
Cummins knows how to protect a server room. SaskTel’s downtown Saskatoon data centre needed more standby power, so Cummins supplied a 3,250 kW QSK95 generator set large enough to keep a substantial slice of the digital world breathing when the grid stops cooperating. The installation required a 300-ton crane, a third-floor lift and months of planning, all so SaskTel could keep its machines alive when everything outside went dark. Cummins eventually gave the result one of those magnificently absolute industrial descriptions that sounds as though Legal, Engineering and Marketing all signed the same hymn sheet: “best-available server room protection”.
The QSK95 sat there waiting for darkness like a diesel fucking cathedral to redundancy. If utility power vanished, the engine could wake up and keep the racks humming. Cummins talked about maximum uptime, high reliability, reduced servicing and dependable protection for SaskTel’s expanding customer base. Every kilowatt existed because data mattered, continuity mattered and a dead telecommunications data centre can turn into a corporate bowel movement before somebody has even located the emergency PowerPoint.
Unfortunately, the server room was not the only place inside SaskTel containing information worth protecting. Years before Cummins began admiring the generator, Saskatchewan’s Information and Privacy Commissioner investigated SaskTel’s handling of customer information and found a rather uglier architecture. The Commissioner concluded that SaskTel lacked authority to collect customers’ Saskatchewan Health Services Numbers, had not justified collecting certain other unique identifiers, had problems with notice and indirect collection, and had insufficient safeguards to fully protect personal and personal-health information.
Then SaskTel disagreed with the recommendation to stop collecting the health number.
Fourteen years later, its own website still explains why SaskTel may ask you for one.
That is quite a fucking uptime statistic.
A Phone Bill Opened The Wrong Door
The whole thing began with something spectacularly mundane. In 2006, a SaskTel customer phoned with questions about charges on his telephone bill. According to the Privacy Commissioner’s later report, SaskTel asked for identifying information and then wanted either his Social Insurance Number or Health Services Number to verify who he was.
The customer objected, and you can understand why. A telecommunications company obviously needs to establish identity, but that does not automatically mean a number created for Canada’s social-insurance system or Saskatchewan’s healthcare system should be dragged into a phone-bill query like some bureaucratic Swiss Army knife. The caller eventually established a password and got his billing question answered, but during the exchange he learned that SaskTel already had his driver’s licence number, SIN and health number on file.
That is when the transaction became more interesting than the bill. A customer asking why his phone cost what it did instead discovered a little identity warehouse sitting behind the counter. Driver’s licence, SIN, health number: enough personal identifiers to make a fraudster start rubbing his grubby fucking hands together.
The customer wanted them removed. From there, the question became much larger than one account. Why was SaskTel collecting this material? What authority did it have? How much did it genuinely need? And once the data entered the system, who exactly was standing guard over the bastard?
SaskTel’s Privacy Response Loaded At Dial-Up Speed
The Privacy Commissioner’s office began investigating in September 2006. In February 2007, it asked SaskTel for a more detailed response to a series of questions.
That detailed response arrived on 1 February 2011.
Nearly four years.
For a telecommunications company, that is fucking performance art.
The Commissioner recorded that his office wrote again during the intervening years, summarising what remained unanswered and inviting SaskTel to respond formally. Eventually the material arrived after enough calendar pages had died to qualify for their own memorial service.
The contrast with Cummins’ later engineering is glorious. Data centres measure interruption in seconds because nobody running critical infrastructure wants to watch a loading icon while expensive machines lose consciousness. The QSK95 exists because hesitation is costly. Utility power disappears, sensors react, machinery wakes up and everybody hopes several million dollars of technology never notices the lights went out.
SaskTel’s privacy response apparently operated on geological time. You could have installed the generator, craned it three floors into position, serviced the bloody thing repeatedly and probably trained somebody’s replacement before the paperwork crossed the finish line.
The Commissioner Said SaskTel Had No Authority To Collect The Health Number
The eventual report landed in August 2012, and the conclusion on Saskatchewan Health Services Numbers was not dressed up in mystery. The Commissioner found that SaskTel did not have the requisite authority to collect its customers’ health services numbers.
That matters because a Health Services Number is not some throwaway loyalty-card reference or an account number created by SaskTel itself. The report treated it as personal health information and examined whether SaskTel had a proper legal foundation for gathering it.
The foundation did not exactly emerge wearing a hard hat.
The Commissioner also found SaskTel had not adequately justified its collection of other unique identifiers and several pieces of information used to establish creditworthiness. He identified shortcomings involving statutory notice, indirect collection of third-party information and broader compliance with Saskatchewan privacy law.
