1) Introduction: Information, Connection and Obligation
We live in an age of information, in which information is currency. Participation in an information economy constantly gives rise to relationships of trust, in which personal information is entrusted to those who are tasked, expressly or impliedly, with safeguarding it. In Jones v Tsige, the Court of Appeal for Ontario recognized that the relationships that necessarily emerge in an increasingly networked world must be regarded as legal relationships that gave rise to legal duties at common law:
The Internet and digital technology have brought an enormous change in the way we communicate and in our capacity to capture, store and retrieve information… routinely kept electronic databases render our most personal financial information vulnerable. Sensitive information as to our health is similarly available, as are records of the books we have borrowed or bought, the movies we have rented or downloaded, where we have shopped, where we have travelled and the nature of our communications by cellphone, e-mail or text message. It is within the capacity of the common law to evolve to respond to the problem posed by the routine collection and aggregation of highly personal information that is readily accessible in electronic form.[1]
The tort that the court recognized was termed “intrusion upon seclusion”, and it required establishing the following three elements: 1) intentionality by the defendant, which includes recklessness,[2] 2) an invasion by the defendant, and 3) that what was invaded would be regarded by a reasonable person as “highly offensive causing distress, humiliation or anguish”.[3] While the plaintiff would have to show that the invasion caused significant offence, they would not need to prove harm, since the remedy is for the “moral damages” caused by the invasion itself.[4] Impliedly, “intrusion upon seclusion” was meant to remedy the injury caused to the dignity of the plaintiff, in having their sensitive, personal information exposed to those not entitled or entrusted to access it.
2) Privacy Class Actions and the “Database Defendant”
The need to share information, to participate in a networked economy, also means that information is increasingly concentrated, at mass-scale, in the possession of the parties that collect it. And with that increased concentration comes an increased risk of breach by third parties (hackers) who seek to gain access to the information. And with the unavoidability of sharing information comes the increased frequency of breach, which can affect massive numbers of people.[5]
The breadth of the impact of database breaches naturally led to attempts to certify class actions. However, unlike the individual case of Jones v Tsige, in which the defendant was the party that invaded the plaintiff’s privacy, the wronged parties in data breaches do not know the identity of the hackers that illegally gained access to their information. This challenge led to a series of attempts to hold liable the “database defendants” - those who rightfully possessed the information but allowed the unauthorized hackers to gain access to it.
However, common law courts have been reluctant to apply the tort of intrusion upon seclusion to third parties who did not themselves intrude but rather were subject to, and did not prevent, the breach.
a) The Equifax Trilogy and the Third-Party Problem
The leading case is the Equifax “trilogy”, as decided by the Court of Appeal for Ontario. In the eponymous case, Equifax provided credit reporting and protection services, and in providing credit ratings, the company collected and aggregated financial and personal information from millions of customers. Between May and July 2017, an unknown group of hackers gained access to that information, which included customers’ social insurance numbers, names, dates of birth, addresses, driver’s licence numbers, credit card numbers, email addresses, and passwords. This breach was estimated to have affected 20,000 people.[6] A group of customers sued Equifax and sought to certify a class action. In the certification decision, the motion judge certified the class action, holding that Equifax could potentially be held liable on all proposed grounds,[7] but the majority of the Divisional Court and the Court of Appeal reversed that decision, ruling that Equifax could not be held liable for intrusion upon seclusion, since it was not the intruder.
In its analysis, the Court of Appeal held that the intent of intrusion upon seclusion is to hold the invader liable. The court stressed that this does not foreclose liability for a database defendant, since its potential wrong is in negligently allowing an unauthorized party to breach its security and gain access to the customers’ personal information. Thus, the motion judge was not incorrect in certifying negligence or breach of contract as viable causes of action for the class proceeding, but, as a third party, Equifax could not be held liable for the breach of its customers’ right to privacy. Even if the firm had been reckless in ignoring the risks posed, since it was not the party that invaded the plaintiffs’ privacy, it did not meet the conduct element of the tort. As the Court of Appeal held,
On the allegation made, Equifax failed to take steps to prevent independent hackers from conduct that clearly invaded the plaintiffs’ privacy interests in the documents stored by Equifax. Equifax did not, however, itself interfere with those privacy interests. The wrong done by Equifax arose out of Equifax’s failure to meet its obligations to the plaintiffs to protect their privacy interests…
The defendant must either intend that the conduct which constitutes the intrusion will intrude upon the plaintiffs’ privacy, or the defendant must be reckless that the conduct will have that effect. If the defendant does not engage in conduct that amounts to an invasion of privacy, the defendant’s recklessness with respect to the consequences of some other conduct, for example the storage of the information, cannot fix the defendant with liability for invading the plaintiffs’ privacy.[8]
Both the majority of the Divisional Court and the Court of Appeal distinguished the plight of the plaintiff in Jones v Tsige from the plaintiffs in this case. These plaintiffs could not rightly cry out for a remedy in being denied certification on the grounds of intrusion upon seclusion, since the remedies for breach of contract and negligence remain available. The purpose of the tort is to remedy the injury to dignity of the plaintiff whose privacy was invaded, but such vindication of rights can only be asserted against the party that actually wronged them, not against a negligent third party.
In Jones, the plaintiff had no remedy of any kind against the defendant who had intentionally invaded her privacy. [The representative plaintiff] and the other class members have a remedy against the hackers who intentionally invaded their privacy. They can sue for invasion of privacy. No doubt, they face a very real problem. In most cases it will be impossible to identify, much less sue, the hackers. The inability to sue the actual hackers is not, however, justification for creating a remedy against a different defendant who has committed a different tort for which the plaintiffs have all the usual remedies available to them. The inability to successfully sue the hacker is no reason to make a Database Defendant liable, not only for its own wrongdoing, but also for the invasion of privacy perpetrated by the hacker.
XXTo award “moral damages” against Equifax for what is essentially its negligence or breach of contract runs contrary to the very purposes underlying the award of such damages. Moral damages are awarded to vindicate the rights infringed, and in recognition of the intentional harm caused by the defendant. These purposes are served only if the damages are awarded against the actual wrongdoer, that is the entity that invaded the privacy of the plaintiff.[9]
Besides ruling on the inappropriateness of certifying the class on the basis of intrusion upon seclusion in this case, the Court of Appeal saw the private law issue as sufficiently settled to preclude certification when the defendant was not the party who unlawfully gained access to the plaintiffs’ data but rather the party charged with the responsibility to prevent that invasion and failed. Citing Babstock, the Court of Appeal affirmed that this question was sufficiently settled such that it could not meet the low bar set by the Class Proceedings Act, and a court ought to dispose of it at the certification stage.[10]
b) The Third-Party Threshold following the Trilogy
Caselaw decided since the Equifax trilogy has generally affirmed and applied its holding that the tort of intrusion upon seclusion can only be applied to the party that invaded the plaintiff’s privacy. Thus, class actions advanced against “database defendants” cannot be certified on that ground.
