Sentrix

Breakdown · Privacy

PIPEDA: reporting a breach of security safeguards

When a breach must be reported to the Privacy Commissioner of Canada, how to assess the real risk of significant harm, and how to keep the breach record.

By Sentrix · Published 2026-09-20

An exposed access key, a stolen laptop, an email sent to the wrong recipient: the question that follows is always the same. Do we have to report it? Since November 1, 2018, according to the news release of the Office of the Privacy Commissioner of Canada dated October 29, 2018, the Personal Information Protection and Electronic Documents Act (PIPEDA) answers it with a precise test and obligations that apply to every private-sector organization subject to the federal act, whatever its size.

What the Act and the regulations say

Section 10.1 of PIPEDA requires reporting to the Commissioner any breach of security safeguards involving personal information under the organization's control if it is reasonable to believe that the breach creates a real risk of significant harm to an individual. The same breach must be notified to the affected individuals, unless prohibited by law, with enough information for them to understand the significance of the breach and take steps to reduce the risk. Both are done "as soon as feasible" after the organization determines that the breach has occurred.

The Act defines significant harm: bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. It also sets the factors for assessing the risk: the sensitivity of the personal information involved and the probability that it has been or will be misused. The Commissioner adds in its guidance that any information can be sensitive depending on the context, and offers a self-assessment tool whose result, it says, is only one element to consider.

Section 10.2 adds an obligation that is often overlooked: notifying any other organization or government institution that may be able to reduce the risk of harm or mitigate it, a bank or an authentication platform for example. Section 10.3 requires keeping a record of every breach of security safeguards, reported or not, and providing it to the Commissioner on request.

The Breach of Security Safeguards Regulations (SOR/2018-64) set out the mechanics. The report to the Commissioner is in writing and describes the circumstances and, if known, the cause of the breach, the date or period, the nature of the information, the number of individuals affected, the steps taken to reduce the risk, the notifications given or planned, and a contact person. Notification to individuals is given directly (in person, by telephone, mail or email), or indirectly by public communication when direct notification would likely cause further harm, would cause undue hardship, or is impossible for lack of contact information. The record is kept for twenty-four months after the day the organization determines that the breach has occurred.

Finally, section 28 of the Act makes anyone who knowingly contravenes the reporting, notification or record-keeping obligations liable to a fine: up to $10,000 on summary conviction and up to $100,000 on indictment.

Why it matters

The real risk of significant harm test is not a legal formality: it is a management decision made under pressure, often at night, with incomplete facts. Three mistakes come back in the incidents we support.

Confusing investigation and reporting. Waiting to know the exact cause before reporting contradicts the text, which provides for a cause "if known". The regulator prefers an early report completed afterwards.

Recording nothing when concluding there is no risk. The record covers every breach. An organization that records only the reported cases has no record within the meaning of the Act.

Forgetting the vendors. When the breach happens at a subcontractor, the obligation remains with the organization that has control of the information. Without a contractual clause for prompt notice, it learns too late.

For organizations in Quebec, Law 25 sets parallel obligations toward the Commission d'accès à l'information; the same process must produce both reports.

What we think at Sentrix

The right time to understand section 10.1 is before the incident. Concretely:

  1. Write the qualification procedure: who decides that an event is a breach of security safeguards, who assesses the real risk of significant harm, who signs the report. Three names, with backups. This is control 5.24 of ISO 27001:2022 applied to privacy.
  2. Keep the record starting today, with a template that takes up the fields of the regulations: circumstances, cause, period, information, number of people, measures, notices, risk analysis and reasoned conclusion. A well-kept record also answers the CC7 criteria of SOC 2 and controls 5.25 to 5.28 of ISO 27001.
  3. Prepare the notice templates for individuals and third-party organizations, reviewed by legal counsel once, not at every incident.
  4. Require prompt notice from vendors in contracts, with a stated deadline and a point of contact, and verify it during the annual third-party review.
  5. Run the tabletop exercise once a year with a realistic scenario: misaddressed email, exposed token, ransomware at a subcontractor. Time the interval between discovery and the decision to report.
  6. Connect privacy and security: the committee that reviews security incidents must see privacy breaches, and the reverse.

Our page on PIPEDA summarizes the obligations; our data protection and incident response services help put the procedure in place.

The next step

Pull out your breach record. If it does not exist, or if it contains only the reported cases, that is your first action, and it takes a day. If you want to do it with us, write to us.

Sources

Frequently asked questions

Must every breach be reported to the Commissioner?
No. Only breaches that present a real risk of significant harm to at least one individual must be reported to the Commissioner and notified to the affected people. However, every breach, reported or not, must be entered in a record kept for twenty-four months, which the Commissioner can request. The record is therefore the most frequent obligation, and the most often forgotten.
How do we assess the real risk of significant harm?
The Act sets two factors: the sensitivity of the personal information involved and the probability that it has been or will be misused. Significant harm includes bodily harm, humiliation, damage to reputation or relationships, financial loss, identity theft, negative effects on the credit record and loss of employment or business opportunities. Document the analysis, even when the conclusion is negative.
What is the deadline for reporting?
The Act says "as soon as feasible" after the organization determines that a breach has occurred. There is no number of hours, but waiting for the end of the investigation is not an option: the regulations provide that the report describes the cause if known and that missing information can be provided later. Report with what you know, then complete.

Let's talk about your compliance program.

Last updated: 2026-09-20