Employee Data Breaches: Why Companies Protect Customers More Than Staff
Walk into most retail stores and you’ll see the same split. Cameras, alarm tags, a guard at the door, all pointed at the shop floor where the customers are. Walk into the stockroom and half the time the lock is a keypad nobody’s changed the code on since the manager before last left. The customer-facing side gets the security budget. The back office gets a shrug.
I see the same split in how companies handle data, and it’s a far worse habit when the asset isn’t stock, it’s people’s social insurance numbers, banking details and health records.
The asymmetry is the point, not a footnote
Customer data gets the security investment because customers are the ones who sue, churn and post on social media. Regulators built entire enforcement regimes around it. Boards ask about it by name. Employee data gets a line in the HR handbook and a password reset policy, because for years the working assumption was that employees don’t leave, don’t sue and don’t generate headlines the way customers do.
That assumption is now actively dangerous, and it fails in two directions at once. Attackers don’t care which database has better PR optics; they care which one has richer, less-monitored data, and payroll and benefits systems are full of it: banking details, health information, dependants’ data, SINs going back decades for people who left the company years ago and have no idea their file is still sitting there. And even without an attacker in the picture, data that nobody scrutinizes is data that gets mishandled by the people who are supposed to be protecting it.
In February 2025, a manager at the Canada Border Services Agency asked HR for a staff list to sort out shift scheduling. What came back was a spreadsheet with a second, hidden tab: personal record identifiers, classification levels and leave balances for more than 18,000 employees who had nothing to do with that shift. It got forwarded on to 70 more people before anyone noticed. When the Privacy Commissioner’s office dug in, it found the same sloppy handling had caused a near-identical breach the year before, plus four more like it.
No hacker. No ransomware. Just a spreadsheet nobody thought to check before hitting send, because it was internal, HR-facing data, and internal HR-facing data doesn’t get the same scrutiny a customer file would.
That’s not a freak case. It’s the shape of things when a system holds sensitive data and gets comparatively low-priority handling.
The law isn’t coming to save you, and it’s getting less likely to
For a while, Canadian plaintiffs’ lawyers had a useful tool against companies that got hacked: a tort called intrusion upon seclusion, which let a class of victims sue without proving they’d actually lost money. The Ontario Court of Appeal shut that door in 2022, in a trilogy of rulings involving Equifax, TransUnion and Marriott, and Alberta courts have followed. If a third party hacks your systems, you generally can’t be found liable for that tort anymore, no matter how badly you stored the data. Plaintiffs are left with negligence claims, which require proof of real financial loss, a much higher bar to clear.
British Columbia has gone the other way. Its Court of Appeal has held that a hacked company can still be liable under the province’s statutory Privacy Act, without the victims needing to prove any harm at all. So depending entirely on which province a class action gets filed in, the exact same breach carries very different legal exposure.
That’s not a stable deterrent. That’s a coin flip dressed up as a legal system. And a coin flip that’s landing “no liability” more often than not in the country’s two largest provinces is not something to plan a security programme around.
Here’s the reframe: if you’re relying on the threat of a lawsuit to force better handling of employee data, you’re relying on a backstop that courts are actively dismantling. The law was never going to be your control. It was, at best, a fallback for when your control failed. Now even the fallback is unreliable.
What this actually asks of you
Three things follow, and none of them are about waiting on regulators.
Treat HR and payroll like the crown jewels they are. Segment access the way you’d segment a customer payments environment. If a marketing coordinator can query the full employee SIN table because nobody ever locked it down, that’s not an HR problem, it’s a security architecture failure with your name on it.
Stop treating credit monitoring as a security control. Two years of free credit monitoring is a PR gesture, not a defence. It doesn’t undo a stolen SIN, which is valid for that person’s entire life. Cavoukian’s line from years ago still holds: the goal is making the hackers move on because the protections are too strong, not cleaning up efficiently after they’ve already won.
Ask the uncomfortable question in your next risk review: what’s the actual security parity between your customer-facing systems and your HR stack? If you can’t answer that in a specific, measurable way, you already know which side is weaker.
None of this needs a change in the law. It needs a CISO willing to stop treating employee data as a compliance afterthought and start treating it as what it is: a target that’s every bit as valuable as the customer database, sitting behind a much thinner door.
The lock on the stockroom is your call, not the court’s.

Responses