home / guides / pipeda-breach-of-security-safeguards

Privacy and breach duties · Office of the Privacy Commissioner of Canada

PIPEDA breach reporting

Private-sector organizations must report certain breaches, notify people, and keep a record of every breach.

Who this applies to

Private-sector organizations covered by PIPEDA that hold personal information under their control.

What to know

  • A breach of security safeguards must be reported to the Privacy Commissioner and to the affected individuals when it creates a real risk of significant harm.
  • Deciding whether the risk is significant depends on how sensitive the information is and how likely it is to be misused.
  • Organizations must keep a record of every breach of security safeguards, reported or not, and keep that record for 24 months.
  • Quebec has its own regime for private-sector organizations in the province. See the Law 25 guide.

What to do

  • Write a breach response procedure that names who decides whether harm is significant.
  • Keep a breach register from day one, including near misses and breaches you judged below the threshold.
  • Contact legal counsel before you send notices, because wording matters.