Data Security & Breach Notification
Personal Information Protection and Electronic Documents Act — breach of security safeguards
Canada · November 1, 2018
The trigger is a 'real risk of significant harm' to an individual — a materially different test from the GDPR's, and one PIPEDA defines expansively enough to catch humiliation, damage to reputation or relationships, and loss of employment or business opportunity, not just financial loss and identity theft. Where it is met, the organization must report to the Office of the Privacy Commissioner as soon as feasible, notify affected individuals, and notify any other organization that may be able to reduce the risk. The duty most often missed is the one that has no threshold at all: s. 10.3 requires keeping a record of EVERY breach of security safeguards, reportable or not, for 24 months, and the OPC can demand those records. Applies to breaches involving personal information under an organization's control in the course of commercial activity, including where the processing itself happened outside Canada.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.