" principle, which allows for proportionate, public interest-based exceptions.1 Our client appreciates the Board's recognition that...
AI summary NS Power seeks clarification on the procedural order regarding the handling of sensitive information in cybersecurity investigations, referencing the 'open courts' principle and the need for confidentiality. They reference privacy regulatory procedures and attach statutory provisions for reference.
B. Request for Confidentiality Further to the Board's request, attached to this letter as Appendix B are detailed reasons why NS Power's confidential submission of August 8, 2025 (the Confidential Submission ) should be held in confidence...
AI summary NS Power has submitted a request for confidentiality regarding its submission to the Board, citing Rule 12(2) of the Board Regulatory Rules. It agrees to allow the Board to disclose the information to intervenors who have been granted standing. NS Power expresses willingness to provide further information and reaffirms its commitment to cooperation with the Board.
Confidentiality 20 (1) Subject to subsections (2) to (7), 12(3), 12.2(3), 13(3), 19(1), 23(3) and 23.1(1) and section 25, the Commissioner or any person acting on behalf or under the direction of the Commissioner shall not disclose any inf...
AI summary This section outlines confidentiality obligations for the Commissioner and those acting on their behalf, prohibiting the disclosure of information obtained through the performance of duties under this Part, except as specified in certain subsections and sections of the legislation.
Confidentiality — reports and records (1.1.) Subject to subsections (2) to (7), 12(3), 12.2(3), 13(3), 19(1), 23(3) and 23.1(1) and section 25, the Commissioner or any person acting on behalf or under the direction of the Commissioner shal...
AI summary This section outlines confidentiality rules regarding reports and records, stating that the Commissioner or their representatives must not disclose information from specific reports or records. It references the Personal Information Protection Act (PIPA BC) from British Columbia.
Confidentiality of information 132 (1) A person who is or has been the Commissioner, or a member of the Commissioner's staff or an agent of the Commissioner, must not disclose information which— - (a) has been obtained by, or provided to,...
AI summary This section outlines confidentiality obligations for the Commissioner and their staff, prohibiting the disclosure of non-public information obtained in the course of their duties, unless authorized by law. It also references the French Data Protection Act, which imposes similar confidentiality requirements on commission agents.
Unofficial Translation Art II The commission's agents are bound to secrecy with regard to facts, acts or information of which they may have become aware by reason of their functions, under penalty of the sanctions provided for in Article 4...
AI summary This section outlines the confidentiality obligations of the commission's agents, requiring them to maintain secrecy regarding information obtained through their functions, with penalties under the Penal Code. It also mentions the exception for information necessary for the annual report.
N-17NS Power Rebuttal Evidence - Redacted
10 passages
Cybersecurity Accountability REDACTED provide the most meaningful incentive for accountability while avoiding unintended consequences that could impair employees' ability to perform their duties and serve customers effectively. Recommendat...
AI summary The document discusses recommendations for improving NS Power's privacy policy, including specifying the business purpose and retention period for customer data. It notes that NS Power's current policies are under review by an external firm and align with PIPEDA obligations. A reference is made to an incident report and related exhibits.
5.0 EVIDENCE OF INQ LAW - NS Power acknowledges that the INQ Evidence may assist the Board in understanding privacy - concepts and generally accepted privacy practices. However, care must be taken in assessing Ms. - Ralph's conclusions reg...
AI summary NS Power acknowledges the INQ Evidence may help the Board understand privacy practices but argues that the Board's task is to assess the reasonableness of its actions as a regulated utility, not whether it complied with privacy law. The OPC is recognized as having expertise in privacy compliance.
The reasonableness of NS Power 's actions regarding use of a PI inventory. INQ notes: An adequate PI inventory as a privacy program control is a critically important building block. In their guidance, the regulators explain that organizati...
AI summary The document discusses concerns regarding the adequacy of NS Power's PI inventory practices, noting that NSPI did not provide a copy of the inventory and claimed it could not determine what data points were exposed during an incident, raising questions about the completeness of their privacy program controls.
Cybersecurity Accountability REDACTED each number. This was done to mitigate the risk of adverse impacts within CIS as the removal of the data / line-item could have broader implications within the system and result in catastrophic impacts...
AI summary NS Power addressed cybersecurity risks in its Customer Information System (CIS) by replacing SINs with zeros to mitigate data risks. The manual removal process was slow and resource-intensive, leading to the presence of customer data in the Azure Data Lake. The Data Lake was encrypted, but automatic data removal settings were not enabled for the affected area. Post-attack, the Data Lake is on legal hold and will be destroyed once released.
