OPC (Canada) · August 31, 2026

OPC Canada: WestJet Commits to Enhanced Security Measures Following Data Breach

The Office of the Privacy Commissioner of Canada announced that WestJet has committed to improving its security measures following a data breach investigation. Details of the underlying breach and remediation commitments were not included in the available excerpt.

What Was Announced

The Office of the Privacy Commissioner of Canada (OPC) issued a news release stating that WestJet has committed to improving its security measures following a data breach. The excerpt provided consists only of the release's header material, and does not include further detail on the nature of the breach, the scope of affected individuals, or the specific security commitments made by WestJet.

Limited Available Detail

Because the source excerpt is limited to the news release title and a generic "News release" label, this post cannot confirm specifics such as the timing of the breach, the type of personal information involved, the OPC's findings on compliance with Canadian privacy law, or the precise remedial steps WestJet has agreed to undertake. Organizations seeking full context should consult the complete OPC news release at the cited URL once available.

What This Means

Even in the absence of full details, the announcement itself signals that the OPC continues to actively investigate data breaches involving large Canadian organizations and to secure public commitments to remediation. Privacy and security teams should treat regulator-driven commitments of this kind as a reminder to:

  • Review incident response and breach notification protocols to ensure they align with OPC expectations.
  • Confirm that security safeguards for customer personal information are periodically tested and updated, particularly for organizations handling high volumes of sensitive travel or payment data.
  • Monitor the full OPC release for specifics once published, as it may outline expectations or best practices applicable beyond this single case.

Organizations in similarly regulated sectors should watch for the full text of this release, as it may provide useful benchmarks for acceptable post-breach remediation commitments under Canadian privacy law.

We use cookies to run this site. Necessary cookies are always on; functional, analytics, and marketing cookies are off unless you choose to enable them. See our Privacy Statement for details.