KITCHENER — A break-in initially described by Waterloo Regional Police only as an incident at a “government building” involved the Waterloo Region District School Board and the personal information of children enrolled in its Extended Day Program.

Police announced Monday that two Kitchener men had been arrested after a July 5 break-in near Ardelt and Hanson avenues. Investigators said “various items” were stolen, including records containing sensitive information, and that the stolen material was later recovered.

The police statement did not identify the government agency, describe the records or explain whose information had been placed at risk.

The affected building was the WRDSB Education Centre at 51 Ardelt Avenue, the public school board’s administrative headquarters. Subsequent reporting identified the stolen material as detailed records concerning 36 children in the board’s before- and after-school Extended Day Program.

That changes the significance of the story. The stolen material was not simply internal government paperwork. It involved identifiable children and, depending on the individual files, potentially their education identifiers, family contact details and medical plans of care.

The records have been recovered. That is reassuring, but it does not establish that the information was never viewed, photographed or copied while outside the board’s control.

It also leaves an important public-interest question unanswered: why were sensitive children’s records physically accessible to intruders inside an administrative building?

The break-in and arrests

According to the Waterloo Regional Police Service, the building was entered on July 5. The break-in was discovered the following day, July 6, when the service’s Break, Enter, Auto Theft and Robbery Unit took over the investigation.

A 48-year-old Kitchener man was arrested on July 9. Police arrested a second Kitchener man, 46, on July 13.

WRPS has not publicly named either accused. Its July 20 release also did not list the specific charges, state whether either man remained in custody or disclose where the stolen property was found.

The allegations have not been proven in court.

Police said investigators recovered numerous stolen items, including the sensitive records. The investigation remains open.

The delayed public announcement is notable. Both arrests had occurred at least one week before WRPS issued its release. Families, however, had begun receiving privacy-breach notifications from the school board earlier in July.

That means the public first learned about the privacy implications through affected families and news reporting—not through the eventual police announcement, which continued to describe the location only as a government building.

Police sometimes withhold the identity of a victim organization to protect an investigation or reduce the risk of further offences. But once arrests had been made and the records recovered, the omission had the effect of concealing the most important element of the case: the stolen files belonged to a public education system and concerned children.

What records were stolen?

Public reporting indicates the records related to 36 children enrolled in the WRDSB Extended Day Program, which provides care outside regular classroom hours.

The school board’s initial communications reportedly described information contained in Extended Day documentation and plans of care. Not every child’s file would necessarily contain every category of information.

The precise, final inventory of exposed fields has not been published in a single public statement. That distinction matters. It would be irresponsible to assume, without documentary confirmation, that all 36 files contained medical diagnoses or every piece of information the board maintains about a student.

However, records used to administer extended-day child care can contain substantially more than a child’s name.

Depending on the form and the child’s needs, those records may include:

  • A child’s name and Ontario Education Number;
  • Parent or guardian names and contact information;
  • Emergency contacts and authorized pickup information;
  • Attendance or program details;
  • Allergies, medication instructions or emergency procedures;
  • Medical plans of care for conditions such as asthma, anaphylaxis, diabetes or epilepsy; and
  • Information about accommodations or other individual safety needs.

The WRDSB itself says important medical information may be collected to develop a student’s medical emergency plan or to permit staff to administer medication. Its student-information practices also acknowledge the use of parent and guardian contact information for safety and emergency purposes.

The board should now publish a definitive list of the data fields contained in the recovered records, separated by affected person if necessary. Families should not be left to infer the extent of a breach from a general description.

Were residents’ personal records involved?

Yes—but the affected residents were a limited group, not the Waterloo Region population generally.

The available evidence indicates that records relating to 36 children, and potentially their parents, guardians or emergency contacts, were involved. There is no indication that a region-wide government database, municipal tax system or general population registry was accessed.

There is also no public evidence that the main WRDSB student-information database was entered during this incident. This appears to have been a physical theft of records and other property, not a cyberattack on the board’s network.

That distinction is important. The incident should not be confused with the school board’s 2022 cyberattack, in which hackers accessed employee payroll and benefits information as well as certain historical student data.

The current breach appears much smaller in scale, but the information may still be highly sensitive because it concerns young children and could include medical or family-safety details.

What can someone do with an Ontario Education Number?

An Ontario Education Number, or OEN, is a unique nine-digit identifier assigned to a student. It remains with that person throughout elementary, secondary and post-secondary education.

The number appears on student records, report cards, education-program applications, assessments and other official documents. Ontario restricts who may collect, use or disclose it.

An OEN is not equivalent to a Social Insurance Number. By itself, it does not provide access to a bank account, credit file or the province’s student database. Access to the Ministry of Education’s OEN Registry is restricted to authorized users.

It should nevertheless be treated as sensitive. When combined with a child’s name, birth information, school, contact details or parent information, a permanent education identifier can make impersonation and targeted social engineering more convincing.

Unlike a password, an OEN is not normally changed every time it may have been exposed. That makes it particularly important for the board to explain whether OENs were among the recovered information and what precautions affected families should take.

The province’s description of the OEN system says the number is designed to identify education records and that unauthorized collection, use or disclosure is an offence.

Does recovery mean the privacy risk is over?

No—not conclusively.

Recovering the original records prevents their continued physical circulation, assuming police recovered the complete set. It does not prove that nobody read them, photographed them or made copies.

Police have not said:

  • How long the records were outside the board’s control;
  • Where or from whom they were recovered;
  • Whether they appeared to have been opened or examined;
  • Whether phones, scanners or computers were seized;
  • Whether investigators found evidence that information had been copied;
  • Whether any records remain unaccounted for; or
  • Whether police believe the files were deliberately targeted.

There is an important difference between “the records were recovered” and “the information was not compromised.”

The first statement concerns possession of the physical documents. The second requires a forensic and privacy assessment that police and the school board have not publicly provided.

At the same time, there is presently no evidence that the information was sold, posted online or used for fraud or harassment. It would be equally wrong to claim that misuse occurred without evidence.

The accurate conclusion is narrower: the original material has been recovered, but public information is insufficient to rule out copying or viewing.

Why were paper files being used?

Paper records are not automatically a sign of obsolete or negligent administration.

Extended Day employees may need immediate access to emergency contacts, pickup authorizations and medical instructions. During an allergic reaction, seizure or other emergency, staff cannot depend exclusively on an internet connection, a functioning device or access to a centralized database.

A readily available paper plan can protect a child.

But availability to authorized staff must be balanced against secure storage. Sensitive records should not be left where anyone entering a building can remove them. Appropriate safeguards can include locked cabinets, controlled rooms, documented sign-out procedures, minimum necessary information, overnight storage rules and an inventory showing who has each binder.

The incident raises questions about whether the problem was the existence of paper records or the way they were stored.

If the files were inside a locked cabinet that intruders forcibly opened, that presents one security issue. If they were left on an accessible desk or shelf after hours, it presents another. Neither WRPS nor the board has publicly explained which occurred.

Nor has the board disclosed how the intruders entered the Education Centre, whether an alarm activated, whether security cameras captured the break-in or how much time passed before the intrusion was detected.

Those facts are relevant to public accountability and can be released without publishing a detailed blueprint that would make future break-ins easier.

Has security changed?

The school board has said it would review its practices to ensure personal information is protected. That is an acknowledgement that the incident requires more than recovery of the stolen property.

But as of July 22, the WRDSB had not publicly released a completed security review or a detailed list of physical safeguards introduced because of the break-in.

There is therefore no verified basis to say that locks were changed, paper files were relocated, alarms were upgraded, camera coverage was expanded or overnight record-storage rules were rewritten.

The board may have taken some or all of those measures internally. If so, it has not described them publicly in sufficient detail to permit independent assessment.

Security changes also should not be confused with separate information-technology measures that took effect July 1. Before the break-in, WRDSB announced restrictions on third-party artificial-intelligence tools, browser extensions and unmanaged Chromebook access. Those changes concerned cybersecurity and do not answer how physical records were protected inside the Education Centre.

A credible post-incident response should include at least:

  • Confirmation that all affected records have been identified;
  • Direct notice describing each family’s exposed information;
  • A review of every location where Extended Day records are stored;
  • Mandatory locked storage when programs or offices are closed;
  • A documented chain of custody for portable binders;
  • Removal of information not required for immediate care;
  • Staff retraining on physical-record security;
  • Review of alarms, access controls and camera coverage; and
  • A written assessment of whether the incident must be investigated by Ontario’s privacy commissioner.

The public does not need to know alarm codes or camera blind spots. It should be told what category of failure occurred and what category of safeguard has replaced it.

The privacy-law question

As a public school board, WRDSB is governed principally by Ontario’s Municipal Freedom of Information and Protection of Privacy Act for much of the personal information it holds. Some student health information may also engage additional health-privacy requirements depending on who created and controls the record.

The central legal obligation is straightforward: personal information in the board’s custody or control must be protected through reasonable security arrangements.

A criminal break-in does not automatically mean the board violated privacy law. No physical security system can guarantee that theft will never occur. The legal and governance questions are whether the safeguards were reasonable before the incident and whether the board responded adequately afterward.

Ontario’s Information and Privacy Commissioner generally expects institutions handling a breach to contain it, assess the information involved, notify affected people where appropriate, investigate the cause and prevent a recurrence.

The board should publicly confirm whether it reported this incident to the commissioner, whether the commissioner opened a file and whether the board has been directed to take further action.

That confirmation matters because an internal review conducted by the organization whose safeguards failed is not the same as independent privacy oversight.

A second warning for the school board

The WRDSB already has experience with a major information-security failure.

In July 2022, attackers entered the board’s computer systems and accessed highly sensitive information. The board later confirmed that the material included names, birthdates, banking information and Social Insurance Numbers belonging to current and former employees, along with some student information.

The present break-in is different in method and scale. There is no indication that the two events are connected.

But together they expose a broader weakness in the way institutions discuss information security. Cybersecurity often receives the money, specialist staff and public attention, while paper files, portable binders, unlocked rooms and after-hours building access are treated as routine facilities issues.

To a child whose medical information or family contacts have been exposed, the method makes little difference.

Privacy protection must cover the full life of a record—from the moment information is collected to where it is stored, who can carry it, when it is duplicated and how it is destroyed.

Questions the board and police still need to answer

The arrests resolve only one part of the story. They do not complete the public accounting.

WRPS should explain, without compromising the prosecution, the offences charged, whether the records appeared to have been targeted and whether investigators found evidence of copying or attempted misuse.

The school board should disclose:

1. The exact number of children and adults whose information was involved; 2. The categories of personal information exposed; 3. Whether any medical plans, custody details or pickup authorizations were included; 4. Whether every original record has been recovered; 5. Where and how the files had been stored; 6. What physical security was defeated; 7. How long the files were outside the board’s control; 8. Whether the privacy commissioner was notified; 9. What concrete security changes have been completed; and 10. What monitoring or assistance is being offered to affected families.

There may be legitimate reasons to withhold details while the criminal case remains active. But “ongoing investigation” should not become a blanket answer to questions about the board’s own information practices.

What families should know

Families who received a notice should preserve it and ask the WRDSB to specify which records relating to their child were involved.

If an Ontario Education Number was exposed, parents should understand that it is an education identifier, not a password or direct key to financial accounts. There is no reason, based on currently available information, to cancel bank cards or assume identity theft has occurred solely because an OEN was involved.

Families should nevertheless be cautious about calls or messages from people claiming to know their child’s school, medical needs or Extended Day arrangements. A person using genuine background information can make a fraudulent request sound credible.

Any affected parent who believes the board’s explanation or response is inadequate can contact the WRDSB’s Freedom of Information and Privacy Office and may file a complaint with the Information and Privacy Commissioner of Ontario.

Recovery is not accountability

The strongest fact in the board’s favour is that police recovered the sensitive material. There is no public evidence that the records were released online or used to harm a child.

The most troubling fact is that detailed records concerning 36 children could be carried out of a public education office in the first place.

The police announcement framed the case as a successful property-recovery investigation. From a criminal perspective, that is understandable: two arrests were made and stolen items were located.

From a privacy perspective, the case remains unfinished.

The public still does not know exactly what information left the building, whether it was copied, why it was accessible or what has changed to prevent another breach. Until those questions are answered, “the records were recovered” is a description of what police found—not proof that the risk has been eliminated or that the system has been repaired.