6.0 PIPEDA AND THE ROLE OF THE OFFICE OF THE PRIVACY COMMISSIONER - The Personal Information Protection and Electronic Documents Act (PIPEDA) is federal privacy - legislation that governs how private-sector organizations collect, use, reta...
AI summary The document discusses the incident involving NS Power and the Office of the Privacy Commissioner (OPC) under PIPEDA. NS Power reported a privacy breach to the OPC, cooperated with the investigation, and signed a Compliance Letter outlining measures to safeguard personal information, including data segregation and third-party security assessments.
7.0 NS POWER'S ENHANCED PRIVACY GOVERNANCE PROGRAM Beyond the circumstances of this Attack and the response to it, the Company recognizes that the privacy, cybersecurity, and related regulatory landscape is ever evolving with significant a...
AI summary NS Power is enhancing its privacy governance program in response to evolving regulatory and technological challenges, including Bill C-36 and the increasing use of AI. The company is strengthening its privacy framework, policies, and oversight mechanisms, with a dedicated Privacy Officer role being formalized and elevated in the organizational structure.
8.0 CONCLUSION Over the past 16 months, the team at NS Power has worked around the clock to restore and strengthen all systems and to support its customers. NS Power acknowledges the significant impact the Attack and consequent privacy bre...
AI summary NS Power acknowledges the impact of a cyberattack and subsequent privacy breach on its customers and emphasizes its commitment to transparency, customer support, and continuous improvement. The company asserts that its response was reasonable and customer-centered, and requests that the Board's findings align with the evidence provided, preserving normal regulatory processes while recognizing its commitments.
9 2.0 QUALIFICATIONS - 10 I am Co-Chair of Greenberg Traurig's U.S. Data Privacy and Cybersecurity Practice. Since 2012, - 11 I have advised clients on more than a thousand data security incidents, including ransomware, - 12 extortion, bus...
AI summary The individual is a Co-Chair of Greenberg Traurig's U.S. Data Privacy and Cybersecurity Practice, with extensive experience in data security incidents and breach response. They have advised on breach notification obligations, including Canadian requirements, and have reviewed findings from the Ralph Report and Mollard Report, noting areas of disagreement and overlooked considerations.
Cybersecurity Accountability Rebuttal Attachment 1 Page 4 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 questions of legal interpretation...
AI summary Jena Valdetero, an expert in data security and privacy law, provides an opinion on whether NS Power acted reasonably in response to a cybersecurity incident. She has extensive experience managing data security incidents and advising on privacy laws, including PIPEDA and similar legislation.
15 (b) Current Customer Notification Speed Does Not Establish What Was Feasible for 16 Former Customers 17 Based on the information in the record and information obtained from individuals directly involved 18 in the Incident response, NS P...
AI summary NS Power quickly notified current customers of a data breach by using existing customer data, but faced challenges in notifying former customers due to the lack of current contact information, which is common given the transient nature of the customer base and the presence of universities in Nova Scotia.
101930Confidential Undertaking
3 passages
- 1. NS Power will provide Designated Confidential Information, as defined herein, to the Designated Recipient as defined in the undertaking to which this schedule is attached. - 2. Designated Confidential Information shall consist of mate...
AI summary NS Power will provide designated confidential information to a specified recipient, including financial data, internal policies, and information related to a cyber incident, as defined in the undertaking attached to this schedule. This information has been filed with the Nova Scotia Energy Board and may be subject to future information requests.
- 5. No Designated Confidential Information furnished by NS Power shall be given or communicated to persons other than the Designated Recipients. For greater certainty, no Designated Confidential Information shall be provided to the client...
AI summary This section outlines rules for handling designated confidential information in the proceeding, including restrictions on disclosure, requirements for referencing such information in legal documents, and procedures for handling confidential submissions and appeals.
laws and procedures but under seal and designated confidential. - 9. (a) Unless otherwise precluded by law, within 30 days after the Board has reached a final decision in this proceeding, each person to whom Designated Confidential Informa...
AI summary The text outlines procedures for returning and handling Designated Confidential Information following a final decision by the Board. It specifies that recipients must return or destroy such information, with exceptions for members of the Nova Scotia Barrister's Society who may retain it for client-related purposes. The use of this information is restricted to regulatory proceedings involving NS Power.
