Don’t do SECURITY. Do business SECURELY.

Canada’s mandatory breach reporting under PIPEDA takes effect

Canadian organisations must now report breaches creating a real risk of significant harm and keep records of all breaches.

Mandatory breach of security safeguards requirements under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) come into force today.

Key points

  • Breaches creating a real risk of significant harm must be reported to the Office of the Privacy Commissioner.
  • Affected individuals must be notified as soon as feasible.
  • Other organisations that may reduce the risk of harm must also be notified.
  • Records of all breaches must be kept for 24 months.
  • Knowingly failing to report or keep records can lead to fines.

UK organisations handling Canadians’ personal information should align incident response with PIPEDA’s harm threshold and record-keeping duties, which differ from the UK GDPR.

Source: Breach of Security Safeguards Regulations, SOR/2018-64 (Justice Laws)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights