Assessing and Responding to Privacy Breaches

Key Takeaways

  • Assess both information sensitivity and the probability of misuse. Significant harm includes reputational and relationship harm as well as financial loss.

  • Report and notify as soon as feasible when PIPEDA’s threshold is met. Check provincial and contractual duties separately instead of inventing one universal hourly deadline.

  • Retain a record of every covered breach for 24 months after determining that it occurred. Explain the risk assessment even when reporting is not required.

Last updated: October 2026

What counts as a breach

A breach of security safeguards can involve loss, unauthorized access or unauthorized disclosure of personal information. It need not involve a hacker. A misdirected application, a lost unprotected laptop or an employee browsing a relative's file can create a breach.

The organization should have a response process so staff know how to escalate an incident. Report internally promptly, preserve relevant evidence and take authorized containment steps. Deleting the only evidence or waiting for a customer complaint can make the problem harder to investigate.

Determine which privacy regime governs. The following reporting and record requirements describe PIPEDA. Provincial laws can have their own triggers, recipients and procedures, so applying the federal threshold alone may be insufficient in a provincial-law case.

Containment and fact-finding

  • Identify what happened, when it was discovered, which information was involved and who may have accessed it. Restrict compromised accounts, recover records where possible and prevent further unauthorized disclosure. Coordinate with the responsible privacy and security personnel instead of making an unsupported public statement.

  • If an application goes to the wrong recipient, seek secure deletion and assess whether the recipient retained or shared it. A verbal promise of deletion is a fact to evaluate, not conclusive proof that no harm can occur. The relationship between recipient and client can matter: disclosure of a sensitive diagnosis to an employer or estranged relative creates a different risk from an unread routine notice.

  • Document uncertainties. You may not immediately know whether a stolen device was accessed. Investigate the protection actually present, including encryption and authentication, without assuming that a password alone eliminates the risk.

Real risk of significant harm

Under PIPEDA, a breach involving information under the organization's control must be reported to the OPC and affected individuals notified where it is reasonable to believe it creates a real risk of significant harm.

The assessment considers the sensitivity of the information and the probability it has been, is being or will be misused. Significant harm can include financial loss, identity theft, humiliation, damage to reputation or relationships and other serious consequences. It is broader than direct theft of money.

Medical histories and financial identifiers can be highly sensitive. Context also changes sensitivity: a seemingly ordinary mailing list can reveal participation in a sensitive health service. The number of records is relevant to managing the incident, but a breach affecting one person can still meet the threshold.

Do not use a mechanical rule that every lost record must be publicly announced or that every accidentally sent email is harmless. Assess the actual information, recipients, exposure, safeguards and possible consequences.

Reporting and notification

Where the federal threshold is met, report to the OPC and notify affected individuals as soon as feasible after determining that the breach occurred. This is not a universal fixed 24-hour or 72-hour deadline.

The report and notice must contain the required information and help people understand the event and protect themselves. Clear customer communication should explain relevant circumstances, information involved, protective steps and how to obtain assistance. Avoid including unnecessary personal details that create another disclosure.

PIPEDA can also require notification to a government institution or another organization where that notice may reduce or mitigate harm. Do not assume every breach requires identical simultaneous notice to police, every regulator and every service provider. Consider the actual legal duties and appropriate risk-reduction measures.

An insurer or agency agreement may impose additional internal reporting requirements. Comply with them while distinguishing those contractual procedures from the federal statutory standard.

Record every breach

Organizations must keep a record of every breach of safeguards involving personal information under their control, including breaches below the reporting threshold. The record must allow the OPC to verify compliance with reporting and notification duties.

Retain the record for 24 months after the day the organization determines that the breach occurred. That starting point is the determination date, not necessarily the day of the original incident. Other legal obligations can require a longer period.

Record what information was affected, the circumstances, containment actions, risk assessment and reasons for reporting or not reporting. A note saying “low risk” without explaining sensitivity and misuse probability is inadequate support for the decision. Protect the breach log itself because it may contain sensitive information.

Example and follow-up

An agent discovers that a detailed medical application was emailed to an unrelated address. The agency recalls the message where possible, contacts the unintended recipient through an approved process, identifies the exposed information and assesses the probability of further disclosure. It records the evidence and determines whether the federal reporting threshold is met.

If the recipient is unknown and the file includes identifiers and a serious diagnosis, the analysis may support significant-harm reporting. If strong evidence shows the attachment was inaccessible and promptly deleted, the outcome may differ. Either way, the organization records the breach and rationale.

After containment, examine why it happened. Improve recipient verification, approved transmission methods and staff training. Insurance against cyber losses does not replace legal notification or privacy duties. The OPC's breach guidance and inspection findings explain the federal risk and record requirements.

Test Your Knowledge

A covered PIPEDA breach is assessed as below the significant-harm reporting threshold. What record duty remains?

A

Keep a breach record for 24 months after determining that the breach occurred.

B

Delete all evidence because no notice is needed.

C

Record only incidents affecting more than 100 clients.

D

Keep a record only if the OPC first requests one.

Sections you finish are checked off in the contents.