Topic/Matter Intersection

Topic:"Information Disclosure" in M12600

Matter: Nova Scotia Power - Cybersecurity Accountability IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED’s collection and retention of customer information, customer service and communications, billing processes and regulatory matters
99 passages 34 documents

Information Disclosure across all matters →

N-1LOCs Redacted (N-1 from M12273) 5 passages
\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \ p. p. 36
- Precisely what personal information of mine was on file with you at the time your server was breached by an authorized third party? - If I accept the Transunion account does that, from the perspective of NS Power, prevent me from enterin...

AI summary The individual is inquiring about the personal information held by NS Power following a security breach, seeking clarification on legal recourse, financial liability, and accountability from NS Power and the Government of Nova Scotia. They are concerned about the misuse of their data and the lack of safeguards after the privatization of the power entity.

Contact Information p. pp. 51-89
Contact Information Name on account: Lisa Winch Account number: \ \ \ \ \ \ \ \ Business contact: Account address: Address 1: \ \ \ \ \ \ \ \ Address 2: \ \ \ \ \ \ \ \ City: \ \ \ \ \ \ \ Province: \ \ \ \ \ \ \ Postal code: \ \ \ \ \ \ \...

AI summary A customer of NS Power reports that their personal and financial information was compromised in a ransomware attack, leading to identity theft and financial fraud. The customer criticizes NS Power for not providing adequate legal protection or compensation, and calls for stronger transparency, policy changes, and consumer support measures.

Section 174 p. p. 146
eding does not currently establish where customer personal information is stored, which vendors and subprocessors hold it, in what jurisdiction, or what exposure that creates to foreign legal process. Why this is within the inquiry's scope...

AI summary The document highlights concerns about where customer personal information is stored, who has access to it, and the implications for ratepayers. It argues that this information is central to the inquiry and the Board's mandate, as it relates to prudent utility practices and ratepayer costs. The request is for the Board to require NS Power to disclose jurisdiction-level information about data storage and legal exposure, even if technical details are confidential.

Section 175 p. p. 146
n where granular technical specifics are filed confidentially. A confidentiality claim over implementation detail should not be permitted to withhold the basic fact of where Nova Scotians' data lives. Question 1 — Vendor and processor inve...

AI summary The text outlines two questions related to data privacy and transparency, focusing on the inventory of third-party vendors and the locations where customer personal information is stored and processed by Nova Scotia Power. It emphasizes the need for full disclosure of data handling practices.

Section 178 p. p. 146
nt, and the Customer Information System replacement store or process customer personal information. For each, provide the storage and processing location per Question 2 and the vendor per Question 1. Question 10 — Customer-facing disclosur...

AI summary The text outlines several questions regarding NS Power's handling of customer data, including storage locations, vendor processing, and disclosure practices. It also raises concerns about affordability analytics and data confidentiality. The author requests transparency on jurisdictional data storage and processing and limits confidentiality claims to genuine security details.

N-2NSPI (NSEB) RIR 1 to 12 - Redacted (N-2 from M12273) 1 passage
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests p. pp. 11-56
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests 1 • Monday, April 28, 2025 27 Mainland (noted in chart below), as well as information being shared with 28 AllNovaScoti...

AI summary The document outlines the Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) and includes NSPI responses to NSEB Information Requests. It notes the involvement of media outlets such as AllNovaScotia.com, Global Halifax, MBS Radio, Halifax Examiner, and the Chronicle Herald.

N-3Incident Report - Redacted (N-3 from M12273) 2 passages
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED p. pp. 3-4
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 The NSEB replied to the Premier by letter on December 10, 2025, providing, in part, the following: 2 3 4 5 6 Upon receipt of your letter, the Board opened a new matter (M126...

AI summary The NSEB opened a new matter (M12600) following a letter from the Premier, considering whether issues raised should be addressed in the ongoing cybersecurity inquiry (M12273) or separately. NS Power argues that M12273 is the appropriate proceeding to address the issues, as many were already covered in prior reports and the second set of Information Requests (IRs) focuses on customer billing.

1 3.2 Data & Personal Information p. pp. 10-12
1 3.2 Data & Personal Information 2 3 The process to 4 identify the customers who were directly impacted has been extremely complex, and has been 5 completed. As set out in the notices sent to impacted customers, the impacted data would ha...

AI summary The process to identify customers directly impacted by a data breach has been completed. The breach involved access to personal information such as names, contact details, account history, and SINs. The Company issued two versions of notification letters to affected customers, varying slightly in the information provided about the breach.

N-6NSPI (CA) RIR 1-11 - Redacted 3 passages
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Consumer Advocate Information Requests
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Consumer Advocate Information Requests 1 (d) Threshold for phishing is <= 3 percent Cyber Security phish failure rate following the 2 removal of the...

AI summary The document discusses Nova Scotia Power Inc.'s responses to information requests regarding cybersecurity phishing thresholds and customer data retention standards. It references the NSPI Customer Privacy Policy and compliance with PIPEDA.

NON-CONFIDENTIAL
NON-CONFIDENTIAL 1 Request IR-3: 2 3 Customer Data Retention 4 5 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 40, 6 ll. 10-24 7 8 Quote: 9 10 With respect to the collection and retention of customer...

AI summary The document discusses NSPI's process of collecting and purging customer social insurance numbers (SINs). It notes that SINs were collected until 2018, but were removed from systems by 2024. The request asks NSPI to confirm that all SINs have been purged from their systems.

Section 16
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Consumer Advocate Information Requests

AI summary The Minister of Energy is seeking accountability from Nova Scotia Power Inc. (NSPI) regarding responses to information requests from the Consumer Advocate. This proceeding involves NSPI's compliance with information disclosure requirements and transparency in its operations.

N-7NSPI (David MacLeod) RIRs C-4 to E-2 1 passage
1 Request IR C-4: p. p. 3
1 Request IR C-4: 2 3 (a) Provide a complete timeline of NSP's notifications to regulatory and law 4 enforcement bodies following discovery of the Attack, including: 5 6 (i) notification to the NSEB / UARB; 7 8 (ii) notification to the Off...

AI summary The document requests a timeline of NSP's notifications to regulatory and law enforcement bodies following a cyber attack, and details on NSP's data inventory and retention practices. NSP responded by referencing sections of the Incident Report and existing information requests for data inventory details.

N-9NSPI (INQ Law) RIRs 1-7 2 passages
30
30 1 (g) NS Power did not conduct a formal audit of access to personal data of customers in the 2 9 (b) Amount of access to information requests made by customers related to the 10 cybersecurity incident. 11 12 (c) Information about whethe...

