- Under PIPEDA, a reportable event is not just a hack.
- PIPEDA does not require reporting every incident.
- If the real-risk threshold is met, PIPEDA generally requires two separate notifications: - The federal Privacy Commissioner — a report describing the breach's circumstances, its scope,…
A breach can happen to any business that holds customer data — a phished email account, a lost laptop, a misconfigured server, or an employee who sends the wrong file to the wrong person. Federal law imposes specific legal duties once that happens, and getting the response wrong can turn a technical problem into a legal one.
This article explains when mandatory data breach reporting duties are triggered under Canada's federal privacy law, PIPEDA, who has to be told, and what a business has to document. It is general information, not a substitute for advice about your specific breach.
What Counts as a "Breach of Security Safeguards"
Under PIPEDA, a reportable event is not just a hack. It covers the loss of personal information, unauthorized access to it, or unauthorized disclosure of it — regardless of whether the cause was an external attacker, an employee mistake, or a lost device. A single misdirected email containing personal information can, in principle, be a breach of security safeguards in exactly the same way a ransomware attack is.
The "Real Risk of Significant Harm" Test
PIPEDA does not require reporting every incident. It requires reporting a breach when it is reasonable to believe the breach creates a real risk of significant harm to an affected individual. Significant harm is defined broadly and can include humiliation, damage to reputation, financial loss, identity theft, and negative effects on a credit record. Assessing this risk means weighing the sensitivity of the information involved against the probability it will actually be misused — a judgment call, and one where the safer course, when genuinely in doubt, is usually to treat the risk as real rather than explain it away.
Who You Must Notify, and What to Include
If the real-risk threshold is met, PIPEDA generally requires two separate notifications:
- The federal Privacy Commissioner — a report describing the breach's circumstances, its scope, and your response.
- Affected individuals — direct notice, or public notice in limited circumstances, that lets them understand the risk to them and take steps to protect themselves.
Depending on the situation, you may also need to notify other organizations — a bank, a credit bureau, or law enforcement — if doing so could reduce the harm to affected individuals.
Record-Keeping Obligations
Even when a breach does not meet the real-risk-of-significant-harm threshold, PIPEDA still requires organizations to keep a record of every breach of security safeguards they experience, for a period the legislation specifies. Confirm the current retention requirement before you rely on it, since this is exactly the kind of technical detail worth verifying rather than assuming. Keeping a breach log — even for incidents you conclude are not reportable — is one of the simplest things a business can do to show it takes its privacy obligations seriously if a regulator ever asks.
What to Do in the First Hours After a Breach
- [ ] Contain the breach — cut off ongoing unauthorized access before doing anything else.
- [ ] Identify what personal information was involved and how sensitive it is.
- [ ] Assess whether a real risk of significant harm exists, and document your reasoning.
- [ ] Loop in legal counsel before drafting any notification — what you say can matter later.
- [ ] Record your timeline and decisions as you go, not after the fact.
- [ ] Notify the Privacy Commissioner and affected individuals if the threshold is met.
Frequently asked questions
Does a lost company laptop count as a breach if it was encrypted?
Possibly not. Proper encryption meaningfully reduces the risk that lost or stolen information can actually be accessed or misused, which is directly relevant to the real-risk analysis. It is still worth documenting the incident and working through the assessment rather than assuming encryption automatically clears you.
What if the breach only affects employee information, not customers?
The same PIPEDA framework can still apply, though whether PIPEDA governs a given employee's records depends on whether your business is federally or provincially regulated. Either way, treat any breach involving employee personal information with the same seriousness as a customer breach.
Can we just fix the problem quietly without notifying anyone?
No. If the real-risk threshold is met, notification is not optional, and failing to report is itself a separate compliance problem on top of the breach. Deciding the threshold is not met without a documented, reasoned assessment is a common and risky shortcut.
Do we need a lawyer involved right away, or can our IT team handle it alone?
IT should lead containment, but the notification decision has legal consequences, and the language used in a breach notice can affect your exposure later. Involving a lawyer early, even briefly, is generally worth it.
This is a corporate question
Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.