The words “use” and “loss” in privacy laws may not mean what you think in a cyber-security incident @privacylawyer
The words “use” and “loss” in privacy laws may not mean what you think in a cyber-security incident  @privacylawyer
Uploaded September 2025 | Updated September 2026, 2 hours ago
In this episode, David Fraser, PrivacyLawyer, unpacks the recent Ontario Divisional Court decision in Hospital for Sick Children v. Information and Privacy Commissioner of Ontario. The case arose from ransomware attacks that temporarily encrypted servers at SickKids and the Halton Children’s Aid Society. No evidence suggested that hackers viewed, copied, or exfiltrated personal information—yet the Information and Privacy Commissioner found there had been an unauthorized “use” and “loss” of data, triggering notification obligations. The Court upheld those findings, deferring to the regulator’s broad interpretation.

David explains why this matters for organizations across Ontario (and beyond), focusing on how common words like “use” and “loss” may not mean what you think when regulators are involved. He also contrasts Ontario’s strict approach with the federal private-sector law, PIPEDA, which only requires notification where there is a “real risk of significant harm.” The key takeaway: Ontario’s laws can demand notification even when no harm to individuals exists, a standard that may lead to over-notification and notice fatigue.

The Divisional Court decision can be found here: canlii.ca/t/kffpm

Where you can find me
► Privacylawyer blog: blog.privacylawyer.ca
► Twitter: twitter.com/privacylawyer
► LinkedIn: linkedin.com/in/davidtsfraser

Disclaimer: This is intended for education and information only and should not be taken as legal advice. If you need advice for your particular situation, you should seek out qualified counsel.

All views expressed are solely those of the creator and should not be attributed to his firm or any of its clients.
The words “use” and “loss” in privacy laws may not mean what you think in a cyber-security incidentThe Bill C-2 #LawfulAccess Charter Statement contains incorrect and misleading statementsLawful Access is back: All about Bill C-22 (Spoiler alert: Part 2 is very troubling.)Bill C-27s Consumer Privacy Protection Act is dead. Long Live PIPEDA!#LawfulAccess is back: An overview of Part 14 of Bill C-2: Strong Borders ActDigital bills at risk if this government falls (or if Parliament is prorogued)Privacy, Online Harms and Lawful Access: Keep an eye on Parliament this fallLearning from online scams so you can recognize them and protect yourself
PrivacyLawyer - David Fraser |

The words “use” and “loss” in privacy laws may not mean what you think in a cyber-security incident

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER