TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Articles/Corporate
№ 274 Corporate

Mandatory Data Breach Reporting Under PIPEDA: What Ontario Businesses Must Do

Find out when Ontario businesses must report a data breach under PIPEDA, who has to be notified, and what records the law requires you to keep.

Corporate5 min readTSLBy the Treadstone Law team · OntarioUpdated 2026-07
All articles
Key takeaways
  • Under PIPEDA, a reportable event is not just a hack.
  • PIPEDA does not require reporting every incident.
  • If the real-risk threshold is met, PIPEDA generally requires two separate notifications: - The federal Privacy Commissioner — a report describing the breach's circumstances, its scope,…

A breach can happen to any business that holds customer data — a phished email account, a lost laptop, a misconfigured server, or an employee who sends the wrong file to the wrong person. Federal law imposes specific legal duties once that happens, and getting the response wrong can turn a technical problem into a legal one.

This article explains when mandatory data breach reporting duties are triggered under Canada's federal privacy law, PIPEDA, who has to be told, and what a business has to document. It is general information, not a substitute for advice about your specific breach.

What Counts as a "Breach of Security Safeguards"

Under PIPEDA, a reportable event is not just a hack. It covers the loss of personal information, unauthorized access to it, or unauthorized disclosure of it — regardless of whether the cause was an external attacker, an employee mistake, or a lost device. A single misdirected email containing personal information can, in principle, be a breach of security safeguards in exactly the same way a ransomware attack is.

The "Real Risk of Significant Harm" Test

PIPEDA does not require reporting every incident. It requires reporting a breach when it is reasonable to believe the breach creates a real risk of significant harm to an affected individual. Significant harm is defined broadly and can include humiliation, damage to reputation, financial loss, identity theft, and negative effects on a credit record. Assessing this risk means weighing the sensitivity of the information involved against the probability it will actually be misused — a judgment call, and one where the safer course, when genuinely in doubt, is usually to treat the risk as real rather than explain it away.

Who You Must Notify, and What to Include

If the real-risk threshold is met, PIPEDA generally requires two separate notifications:

Depending on the situation, you may also need to notify other organizations — a bank, a credit bureau, or law enforcement — if doing so could reduce the harm to affected individuals.

Record-Keeping Obligations

Even when a breach does not meet the real-risk-of-significant-harm threshold, PIPEDA still requires organizations to keep a record of every breach of security safeguards they experience, for a period the legislation specifies. Confirm the current retention requirement before you rely on it, since this is exactly the kind of technical detail worth verifying rather than assuming. Keeping a breach log — even for incidents you conclude are not reportable — is one of the simplest things a business can do to show it takes its privacy obligations seriously if a regulator ever asks.

What to Do in the First Hours After a Breach

Frequently asked questions

Does a lost company laptop count as a breach if it was encrypted?

Possibly not. Proper encryption meaningfully reduces the risk that lost or stolen information can actually be accessed or misused, which is directly relevant to the real-risk analysis. It is still worth documenting the incident and working through the assessment rather than assuming encryption automatically clears you.

What if the breach only affects employee information, not customers?

The same PIPEDA framework can still apply, though whether PIPEDA governs a given employee's records depends on whether your business is federally or provincially regulated. Either way, treat any breach involving employee personal information with the same seriousness as a customer breach.

Can we just fix the problem quietly without notifying anyone?

No. If the real-risk threshold is met, notification is not optional, and failing to report is itself a separate compliance problem on top of the breach. Deciding the threshold is not met without a documented, reasoned assessment is a common and risky shortcut.

Do we need a lawyer involved right away, or can our IT team handle it alone?

IT should lead containment, but the notification decision has legal consequences, and the language used in a breach notice can affect your exposure later. Involving a lawyer early, even briefly, is generally worth it.

This article is general information, not legal advice. Reading it does not create a lawyer-client relationship. Ontario laws, tax rates, and government programs change, and how the law applies depends on your specific facts. For advice about your situation, speak with a licensed Ontario lawyer. Treadstone Law is licensed by the Law Society of Ontario — reach us at 1-844-900-1070 or start a file online.

This is a corporate question

Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.

ContactStart a File →