A public audit released on Monday (21 September 2026) found that a $1.3 billion‑CAD (about €850m / $960m) contract between the federal government and telecom firm AuroraTel included clauses that allowed commercial staff to retrieve unredacted files from the new Pan‑Canadian Digital Locker service. The audit says those so‑called maintenance powers were not spelled out to Parliament and were accompanied by a network of subcontracts worth a further $175 million‑CAD (about €115m / $130m) that flowed to firms with opaque ownership structures.
The Auditor General’s report says approximately 5.6 million Canadians had accounts linked to the Locker at the time the contract was signed in late 2024, and that routine data migrations were already under way when the access entitlement was exercised. The government announced an immediate halt to migrations and said it had suspended parts of the contract pending an external review.
What the audit found
The 92‑page audit, obtained and published by the Auditor General’s office, describes a technical backdoor in the platform: AuroraTel engineers and a small team from subcontractor Northern Bay Holdings were issued long‑lived API tokens that bypassed the service’s redaction and consent screens. The report says the tokens were justified in procurement paperwork as a temporary “debugging” measure but were used in live environments.
“The tokens permitted access to whole files, including medical records and legal documents, without the same user consent recorded in the public interface,” the report states. Ex‑AuroraTel systems engineer Matúš Bača‑Virčíková, who spoke to reporters after providing testimony to the audit team, said the arrangement was known inside the company as a way to speed problem resolution. “I was given keys that pulled raw data. Management called it maintenance; customers saw it as private,” he said.