IPC Investigating PowerSchool Cyberattack
Between January 8 and 16, 2025, our office was informed by the Ontario Ministry of Education and 20 school boards about a cyberattack involving PowerSchool’s software. We are actively investigating this breach from the perspective of the ministry and the school boards, while the federal commissioner (with jurisdiction over private sector organizations) is investigating PowerSchool.
The potential impact of this incident on Ontario students is deeply concerning and is a stark reminder of the critical importance of safeguarding personal data. While schools and school boards may outsource their functions to third-party vendors, they cannot outsource their accountability for protecting personal information.
We have long advocated for stronger accountability measures in Ontario’s municipal privacy law, including:
- mandatory privacy impact assessments (PIAs)
- reach notifications for MFIPPA institutions
These measures are critical to closing gaps in the existing law and fostering trust in the digital world.
Explore our guidance on Privacy and Access in Public Sector Contracting with Third Party Service Providers and our comments on Bill 194, the Strengthening Cyber Security and Building Trust in the Public Sector Act (read the full submission).
Media Contact
For a quick response, kindly e-mail or phone us with details of your request such as media outlet, topic, and deadline:
Email: @email
Telephone: 416-326-3965
Social Media
The IPC maintains channels on LinkedIn, X (formerly Twitter), YouTube and Instagram in its efforts to communicate to Ontarians and others interested in privacy, access and related issues.