In Winder, a hacker compromised the databased of the Marriott Hotel chain, gaining illicit access to the personal and financial information provided by customers in making reservations and purchases in dealing with the defendant. Justice Perell interpreted Jones v Tsige in line with the Equifax trilogy, holding that even if, through its failing to maintain sufficient cybersecurity, a database defendant could be construed as a “constructive intruder”, the scope of the tort is meant to batten down the proverbial floodgates and is restricted to “real” intruders.[11] Public policy does not demand expanding the scope, since the law of negligence and breach of contract offers sufficient private legal avenues to hold a third party liable.[12]
In Del Giudice,[13] hackers gained access to the financial information gathered by Capital One in accepting applications for credit cards, stored in Amazon Web Services (“AWS”) cloud servers. The plaintiffs sought to certify a class action against Capital One and AWS for allowing the hackers to breach their privacy and gain access to their personal data. The Court of Appeal affirmed the ruling of the motion judge and applied the holding in Equifax: since the database defendants were not the invading parties, they cannot be held liable on the basis of intrusion upon seclusion. Further, the subject matter of the breach was personal, but its exposure was not “highly offensive”, as it did not go to the plaintiffs’ “biographical core”.[14]
In Litvin, an investment management company had subcontracted with a firm to provide compliance and customer communication, which necessarily involved the disclosure of clients’ financial information. The subcontractor was infiltrated by hackers who exploited a vulnerability in its file transfer software.[15] The clients sought to certify a class action against both companies for the data breach, and the court found that causes of action for negligence, breach of contract and breach of fiduciary duties (in the provision of financial services) could serve as common issues, but the court declined to certify the class on the grounds of intrusion upon seclusion, applying the logic explicated in Equifax. Even if the firms had been reckless in ignoring the risks of failing to maintain a certain standard of cybersecurity, since they were not the invading parties, they could not be held liable for intrusion upon seclusion.[16]
Finally, in Trueman, a class action against a “database defendant” was certified on grounds including intrusion upon seclusion, but that was because the defendant actively disclosed personal information without right. Here, Rogers Communication shared its clients’ financial information with Rogers Bank, to facilitate obtaining credit reports of those customers.[17] While the two companies share a name, they are distinct corporate entities, and even if customers were clients of both, they had only shared that financial information with the former, in exchange for its services, and never authorized use by the latter.[18] While there was no invasion by a hacker, the wrong to be remedied by the tort was in the crossing of the threshold between those authorized to use personal information and those not unauthorized. Whether one invades or discloses, that is the dispositive issue.
c) Potential Opportunities to Advance a Claim of Intrusion upon Seclusion against a Database Defendant: Recklessness in Creating Risk
As discussed above, after the Equifax trilogy, courts regularly decline to certify class actions for data breaches against “database defendants” on the ground of intrusion upon seclusion, where the defendant did not disclose or intrude on the data themselves. The scope of the tort excludes third parties to the invasion or disclosure. However, some recent caselaw suggests that the recklessness of a database defendant could be construed as a material contribution to the act of the intruding hacker, such that a court ought not strike the ground at the certification stage and should hear evidence to determine potential liability.
In Quantz, there were no hackers but rather the defendant accidentally disclosed personal information, but the Superior Court still held that it did not meet the threshold of intrusion upon seclusion. Here, the Ministry of Children, Community and Social Services gathered the following information from its vulnerable client base of persons with disabilities: names, email addresses and ODSP identification numbers. The Ministry provided a spreadsheet containing that information to its caseworkers, and one of whom accidentally sent an email with that spreadsheet attached to a group of clients, who were not authorized to access other clients’ personal information.[19]
The court declined to certify the class action on the ground of intrusion upon seclusion, but it did not foreclose the potential to find that a third party’s creation of risk could be regarded as part of the wrongful conduct. The plaintiffs argued that the Ministry’s dissemination of the information to its caseworkers constituted intrusion upon seclusion, but the court compared this to a database defendant’s merely careless storage of data. Even if the Ministry was at fault for disclosure to unauthorized parties,[20] the act was not deliberate or reckless and thus could not constitute the mens rea of the intentional tort. However, the court considered the potential to find a third-party database defendant liable for intrusion upon seclusion, if it was sufficiently reckless and created a significant enough risk for affected parties.[21]
While common law courts are reluctant to provide a remedy for the mere risk of harm that has not yet eventuated, the significance of the risk and the third party’s deliberate or reckless contribution thereof remains an outstanding question of liability. In Setoguchi, the Alberta Court of Appeal drew on American jurisprudence to carve out the potential that a “sufficiently significant risk” can be compensable.[22] In that context, the question was whether a “database defendant” could be held liable when the disclosed information has not yet given rise to material harm,[23] but the principle remains applicable: where a party has materially contributed to significant risk, there is the potential for liability.
This potential was actualized in a Federal Court case settled earlier this year. In Sweet, the motion judge departed from the rule laid out in the Equifax trilogy and opted to certify a class action on grounds including intrusion upon seclusion against a database defendant. Here, the defendant was the federal government, as the Canada Revenue Authority (CRA) had failed to maintain sufficient cybersecurity and allowed hackers to access online accounts accessed via the Government of Canada Branded Credential Service Key, which was specifically designed to provide a certain level of security.[24] Here, the judge declined to follow Equifax in seeing the scope of the tort as sufficiently settled and certified intrusion upon seclusion as a common issue, so parties could adduce evidence and submit argument on whether it ought to include third parties in certain circumstances. In particular, the judge found that the express pleading of recklessness on the part of the database defendant was sufficient to merit certification, as the CRA had failed to attend to attempts to raise its awareness of the risks of breach.[25]
While the jurisprudence heavily leans against including third party database defendants in data breach class action claims of intrusion upon seclusion, the cases discussed above provide some hints at the potential to expand the tort’s scope incrementally. First, a plaintiff would have to plead facts that establish the database defendant was not merely negligent but was reckless to risks of which it was made aware, regarding the plaintiffs’ security of information. Second, the plaintiff would have to argue that the risk was sufficiently significant that the database defendant’s recklessness in ignoring it ought to be seen as tantamount to collaborating in the hack. Lastly, while it is not discussed expressly, the vulnerability of the plaintiffs may also lend toward providing a remedy. Where the plaintiffs’ provision of information places them in a precarious position, the defendants’ standard of care is heightened. In Quantz, the plaintiffs were disabled persons who had been forced to disclose their personal information to the provincial government in order to access certain benefits. In Sweet, the plaintiffs were legally obligated to submit financial and personal information to the CRA, at the risk of penalty. The vulnerability of the plaintiff and the imbalance of power held by the defendant may lead a court toward incrementally expanding the scope of the tort, in those specific circumstances.
3) The Problem and Potential of Negligence
As discussed above, courts have been reluctant to expand the scope of intrusion upon seclusion to database defendants, because the tort’s remedy of moral damages is intended to vindicate the invaded party’s rights against the invader and because alternative private law remedies are putatively available to advance against database defendants: negligence and breach of contract. Below, I discuss the limits and promise of certifying a data breach class action against a database defendant on the ground of negligence.
While the tort of negligence is presented in the jurisprudence as a ready-and-available alternative to remedy a data breach, courts have also expressed reservations about certifying on this ground. Unlike breach of contract, which entails strict liability, to establish negligence, the plaintiff must show that they have suffered compensable damage. This, too, has served as a hurdle preventing plaintiffs in privacy class actions from accessing a remedy, since the information stolen often grounds only the risk of material harm, and, as discussed above, common law courts are reluctant to remedy a risk.[26] So, even with the tort of negligence there is an additional threshold that precludes a remedy, which is that the plaintiff must show that the breach has led to actual, material harm.
While this requirement makes sense as a matter of private law, it displaces the motivating issue that compelled the creation of a novel tort: the right of the plaintiff is a right to privacy, and the wrong they suffer is an invasion of that privacy that, through unauthorized disclosure or invasion, causes real hurt or offence. Even accepting that courts are correct in narrowly construing the tort’s scope to exclude third parties, the logic at play recognizes that the intrusion itself is a wrong and constitutes an injury to the plaintiff’s dignity. Thus, where the plaintiff can establish that the database defendant’s negligence led to the violation of their privacy that gave rise to an injury to dignity, the correct remedial framework to apply is not compensable damages but moral damages. As the court has held, moral damages are awarded where a plaintiff can establish a breach of right, which does not translate into a material loss.[27]
Courts have been reluctant to regard the mere fact of a data breach as sufficient, in and of itself, to give rise to an injury that per se demands a remedy. As noted above, participating in a networked world and informational economy lends toward the increased incidence of data breaches, which have now become an annoying, but not destroying, feature of our lives. Accordingly, courts begin with the premise that plaintiffs must show that the “stress and anxiety” they have experienced are “serious and prolonged and rise above life’s ordinary annoyances”.[28]
Thus, a necessary element to establish negligence against a database defendant in the absence of material loss is the severity of the exposure caused by the breach. Recent decisions have gestured to a categorical denial that breach per se could give rise to damages, but those decisions have also acknowledged that the plaintiffs did not plead the requisite emotional harm that would merit such a finding. In Del Giudice, the Court of Appeal noted that none of the precedents cited supported that a breach per se could merit moral damages, but its holding affirmed the decision of the motion judge, who noted that “the material facts needed to support it were not pleaded”.[29] Similarly, in Quantz, the plaintiffs pled that the breach caused “stigma, psychological harms, and exposure to fraud”, but the court found that there was a “doubtful air of reality” surrounding the pleading since the plaintiffs had joked about the breach on their publicly accessible Facebook page.[30]
I would propose that, for a data breach to be certified as a class action on the ground of negligence, it must be that the breach disclosed not merely personal information but the plaintiffs’ private information. This requirement is consistent with the impetus that motivated the court’s creation of a tort protecting privacy at common law and is also consistent with its standard: the invasion of privacy must cause non-trivial offence. The invasion itself is the injury, not the consequent potential material loss, and it is an injury to the plaintiff’s dignity, which per se demands a remedy. At the certification stage, a court ought to establish the ground of negligence as a common issue, so the plaintiffs can lead facts that show the injury they suffered to their dignity, in entrusting their private and sensitive information to a negligent safeguard.
While courts have not yet recognized this ground, I would argue it is an incremental expansion appropriate for the common law, and consistent with courts’ own reasoning. In Setoguchi, the Alberta Court of Appeal declined to certify a data breach class action against Uber on this ground because the information disclosed was merely financial and thus insufficiently sensitive:
While the appellant asks the court to recognize the value of the information lost, ultimately her focus is not only the information itself but rather on the consequences of criminals being in the possession of the names, phone numbers and email addresses of the proposed class members. It is not the viewing or access to the information by others that is said to be harmful; the appellant herself recognizes that though the information is personal, it is not necessarily private.[31]
Here, the Court of Appeal of Alberta recognizes the potential of finding that a data breach is itself deserving of remedy where the information to which the hackers gained access was not merely personal but private. Similarly, in Accor, the British Columbia Supreme Court also declined to recognize that the data breach at issue potentially merited moral damages. However, it did not make this determination because a data breach is incapable of causing an emotional injury that could ground liability but rather because, in this case and on these facts, the plaintiffs failed to plead that the psychological upset they experienced rose above the “ordinary annoyances, anxieties and fears” of living in an increasingly networked world.
The plaintiff has pled the Data Breach caused the putative class members “psychological or mental distress which is serious and prolonged, and rises above ordinary annoyances, anxieties and fears”. However, a bald recitation of the Mustapha test for compensable injury is not a substitute, nor does it obviate the requirement, for pleading facts that satisfy the compensable harm requirement. The plaintiff has failed to plead facts to support the conclusion that any of the putative class members have suffered or will suffer psychological or mental distress which is serious and prolonged and rises above the ordinary annoyances and fears of life in the digital age…[32]
In its analysis, the court did not take issue with the premise that a data breach can possibly cause sufficient psychiatric harm to ground liability, but rather the inappropriate conclusion the plaintiffs sought to adduce on inadequate facts. The court recognized that the data breach was upsetting, but mere anxiety is not enough to ground a psychological or emotional injury. But the court did not foreclose the potential for liability where a data breach exposes sensitive enough information that would reasonably give rise to serious offence or emotional harm.
In conclusion, it would not be a radical step for courts to certify a data breach class action against a database defendant on the ground of negligence, despite a lack of material loss, where the breached information was not merely personal but private, reasonably giving rise to psychic harm in and of itself. In this way, the tort would protect the plaintiff’s right to privacy in a manner that is appropriate, in relation to a third party, where their negligence materially contributed to a recognizable injury. In this way, the common law would continue to reflect and respond to the world in which we find ourselves: one in which we constantly must entrust our personal and private information to others for them to keep safe and use appropriately. The heightened connection of a networked world and informational economy places all of us in a vulnerable position, which the courts are well-positioned to recognize and remedy.
