Writing

The Governance Crisis: The Call

The phone rang at 5:47 on a Tuesday morning. Sixty-two million policyholder records, four privacy commissioners, and a junior analyst who could see all of it from a standard dashboard login.

The Governance Crisis, part 1 of 5

The Seven Pillars of Data Management, a novel in seven acts.

Chapter I, The Governance Crisis. Pillar I: Data Governance. Part 1 of 5.

Data is a precious thing and will last longer than the systems themselves.

Tim Berners-Lee

The Summons

The phone rang at 5:47 on a Tuesday morning, thirteen minutes before Nadia Okafor-Tremblay’s alarm was set to wake her. She knew, even before her hand found the cold glass of the device on her nightstand, that this was the call. Not the kind of call that delivers news of a death in the family, though in its own way, what followed would kill something she had spent twenty-three years building. This was the call that arrives when an institution begins to hemorrhage, when the architecture of trust that holds a corporation together starts to fracture along invisible fault lines that everyone knew existed but nobody had the courage to name.

“Ms. Okafor-Tremblay?” The voice was male, clipped, professional, the kind of voice trained to deliver catastrophic information with the emotional register of a weather forecast. “This is Marcus Pellerin, Deputy Commissioner, Office of the Privacy Commissioner of Canada. I apologize for the early hour. We have a situation.”

Nadia sat up in bed. Through the floor-to-ceiling windows of her Yorkville condominium, the skyline of Toronto was still dark, the CN Tower a needle of light piercing the November fog. She had been Chief Data Officer of Northbridge Mutual Insurance for exactly fourteen months. Before that, she had spent two decades climbing the ranks of Canadian financial services: actuary, risk analyst, VP of Information Management at Manulife, then the lateral move to Northbridge that her mentor had called “either the bravest or the most foolish decision of your career.”

“What kind of situation, Mr. Pellerin?”

“The kind that involves sixty-two million policyholder records, four provincial privacy commissioners, the Information Commissioner’s Office in the United Kingdom, and the California Attorney General’s office. The kind where I am calling you as a courtesy before the formal investigation notice is served at nine o’clock this morning.”

Nadia closed her eyes. In the darkness behind her lids, she could see the data architecture of Northbridge Mutual: a sprawling, beautiful, terrible thing. Seventeen legacy systems accumulated across forty years of mergers and acquisitions. Customer records scattered across data centres in Toronto, Montreal, Calgary, London, and a disaster recovery site in Halifax that nobody had audited since 2019. A modernization program that the board had approved eighteen months ago and then slowly starved of funding as quarterly earnings pressure mounted.

She had warned them. God, she had warned them.


The Company

To understand what happened at Northbridge Mutual Insurance, you must first understand what Northbridge was, and more importantly, what it believed itself to be.

Founded in 1952 by Alistair Northbridge, a Scottish immigrant who had survived the Battle of the Atlantic and decided that the business of protecting people against catastrophe was the noblest profession a man could enter, the company had grown from a single office on King Street in Toronto to a multinational operation serving 4.2 million policyholders across Canada, the United Kingdom, and the western United States. Its products ranged from basic homeowner’s insurance to complex commercial liability instruments, from life insurance to reinsurance treaties that backed some of the largest infrastructure projects in the Commonwealth.

Northbridge had survived the recession of 1990, the ice storm of 1998, the financial crisis of 2008, and the pandemic of 2020. It had survived hostile takeover attempts, regulatory overhauls, and the slow erosion of customer loyalty that came with the digital age. Through it all, the company clung to a self-image that was equal parts myth and aspiration: that it was the most trustworthy name in Canadian insurance. That it protected people. That it kept its promises.

The irony, and it was an irony so bitter that Nadia would taste it for years, was that the company’s most catastrophic failure would not involve a denied claim or a fraudulent policy. It would involve the most basic promise any institution can make to the people who entrust it with their personal information: that it will know what it has, who can access it, and why.

Northbridge did not know. And in not knowing, it had broken the law in four countries.


The Discovery

The breach: though “breach” was a word that the lawyers would spend months debating, because what happened at Northbridge did not fit neatly into any existing legal definition: had been discovered not by Northbridge’s own security team, not by its internal auditors, not by its compliance officers, but by a twenty-six-year-old data analyst named Priya Chakraborty who had been with the company for less than eight months.

Priya had been hired to build dashboards. That was the scope of her role as it had been described in the job posting: “Junior Data Analyst, Business Intelligence Team.” She was supposed to take data from the company’s data warehouse, apply transformations, and produce visualizations that helped regional managers understand their portfolios. It was, on paper, a perfectly contained job. The kind of job where you come in at nine, build your charts, attend your stand-ups, and go home at five-thirty without the weight of institutional knowledge pressing on your chest.

But Priya was not the kind of person who could see a discrepancy and walk past it.

On a rainy Thursday in October, while building a routine claims frequency report for the Atlantic Canada region, she noticed that her query was returning policyholder records that should not have existed in the dataset she was accessing. Specifically, she was seeing health-related data, prescription histories, physician referral notes, mental health assessment scores, embedded in property insurance claim files. Not just a few records. Thousands of them. Records that belonged to policyholders who had never filed a property claim. Records that, according to every data governance policy Priya had been given during onboarding, should have been isolated in a completely separate system with entirely different access controls.

She checked her access permissions. She was a junior analyst with a standard BI team login. She should not have been able to see health data under any circumstances. The Personal Information Protection and Electronic Documents Act, PIPEDA, classified health information as “sensitive personal information” requiring enhanced protections. Quebec’s Law 25, which had come into full force the previous year, imposed even stricter requirements on health data processed within the province. The UK General Data Protection Regulation, UK GDPR, classified health data as a “special category” requiring explicit consent and a documented lawful basis for processing. The California Consumer Privacy Act, as amended by the California Privacy Rights Act, designated health information as “sensitive personal information” subject to enhanced opt-out rights and purpose limitations.

Priya was seeing all of it. From a standard dashboard login.

She sat at her desk for a long time, the fluorescent lights of the twentieth floor humming above her, the rain streaking down the windows of the Commerce Court building, and she felt a sensation that she would later describe to Nadia as “like standing at the edge of a cliff and realizing the ground you’ve been walking on was never solid to begin with.”

Then she did what the governance framework should have made unnecessary: she walked down two floors to the office of the Chief Data Officer and knocked on the door.

Also posted on LinkedIn.

Papa S. Nguer

Papa S. Nguer is a keynote speaker, presales leader, and author of Winning the Moments That Matter. 25 years in enterprise data and technical sales, $93M+ influenced, 300+ proving engagements.

Book him to speak  ·  Work with him  ·  LinkedIn

← All writing