AI summary The document outlines a series of information requests related to a cybersecurity incident, focusing on customer data access, response times, and privacy complaints. These requests are part of an inquiry into NS Power's handling of customer data and privacy issues.

Section 14
(a) NS Power's "Access to Personal Information Procedure" has been provided as Confidential Attachment 4 to NSEB IR-9 . (b-d) NS Power employs an established access request response procedure which is designed to ensure a standard response...

AI summary NS Power faced a surge in access requests and privacy complaints following a cybersecurity incident, which required significant resource allocation. NS Power could not respond to all requests within 30 days but addressed them within 60 days. Privacy complaints were often tied to access requests and were handled similarly due to resource constraints.

N-10NSPI (NSEB) RIRs 1-25 - Redacted 4 passages
NON-CONFIDENTIAL p. pp. 4-5
NON-CONFIDENTIAL Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to NSEB Information Requests

AI summary The document outlines the Minister of Energy's accountability for Nova Scotia Power, with NSPI responding to NSEB information requests. It includes a reference to a figure and a matter number, indicating a regulatory proceeding involving information disclosure.

Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to NSEB Information Requests p. pp. 7-16
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to NSEB Information Requests 1 (ii) Customers can call into NS Power and receive information on both their 3 4 5 6 7 8 The Company has also included, as...

AI summary The document outlines information requests from the Nova Scotia Energy Board (NSEB) to Nova Scotia Power Inc. (NSPI) regarding data accuracy, estimation methods, and data recovery timelines for the 2025 Annual Report and Appendix B. Questions also address the unavailability of 2020-2024 data following a cyber incident.

CONFIDENTIAL (Attachment Only) p. p. 16
CONFIDENTIAL (Attachment Only) 1 More specifically, NS Power maintains internal records-management retention standards 2 (see Confidential Attachments 9 and 10), which establish the length of time records 3 are retained to meet customer se...

AI summary This document discusses NS Power's internal records-management retention standards, which are maintained to meet customer service, operational, legal, and regulatory requirements. It also mentions the retention of customer data beyond standard time frames and NS Power's efforts to enhance its privacy governance framework following an incident.

Safeguarding your information p. p. 16
Safeguarding your information We use security safeguards appropriate to the sensitivity of the information. These safeguards include organizational, technological, physical and contractual measures. We audit our procedures and security mea...

AI summary The document outlines the security measures used to protect customer information, including organizational, technological, physical, and contractual safeguards. Regular audits are conducted to ensure these measures are appropriate and properly administered.

N-11NSPI (SBA) RIRs 1-20 - Redacted 1 passage
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Small Business Advocate Information Requests
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Small Business Advocate Information Requests 1 Request IR-15: 2 3 Refer to M12600, Exhibit N-1, NESB IR 6(a): 4 5 6 7 8 The Company's investigations...

AI summary The document discusses ongoing investigations by Nova Scotia Power regarding a data breach affecting personal customer information. The company states that it is not possible to definitively identify which specific data was accessed or exfiltrated, and this assessment is unlikely to change.

N-12NSPI (David MacLeod) RIR A-6 & RIR B-4, 1 passage
NON-CONFIDENTIAL
NON-CONFIDENTIAL 1 Request IR A-6: 2 3 (a) NSP's Chief Operating Officer filed a report titled IT – OT Cyber Security Control 4 Implementation Phase 1 with the UARB on February 27, 2025, twenty days before the 5 Attack. With respect to tha...

AI summary The document discusses a cybersecurity control implementation plan filed by NSP's Chief Operating Officer with the UARB in 2025, twenty days before a cyber attack. The plan focused on OT systems and not IT systems, customer data systems, billing platforms, or AMI infrastructure. The IT systems were covered under a separate plan started in 2021. The scope of the OT plan was defined by Deloitte LLP and approved by NS Power's Director of Information Security and Risk Management.

N-13Evidence - InterGroup, on behalf of CA - Redacted 3 passages
5.2 FORMER CUSTOMER DATA p. pp. 13-14
t be necessary for all customer information fields. Further, some information may need to be retained in a reasonably accessible format, but other sensitive data could be stored more securely offline. 3. NSP acknowledges it failed to compl...

AI summary The document discusses NSP's failure to comply with its internal data retention standards, exposing former customers to unnecessary risks. It highlights the need for NSP to update its privacy policy to specify the purpose, retention period, and storage requirements for customer information, with particular emphasis on sensitive data such as SINs and driver's licences.

6.0 STAKEHOLDER COMMUNICATION p. pp. 14-15
6.0 STAKEHOLDER COMMUNICATION NS Power states that its incident response and business continuity processes were activated following the detection of the Cybersecurity breach.[40](#page-15-2) NS Power notified relevant law enforcement agenc...

AI summary NS Power activated its incident response and business continuity processes after a cybersecurity breach was detected. It notified law enforcement agencies and the OPC, and implemented a multi-channel communication approach, including public postings, direct notices to impacted customers, and updates through various platforms.

6.2 FREQUENCY OF COMMUNICATIONS TO CURRENT CUSTOMERS p. pp. 16-17
6.2 FREQUENCY OF COMMUNICATIONS TO CURRENT CUSTOMERS NSP issued only one direct notice to current customers (sent on May 13, 2025 to initially identified 277,000 customers[50](#page-16-5) and October 31, 2025 to 97,000 additional customers...

AI summary NSP issued direct notices to customers affected by a data breach, but delays in notification were criticized. Customers were not informed until May 23, 2025, two months after the breach. A survey showed that direct notifications were the most effective method, but some argued that more frequent updates would have been better.

N-14Evidence & Appendix A Resume - Tricia Ralph INQ Law/Consulting - BCC 8 passages
Privacy Governance Program p. p. 4
- o Personal information inventory, policies, risk assessment tools, training and education, breach and incident management response protocols, service provider management, and external communication. - 10. As set out in its non-confidenti...

AI summary The document discusses NSPI's privacy governance program, including its policies, procedures, and compliance with PIPEDA. It notes the presence of a Privacy Officer and Office, but highlights gaps in senior management oversight and the lack of a complete PI inventory, which raises concerns about the effectiveness of NSPI's privacy program.

Additional Customer Notification p. p. 8
Additional Customer Notification - 47. In Section 4.2 of the Incident Report, NSPI explained that as it continued its investigation into the scope and nature of the impacted data, it identified approximately 97,000 additional customers in...

AI summary NSPI identified an additional 97,000 customers impacted by a data incident and sent notices on October 31, 2025. The delay in notification was deemed unreasonable by the reviewer.

Contents of Direct Customer Notification p. pp. 8-13
customers. The letters were substantively identical, except that one version advised the customer that based on the investigation, their social insurance number may have been affected by the Incident.

AI summary The document describes direct customer notifications sent to customers, with one version informing them that their social insurance number may have been affected by an incident.

Issue 4 – Collection and Retention of Customer Information p. pp. 13-14
Issue 4 – Collection and Retention of Customer Information - 58. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions in delivering services to its customers concerning collection and retention of custo...

AI summary The document discusses the reasonableness of NSPI's collection and retention of customer information under PIPEDA, focusing on principles such as limiting collection and retention periods. The Board counsel requests an opinion on NSPI's actions related to customer data handling.

Reasonableness of Type of PI Collected p. p. 14
- 65. In Section 8.5 of the Incident Report, NSPI explained that in addition to the information it collects identified above, prior to the Incident, there was also a practice of collecting social insurance numbers (SINs): - Prior to 2018,...

AI summary NSPI collected SINs from customers prior to 2018 for account authentication but stopped in 2018. In 2021, during the MyEnergy Insights program, SINs were inadvertently exported to a cloud environment and may have been exfiltrated. SINs are considered highly sensitive due to the difficulty in remediation if compromised.

Reasonableness of length of Time PI was Retained p. p. 17
Reasonableness of length of Time PI was Retained - 76. As NSPI's record retention schedule was not provided, it is not possible for me to opine on whether the periods of time that NSPI established by information/record type were reasonable...

AI summary The review found that NSPI did not adhere to its own internal record retention standards for personal information, leading to unreasonable retention periods. This lack of compliance negatively impacted customer services by allowing threat actors to exfiltrate data that should have been deleted.

F. Conclusion p. pp. 21-24
F. Conclusion - 105. In conclusion, in my opinion, the following actions by NSPI met best practice, and were reasonable in terms of expectations for customer service and limiting the impacts of the cybersecurity attack on customers: - Asid...

AI summary The conclusion evaluates NSPI's actions following a cybersecurity attack, finding some measures reasonable and others not. While NSPI's privacy governance, notification timelines, and customer communication were deemed reasonable, the use of a PI inventory, retention of SINs, and lack of record-keeping were considered unreasonable.

Contractor September 2019-March 2020 Office of the Information and Privacy Commissioner for Northwest Territories and Nunavut p. p. 26
Contractor September 2019-March 2020 Office of the Information and Privacy Commissioner for Northwest Territories and Nunavut - Resolved contested access to information requests and issued public reports at the direction of the Commissione...

AI summary The Office of the Information and Privacy Commissioner for Northwest Territories and Nunavut resolved contested access to information requests and drafted public privacy breach investigation reports during the period of September 2019 to March 2020.

N-15INQ Law/Consulting (CA) RIRs 1-4 2 passages
14 The relevant components of ID.IM-P are:
14 The relevant components of ID.IM-P are: Subcategory Function ID.IM-P1: Systems/products/services that process data are inventoried. Gives the closed set of systems to check against the incident's affected asset list. ID.IM-P2: Owners or...

AI summary This section outlines the components of ID.IM-P, focusing on inventorying systems, data processing, and data actions to manage data breaches and incidents. It details how to identify affected systems, individuals, data elements, and the environments where data is processed.

Request IR-4:
Request IR-4: 15 In paragraph 106, page 26 of the Report, INQ Law/Consulting concludes that 8 of the 18 actions 16 of Nova Scotia Power relating to personal information that were reviewed, "did not meet best 17 practices, and were unreason...

AI summary The text discusses concerns raised about Nova Scotia Power's handling of personal information following a cyber security attack. It highlights that collecting SINs unnecessarily and retaining customer data longer than necessary were significant issues impacting customer expectations and the mitigation of the attack's effects.

N-16NSPI Refiled Formal Incident Report - Redacted (filed in M12273 as N-5 on April 27, 2026) 8 passages
1 3.2 Data & Personal Information
1 3.2 Data & Personal Information 2 3 . The process to 4 identify the customers who were directly impacted has been extremely complex, and has been 5 completed. As set out in the notices sent to impacted customers, the impacted data would...

AI summary The document discusses the complexity of identifying customers impacted by a data breach involving NS Power. It outlines the types of personal information accessed, including names, contact details, account history, and sensitive identifiers like SIN and bank account numbers. Two versions of notification letters were issued depending on whether a customer's SIN was affected.

Re: Important Notice About Your Personal Information
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...

AI summary Nova Scotia Power informed customers of a cyber incident on April 25, 2025, where unauthorized access occurred to parts of its Canadian network. Personal information, including names, contact details, and account history, may have been accessed. The company has activated incident response protocols and provided free credit monitoring through TransUnion. Customers are advised to remain cautious of unsolicited communications.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) The privacy commissioner of Canada stated last week that: "Data breaches have surged over the past decade, and this incident highlights the growing risks of cyberatta...

AI summary NS Power discusses a recent cyber incident, emphasizing their commitment to cybersecurity and compliance with standards like NIST and NERC. They confirmed no payment was made to attackers and detailed their response, including engaging third-party experts and notifying affected customers.

I haven't been a customer for 10 years? Do you still have my data?
I haven't been a customer for 10 years? Do you still have my data? Last updated: Wednesday, June 25, 2025 This is a really important question to be answered as part of the investigation into the incident.

AI summary This section addresses a question about whether customer data is retained by the organization even after a customer has not been active for 10 years, emphasizing its importance in the investigation into an incident.

A. Clarification of the Procedural Order Sought
A. Clarification of the Procedural Order Sought NS Power understands that the Board applies the "open courts" principle, which allows for proportionate, public interest-based exceptions.1 Our client appreciates the Board's recognition that...

AI summary NS Power seeks clarification on the procedural order regarding the handling of sensitive information in cybersecurity investigations, referencing the 'open courts' principle and the need for confidentiality. They reference privacy regulatory procedures and attach statutory provisions for reference.

B. Request for Confidentiality
B. Request for Confidentiality Further to the Board's request, attached to this letter as Appendix B are detailed reasons why NS Power's confidential submission of August 8, 2025 (the Confidential Submission ) should be held in confidence...

