Canada’s new data breach notification rules: What you need to know

November 1, 2018

All businesses, big and small, need to be ready for Canada’s new mandatory data breach notification rules under the Personal Information Protection and Electronic Documents Act (“PIPEDA”).  These changes came into effect on November 1, 2018.   Failure to comply with the new rules – including failing to report breaches that pose a real risk of significant harm or deliberately failing to keep records related to such data breaches – may result in fines of up to $100,000.  To comply with the rules and avoid a potential fine, businesses are encouraged to consider the following steps if they believe they have experienced a breach.

Limit the breach: identify, investigate, contain, and assemble a response team.

Potential steps to immediately contain the breach include stopping the unauthorized practice, addressing breached servers, changing passwords, and/or correcting weaknesses in security/completing program updates.  Be sure to retain any evidence that may help determine the cause of the breach while conducting an initial investigation to determine whether a more detailed inquiry is necessary. Assemble a response team of key people within the organization that have the knowledge, access, and authority to deal with the issue(s) at hand. Members could include:

  • Chief Operating Officer or Operations Manager
  • Data Privacy Officer
  • Senior IT Staff / Chief Technology Officer
  • Chief Marketing Officer and/or Communications
  • Legal Counsel

Determine if the breach poses a “real risk of significant harm” to any individual whose information was involved in the breach.

To determine “real risk”, consider:

  • The sensitivity of the personal information involved in the breach;
  • The probability that the personal information has been, is being, or will be misused; and
  • Other factors that may be set by regulation.

“Significant harm” to the individual includes:

  • Bodily harm, financial loss, property damage
  • Humiliation
  • Identity theft, negative effects to credit record
  • Damage to reputation or relationships
  • Loss of employment or business opportunities

If the breach poses a real risk of significant harm, consult with your response team and notify the commissioner, affected individuals, and other organizations.

The Commissioner

When: As soon as feasible.
What: Information about the breach and steps that have been taken as a result of the breach to reduce the risk of harm to affected individuals.
How: In writing, sent securely.

Affected Individuals

When: As soon as feasible.
What: Information about the breach and steps that have been taken as a result of the breach to reduce the risk of harm to affected individuals.
How: Organizations must generally notify affected individuals directly.

Any other organization that may be able to mitigate harm to affected individuals.

Maintain records.

Organizations must keep records of every security safeguard breach involving personal information, even if they do not pose a real risk of significant harm to an individual.  These records must be maintained for a period of 24 months after determining that a breach has occurred.

The Cybersecurity and Data Privacy Practice Group at Cox & Palmer is happy to assist businesses and organizations prepare for and respond to the roll-out of Canada’s new data breach notification requirements.

 

For a printable PDF version of this publication, please click the link below:
Canada’s new data breach notification rules: What you need to know

Related Articles

At the Very Lease…What to Know Before you Sign a Commercial Lease

It’s exciting when your business grows beyond the family basement (or your dining room table) and is ready to take up commercial space of its own. Leasing space, whether a storefront or an office, is a sign of business legitimacy, sustainability, and growth. Like any contract, a commercial lease sets out the terms that the […]

read more

Rule 22 Motions: No Discovery? No Problem!

In Linda Trevors v. Anne Doucet, Lea Allard, Enterprise Rent-A-Car Canada Company, and Co-operators General Insurance,1  (hereinafter “Trevors v. Doucet”) the moving party applied for summary judgment early in the proceeding.  Discovery had not yet occurred.  The applicants were successful on the motion despite allegations it was premature. Background On May 16, 2015, a head […]

read more
view all
Cox & Palmer publications are intended to provide information of a general nature only and not legal advice. The information presented is current to the date of publication and may be subject to change following the publication date.