home / hubs / privacy-breach-response-canada

// resource hub

Privacy breach response in Canada

A practical sequence for handling a breach involving personal information, covering PIPEDA and Quebec Law 25 duties.

For: Privacy officers, IT and security leads, legal counsel, and business owners at private-sector organizations. · Reviewed October 2026

When personal information is lost or exposed, the law sets duties on assessment, reporting, notification, and record keeping. Which rules apply depends on where the organization operates and where the affected people live.

This hub gives the sequence most organizations follow. It is general information. Get legal advice for your situation, especially before sending notices.

Six steps after a breach

  1. Contain and preserveStop the loss without destroying the evidence.
    • Isolate affected systems and revoke exposed credentials.
    • Preserve logs, emails, and copies of what was exposed.
    • Start a timeline with names, times, and decisions.
  2. Assess the risk of harmReporting depends on the level of risk.
    • Under PIPEDA, a breach of security safeguards must be reported to the Privacy Commissioner and to affected individuals when it creates a real risk of significant harm.
    • Quebec Law 25 uses a risk of serious injury threshold for reporting a confidentiality incident to the Commission d’accès à l’information and to the people affected.
    • Weigh how sensitive the information is and how likely it is to be misused.
  3. Record every incidentRecord keeping applies even when you do not report.
    • PIPEDA requires a record of every breach of security safeguards, kept for 24 months.
    • Quebec requires a register of confidentiality incidents, kept for five years.
    • Write down what happened, what you assessed, and why you did or did not report.
  4. Report and notifyDo it as soon as feasible once the threshold is met.
    • Report to the Office of the Privacy Commissioner of Canada when PIPEDA applies and the threshold is met.
    • Report to the Commission d’accès à l’information for Quebec incidents that present a risk of serious injury.
    • Notify affected individuals directly, with enough detail for them to protect themselves.
    • Check whether other provinces, such as Alberta, apply their own rules to your organization.
  5. Tell others who can reduce the harmSome third parties can limit damage if they know.
    • Consider notifying banks, card brands, law enforcement, or other organizations that can reduce the risk of harm.
    • Tell your cyber insurer early, because many policies require prompt notice and set conditions on response vendors.
  6. Fix the cause and learnA breach that repeats is the expensive kind.
    • Find the root cause and fix it, not just the symptoms.
    • Update your breach response procedure and train the people who used it.
    • Review the incident with leadership and record the actions taken.

// firms

Canadian firms that work on this

Firms whose own websites name PIPEDA, Law 25 or list closely related services. A listing is not an endorsement.

Specialist · Montreal, Quebec

Appollon Inc.

Managed detection and response with 24/7 SOC monitoring, behavioural detection, active threat response and forensic investigation and remediation, aimed at gaming and tech companies in Quebec.

  • MDR and SOC
  • IR and forensics
  • SOC 2
  • ISO 27001
  • Law 25
Focused · Montreal, Quebec

CyberSpective

Montreal-based firm offering virtual CISO, privacy impact assessments, cybersecurity maturity assessments and audits, vendor risk, governance consulting, penetration testing and awareness training across Canada.

  • GRC advisory
  • Privacy
  • Pen testing
  • Training
  • Audit and certification
  • SOC 2
  • PIPEDA
Full service · Concord, Ontario

Cyberwall

Ten managed security services including 24/7 managed SOC, MDR, SIEM as a service, endpoint, identity and cloud security, plus consulting in incident response, penetration testing, compliance and privacy.

  • MDR and SOC
  • MSSP
  • IR and forensics
  • Pen testing
  • GRC advisory
  • +3
  • SOC 2
  • PIPEDA
  • HIPAA
  • PCI DSS
  • ISO 27001
Full service · Toronto, Ontario

IRM Consulting & Advisory

Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.

  • GRC advisory
  • Audit and certification
  • Privacy
  • Pen testing
  • AppSec
  • +3
  • SOC 2
  • ISO 27001
  • CMMC
  • CIS Controls
  • GDPR
  • +3
Full service · Vancouver, British Columbia

Kobalt.io

Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.

  • GRC advisory
  • Audit and certification
  • Pen testing
  • IR and forensics
  • MDR and SOC
  • +1
  • CPCSC
  • CMMC
  • NIST 800-171
  • SOC 2
  • ISO 27001
  • +6
Specialist · Montreal, Quebec

Noraa Consulting

Montreal consultancy offering Law 25 compliance support, ISO 27001 and 27005 training and certification preparation, Microsoft 365 security configuration and security architecture consulting; French and English.

  • GRC advisory
  • ISO 27001
  • Law 25
  • SOC 2

See all matching firms · How the directory works

// faq

Common questions

How fast do we have to report?

PIPEDA requires reporting as soon as feasible after you determine the breach meets the threshold. Do not wait for a full investigation before you assess and decide.

Do we report breaches that are below the threshold?

You do not report them to the regulator, but you still record them. Both PIPEDA and Quebec require records of incidents regardless of reporting.

Who decides whether harm is significant?

Name that person or group in advance, and involve legal counsel. Deciding under pressure, with no procedure, is where organizations go wrong.