Skip to content

Client Update: It’s here now! Breach reporting for Canadian businesses under PIPEDA

Rob Aske

You likely heard rumblings over the spring and summer, but now it’s here. Canada’s federal privacy law known by the acronym PIPEDA (Personal Information Protection and Electronic Documents Act) adds privacy breach reporting as of November 1, 2018.

The gist of the breach reporting obligations is as follows:

A business will be required to report to the Privacy Commissioner a breach involving personal information (“PI”) under its control (including with a service provider) if it is reasonable to believe that the breach creates a real risk of significant harm to the individual. (The Privacy Commissioner notes that it does not matter if it is one or thousands of affected persons).

Significant harm is defined to include humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on credit record, and damage to or loss of property.

Factors relevant to the real risk of significant harm include sensitivity of the PI, and the probability that it may be misused.

The report to the Commissioner would need to describe the breach, when it occurred, the PI that is subject, the estimated number of individuals affected, and the steps that the organization is taking in response.

Your business would also need to notify individuals whose PI is involved, if that breach creates a real risk of significant harm to the individual.

The notice to the individual would need to describe the breach, when it occurred, the PI affected, the steps the organization is taking, plus information about the business’ complaints process and the individual’s rights under PIPEDA.

The business could be obliged to notify other organizations or government if the business believes that these other bodies may be able to reduce the risk of harm.

Reports must be made “as soon as feasible after the breach”. The express goal is in part to reduce risks of harm, so reports may need to be made well before the full story of the breach is known.

Another big change with this new legislation is that businesses shall be obliged to keep and maintain records of EVERY breach of security safeguards involving PI; i.e. whether or not it meets any particular harm test. In addition, businesses must, on request, provide the Commissioner with access to copies of these records. (So businesses will be obliged to maintain records which will help the Commissioner and any claimant build a case against the business.)

The regulations require records of breach to be maintained for 24 months after the date that the business determined that the breach occurred. In addition, these records must enable the Commissioner to verify compliance with the business’ reporting obligations to the Commissioner and to individuals, if there has been a breach which creates a real risk of significant harm.

Any breach of these obligations may result in the business being charged with an offence, which could result in a fine not exceeding $100,000.

The obligation to report privacy breaches is not new to many jurisdictions, but will be new to much of Canada, and compels every business to sharpen their privacy practices – because going public with a breach can make the impact a much larger mess.

You can find the federal Privacy Commissioner’s Guidelines on reporting breaches here.


This update is intended for general information only. If you have questions about the above information, please contact Rob Aske, or a member of our information technology, internet and privacy group.

SHARE

Archive

Search Archive


 
 

Client Update: Perrin v Blake reaffirms the law on contributory negligence and recovery of damages

April 14, 2016

In a case where there is a contributorily negligent plaintiff and two or more negligent defendants, can the plaintiff recover 100% of her damages from any of the defendants? The answer in Nova Scotia is…

Read More

Client Update: Interest arbitration changes for New Brunswick postponed for further study

April 11, 2016

On Friday, the Province of New Brunswick announced that it would not proceed at this time with the recently proposed changes to binding interest arbitration. The Province announced that a joint labour management committee will be struck to examine…

Read More

Client Update: Universal interest arbitration proposed for New Brunswick

April 5, 2016

On March 29, 2016, the Province of New Brunswick tabled proposed changes to the Industrial Relations Act and the Public Services Labour Relations Act. If passed, these changes would dramatically alter well-established principles of private sector collective bargaining.…

Read More

Good Faith Fisheries: New case on Crown consultation & regulation of Aboriginal fisheries

March 22, 2016

By Jennifer Taylor Why is this case a big deal? It started with two salmon. Now, after several years of litigation, the Nova Scotia Provincial Court in R v Martin, 2016 NSPC 14 has stayed proceedings against…

Read More

Atlantic Employers’ Counsel – Winter 2016

March 10, 2016

THE EDITORS’ CORNER Michelle Black and Sean Kelly One day, the line between mental and physical disabilities may not be so pronounced, but, for now, distinctions are still drawn between Employee A with, for example, diabetes and…

Read More

Hiring the “Right” Employee

February 24, 2016

By Lisa Gallivan Employees can be your biggest asset, if you hire the right people. This can often be one of the biggest decisions that you make as a business owner or employer. The “right” employee…

Read More

Bye, Bye Canadian P.I.?: What Apple’s fight against the FBI means for the protection of Personal Information in Canada

February 23, 2016

By Burtley Francis and Kathleen Leighton Order Up: Apple, P.I. Recently, the public safety versus personal privacy debate has been brought to main headlines. Apple is facing a court order (available here) requiring the company to assist the FBI in the investigation of…

Read More

Client Update: Outlook for the 2016 Proxy Season

February 12, 2016

In preparing for the 2016 proxy season, you should be aware of some regulatory changes and institutional investor guidance that may impact disclosure to and interactions with your shareholders. This update highlights what is new…

Read More

Left Sharks and Copy Cats: The Super Bowl’s Impact on Protecting a Brand

February 5, 2016

By Burtley Francis and Michael MacIsaac You remember Left Shark… The Super Bowl is a lot of things to a lot of people and is arguably the most anticipated event of the year that is not a holiday…

Read More

The Labour Relations of First Nations’ Fisheries: Who gets to decide?

February 2, 2016

By Jennifer Taylor Summary The Canada Industrial Relations Board recently held that it had no jurisdiction as a federal board to certify a bargaining unit comprised of fisheries employees of the Waycobah First Nation. The decision…

Read More

Search Archive


Scroll To Top