Mandatory breach of security safeguards requirements under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) come into force today.
Key points
- Breaches creating a real risk of significant harm must be reported to the Office of the Privacy Commissioner.
- Affected individuals must be notified as soon as feasible.
- Other organisations that may reduce the risk of harm must also be notified.
- Records of all breaches must be kept for 24 months.
- Knowingly failing to report or keep records can lead to fines.
UK organisations handling Canadians’ personal information should align incident response with PIPEDA’s harm threshold and record-keeping duties, which differ from the UK GDPR.
Source: Breach of Security Safeguards Regulations, SOR/2018-64 (Justice Laws)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.