Compliance

PIPEDA Breach Reporting: What Canadian Businesses Must Do

Hanatech Inc. · Updated September 24, 2026

Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) requires private-sector organizations to report certain data breaches. The rules apply whether one person or thousands are affected, so every business that holds customer or employee information needs a plan.

When a breach must be reported

PIPEDA calls a data breach a "breach of security safeguards". You must report it to the Office of the Privacy Commissioner of Canada (OPC) when it creates a real risk of significant harm to an individual. Significant harm includes identity theft, financial loss, humiliation, damage to reputation or relationships, and loss of employment or business opportunities.

Assessing real risk of significant harm

  • Sensitivity: how sensitive the information is, such as financial, health or identity data
  • Probability of misuse: who accessed it, for how long, and whether there are signs of malicious intent

Who to notify

  • The Office of the Privacy Commissioner of Canada, as soon as feasible
  • Affected individuals, as soon as feasible, in a clear and conspicuous notice
  • Other organizations or government institutions that can reduce the harm, such as police or a payment processor

Keep a record of every breach

You must keep a record of every breach of security safeguards for two years, even when it doesn't meet the reporting threshold. The record should include the date, the circumstances, the information involved, and whether you reported it. The OPC can ask to see these records.

Penalties

Knowingly failing to report, notify or keep records is an offence, with fines of up to $100,000 per violation.

How to prepare now

  • Know where personal information lives: systems, cloud apps and backups
  • Monitor systems so breaches are found quickly
  • Write a short incident response plan with a breach assessment step
  • Keep a breach register, even if it stays empty
  • Protect data with MFA, patching, encryption and tested backups

Hanatech's network security and business continuity services help you prevent, detect and recover from breaches. Start with the free Cyber Risk Check or contact us.

This article is general information, not legal advice. For your specific situation, consult a privacy lawyer or the OPC.

Ready for IT you don't have to think about?

Start with a free network assessment.

Book a consultation