AI summary NS Power has submitted a request for confidentiality regarding its submission to the Board, citing Rule 12(2) of the Board Regulatory Rules. It agrees to allow the Board to disclose the information to intervenors who have been granted standing. NS Power expresses willingness to provide further information and reaffirms its commitment to cooperation with the Board.

Restrictions on disclosure of information by commissioner and staff
Restrictions on disclosure of information by commissioner and staff 41 (1) The commissioner and anyone acting for or under the direction of the commissioner must not disclose any information obtained in performing their duties or exercisin...

AI summary This section outlines restrictions on the disclosure of information by the commissioner and staff under the Act, except as permitted by specific subsections. It references Alberta's Personal Information Protection Act (PIPA Alberta) as a relevant legal framework.

Restrictions on disclosure of information
Restrictions on disclosure of information 41 (1) The Commissioner and anyone acting for or under the direction of the Commissioner shall not disclose any information obtained in performing their duties, powers and functions under this Act,...

AI summary This section outlines restrictions on the disclosure of information by the Commissioner and their representatives, except as specified in subsections (2) to (4). A reference is made to the UK Data Protection Act 2018, specifically section 132(1).

N-17NS Power Rebuttal Evidence - Redacted 8 passages
The reasonableness of NS Power 's actions regarding use of a PI inventory. p. p. 41
The reasonableness of NS Power 's actions regarding use of a PI inventory. INQ notes: An adequate PI inventory as a privacy program control is a critically important building block. In their guidance, the regulators explain that organizati...

AI summary The document discusses concerns regarding the adequacy of NS Power's PI inventory practices, noting that NSPI did not provide a copy of the inventory and claimed it could not determine what data points were exposed during an incident, raising questions about the completeness of their privacy program controls.

Preamble p. pp. 43-46
While I agree that it is important to take steps to identify whether sensitive personal data was affected in an incident and act quickly to notify as soon as feasible, a finding of unreasonableness is not sustained by the evidentiary recor...

AI summary The text discusses the reasonableness of NS Power's response to a cybersecurity incident, emphasizing the need to balance timely notification with operational challenges. It highlights that NS Power prioritized service continuity and took steps such as restoring systems, extracting documents, and engaging third parties for credit monitoring and customer communication.

8.0 CONCLUSION p. pp. 59-64
8.0 CONCLUSION Over the past 16 months, the team at NS Power has worked around the clock to restore and strengthen all systems and to support its customers. NS Power acknowledges the significant impact the Attack and consequent privacy bre...

AI summary NS Power acknowledges the impact of a cyberattack and subsequent privacy breach on its customers and emphasizes its commitment to transparency, customer support, and continuous improvement. The company asserts that its response was reasonable and customer-centered, and requests that the Board's findings align with the evidence provided, preserving normal regulatory processes while recognizing its commitments.

8 Summary of Ms. Ralph's Finding p. p. 72
8 Summary of Ms. Ralph's Finding 9 At paragraph 46 of the Ralph Report, Ms. Ralph concludes that the approximately two-month 10 delay between the discovery of the Incident on April 25, 2025, and the public notification to former customers...

AI summary Ms. Ralph found that NS Power's two-month delay in notifying former customers about a data incident was unreasonable. She noted that NS Power should have been aware of former customer data in its systems and should have assessed if it was impacted. Best practices require notification within days unless extenuating circumstances exist, which were not identified.

17 Expert Opinion p. p. 72
17 Expert Opinion 18 I disagree with this finding. While I agree that it is important to take steps to identify whether 19 sensitive personal data was affected in an incident and act quickly to notify as soon as feasible, a 20 finding of u...

AI summary The expert disagrees with the finding of unreasonableness regarding NS Power's handling of a data incident, emphasizing the contextual nature of reasonableness and the operational challenges of notifying former customers without reliable contact information.

3 Rationale p. p. 79
3 Rationale - 4 Individualized Data Element Identification Was Not Reasonably Feasible on the Notification - 5 Timeline - 6 The record establishes clearly that the absence of customer-specific data element information in - 7 the notices wa...

AI summary The text discusses the rationale for not providing individualized data element identification in breach notifications, citing forensic impossibility and the need for speed. It notes that NS Power provided clarity regarding SIN exposure through two letter versions, which was deemed appropriate.

11 RECOMMENDATIONS p. p. 86
11 RECOMMENDATIONS - 12 Recommendation 4: That the Board Direct NS Power to Update Its Communications Policy - 13 to Require a Minimum of Two to Three Direct Notifications to All Customers and Not - 14 Only Those Potentially Affected in th...

AI summary The recommendation suggests that the Board direct NS Power to update its communications policy to ensure a minimum of two to three direct notifications are sent to all customers, not just those potentially affected, in the event of future privacy breaches.

4 (b) A Fixed Minimum Number of Notices Is Not Standard Practice p. p. 86
4 (b) A Fixed Minimum Number of Notices Is Not Standard Practice - 5 I am aware of no incident response framework or guidance including those published by NIST, - 6 the IAPP, and Canadian privacy regulators that sets a minimum notification...

AI summary The text argues that sending multiple notices for a single data breach is not standard practice and could lead to confusion and fatigue. It highlights that a comprehensive public communications program was implemented, resulting in high awareness of the incident among Nova Scotians.

102138Board Decision Letter - Scope of IRs 2 passages
Section 2 p. p. 0
relevant in Matter M12273. The Board invited intervenors to respond to NS Power's objections. Mr. MacLeod submitted the IRs he requested were all within the scope of the current proceeding and were: … intended to shed light on NSPI's corpo...

AI summary The proceeding discusses NS Power's objections and the need for information requests to understand NSPI's corporate culture and risk management practices, particularly in cybersecurity. The Small Business Advocate argues that evidence from Matter M12273 is relevant to the current proceeding for full regulatory context.

Section 5 p. pp. 0-1
Final Issues List in its letter dated March 25, 2026, supported the suggestion that there could be overlap and argued, to the contrary, that it supported a clearer delineation between the two matters. For the most part, the Board agrees wi...

AI summary The Board agrees with NS Power's position that privacy-related governance and risk management procedures in this proceeding are distinct from cybersecurity issues in Matter M12273. Most information requested in the impugned IRs is deemed relevant to Matter M12273. The Board also notes that Mr. MacLeod may still participate in Matter M12273 once a hearing order is issued.

100853NS Power's Monthly Update #2 (M12273) 2 passages
Recovery Program Office p. p. 0
Recovery Program Office The RPO has continued to advance recovery activities across all major business and technology areas. The RPO was established following the incident response to coordinate recovery and restoration efforts across the...

AI summary The Recovery Program Office (RPO) was established to coordinate recovery and restoration efforts after an incident. It manages program delivery, regulatory and insurance obligations, resourcing, internal controls, cybersecurity, enterprise architecture, organizational change management, reporting, and data privacy across all major business and technology areas.

E1's Residential Behaviour Program p. p. 9
E1's Residential Behaviour Program As noted by the NSEB in its letter of September 17, 2025, the ability to provide relevant customer data to Efficiency One (E1) has been affected by the cybersecurity incident. Customer consumption data de...

AI summary The NSEB informed E1 that a cybersecurity incident has disrupted access to customer data from AMI meters and the MEI platform, impacting E1's programs. NS Power is working to restore data flows by 2026 and is discussing interim solutions with E1.

100855NS Power's Monthly Update #4 (M12273) 2 passages
Fuel Adjustment Mechanism p. p. 3
Fuel Adjustment Mechanism As identified in the Second Monthly Update Report, Fuel Adjustment Mechanism (FAM) related matters have been affected by the Incident. The Company has commenced preparations for the 2024/2025 FAM Audit. Significan...

AI summary The Fuel Adjustment Mechanism (FAM) has been impacted by an Incident, leading to preparations for the 2024/2025 FAM Audit. Progress has been made in recovering data and systems, though some areas remain under remediation. The Company is working to provide alternative data sets to validate fuel cost management prudence.

Opening statement p. p. 7
Thanks to our robust systems, ongoing investments, and the dedication of our people, we ensured that core operations and the electric grid continued uninterrupted – no power was lost to Nova Scotians. There is still much work ahead, and as...

AI summary Nova Scotia Power ensured uninterrupted operations during a recent incident, implementing recovery measures such as IT security upgrades and customer support options. They are addressing billing and payment challenges, removing social insurance numbers from systems, and working to reconnect meters with billing systems by the end of March.

101333Comments on preliminary issues list - NS Power 1 passage
Issues p. p. 0
Issues - (1) Privacy policies and procedures development, implementation, and adherence, including, but not limited to: - (i) Privacy training and percentage of staff that completed privacy training; - (ii) Policies for receiving and respo...

AI summary The issues outlined pertain to privacy policies, governance, risk management, breach response, data collection, and third-party involvement in a privacy-related incident. Key areas include training, complaint procedures, breach containment, reporting, and mitigation of fraud risks.

101377Board Letter re: Final Issues List 1 passage
Section 3 p. pp. 0-1
supervisory power includes the ability to investigate and the authority to consider the reasonableness of any "practice or act whatsoever affecting or relating to the operation of any public utility". The Privacy Commissioner of Canada is...

AI summary The document outlines the Board's decision to address certain issues in the proceeding while removing others, citing their relevance to separate matters. Issue #3 is removed as it pertains to a different proceeding, while Issue #7 remains as it includes non-technical aspects related to customer information sharing policies.

101524David MacLeod (NSPI) IR A-1 to G-5 1 passage
IR D-1 — Data Inventory and Classification
IR D-1 — Data Inventory and Classification - (a) Produce NSP's data inventory or data map as it existed prior to March 19, 2025, - identifying: - (i) all categories of personal information held by NSP; - (ii) the systems in which each cate...

AI summary The document requests NSP to provide a data inventory prior to March 19, 2025, including categories of personal information, storage systems, retention periods, and access controls. It also asks for an explanation of why SINs were held and data minimization practices before the Attack.

101618INQ Law Consulting (NSPI) IR-1 to IR-7 2 passages
Request IR-3:
Request IR-3: - With respect to reporting to regulators, notification to affected individuals, management and communication, please provide the following documentation or information, as applicable. If any of the documents or information i...

AI summary Request IR-3 seeks information related to a cybersecurity incident involving Nova Scotia Power, including dates of awareness, notifications to regulators and affected individuals, and templates of notification letters.

Request IR-4:
Request IR-4: - With respect to collection and retention of customer information, please provide the following - documentation or information, as applicable. If any of the documents or information is not - available, please provide the rea...

AI summary Request IR-4 seeks information on how customer data is collected, retained, and destroyed, including policies, records of data destruction activities prior to a cybersecurity incident, and types of personal data collected and their purposes.

101623NSPI Monthly Update Report #7 (M12273) 1 passage
Customer SIN Deletion p. p. 0
Customer SIN Deletion In the Compliance Letter, NS Power committed to the OPC that by March 31, 2026, NS Power would initiate a process to identify and remove instances of customer social insurance numbers (SINs) contained within its syste...

AI summary NS Power committed to the OPC to delete customer SINs by March 31, 2026, except for those required by law. The process was completed on March 27, 2026, with Legally Required SINs segregated and protected for lawful use only.

101694NSEB (NSPI) IR-1 to IR-25 3 passages
Request IR-15:
Request IR-15: - In its response to NSEB IR-1 (Exhibit N-2), NS Power said it "adopted a best-practices approach - to mitigating potential harm to customers whose personal information was impacted by the - Incident." Please explain why NS...

AI summary The document requests NS Power to explain why its approach to mitigating harm to customers affected by an incident is considered a 'best-practice' and to identify the benchmarks or metrics used to assess this approach, as outlined in its response to NSEB IR-1.

Request IR-17:
Request IR-17: - Regarding the theft or suspected theft of personal information about individuals who were - previously customers of NS Power, but who were no longer customers at the time of the cyber - attack: - a) Is NS Power able to pro...

AI summary The document requests NS Power to provide more detailed information about former customers whose personal information may have been compromised in a cyber attack, including the total number impacted and a breakdown by when they ceased being customers.

I haven't been a customer for 10 years? Do you still have my data?
I haven't been a customer for 10 years? Do you still have my data? Last updated: Wednesday, June 25, 2025 This is a really important question to be answered as part of the investigation into the incident. [Emphasis in original] Please prov...

AI summary The document raises a question about whether NS Power still retains customer data for individuals who have not been customers for 10 years. It emphasizes the importance of answering this as part of an investigation and requests an explanation from NS Power regarding their lack of knowledge on this matter as of June 25, 2025.

101697SBA (NSPI) IR-1 to IR-20 1 passage
Request IR-15:
Request IR-15: Refer to M12600, Exhibit N-1, NESB IR 6(a): The Company's investigations remain ongoing. At this time, it is not possible to determine precisely what specific personal customer information, if any, was affected by this incid...

AI summary The Company is still investigating the incident and cannot yet determine what specific personal customer information was affected. The inquiry asks whether the situation is expected to change and, if so, when.

101762Letter David MacLeod re: Response to NSPI's letter 1 passage
Section 1
David T. MacLeod 2026-04-28 Cry tal Henwood Clerk of the Board ova cotia En rgy Board 1601 Lower Water treet, 3rd Floor Halifax, N B3J 3 3 RE: M12600 - Min ter of Energy - Accountability for Nova cotia Power Ms. Henwood, I am writing in re...

AI summary The letter from David T. MacLeod responds to Nova Scotia Power's objection to answering Information Requests related to the 2025 cyber breach. The requests are tied to governance, data collection, risk mitigation, third-party involvement, and customer communications, with a focus on privacy risks for ratepayers, especially those with federal security clearances.

101810Letter CA re: Comments on NS Power's letter about scope of IRs 1 passage
Re: M12600 - Minister of Energy - Accountability for Nova Scotia Power p. p. 0
Re: M12600 - Minister of Energy - Accountability for Nova Scotia Power This is further to the Board's request for comments on the objections Nova Scotia Power has raised over the scope of some of the information requests that have been fil...

AI summary Nova Scotia Power objects to certain information requests in M12600, arguing they are more relevant to M12273. The Consumer Advocate and others argue that the overlap between the two matters is inevitable and that separating technical and non-technical aspects could hinder transparency. The Board has acknowledged the potential overlap and the importance of addressing both technical and governance-related issues in M12600.

101820Letter SBA re: Comments on NS Power's letter about scope of IRs 1 passage
Section 2 p. p. 0
evidence between the two matters is contemplated and potentially necessary in order to understand the full context of the cybersecurity incident and NS Power's response within the regulatory context. In its March 25, 2026 letter to the Par...

AI summary The Small Business Advocate (SBA) argues that evidence from two regulatory matters, M12600 and M12273, should be considered together to provide a more comprehensive understanding of NS Power's cybersecurity incident and response. The SBA emphasizes the value of clarifying non-technical aspects of cybersecurity standards and policies in M12600.

101835Letter NSPI re: Reply comments for out of scope IRs 1 passage
Section 2 p. p. 0
be part of the record in M12273, not M12600. Including the subject matter of the Out of Scope IRs in M12600 would lead to a scenario where issues are before the Board without a full or proper record. In its comments, the CA states that the...

AI summary The Consumer Advocate (CA) argues that the Out of Scope IRs in M12600 could provide insights into Nova Scotia Power's governance and risk management. However, the scope of M12600 is limited to the impact of a cyber incident on data collection, billing, and regulatory matters. The CA and SBA reference the Board's March 25, 2026 letter regarding overlap between matters.

101894Email NSEB re: NSPI to provide letter and Confidential undertaking 1 passage
Good afternoon, p. p. 0
Good afternoon, Further to NS Power' filings of IR responses yesterday, NS Power did not provide a cover letter regarding justification for the confidentiality claims or a Confidential Undertaking for the partially confidential IR response...

AI summary The Board is requesting NS Power to provide a cover letter justifying confidentiality claims and a draft Confidential Undertaking for partially confidential IR responses. The Board also reminds all parties that documents must be submitted via a secure file transfer service starting Monday, 3 November 2025.

102138Board Decision Letter - Scope of IRs 1 passage
Section 2 p. p. 0
relevant in Matter M12273. The Board invited intervenors to respond to NS Power's objections. Mr. MacLeod submitted the IRs he requested were all within the scope of the current proceeding and were: … intended to shed light on NSPI's corpo...

AI summary The document discusses the relevance of Matter M12273 in the current proceeding, with NS Power objecting to the scope of intervenor requests. Mr. MacLeod argues that the requested information is within the proceeding's scope and relates to NSPI's corporate culture and risk management. The Small Business Advocate notes some overlap between the current proceeding and M12273 to fully understand the cybersecurity incident and NS Power's response within the regulatory context.

103319Undertaking List 1 passage
CONTINUED M12600
CONTINUED M12600 DATE UND# DESCRIPTION REQUESTED OF FOR DUE DATE August 19, 2026 U-13 To provide the volume of data in the July 2021 cut in the Azure staging area in terms of actual size of the total IT network. NSPI by NSEB September 4, 2...

AI summary The document contains a list of data requests related to IT network data volumes, data retention schedules, data storage fees, and customer communication regarding a cyber-incident. These requests were made by the Nova Scotia Energy Board (NSEB) to the Nova Scotia Public Inquiry (NSPI).

20260818-1Hearing Transcript — 08/18/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams) 12 passages
NOVA SCOTIA POWER PANEL 45 Cr-ex, (Roberts)
NOVA SCOTIA POWER PANEL 45 Cr-ex, (Roberts) 1 The information that's in this list 2 right now, essentially maybe the best way to answer it is 3 what information is currently not retained. 4 So the driver's licence number would 5 not be ret...

AI summary The discussion centers on data retention practices by Nova Scotia Power, specifically regarding the non-retention of driver's licence numbers and Social Insurance Numbers, except for tax reporting. The conversation also touches on credit reporting tools and the factors that may prevent customer identification through these tools.

NOVA SCOTIA POWER PANEL 51 Cr-ex, (Roberts)
NOVA SCOTIA POWER PANEL 51 Cr-ex, (Roberts) 1 A. (Williams) So I'll offer a 16 your personal information inventory system as being 17 "unreasonable" in terms of your inability to do what we're 18 talking about. 19 What do you say to that c...

AI summary The discussion revolves around the adequacy of Nova Scotia Power's personal information inventory system, with a focus on the inability to determine the exact data taken during a breach. The witness acknowledges the limitations of the system and the difficulty in assessing the impact of the breach.

NOVA SCOTIA POWER PANEL 59 Cr-ex, (Roberts)
NOVA SCOTIA POWER PANEL 59 Cr-ex, (Roberts) 1 information. So that suggests that there may be other 14 could have two identical homes. If you have just a single 15 person living in one and you have a family of five living 16 in another, th...

AI summary The discussion revolves around the retention of customer energy use data in Nova Scotia Power's legacy Customer Information System (CIS), highlighting that information provided through the My Energy Insights survey is not subject to the attack and that data is retained for extended periods due to the system's limitations.

Section 46
information included within that category, yes. Q. And you the you have, at this stage at least, an inability to excise that information, apart from the specific example you gave of the Social Insurance Number? A. (Williams) That's right....

AI summary The discussion revolves around the inability to remove certain customer data from the CIS system due to the risk of catastrophic failure. The witness explains that while deletion is technically possible, the risks involved are considered too significant given the system's integral role in customer services.

NOVA SCOTIA POWER PANEL 81 Cr-ex, (Roberts)
NOVA SCOTIA POWER PANEL 81 Cr-ex, (Roberts) of, I think she used the word ad hoc , the ad hoc approach between 2018 and 2024 in terms of removal, and waiting six years, essentially, to take a proactive step to remove the SINs. What do you...

AI summary The discussion focuses on the removal of Social Insurance Numbers (SINs) from the Customer Information System (CIS) by Nova Scotia Power. The witness clarifies that SINs were being removed as they were encountered, and by 2024, most had been removed, though some remained in historical records. The removal was not completed by March 2025, but the majority had been purged prior to an attack.

NOVA SCOTIA POWER PANEL 165 Cr-ex, (MacAdam)
NOVA SCOTIA POWER PANEL 165 Cr-ex, (MacAdam) 1 A. (Lanteigne) That's my 15 part it is being responsive to the issues she's raised. 16 Q. Okay. And the audit of the Data 17 Lake, would that have included I know she was referring 18 specific...

AI summary The discussion revolves around an audit of the Data Lake conducted in December 2024, focusing on whether it included a review of access permissions to ensure only legitimate users had access. Concerns about the confidentiality of the audit were raised, and the auditor was cautious about responding fully.

to date?
to date? 1 (Williams) We can provide that. A. 2 MS. MacADAM: If I could have that as 3 an undertaking? 4 THE CHAIR: It'll be Undertaking U-5. 5 UNDERTAKING U-5 - To provide an 6 updated phishing failure rate for 7 the period of April 2025...

AI summary The discussion revolves around the provision of an updated phishing failure rate for April 2025 to date and a request for information on cyber incidents recorded by NSPI over the last five years. The participants are discussing the appropriate handling of undertakings and commitments related to cybersecurity.

NOVA SCOTIA POWER PANEL 329 Cr-ex, (Mahody)
NOVA SCOTIA POWER PANEL 329 Cr-ex, (Mahody) that's generated as a result of the customers' energy usage is information that Nova Scotia Power has a custodial responsibility as part of the utility/customer relationship? A. (Williams) So as...

AI summary The discussion revolves around Nova Scotia Power's custodial and stewardship responsibilities regarding customer energy usage data. The witness confirms accountability for this information and agrees to retaining it only as necessary for providing electricity services.

NOVA SCOTIA POWER PANEL 333 Cr-ex, (Mahody)
NOVA SCOTIA POWER PANEL 333 Cr-ex, (Mahody) 1 within what is understood and known to be a very fragile 16 to advise how many SIN numbers 17 were purged from NS Power's 18 system 19 BY MR. MAHODY: INTERNATIONAL REPORTING INC. CERTIFIED COUR...

AI summary The discussion revolves around Nova Scotia Power's 2024 program to delete Social Insurance Numbers (SINs) from its system. The witness confirms the program was implemented and completed in 2024, but the exact number of SINs purged is not immediately available and would need to be checked.

NOVA SCOTIA POWER PANEL 341 Cr-ex, (Mahody)
NOVA SCOTIA POWER PANEL 341 Cr-ex, (Mahody) taken in the interim to limit the risk, while at the same time recognizing potential impacts to the system itself were action taken too hastily. Q. But the fragile system was able to withstand th...

AI summary The discussion revolves around Nova Scotia Power's handling of personal data, specifically the removal of Social Insurance Numbers (SINs) and other sensitive information. The witness acknowledges the complexity of the data system and explains that SINs are easier to remove due to their uniform format, while other data like driver's licence and bank information are more complex to manage.

NOVA SCOTIA POWER PANEL 347 Cr-ex, (Mahody)
NOVA SCOTIA POWER PANEL 347 Cr-ex, (Mahody) 1 Insurance Numbers and who didn't, when you made that 2 decision, did you know at that point that the data breach 3 was the cut of data from 2021? 4 [4:50:20] A. (Lanteigne) Yes, we would have....

AI summary The proceeding discusses a data breach involving Nova Scotia Power, with questions about when the company became aware of the breach and how it communicated with affected customers. Concerns are raised about the clarity of the company's communications, particularly regarding the exposure of Social Insurance Numbers (SINs).

Section 198
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 clarity frankly, from my perspective, and you can take it 2 or not, that these lines 26 and 27 do, why wasn't this 3 level of clarity expressed at that time? 4 A. (Williams) So I bel...

AI summary The discussion revolves around the clarity of letters sent on May 13th, specifically regarding the inclusion of SINs. The witness suggests that there were two separate letters, one with SINs and one without, and emphasizes the need to review the actual letters for clarity.

20260819-1Hearing Transcript — 08/19/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams) 13 passages
I N D E X O F P R O C E E D I N G S
I N D E X O F P R O C E E D I N G S August 18, 2026 PAGE NO. 2 So just moving up to the top of the 3 page, then, about the retention schedule and Personal 4 Information Inventory, I just wanted to confirm that the 5 Personal Information In...

AI summary The text discusses a rebuttal affidavit submitted by Nova Scotia Power, specifically focusing on the Personal Information Inventory attached as a confidential attachment. The inventory is used to identify personal information held by Nova Scotia Power and its storage locations. This is the first time the inventory has been presented in the proceeding.

NOVA SCOTIA POWER PANEL 417 Questions, (Melanson)
NOVA SCOTIA POWER PANEL 417 Questions, (Melanson) 1 the information that they're receiving as well. 5 were there was a subset of customers that you had their 6 Social Insurance Number on record, and that may have been 7 accessed. 8 All I'm...

AI summary The discussion centers on the clarity of communication regarding the access of Social Insurance Numbers (SINs) in customer records. A suggestion is made to improve transparency by explicitly stating the handling of SINs in correspondence to avoid confusion.

NOVA SCOTIA POWER PANEL 441 Questions, (Deveau)
NOVA SCOTIA POWER PANEL 441 Questions, (Deveau) 1 actions that we'll take forward. 13 Numbers to be in places on our systems in unintended 14 manner, we thought it prudent to search the entirety of 15 our systems as opposed to the CIS wher...

AI summary The text discusses data management practices, specifically the handling of Social Insurance Numbers and the process of purging data after a breach. It references an undertaking to provide data volume details from the Azure staging area and mentions the timeline of data purging efforts between 2018 and 2024.