This is where Cummins’ later language begins making a faint electrical crackle. Best-available protection sounds magnificent when a 3.25-megawatt generator is standing behind it. It sounds rather less majestic when the privacy regulator has already wandered into another room, lifted the floor tiles and found a bunch of questionable fucking cables underneath.
If Less Information Will Do, Stop Hoovering The Lot
One of the clearest principles running through the Commissioner’s reasoning is also one of the least glamorous: if less information will achieve the purpose, collecting more is excessive. Data minimisation is not sexy. Nobody unveils it with champagne or has a 300-ton crane lower it through a roof. It is simply the discipline of not grabbing every useful-looking identifier because some bastard in a process meeting thinks more fields must mean more certainty.
Every additional piece of personal data creates work and risk. It needs to be stored, governed, secured, retained for the correct period and eventually destroyed. It creates another object somebody can misuse, expose or steal. There is no magical point at which hoarding identifiers becomes a security feature merely because the database still has space.
SaskTel had business reasons for wanting the information. It argued that unique identifiers could help establish identity, assess creditworthiness, reduce bad debt and support debt recovery. Those may be commercially useful objectives, but “useful to us” and “necessary and properly authorised” are not the same fucking concept.
Keep following pure utility far enough and every customer becomes a walking KYC carcass. Phone number? Useful. Date of birth? Useful. Driver’s licence? Useful. SIN? Useful. Health number? Why not? Maybe get a blood type while we are here in case Accounts Receivable develops an interest in haematology.
That is precisely why restraint exists as a privacy principle. The safest unnecessary data is the shit you never collected.
Then The Commissioner Looked At The Safeguards
The Commissioner did not stop at asking what SaskTel collected. He also examined what happened after the information entered SaskTel’s custody, and this is where the later Cummins phrase becomes almost indecently convenient.
The conclusion was that SaskTel’s safeguards were insufficient to fully protect personal information and personal health information in its possession, custody or control.
That is a beautifully awkward historical sentence for a company later celebrated for best-available server room protection.
The Commissioner said SaskTel’s submission offered limited detail about the specific safeguards it used and concentrated more heavily on explaining why confidentiality was important. Sensitive information, he stressed, demands stronger protection. He recommended an immediate Privacy Impact Assessment.
There is a lesson here that any engineer could explain before lunch. Saying “safety matters” is not the same thing as designing a safe machine. Saying “privacy matters” is not the same thing as demonstrating the controls protecting sensitive personal information. Corporate declarations are cheap as piss compared with architecture, testing, access controls, audit trails and the tedious practical shit that stops a system becoming tomorrow morning’s breach notification.
Cummins understands this perfectly where electricity is involved. Nobody buys a QSK95 because Cummins has strong feelings about power continuity. They buy the enormous bastard because it physically does the job.
Stop Collecting It, Said The Commissioner
The Commissioner’s recommendations were not esoteric. He wanted SaskTel to conduct a Privacy Impact Assessment, improve its privacy policy and customer scripts, review its collection practices and purge information obtained without the required authority.
Most importantly for the Health Services Number, he recommended that SaskTel immediately cease collecting customers’ HSNs and develop a plan to purge them from its systems.
SaskTel did not agree.
The company said collecting the health number remained important to effective business operations and financial health. It argued that the identifier could help establish identity, reduce bad debt, determine creditworthiness and support debt collection.
There is an almost perfect collision of institutional dialects in those positions. The privacy regulator is asking, essentially, what gives you the authority to collect this piece of personal health information? SaskTel replies with a list of reasons the number is commercially handy.
One side is talking about legal authority and informational restraint. The other is looking at the same digits and seeing cleaner debt collection.
That is some cold fucking arithmetic.
The Commissioner Was “Especially Troubled”
SaskTel accepted a number of the Commissioner’s recommendations. It agreed to undertake a Privacy Impact Assessment, review aspects of its practices and improve elements of its privacy framework.
But it did not accept everything.
The Commissioner said he issued the report publicly because SaskTel had not agreed to comply with all of his recommendations. On the Health Services Number in particular, he said he was “especially troubled” by SaskTel’s decision to continue collecting it.
That phrase does a lot of work without TCAP needing to dress it up in fake outrage. Privacy regulators spend their professional lives wading through data collection, legislative interpretation and institutional excuses. When one of them stops and tells the world he is especially troubled, you do not need to add circus music.
The formal finding remained that SaskTel lacked the requisite authority to collect customers’ health services numbers. SaskTel nevertheless continued defending the business case for asking.
Somewhere between compliance and commercial appetite, the fuse simply refused to blow.