20260818-1Hearing Transcript — 08/18/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams)
5 passages
NOVA SCOTIA POWER PANEL 165 Cr-ex, (MacAdam) 1 A. (Lanteigne) That's my 15 part it is being responsive to the issues she's raised. 16 Q. Okay. And the audit of the Data 17 Lake, would that have included I know she was referring 18 specific...
AI summary The discussion revolves around an audit of the Data Lake conducted in December 2024, focusing on whether it included a review of access permissions to ensure only legitimate users had access. Concerns about the confidentiality of the audit were raised, and the auditor was cautious about responding fully.
GLEN MacLEOD, Resumed: 17 off when he was saying "My question is". 18 MR. MacLEOD: It's all good. Right. 19 BY MR. MacLEOD: INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 So my question is, did you spend Q. 2 any time or does NSP...
AI summary The proceeding involves a question from Glen MacLeod regarding whether NSP has consulted with the RCMP to understand the ramifications of data breaches, specifically in the context of data protection and breach analysis.
NOVA SCOTIA POWER PANEL 223 Cr-ex, (Rudderham) 1 It's Exhibit N-8. It's the Q. 2 See that there? 3 [2:20:11] MR. CLARKE: Just hold on one second, 4 please. 5 Can you scroll down? 6 MS. RUDDERHAM: I was just reading the 7 question that was...
AI summary The text is a transcript excerpt from a regulatory proceeding involving Nova Scotia Power Inc. (NSPI) and includes a reference to a confidential attachment. The discussion centers on NSPI's anticipation of costs beyond December 31, 2026.
NOVA SCOTIA POWER PANEL 333 Cr-ex, (Mahody) 1 within what is understood and known to be a very fragile INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 process was the CSRs would then, when they encountered 2 a SIN number, nine-dig...
AI summary The text discusses a proceeding involving Nova Scotia Power and the handling of Social Insurance Numbers (SINs) in their system. It outlines the process used from 2018 to 2024 to remove SINs, with the company acknowledging it could not provide a precise count of removed SINs. A new process was initiated in May 2024, and documentation of this process was referenced.
NOVA SCOTIA POWER PANEL 351 Cr-ex, (Mahody) 1 4? 2 BY MR. MAHODY: 3 Yes. Q. 4 (Williams) So I think A. 5 It's Attachment 1; so it's at the Q. 6 end of IR-1. IR-1 was 18 pages. Thank you very much. 7 And Mr. Williams, if you're okay, I 8 ju...
AI summary The discussion revolves around the handling of personal information, specifically Social Insurance Numbers (SINs), in correspondence sent to customers. The focus is on the clarity of language used in letters sent to customers, with an emphasis on distinguishing between those whose SINs were included and those who were not.
20260819-1Hearing Transcript — 08/19/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams)
3 passages
I N D E X O F P R O C E E D I N G S August 18, 2026 PAGE NO. 2 So just moving up to the top of the 3 page, then, about the retention schedule and Personal 4 Information Inventory, I just wanted to confirm that the 5 Personal Information In...
AI summary The text discusses a rebuttal affidavit submitted by Nova Scotia Power, specifically focusing on the Personal Information Inventory attached as a confidential attachment. The inventory is used to identify personal information held by Nova Scotia Power and its storage locations. This is the first time the inventory has been presented in the proceeding.
NOVA SCOTIA POWER PANEL 491 Questions, (Deveau) INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 2020, that the date on their last reviewer. They would 2 not have been reviewed in the interim between 2020 and 3 now, just because th...
AI summary The discussion revolves around the review of privacy policies by Nova Scotia Power, referencing the existing legislation in 2020 and the impact of new federal legislation and AI technology on the need for policy updates. The speaker affirms that the policies at the time of the incident complied with applicable privacy legislation.
NOVA SCOTIA POWER PANEL 553 Questions, (Chair) 1 We can pull it up quickly. It's a 2 reference to the scanning tool that was used to remove the 3 Social Insurance Numbers, and there's a reference that 4 once it's kind of –– you're comforta...
AI summary The discussion revolves around the use of a scanning tool within Microsoft 365 to identify and remove personal information, including Social Insurance Numbers, and its potential future expansion to other types of personal data. The tool is currently used to scan Microsoft systems like Outlook, SharePoint, and OneNote.