Who this applies to
Private-sector organizations covered by PIPEDA that hold personal information under their control.
What to know
- A breach of security safeguards must be reported to the Privacy Commissioner and to the affected individuals when it creates a real risk of significant harm.
- Deciding whether the risk is significant depends on how sensitive the information is and how likely it is to be misused.
- Organizations must keep a record of every breach of security safeguards, reported or not, and keep that record for 24 months.
- Quebec has its own regime for private-sector organizations in the province. See the Law 25 guide.
What to do
- Write a breach response procedure that names who decides whether harm is significant.
- Keep a breach register from day one, including near misses and breaches you judged below the threshold.
- Contact legal counsel before you send notices, because wording matters.
This guide is a plain-language summary for general information. It is not legal advice and it does not replace the official source. Requirements change, so check the linked source before you act.