4

Incidents

SL-07

Every incident raised, whether or not it was ultimately assessed as a personal data breach. The assessment itself is evidence — a documented 'not reportable' is far better than silence.

DischargesS.8(6)R.7
Incidents
10
Open
2
Reportable breaches
7
Board reports filed
6
Awaiting Board filing
1

10 records

INC-2026-0042
Bulk extraction of citizen records from the Family ID registry
Database Activity MonitoringPersonal data breach
CriticalInvestigating1.48 L6.41 K children--:--:--11 hours ago
INC-2026-0041
Scholarship spreadsheet emailed to an incorrect external recipient
Data Loss PreventionPersonal data breach
HighClosed1.84 K1.84 K childrenFiled27 days ago
INC-2026-0040
Public bucket exposure on the document object store
SIEM / SOCPersonal data breach
CriticalClosed42.6 K3.1 K childrenFiled2 months ago
INC-2026-0039
Privileged DBA queried health records outside any assigned task
Database Activity MonitoringPersonal data breach
HighClosed62084 childrenFiled3 months ago
INC-2026-0038
Vendor laptop with an offline extract reported lost
Reported by a Data ProcessorPersonal data breach
MediumClosed8.9 KFiled4 months ago
INC-2026-0037
Phishing site harvested two officer credentials
Access Gateway
HighClosedNot reportable2 months ago
INC-2026-0036
Grievance narratives pasted into an unsanctioned AI tool
AI Processing GuardPersonal data breach
HighRemediating34012 childrenFiled10 days ago
INC-2026-0035
Ransomware precursor: mass delete attempted on staging
Database Activity Monitoring
MediumClosedNot reportable2 months ago
INC-2026-0034
Misconfigured API returned other applicants' records
Reported by a Data PrincipalPersonal data breach
CriticalClosed21.4 K9.8 K childrenFiled5 months ago
INC-2026-0033
Call recordings accessible to an over-broad support group
Access Assurance
MediumClosedNot reportable4 months ago