That’s right. It was a global genetic genealogical company, which had experienced a privacy breach. People stole information on millions of people, including 300,000 Canadians. You can imagine what that means. Genetic data are extremely sensitive.
When we receive this type of complaint—in this case, I conducted a joint investigation with my U.K. counterpart—we check whether the company took proper precautions when processing data and if it had sufficient protection mechanisms. Unfortunately, we found the company lacked strong passwords and protection systems, and it was too slow to respond to signs that bad actors were trying to get into their system.
My U.K. counterpart and I had similar findings. However, they have order-making powers and the power to impose fines in the event of such significant violations, and they used those powers. I believe they levied millions of pounds in penalties. On the other hand, I could only make recommendations. It was a pretty flagrant situation. We held a press conference, and I was asked why I had not levied fines. I responded that I did not have the power to impose fines.
