What they're not telling you: Telus Data Breach Notification Raises. Questions About Data Retention After Deletion Requests A Telus customer who requested account deletion in 2024 recently received a data breach notification from the
The timing raises a straightforward but uncomfortable question: if the account was deleted, why was there data to breach? This incident exposes a gap between corporate deletion policies and actual data practices. Telus instructed the customer to use a basic "Unsubscribe" email rather than directing them through a formal GDPR-style data deletion process or a dedicated privacy portal—a procedurally unusual approach that may reflect how casually some Canadian telecom companies handle deletion requests. The confirmation email the customer received offered no specificity about what data would be retained, for how long, or for what purposes. This vagueness matters. Many companies distinguish between account deletion (removing access credentials) and data deletion (permanently destroying personal information). Telus's process appears to have blurred this critical distinction. The broader context amplifies the concern. Canada's privacy regulations, including PIPEDA, generally require organizations to delete personal information when it's no longer needed for the purposes it was collected—though enforcement is notoriously weak. Telecommunications companies in particular hold sensitive data: call records, billing addresses, payment information, device identifiers, and sometimes location history. For a customer who explicitly requested deletion months before a breach occurred, retaining that data without clear justification or customer knowledge represents both a regulatory gray area and a practical security risk. What mainstream coverage typically misses is that this scenario isn't anomalous—it's structural. Companies have financial incentives to retain data for as long as technically and legally defensible: customer retention analytics, fraud prevention databases, and backup systems can all serve as justifications for keeping information even after deletion requests. Telus's use of an informal deletion method, rather than a formal data subject access request process, may have inadvertently created a documentation problem where the company itself might have unclear records about which customer data should have been purged and when. The customer's experience illustrates why ordinary people should be skeptical of deletion confirmations that lack detail. A confirmation email saying "your request has been processed" is not the same as a detailed receipt outlining exactly which data categories are being deleted, which are being retained for legal compliance, and when permanent destruction will occur. Without that transparency, customers have no way to verify whether a company actually honored their request or simply stopped sending marketing emails while warehousing their information elsewhere in the organization. Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.What the Documents Show
Follow the Money
What Else We Know
Primary Sources
Telus says I’m affected by a data breach… but I deleted my account in 2024?
Hi everyone, I recently received an email from Telus stating that my data have been involved in a data breach. The strange part is that I had already requested the

Corporate Watchdog — The stories mainstream media won't cover.
🔎 Mainstream angle: The corporate press either ignored this story entirely or buried it in a 3-sentence brief. The framing, when it appeared at all, focused on process rather than impact.
What are they not saying? Who benefits from this story staying buried? Follow the regulatory filings, the court dockets, and the FOIA releases. The truth is in the paperwork — it always is.
