When student data is hacked & stolen: Regulators’ lessons from the #PowerSchool data breach @privacylawyer
When student data is hacked & stolen: Regulators’ lessons from the #PowerSchool data breach  @privacylawyer
Uploaded December 2025 | Updated September 2026, 2 hours ago
A close look at the #PowerSchool #cybersecurity incident, perhaps the largest education-sector data breach ever investigated in Canada, and the findings issued by the Information and Privacy Commissioners of Ontario and Alberta.

PowerSchool is widely used by Canadian school boards to manage student information, including enrollment, grades, contact details, and medical alerts. In late 2024, a threat actor gained access to PowerSchool’s systems using compromised credentials belonging to a support contractor, allowing them to exfiltrate sensitive student and educator data affecting millions of individuals across multiple provinces.

This video explains:

► What PowerSchool is and how school boards rely on it
► How the cyberattack occurred and what data was accessed
► What Ontario and Alberta privacy regulators investigated
► Where the regulators’ findings align — and where they differ

What this case teaches about outsourcing, vendor oversight, and accountability under Canadian privacy law

Both regulators concluded that school boards remained legally responsible for protecting personal information, even though PowerSchool operated the systems. The investigations highlight failures in cybersecurity safeguards, contract management, data retention practices, and breach preparedness — and underscore the heightened sensitivity of children’s personal information.

Relevant links:

► Ontario finding: ipc.on.ca/en/resources/powerschool-report
► Alberta finding: oipc.ab.ca/wp-content/uploads/2025/11/FINAL-Investigation-Report-Regarding-PowerSchool-Breach-FOIP2025-IR-02.pdf
► Saskatchewan finding: oipc.sk.ca/assets/la-foip-investigation_003-2025-035-2025.pdf

Where you can find me
► Privacylawyer blog: blog.privacylawyer.ca
► My law firm: mcinnescooper.com/people/david-fraser
► Twitter: twitter.com/privacylawyer
► LinkedIn: linkedin.com/in/davidtsfraser

Disclaimer: This is intended for education and information only and should not be taken as legal advice. If you need advice for your particular situation, you should seek out qualified counsel.

All views expressed are solely those of the creator and should not be attributed to his firm or any of its clients.
When student data is hacked & stolen: Regulators’ lessons from the #PowerSchool data breachMy Bill C-22 (Lawful Access) testimony to the Committee on Public Safety & National SecurityDo photography/videography bans in police stations and public buildings violate the Charter?The words “use” and “loss” in privacy laws may not mean what you think in a cyber-security incidentThe Bill C-2 #LawfulAccess Charter Statement contains incorrect and misleading statementsLawful Access is back: All about Bill C-22 (Spoiler alert: Part 2 is very troubling.)Bill C-27s Consumer Privacy Protection Act is dead. Long Live PIPEDA!#LawfulAccess is back: An overview of Part 14 of Bill C-2: Strong Borders ActDigital bills at risk if this government falls (or if Parliament is prorogued)Privacy, Online Harms and Lawful Access: Keep an eye on Parliament this fallLearning from online scams so you can recognize them and protect yourself
PrivacyLawyer - David Fraser |

When student data is hacked & stolen: Regulators’ lessons from the #PowerSchool data breach

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER