- PIPEDA applies to organizations that collect, use, or disclose personal information in the course of commercial activity — which covers the vast majority of Ontario businesses, from sole…
- The threshold under PIPEDA is whether the breach creates a real risk of significant harm to an individual — a standard that considers factors such as the sensitivity of the information…
- Where the real-risk-of-significant-harm threshold is met, PIPEDA requires notifying both the federal Privacy Commissioner and the affected individuals, and doing so as soon as feasible…
Discovering that customer data has been exposed — a hacked database, a lost laptop, an email sent to the wrong list — is stressful enough on its own. What makes it worse for many Ontario business owners is not knowing what they are actually required to do next. Data breach notification obligations under Canada's federal privacy law are not optional guidance; they are legal requirements with real consequences for getting them wrong.
Because Ontario has no separate general private-sector privacy statute of its own, PIPEDA is the law that governs almost every Ontario business's response to a data breach involving personal information. This article walks through when PIPEDA's breach rules apply, what a proper response actually involves, and where the obligations go further than most businesses expect.
When PIPEDA's Breach Rules Apply
PIPEDA applies to organizations that collect, use, or disclose personal information in the course of commercial activity — which covers the vast majority of Ontario businesses, from sole proprietorships to large corporations. A "breach of security safeguards" under PIPEDA is broader than the word "hack" suggests: it includes unauthorized access, collection, use, or disclosure of personal information resulting from a security failure, and it also includes losing information entirely, such as a stolen device or a misdirected email.
The Central Test: Real Risk of Significant Harm
Not every incident triggers a mandatory notification obligation. The threshold under PIPEDA is whether the breach creates a real risk of significant harm to an individual — a standard that considers factors such as the sensitivity of the information involved and the likelihood it will be misused.
Significant harm is interpreted broadly and can include:
- Financial loss or identity theft
- Damage to reputation or relationships
- Loss of employment or business opportunities
- Humiliation
Assessing this threshold is a judgment call, and getting it wrong in either direction carries risk — under-notifying can leave a business exposed if the breach turns out to matter more than it seemed, while over-notifying every minor incident can erode customer trust unnecessarily. This is a decision worth making with legal advice rather than guessing.
What a Proper Notification Actually Includes
Where the real-risk-of-significant-harm threshold is met, PIPEDA requires notifying both the federal Privacy Commissioner and the affected individuals, and doing so as soon as feasible after the organization determines the breach has occurred. A notification to affected individuals should generally be direct enough that the person understands what happened and what to do about it, and should typically address:
- What happened, in plain terms
- What personal information was involved
- What the business is doing in response
- What steps the individual can reasonably take to protect themselves
- How to reach the business with questions
Record-Keeping: An Obligation That Applies Even Below the Threshold
One of the most overlooked parts of PIPEDA's breach regime is that businesses must keep records of every breach of security safeguards — not just the ones serious enough to require notification. If your assessment concludes a particular incident does not meet the real-risk-of-significant-harm threshold, you still need to document that assessment and retain the record; the specific retention period is set out in the regulations and is worth confirming directly, since PIPEDA's record-keeping requirements can be updated. The Privacy Commissioner can request these records at any time, and a pattern of undocumented "non-reportable" incidents is a poor position to be caught in.
A Practical Breach-Response Checklist
When you discover a possible breach, a structured response matters more than speed alone:
- Contain it. Stop the ongoing exposure — revoke access, patch the vulnerability, recover the device.
- Assess the scope. What information was involved, how many people are affected, and how sensitive is it?
- Assess the risk. Apply the real-risk-of-significant-harm test with legal input, especially for close calls.
- Notify, if required. The Privacy Commissioner and affected individuals, with clear and actionable information.
- Document everything, whether or not you notify.
- Review and remediate. Fix the underlying gap so the same incident cannot recur.
Beyond PIPEDA: Contracts, Insurance, and Reputational Risk
PIPEDA is the floor, not the whole picture. Many commercial contracts — especially with larger customers, payment processors, or cloud vendors — include their own breach-notification clauses with obligations that can be stricter than PIPEDA's. Cyber insurance policies often require notice to the insurer within a specific window as a condition of coverage. And separate from any legal requirement, how a business communicates about a breach shapes whether customers stay.
Frequently asked questions
Do I have to report every data incident to the federal Privacy Commissioner?
No — only breaches that meet the real-risk-of-significant-harm threshold require reporting to the Commissioner and notice to affected individuals. Every breach, reportable or not, still needs to be assessed and the assessment documented.
What if I am not sure whether a breach meets the threshold?
This is exactly the kind of judgment call worth getting legal advice on quickly, since the consequences of guessing wrong run in both directions — unnecessary panic on one side, regulatory exposure on the other.
Can a small business be investigated by the Privacy Commissioner?
Business size is not a shield from PIPEDA. Any organization engaged in commercial activity that handles personal information can be the subject of a complaint or investigation, regardless of how small it is.
Does cyber insurance replace the need for a legal response plan?
No. Insurance can help cover costs like notification, credit monitoring, or legal fees, but it does not substitute for making the legal determinations PIPEDA requires or meeting contractual notice deadlines, which are often shorter than an insurer's claims process.
This is a corporate question
Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.