[1] Jones v Tsige, 2012 ONCA 32 at paras 67-68.
[2] Here, the court drew on the Supreme Court’s ruling in Sansregret, in which recklessness was found to be sufficient to establish mens rea, since it entails recognition of a risk of harm and a decision to ignore that risk and proceed. See Sansregret v The Queen, 1985 CanLII 79 (SCC) at para 16. . In the Equifax certification decision, the Superior Court expressly made that connection. See Agnew-Americano v Equifax Canada Co, 2019 ONSC 7110 at para 151; Owsianik v Equifax Canada Co, 2021 ONSC 4112 at para 21.
[3] Jones v Tsige, supra, at paras 70-71.
[4] Ibid at para 88.
[5] Courts have recognized the commonplace nature of data breaches in a networked world. See, e.g. KW v Accor Management Canada Inc, 2023 BCSC 1149 at para 62 [Accor].
[6] Owsianik v Equifax Canada Co, 2021 ONSC 4112 at paras 8-12 [Equifax ONDC]; Owsianik v Equifax Canada Co, 2022 ONCA 813 at paras 13-16 [Equifax ONCA].
[7] Agnew-Americano v Equifax Canada Co, 2019 ONSC 7110.
[8] Equifax ONCA, supra, at paras 57, 59.
[9] Ibid at paras 76-77. See also Equifax ONDC at paras 54-55.
[10] Equifax ONCA, supra at para 31; Equifax ONDC, supra at para 53; citing Atlantic Lottery Corp Inc v Babstock, 2020 SCC 19 [Babstock].
[11] Winder v Marriott International, Inc, 2022 ONSC 390 at para 13 [Winder].
[12] Ibid at para 14.
[13] Del Giudice v Thompson, 2021 ONSC 5379 at paras 130-147 [Del Giudice].
[14] Del Giudice v Thompson, 2024 ONCA 70 at para 35.
[15] Litvin et al v Mackenzie Financial Corporation et al, 2025 ONSC 6138 at paras 7-12 [Litvin].
[16] Ibid at paras 46-51.
[17] Trueman v Rogers Communications Canada Inc, 2025 ONSC 5972 at para 2 [Trueman].
[18] Ibid at para 99.
[19] Quantz v Ontario, 2025 ONSC 90 at paras 2-7 [Quantz].
[20] Like Trueman, above.
[21] Quantz, supra at para 44.
[22] Setoguchi v Uber BV, 2023 ABCA 45 at para 55 [Setoguchi].
[23] Negligence and its need for compensable damages will be discussed in the following section.
[24] Sweet v Canada, 2022 FC 1228 at para 5.
[25] Ibid at paras 55, 132.
[26] See, e.g. Quantz, supra at para 58; citing Ernest J Weinrib, The Idea of Private Law, rev ed (London: Oxford University Press, 2012), at 153, 157‑58: “There is no right to be free from the prospect of damage; there is only a right not to suffer damage that results from exposure to unreasonable risk”.
[27] Insurance Corporation of British Columbia v Ari, 2025 BCCA 131 at para 35.
[28] Mustapha v Culligan of Canada Ltd, 2008 SCC 27 at para 9. This principle has been cited in the following privacy class actions: GD v South Coast British Columbia Transportation Authority, 2026 BCSC 773 at para 50; Setoguchi v Uber BV, 2023 ABCA 45 at paras 53, 58; Campbell v Capital One Financial Corporation, 2024 BCCA 253 at para 52; KW v Accor Management Canada Inc, 2023 BCSC 1149 at para 60 [Accor]. See also Saadati v Moorhead, 2017 SCC 28 at paras 19-20.
[29] Del Giudice, supra at para 53.
[30] Quantz, supra at paras 59-60.
[31] Setoguchi, supra at para 52.
[32] Accor, supra at para 60; emphasis in original.