Skip to content

Client Update: It’s here now! Breach reporting for Canadian businesses under PIPEDA

Rob Aske

You likely heard rumblings over the spring and summer, but now it’s here. Canada’s federal privacy law known by the acronym PIPEDA (Personal Information Protection and Electronic Documents Act) adds privacy breach reporting as of November 1, 2018.

The gist of the breach reporting obligations is as follows:

A business will be required to report to the Privacy Commissioner a breach involving personal information (“PI”) under its control (including with a service provider) if it is reasonable to believe that the breach creates a real risk of significant harm to the individual. (The Privacy Commissioner notes that it does not matter if it is one or thousands of affected persons).

Significant harm is defined to include humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on credit record, and damage to or loss of property.

Factors relevant to the real risk of significant harm include sensitivity of the PI, and the probability that it may be misused.

The report to the Commissioner would need to describe the breach, when it occurred, the PI that is subject, the estimated number of individuals affected, and the steps that the organization is taking in response.

Your business would also need to notify individuals whose PI is involved, if that breach creates a real risk of significant harm to the individual.

The notice to the individual would need to describe the breach, when it occurred, the PI affected, the steps the organization is taking, plus information about the business’ complaints process and the individual’s rights under PIPEDA.

The business could be obliged to notify other organizations or government if the business believes that these other bodies may be able to reduce the risk of harm.

Reports must be made “as soon as feasible after the breach”. The express goal is in part to reduce risks of harm, so reports may need to be made well before the full story of the breach is known.

Another big change with this new legislation is that businesses shall be obliged to keep and maintain records of EVERY breach of security safeguards involving PI; i.e. whether or not it meets any particular harm test. In addition, businesses must, on request, provide the Commissioner with access to copies of these records. (So businesses will be obliged to maintain records which will help the Commissioner and any claimant build a case against the business.)

The regulations require records of breach to be maintained for 24 months after the date that the business determined that the breach occurred. In addition, these records must enable the Commissioner to verify compliance with the business’ reporting obligations to the Commissioner and to individuals, if there has been a breach which creates a real risk of significant harm.

Any breach of these obligations may result in the business being charged with an offence, which could result in a fine not exceeding $100,000.

The obligation to report privacy breaches is not new to many jurisdictions, but will be new to much of Canada, and compels every business to sharpen their privacy practices – because going public with a breach can make the impact a much larger mess.

You can find the federal Privacy Commissioner’s Guidelines on reporting breaches here.


This update is intended for general information only. If you have questions about the above information, please contact Rob Aske, or a member of our information technology, internet and privacy group.

SHARE

Archive

Search Archive


 
 

Federal Government announces significant investments in Nova Scotian clean energy initiatives

July 21, 2022

Nancy Rubin & Tiegan Scott On July 21, 2022, the Federal government announced a new investment of up to $255 million for clean energy initiatives in Nova Scotia. The funds will be allocated in two…

Read More

The winds of change (part 2): Crown Land

July 21, 2022

By: John Samms, Sadira Jan, Paul Kiley, Dave Randell, Alanna Waberski,  and Jayna Green Now that the Government of Newfoundland and Labrador (“GNL”) has amended the Order in Council that had banned Crown titles and…

Read More

Significant Amendments to the Business Corporations Act (New Brunswick) Proposed

July 20, 2022

By Paul Smith, Dave Randell and Graham Haynes On June 9, 2022, the Government of New Brunswick (“GNB”) released a consultation paper entitled Proposal to Modernize the Business Corporations Act (the “Proposal”) which outlines several significant…

Read More

Keep your hands off my records: solicitor-client privilege & access to information

July 19, 2022

Included in Discovery: Atlantic Education & the Law – Issue 10 Koren Thomson & Josh Merrigan   Introduction In the wake of the Supreme Court of Canada’s decision in Alberta (Information and Privacy Commissioner) v…

Read More

Beyond the border: Immigration update – July 2022

July 18, 2022

We are pleased to present the ninth installment of Beyond the Border, a publication for employers aiming to provide the latest information and analysis on new immigration programs and immigration-related issues. In this issue, insight…

Read More

A long – but not inordinate – delay may give rise to serious concern, but is not an abuse of process: Law Society of Saskatchewan v Abrametz, 2022 SCC 29

July 14, 2022

Kathleen Nash The Supreme Court of Canada’s recent decision in Law Society of Saskatchewan v Abrametz clarifies the standard of review applicable to questions of procedural fairness and abuse of process, as it relates to…

Read More

Bornfreund v. Mount Allison University: a call for a more balanced approach to disputes under access to information legislation

July 14, 2022

Included in Discovery: Atlantic Education & the Law – Issue 10 Mark Heighton & Chad Sullivan   Overview In Marcus Bornfreund v. Mount Allison University, 2022 NBQB 50 the New Brunswick Court of Queen’s Bench…

Read More

Does academic freedom protect professors who spread COVID-19 misinformation on social media?

July 12, 2022

Included in Discovery: Atlantic Education & the Law – Issue 10 Richard Jordan & Jennifer Taylor    As the COVID-19 pandemic surges on, so does the flow of misinformation online. Academia has not been immune,…

Read More

Update: The winds of change (part 1) – Newfoundland and Labrador Government signaling major shift in energy policy

July 6, 2022

John Samms and Matthew Craig Further to our original article published on May 17, 2022 (included below), on the changing energy policy frameworks in Newfoundland and Labrador, the government amended the Order in Council (“OC”)…

Read More

Nova Scotia municipality plans changes to wind turbine regulations

June 27, 2022

By Nancy Rubin & Colton Smith    Wind turbine regulations in the Municipality of Cumberland are set to change.   On June 22, 2022, Cumberland Council approved a second reading of amendments relating to their…

Read More

Search Archive


Scroll To Top