Skip to content

The firm’s hard drive was stolen from its IT provider’s vehicle.

a sole-practitioner law firm · Alberta · December 2019. A desktop failed at a sole-practitioner Alberta law firm, so its IT provider took the hard drive away to see what could be recovered. The drive was stolen from the provider's vehicle — with about 150 people's files on it.

What happened

Identified in the record as Alberta OIPC Decision P2020-ND-137.

150 people whose files left in a third party’s vehicle
Missing control

Nothing recorded — including whether the drive was encrypted

First page of Decision P2020-ND-137 Alberta OIPC decision Read the original →

On December 20, 2019, a desktop computer at the firm failed. The firm's IT provider removed the hard drive to determine whether any data was recoverable, and took it away.

“While in the IT provider's possession, the hard drive and other items were stolen from the provider's vehicle.”

The provider reported the theft to the firm three days later, on December 23. Approximately 150 people were affected.

“Reported the theft to law enforcement.”

That single line is everything the record lists under steps taken to reduce the risk of harm. The decision makes no finding about whether the drive was encrypted — the record simply does not say. The Commissioner found a real risk of significant harm and ordered the firm to notify everyone affected. Whatever protection those files had, they already had it when the drive went into the car.

The rule that applied — in Alberta

Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected

“There is a real risk of significant harm to the individuals affected by this incident. The Organization is required to notify those individuals pursuant to section 37.1 of the Personal Information Protection Act (PIPA).”

The document

The part that matters

The single line under “steps taken to reduce risk of harm” is “Reported the theft to law enforcement.” There was nothing else to do. Whatever protection those files had, they had it already when the drive went into the car.

The exposure is ordinary and universal: the person who fixes your computers can take your client files out of the building, entirely legitimately, and your obligation to those clients does not travel with the drive.

What your own regulator and insurer require →

The documents

We hold dated copies — ask and we will send you what we read.

DocumentOur copy
Decision P2020-ND-137 Copy held 2026-08-20

The record identifies the organisation as a barrister and solicitor — a title that cannot lawfully be used by anyone who is not a lawyer, which is why we are willing to call it a law firm.

Where are your files right now?

No cost, no obligation — you keep the findings either way.

Get your free Security Snapshot

Or see what we check for small law firms →