What has to happen if my Ontario business has a data breach involving customer information?
Under PIPEDA, a breach of security safeguards involving personal information triggers specific obligations once there's a real risk of significant harm to the individuals affected, assessed by factors like the sensitivity of the information involved and the likelihood it will actually be misused. Where that risk exists, the business generally has to report the breach to the federal privacy regulator and notify the affected individuals, giving them enough information to understand what happened and protect themselves, such as by watching for fraud or changing compromised credentials.
Separately, businesses are generally required to keep records of every breach of security safeguards, even ones that don't meet the threshold for reporting or notification, so there needs to be an internal process for documenting incidents regardless of how serious they turn out to be. Skipping this step because a particular breach seemed minor at the time can leave a business without proper records if the issue resurfaces or a pattern later emerges.
Because assessing whether there's a real risk of significant harm involves judgment calls that carry real consequences if gotten wrong, businesses discovering a breach should get advice quickly rather than deciding informally whether notification is required.
Key takeaways
- A breach creating a real risk of significant harm generally triggers reporting to the federal regulator and notice to affected individuals.
- Notification should give individuals enough information to protect themselves from resulting harm.
- All breaches of security safeguards generally need to be internally recorded, not just reportable ones.
- Get advice quickly to properly assess the risk level and notification obligations after a breach.