Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) requires private-sector organizations to report certain data breaches. The rules apply whether one person or thousands are affected, so every business that holds customer or employee information needs a plan.
When a breach must be reported
PIPEDA calls a data breach a "breach of security safeguards". You must report it to the Office of the Privacy Commissioner of Canada (OPC) when it creates a real risk of significant harm to an individual. Significant harm includes identity theft, financial loss, humiliation, damage to reputation or relationships, and loss of employment or business opportunities.
Assessing real risk of significant harm
- Sensitivity: how sensitive the information is, such as financial, health or identity data
- Probability of misuse: who accessed it, for how long, and whether there are signs of malicious intent
Who to notify
- The Office of the Privacy Commissioner of Canada, as soon as feasible
- Affected individuals, as soon as feasible, in a clear and conspicuous notice
- Other organizations or government institutions that can reduce the harm, such as police or a payment processor
Keep a record of every breach
You must keep a record of every breach of security safeguards for two years, even when it doesn't meet the reporting threshold. The record should include the date, the circumstances, the information involved, and whether you reported it. The OPC can ask to see these records.
Penalties
Knowingly failing to report, notify or keep records is an offence, with fines of up to $100,000 per violation.
How to prepare now
- Know where personal information lives: systems, cloud apps and backups
- Monitor systems so breaches are found quickly
- Write a short incident response plan with a breach assessment step
- Keep a breach register, even if it stays empty
- Protect data with MFA, patching, encryption and tested backups
Hanatech's network security and business continuity services help you prevent, detect and recover from breaches. Start with the free Cyber Risk Check or contact us.
This article is general information, not legal advice. For your specific situation, consult a privacy lawyer or the OPC.