Diane McLeod-McKay, the territory’s information and privacy commissioner, says “highly sensitive” personal information belonging to thousands of Yukon government employees was being widely circulated to more than a dozen departments and the legislative assembly. (Crystal Schick/Yukon News file)

Personal data from thousands of Yukon government employees was accessible to too many people: report

Yukon Information and Privacy Commissioner says the government broken access to information laws

“Highly sensitive” personal information belonging to thousands of Yukon government employees has been widely circulated to over a dozen departments and the legislative assembly, a breach of the territory’s information and privacy legislation, according to an investigative report by the Yukon Information and Privacy Commissioner.

The Public Service Commission (PSC) isn’t authorized to do this, Commissioner Diane McLeod-McKay told the News when the report was released on Jan. 29.

“All employees of the Yukon government and potentially more than that” were impacted by the wholesale exchange of personal data, she said. “The information system itself was being used to process the personal information of all employees.”

That same data, collected at the point of hire and onwards until termination or retirement, was deemed to be insecure.

The report was spurred by a complaint lodged in November 2016 that alleged similar concerns.

Using an electronic human resources tool, PSC distributed details including “biographical information” and job titles to different HR branches belonging to 16 other departments and the legislature, the report says.

“Employees’ names, addresses, telephone numbers, identifying numbers, ages, sex, marital status, family status and information about their educational, financial and employment history is the identifiable information at issue,” it says.

“A short assessment of (the HR management system) security, using publicly available information and scenario-based modeling, recently resulted in the detection of a security risk to the overall system.”

Certain particulars of the report have been redacted for privacy reasons.

“Some departmental human resource professionals across government previously had access to personal information of employees not in their own department,” said Nigel Allan, a PSC spokesperson, in a written statement.

“Access by human resource personnel to employee information is now restricted to employees in their own departments. In addition, any sharing of employee information between departments is now limited to the Public Service Commission for general human resource management purposes and the Department of Finance for payroll purposes.”

Asked if this data was obtained by anyone outside the Yukon government, McLeod-McKay said “We have no indication that there has been any harm caused as a result of (the breach),” adding that making such a finding hinges on PSC conducting evaluations of its system.

Managers with proper clearances had access to personal information, the report says.

“For example, any manager who has such a designation could access the (private information) of any employee in (HR management system) outside the scope of that manager’s public body despite having no reasonable and direct connection to it, nor any necessity to use it,” it says.

The bottom-line is that data was available to people who simply shouldn’t have had access to it, McLeod-McKay said.

“Every government department had access to information to all the employees in the system,” she said. “We determined, in the report, that they did not have authority to do that.”

Personal information must be exclusive to the department in which an employee works, the report says.

Human resources “elsewhere have no function in the collection of (personal information) as it affects employees working in other public bodies.”

Personal data provided to the Department of Finance is authorized because these details are required to process salaries, bonuses and benefits.

The PSC is only able to disclose personal data “if it’s use is consistent with the purpose for which it was obtained or compiled,” according to the report.

There are certain restrictions. The financial branch, for instance, is not privy to biographical information, the report says, attributing it to a statement from the PSC.

“… I am satisfied that the collection of employee (personal information) to provide compensation and superannuation benefits to that employee is a key component of the administrative activity,” it says.

“(Personal information) must be limited to authorized persons whose responsibilities require such access, as opposed to their status, rank or office, or on a premise of practical or functional convenience.”

The report outlines 17 recommendations for the PSC to implement, which include containing the breach, revoking access that “designated employees” have to private information belonging to all government workers, excluding those who are retired, and bringing in prevention measures to ensure such incidents don’t occur again.

“The Public Service Commission has accepted them and we are working actually with them on doing a privacy impact assessment on their (human resources system), which essentially means we walk through the entire system … and find their authorities to collect these and disclose, as well as look at their security parameters to make sure they’re sufficient enough to secure the information appropriately, appropriately in accordance with the act,” McLeod-McKay said.

“Laws are there to protect citizens, which all of us are, so it’s really important, especially in this day in age of cybercrime and other kinds of leaks of information, that these steps now be taken to ensure that the information is properly secured.”

Allan, the PSC spokesperson, said most of the recommendations will likely be implemented by April.

Contact Julien Gignac at julien.gignac@yukon-news.com

Just Posted

Yukon’s Dylan Cozens selected by the Buffalo Sabres seventh overall in the NHL draft

Cozens is the first Yukoner to be selected in the first round of the draft

Man fined after unsuccessfully arguing Yukon driving laws don’t apply to him

Christopher Brown was found guilty of four charges under the Motor Vehicles Act on June 20

WYATT’S WORLD

Wyatt’s World

Fossilized teeth found near Old Crow belonged to ancient hyena

The two fossilized teeth were discovered in 1973 and 1977

Changes could mean closing Whitehorse council and senior management meetings to the public

Sessions, which are separate from official council meetings, would be closed to the public

Letter: Celebrating Indigenous Peoples Day

Celebrated on June 21, National Indigenous Peoples Day is around the corner.… Continue reading

City news, briefly

A summary of some of the issues discussed at the June 17 Whitehorse city council meeting

Whitehorse training conference highlighted trans health care needs

The conference, hosted by the World Professional Association for Transgender Health, was June 13-15

COMMENTARY: Foreign funding for local environmental groups no conspiracy

Foreign funding doesn’t mean activism isn’t locally grown, says CPAWS Yukon’s executive director

Letter: Yukoners want ‘climate action now’

Yukoners Concerned are excited that despite the basketball game on TV, over… Continue reading

Letter: Cars and bikes — let’s take care of each other

As a dedicated long-time cyclist who has plied the Alaska Highway route… Continue reading

Letter: Flag gone missing on the Chilkoot Trail

Note: a copy of this letter has been sent to Christopher Hunter,… Continue reading

Yukon Orienteering Championships continue with sprint races

Held over three weeks, the championships include middle-distance, sprint and long-distance races

Most Read