Preamble
1 would move on and the assumption would be you've dealt 2 within the 14 days. 3 Q. Okay. 4 A. (Williams) Any data that hasn't 5 been touched would remain for 90 days with the assumption 6 that we may still need it, we just haven't gotten...

AI summary The discussion revolves around data retention policies and security risks associated with storing data in a Data Lake and CIS system. It highlights that data not accessed within 90 days is lost, and there are concerns about unauthorized access to data stored in these systems.

NOVA SCOTIA POWER PANEL 475 Questions, (Deveau)
NOVA SCOTIA POWER PANEL 475 Questions, (Deveau) 1 you're expanding it to other platforms or well, the SIN 2 numbers probably wouldn't make it to MyEnergy, but when 3 you're copying it from the CIS system to the Azure system, 4 it's just an...

AI summary The discussion revolves around data security and migration from the CIS system to the Azure system, with concerns raised about potential unauthorized access and data manipulation. The response highlights the use of automated destruction tools and secure environments to mitigate risks.

NOVA SCOTIA POWER PANEL 503 Questions, (Deveau)
NOVA SCOTIA POWER PANEL 503 Questions, (Deveau) 1 it's an audit of access to information that is made 2 no formalized review of compliance or the policies 3 themselves on a regular basis, on a regular cycle; it 4 depends on what the intern...

AI summary The discussion focuses on Nova Scotia Power's audit practices and customer privacy policy, highlighting gaps in compliance reviews and the handling of customer information retention and destruction following a data breach.

NOVA SCOTIA POWER PANEL 531 Questions, (Chair)
NOVA SCOTIA POWER PANEL 531 Questions, (Chair) 1 that has files and folders, is the technical difficulty 2 the fact that you have multiple users and millions of 3 files who have stored and created and put information on 4 this system over...

AI summary The discussion focuses on the technical challenges of managing a large volume of unorganized files and the transition from the NAS system to more advanced solutions like SharePoint Online and MS365 OneDrive. The expert explains that SharePoint provides better categorization and organization capabilities compared to older systems.

NOVA SCOTIA POWER PANEL 535 Questions, (Chair)
NOVA SCOTIA POWER PANEL 535 Questions, (Chair) 1 had plans in place to move away from it and destroy it, 2 because of the limitations that it has in that regard and 3 our inability to control it. The SharePoint Online has 4 much more many...

AI summary The discussion focuses on the use of NAS and SharePoint at Nova Scotia Power, particularly regarding the storage and management of documents. The witness explains that SharePoint was the preferred method for document sharing and collaboration, while NAS was used in certain instances. There is concern about the improper retention of customer personal information on NAS.

NOVA SCOTIA POWER PANEL 551 Questions, (Chair)
NOVA SCOTIA POWER PANEL 551 Questions, (Chair) 1 I, about the evolution of SharePoint and the ability to 2 automate within SharePoint, so and the effect that 3 would have on the ability to then destroy the NAS, migrate 4 anything from the...

AI summary The discussion focuses on the challenges of evolving SharePoint and the automation capabilities needed to transition away from Network Attached Storage (NAS). It contrasts the technical issues with the Customer Information System (CIS) and the more human-related issues with NAS usage. The conversation also references a document (N-17) for specific details.

NOVA SCOTIA POWER PANEL 553 Questions, (Chair)
NOVA SCOTIA POWER PANEL 553 Questions, (Chair) 1 We can pull it up quickly. It's a 2 reference to the scanning tool that was used to remove the 3 Social Insurance Numbers, and there's a reference that 4 once it's kind of –– you're comforta...

AI summary The discussion revolves around the use of a scanning tool within Microsoft 365 to identify and remove personal information, including Social Insurance Numbers, and its potential future expansion to other types of personal data. The tool is currently used to scan Microsoft systems like Outlook, SharePoint, and OneNote.

VALDETERO 633
VALDETERO 633 1 Q. Okay. Thank you. 2 AKCAKIRYAN: Those are all my MS. 3 questions. 4 THE CHAIR: Thank you. 5 Industrial Group? 6 MS. RUDDERHAM: No questions, 7 Mr. Chair. Thanks. 8 THE CHAIR: Department of Energy? 9 KAYTER: No questions,...

AI summary This excerpt from a regulatory proceeding includes cross-examination of Ms. Valdetero by Mr. Mahody, focusing on her experience with data privacy and security in regulated utilities, including telecommunications providers and utilities in the United States. She discusses her role as external counsel for multiple companies.

Section 169
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS different area. THE CHAIR: Yeah. Well, why don't we move on to that one then? BY MR. MAHODY: Q. All right. Ms. Valdetero, could I take you in your evidence to your critique of Ms. Ralp...

AI summary The discussion centers on the reasonableness of the timeframe for notifying former customers of a data breach by Nova Scotia Power. The witness, Ms. Valdetero, indicates that a period from May 1st to June 25th, 2025, was considered reasonable, taking into account the resources required to address the breach.

Section 171
been reasonable, but given all that needed to happen in that timeframe, from when they first identified and I wasn't sure when they first identified former customers, but I was still basing it off INTERNATIONAL REPORTING INC. CERTIFIED COU...

AI summary The testimony discusses the timeline and approach taken by Nova Scotia Power regarding customer notification following a data breach. The witness acknowledges the May 1st public announcement and subsequent October 31st direct mailing as a more individualized outreach step.

20260820-1Hearing Transcript — 08/20/2026 (Jena Valdetero, Ed Mollard, Tricia Ralph) 2 passages
Section 51
especially with former customers, you know, kept track of like what information, contact information, or disposed of that information that it no longer needed anymore. Q. Yeah. Well, with respect to these 97,000, I guess my concern is that...

AI summary The discussion centers around concerns regarding the handling of customer information and the notification process following a privacy breach. The witness addresses the determination of unreasonableness in the delay of informing 97,000 customers and the content of the letters sent to notify them.

Section 58
information, and they weren't sure whether or not they provided it and whatnot. And then the response of Nova Scotia Power when people called to ask that, which to me RALPH Cr-ex, (Clarke) INTERNATIONAL REPORTING INC. CERTIFIED COURT REPOR...

AI summary This text discusses customer concerns about unclear communication from Nova Scotia Power regarding data breaches and information disclosure. The witness, Ralph Clarke, notes that the company's response was not helpful, and that customers would have preferred a clearer explanation.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →