Alberta's Open Vault: How 2.9 Million Voter Records Exposed Canada's Democracy Crisis
Related Episode
Alberta's Open Vault: How 2.9M Voter Records Were Left OnlineThe Breach That Nobody Expected
Somewhere in Alberta, there was a website that let a total stranger type in your name and pull up your home address, your phone number, and the ID number tied to your vote. No hacking required. No password to crack. Just a search bar, sitting wide open for months, while millions of people had no idea it existed.
This isn’t a hypothetical cybersecurity thought experiment. This is what actually happened to 2.9 million Albertans—every single registered voter in the province. Their names, home addresses, phone numbers, and unique elector IDs were leaked and published online by a separatist organization in the middle of one of the most contentious political moments in recent Canadian history.
We’re talking about one of the absolute largest, most consequential privacy breaches in Canadian history. Yet for most Canadians, the silence around this story is deafening. That silence is almost as strange as the breach itself.
How the Chain of Custody Collapsed
Under standard democratic rules, Elections Alberta provides the voter list to registered political parties for legitimate campaign use. It’s a necessary part of how democracies function—parties need to know who the voters are. The Republican Party of Alberta, led by Cam Davies, received the list completely legally.
But then the chain of custody collapsed almost immediately.
The Republican Party of Alberta transferred this highly restricted database to an unauthorized third-party organization called the Centurion Project. The Centurion Project is a pro-separation grassroots data gathering organization directed by political operative David Parker. But here’s where it gets alarming: they didn’t just possess the data behind closed doors. They engineered a publicly accessible, searchable website.
Think of it this way: Elections Alberta gave the master key to a bank vault to a licensed security guard. That guard handed it to a guy on the street who then posted copies of the key on telephone poles all over town.
The scale of the exposure was catastrophic:
- 21 individuals were given complete, unrestricted administrative copies of the entire database
- 545 unique users accessed the live tool before it was flagged
- Elections Alberta was forced to send out 568 cease and desist letters to try and lock the system down
But here’s the problem with cease and desist letters: once a database is digitized and distributed to 21 people who then access it hundreds of times, you can’t put that genie back in the bottle. The data is copied, it’s traded, it’s out in the wild. The structural damage is permanent.
The Weaponization of Data
The real danger emerges when you understand how this leaked data was weaponized against the democratic process itself.
To validate a signature on a citizen initiative petition in Alberta, you don’t just write down a name. You need the unique elector ID—think of it as a two-factor authentication code for your democratic voice. It’s like getting a text on your phone when you log into your bank. If someone has your name and address but not that ID, the signature gets flagged and rejected by the system.
The leaked database provided that 2FA bypass for 2.9 million people.
The real-world fallout was immediate and damning. Regular Albertans started appearing on Reddit threads and Facebook groups, realizing their names appeared on the Stay Free Alberta petition—and they knew for a fact they never signed it. The leaked data wasn’t just viewed. It was actively weaponized to bypass verification mechanisms.
This is where a privacy breach transforms into something far more dangerous: a mechanism for systemic fraud.
The Constitutional Paradox
On May 13th, Justice Shayna Leonard initially quashed the petition entirely, citing a failure by the Crown to consult First Nations and noting that secession could violate Treaty 8 rights. Treaty 8 is a foundational nation-to-nation agreement between First Nations and the federal Crown. A single province attempting to unilaterally sever its ties to Canada fundamentally breaks that legal framework.
But the Alberta government appealed. They went to court to fight to keep the separatist petition alive.
That appeal led directly to the June 29th Court of Appeal ruling by Justice Alice Woolley—a ruling that reads almost like a legal contradiction. The court was looking at a profoundly tainted process, but instead of throwing the whole thing out or letting it proceed normally, Justice Woolley issued a partial stay.
She ruled that Elections Alberta must continue verifying those 300,000 signatures so the public can know the statistical results. But she explicitly blocked the Chief Electoral Officer from taking the next statutory step—sending the results to the Minister of Justice. Under the Citizen Initiative Act, that handoff is the legal trigger that automatically forces a constitutional referendum.
The court recognized a fundamental constitutional paradox: you cannot allow a profoundly compromised petition to trigger a constitutional crisis before the judiciary can even examine the underlying legality of the data gathering.
The Civil Litigation Escalates
The very next day, June 30th, civil litigation dropped. A massive class action lawsuit filed by Clint Dawkin, a retired Alberta lawyer, named the Alberta government, Elections Alberta, the Centurion Project, David Parker, and the Republican Party of Alberta as defendants.
Here’s a detail that strips away the abstraction: Dawkin personally purchased identity theft insurance specifically because of this data breach. When a retired class action attorney buys identity theft insurance to protect his own assets, it tells you this is a tangible threat, not just a theoretical privacy complaint on paper.
The lawsuit escalates the stakes by alleging a Charter Section 7 violation—a claim that shifts the legal framework entirely. This isn’t just about a breach of the Provincial Privacy Act. They’re arguing that by failing to secure this critical data infrastructure, the government and these third-party organizations have infringed on the fundamental constitutional right to life, liberty, and security of the person.
The filing proposes certification of a vulnerable subclass of victims: domestic violence survivors, judges, journalists, police officers, and healthcare workers. If you’re a survivor of domestic violence who has relocated to escape an abuser, your home address being published on a searchable database isn’t just spam. It’s a direct physical threat to your life.
The Legal Paradox
Here’s where the contradictions become staggering: the Alberta government is currently sitting in court as a defendant in a massive class action lawsuit for utterly failing to protect the data of its voters. Simultaneously, that exact same government is acting as an appellant in a separate courtroom, aggressively fighting to revive the very petition process that incentivized and caused that voter data breach.
This is a democracy integrity crisis. This is a system failure at every structural level.
Listen to the Full Investigation
This breakdown only scratches the surface of what happened. The Sanity Project has pulled together civil legal filings, court rulings, press releases from Elections Alberta, and ground-level coverage from Global News, CBC, CP24, and The Guardian to construct a comprehensive picture of how a democratic process became compromised.
If you’re an Alberta voter, we want to hear from you: Did you check the petition registry and find your name on it without your consent? Drop a comment and share your experience.
Listen to the full episode of The Sanity Project to dig deeper into the mechanisms of this breach, the legal contradictions that followed, and what this means for Canadian democracy going forward.