Fourteen Years Later, The Argument Has Its Own Webpage
Fast-forward to 2026 and the story stops looking like regulatory archaeology.
SaskTel maintains a live page entitled “Can SaskTel ask for my SIN and HSC information?” The wording is fascinating because the company openly acknowledges the very issue that sat at the centre of the 2012 dispute.
SaskTel explains that certain provincial and federal departments are lawfully authorised to request Social Insurance Number or Health Services Card information. It then says SaskTel does not have this authorisation.
Then comes the pivot.
SaskTel says there is no legal prohibition preventing it from asking.
That sentence is carrying more weight than a fucking server rack.
The company’s current position is that customers do not have to provide those identifiers, service will not be denied where acceptable alternatives are supplied, and SIN or HSC information can help with identity verification and credit checks.
That is materially clearer than the environment described by the complainant in 2006. Customers now receive explicit notice that the information is optional, and SaskTel identifies alternatives. Those changes deserve to be recognised because accountability without chronology is just bullshit wearing a stern face.
But the underlying disagreement has not vanished. The Commissioner said SaskTel lacked requisite authority and recommended that collection stop. SaskTel’s current page says it lacks the authorisation held by designated public bodies but nevertheless considers itself free to ask voluntarily.
Fourteen years later, the old dispute has not been buried.
It has been fucking optimised for search.
Your Health Number Is Optional, But SaskTel Still Likes The Idea
SaskTel’s current privacy material says a SIN or Health Services Card can be requested for a credit check, although customers can use other forms of identification instead. The dedicated HSC/SIN page explains that the numbers can help distinguish customers with similar names, dates of birth or addresses and assist with verification.
Again, these are business explanations rather than clandestine behaviour. SaskTel is not hiding the practice under a tarp in a basement. It is telling customers what it may ask for and why.
The remarkable bit is that this transparency preserves the old argument rather than resolving it. SaskTel publicly acknowledges that it lacks the particular authorisation enjoyed by various government bodies, yet it still considers the optional request legitimate and useful.
No current source reviewed by TCAP establishes that SaskTel acts unlawfully every time it asks for this information today. Inventing such a conclusion would be unnecessary bollocks because the real documentary tension is better.
The regulator said SaskTel lacked requisite authority to collect the HSN.
SaskTel disagreed with the recommendation to stop.
SaskTel still has a page explaining why it asks.
That is not an allegation. That is the website architecture.
The Privacy Commissioner Has Not Forgotten Either
You might assume a 2012 investigation eventually becomes one of those ancient PDFs that survives online only because nobody knows which intern has the password needed to delete it.
Not here.
The Saskatchewan Information and Privacy Commissioner’s current Guide to FOIP still cites the SaskTel investigation when explaining privacy law. The guide repeats that the Commissioner found SaskTel lacked authority to collect the complainant’s Health Services Number. It also refers to SaskTel’s failure to satisfactorily explain why it required other unique identifiers over the telephone when it could not verify their accuracy.
The guide continues to reference the recommendations surrounding a Privacy Impact Assessment, privacy-policy improvements, customer scripts and purging information collected without proper authority.
That creates a spectacular institutional split-screen. SaskTel still has public material explaining why it may ask. The regulator still has public guidance using SaskTel’s earlier conduct as an example of the limits on collection.
Both pages are online.
Neither side has accidentally misplaced the fucking history.
SaskTel’s Modern Privacy Policy Is Much Cleaner
SaskTel’s current privacy policy, effective from October 2025, contains everything you would expect from a modern telecommunications company. It says protecting privacy is a priority, describes technical, administrative and physical safeguards, and commits SaskTel to identifying purposes for collection, obtaining consent where required and limiting collection to what is necessary.
That is exactly how serious information governance should look. The policy also explains that SaskTel may collect government-issued identification and use identifying information for authentication, fraud prevention and credit checking, while the separate HSC/SIN page makes clear that those particular identifiers are optional.
The present framework is therefore substantially clearer than the environment criticised in 2012. Pretending otherwise would be lazy.
Yet the historical dispute still matters because SaskTel’s modern language itself emphasises necessity and proportionality. Once an organisation has publicly committed to collecting only what is needed, an old regulator finding about excessive or unauthorised collection does not magically evaporate. It becomes a benchmark against which the shiny new policy can be measured.
Privacy policies are easy to make smell clean. The hard part is keeping the plumbing that way.
Then A Suspension Letter Found Open SharePoint
SaskTel later gave the Privacy Commissioner another data-protection problem, although this one ended very differently.
In October 2021, a SaskTel manager inadvertently saved an employee’s suspension letter to an internal SharePoint site with open sharing permissions. The document contained employment information and the employee’s home address, while the site was accessible to SaskTel staff.
Logs later showed that 14 employees encountered the posted letter. Eleven saw the link without opening it. Three opened the document; two closed it after recognising its personal nature, while the third reported the problem.
There is a wonderfully bleak little technical joke sitting in that sequence. SaskTel sells connectivity for a living and spends fortunes ensuring systems remain available. For one unfortunate week, a disciplinary letter also achieved excellent fucking availability.
But unlike the HSN dispute, this episode ended with the regulator largely satisfied.
Credit Where It Is Due, SaskTel Handled That Breach Properly
Once somebody reported the SharePoint problem, SaskTel removed the document within minutes. It reviewed logs, checked backups, interviewed employees and investigated whether copies had been made.
The Privacy Commissioner found that SaskTel contained the breach appropriately, notified the affected employee properly, investigated the cause and took adequate preventive action. His recommendation was that SaskTel take no further action.
That finding belongs here because TCAP is not a fucking slot machine where every customer automatically lands on three skulls. SaskTel handled this incident properly. The breach happened, the company responded quickly, the regulator examined the response and found no further action necessary.
In fact, the competent response makes the old health-number dispute more interesting. SaskTel clearly understands privacy incident management. It can investigate access logs, contain exposure and satisfy the regulator when something goes wrong.
The stubborn question is not whether SaskTel knows how to clean up spilled data.
It is why the organisation spent so long arguing over how much shit belonged in the bucket to begin with.
Cummins Built The Easy Kind Of Protection
Cummins’ engineering problem was beautifully straightforward by comparison. SaskTel already had a 1,750 kW generator at its Saskatoon data centre, but growth required more capacity. Cummins supplied one 3,250 kW QSK95 unit with enough power density to satisfy the expanded requirement within a constrained third-floor installation.
Getting the engine into place was difficult. The underlying logic was not. If utility power fails, start the generator. If demand grows, provide more capacity. If downtime carries unacceptable risk, build redundancy around the failure before some poor bastard is standing in a dark server hall explaining availability statistics to the board.
Everything has a threshold, a specification and a circuit diagram.
Privacy is nastier because the machinery includes judgement. Should we collect this? Do we genuinely need it? Are we authorised? Can we verify it? How long should it stay? What happens when a staff member, attacker or badly configured SharePoint permission gets somewhere it should not?
There is no 3,250 kW engine for institutional restraint.
You have to fucking practise it.
Best-Available Protection Stops At The Server Room
Cummins says SaskTel’s QSK95 delivers maximum uptime and “best-available server room protection”. Fair enough. Nothing TCAP has found suggests the generator does anything other than the job Cummins designed it to do, and the engineering is impressive precisely because it anticipates failure before failure happens.
The magnificence is in the contrast created by SaskTel’s own public history. The servers receive 3,250 kW of standby power from an engine so large it required a 300-ton crane to reach its room. A customer asking about his telephone bill, meanwhile, discovered SaskTel held his driver’s licence, SIN and health number. The Privacy Commissioner later found SaskTel lacked authority to collect customers’ health numbers, had not justified aspects of other collection, identified notice and safeguard problems and recommended SaskTel stop collecting HSNs and purge them.
SaskTel disagreed with that recommendation. Fourteen years later, the company’s own website still acknowledges that it lacks the particular authorisation held by certain government bodies before explaining why it considers itself able to ask customers voluntarily. At the same time, the Privacy Commissioner’s current guidance still points back to the SaskTel investigation.
The old argument therefore survives in two places at once: inside SaskTel’s explanation of why it asks, and inside the regulator’s explanation of why the earlier collection became a teaching example.
That is not a power outage.
That is a policy dispute with fucking failover.
Cummins installed a machine capable of keeping SaskTel’s servers alive when everything outside goes dark. It supplied redundancy, capacity and enough diesel muscle to stop a data centre from blinking.
Nobody appears to have ordered the equivalent system for knowing when to leave a box on the fucking form empty.
Lee Thompson – Founder, The Cummins Accountability Project
Sources
- Cummins – SaskTel Telecom Data Center Case History
- Cummins – QSK95 Series Generator Sets: SaskTel Critical Protection Delivered
- Saskatchewan Information and Privacy Commissioner – Investigation Report F-2012-001
- SaskTel – Can SaskTel Ask For My SIN And HSC Information?
- SaskTel – Current Privacy Policy
- Saskatchewan Information and Privacy Commissioner – IPC Guide To FOIP
- Saskatchewan Information and Privacy Commissioner – Investigation Report 283-2021
