PIPEDA breach notification is a legal requirement, not a best practice
Under the Personal Information Protection and Electronic Documents Act, most Canadian businesses must report certain data breaches to the Office of the Privacy Commissioner of Canada, notify affected individuals, and keep records of all breaches, even ones that do not meet the reporting threshold. This applies to breaches involving personal information under a business's control, whether caused by ransomware, a hacked mailbox, a lost laptop, or human error.
The trigger: 'real risk of significant harm'
Not every incident requires notification, but the threshold is broader than many owners assume.
- 'Significant harm' under PIPEDA includes bodily harm, humiliation, damage to reputation, loss of employment or business opportunities, financial loss, identity theft, and damage to credit records
- Both the sensitivity of the information and the probability it will be misused factor into the assessment
- When in doubt, the safer default is to treat an incident involving personal information as reportable and assess formally rather than assuming it does not qualify
What you are required to do once the threshold is met
Three distinct obligations apply, and missing any one of them is a compliance gap.
- Report to the Office of the Privacy Commissioner of Canada using their breach reporting form, as soon as feasible after determining the breach occurred
- Notify affected individuals directly, in a way that gives them enough information to understand the risk and protect themselves
- Notify any other organization or government institution that may be able to reduce the risk of harm, such as a bank that could flag affected accounts
- Keep a record of every breach, including those below the reporting threshold, for at least 24 months
What a compliant notification actually contains
A notification needs to give affected people enough to act, not just an apology.
- A description of what happened and when it was discovered
- What personal information was involved
- The steps taken to reduce the risk of harm
- Steps the individual can take to protect themselves, such as monitoring accounts or placing a fraud alert
- Contact information for follow-up questions
Practical first steps after discovering a breach
Move through assessment and notification in a defensible order.
- Contain the incident first, following your incident response process
- Determine what personal information was actually affected, not just assumed to be affected
- Assess the real-risk-of-significant-harm threshold, ideally with input from someone familiar with PIPEDA requirements
- Notify the Privacy Commissioner and affected individuals promptly once the threshold is confirmed met
- Document the assessment and decision even if you determine notification is not required
Frequently asked questions
Does PIPEDA apply to a very small business with only a few employees?
In most provinces, yes. PIPEDA applies to personal information collected, used, or disclosed in the course of commercial activity, regardless of business size, except in provinces with substantially similar private-sector privacy laws (such as BC's PIPA), which apply instead for provincially regulated organizations. Either way, breach notification obligations exist; the specific law governing them depends on the province and sector.
What happens if we do not report a breach that met the threshold?
Failing to report a breach that meets the real-risk-of-significant-harm threshold, or failing to keep required records, can result in penalties under PIPEDA, in addition to the reputational and client-trust damage of the breach itself becoming public later without proper notification.
How quickly must we notify after discovering a breach?
PIPEDA requires notification 'as soon as feasible' after determining a breach has occurred, without an exact fixed number of days, but the expectation is prompt action rather than an extended internal review process before deciding to notify.