Canada’s new data breach notification rules: What you need to know

November 1, 2018

All businesses, big and small, need to be ready for Canada’s new mandatory data breach notification rules under the Personal Information Protection and Electronic Documents Act (“PIPEDA”).  These changes came into effect on November 1, 2018.   Failure to comply with the new rules – including failing to report breaches that pose a real risk of significant harm or deliberately failing to keep records related to such data breaches – may result in fines of up to $100,000.  To comply with the rules and avoid a potential fine, businesses are encouraged to consider the following steps if they believe they have experienced a breach.

Limit the breach: identify, investigate, contain, and assemble a response team.

Potential steps to immediately contain the breach include stopping the unauthorized practice, addressing breached servers, changing passwords, and/or correcting weaknesses in security/completing program updates.  Be sure to retain any evidence that may help determine the cause of the breach while conducting an initial investigation to determine whether a more detailed inquiry is necessary. Assemble a response team of key people within the organization that have the knowledge, access, and authority to deal with the issue(s) at hand. Members could include:

  • Chief Operating Officer or Operations Manager
  • Data Privacy Officer
  • Senior IT Staff / Chief Technology Officer
  • Chief Marketing Officer and/or Communications
  • Legal Counsel

Determine if the breach poses a “real risk of significant harm” to any individual whose information was involved in the breach.

To determine “real risk”, consider:

  • The sensitivity of the personal information involved in the breach;
  • The probability that the personal information has been, is being, or will be misused; and
  • Other factors that may be set by regulation.

“Significant harm” to the individual includes:

  • Bodily harm, financial loss, property damage
  • Humiliation
  • Identity theft, negative effects to credit record
  • Damage to reputation or relationships
  • Loss of employment or business opportunities

If the breach poses a real risk of significant harm, consult with your response team and notify the commissioner, affected individuals, and other organizations.

The Commissioner

When: As soon as feasible.
What: Information about the breach and steps that have been taken as a result of the breach to reduce the risk of harm to affected individuals.
How: In writing, sent securely.

Affected Individuals

When: As soon as feasible.
What: Information about the breach and steps that have been taken as a result of the breach to reduce the risk of harm to affected individuals.
How: Organizations must generally notify affected individuals directly.

Any other organization that may be able to mitigate harm to affected individuals.

Maintain records.

Organizations must keep records of every security safeguard breach involving personal information, even if they do not pose a real risk of significant harm to an individual.  These records must be maintained for a period of 24 months after determining that a breach has occurred.

The Cybersecurity and Data Privacy Practice Group at Cox & Palmer is happy to assist businesses and organizations prepare for and respond to the roll-out of Canada’s new data breach notification requirements.


For a printable PDF version of this publication, please click the link below:
Canada’s new data breach notification rules: What you need to know

Related Articles

Employment & Labour – Top Ten Cases of 2018

2018 saw a number of developments in employment and labour law. Below, we provide a summary of the top 10 Canadian decisions from the last 12 months that we believe Atlantic Canadian employers should be aware of coming into 2019. Re Lower Churchill Transmission Construction Employers’ Assn Inc and IBEW, Local 1620 (Tizzard) Arbitrator finds […]

read more

#MeToo and Your Corporate Culture

Over a year has passed since October 15, 2017, the date that Alyssa Milano famously tweeted #MeToo, as a show of support for those who asserted they were sexually harassed or assaulted by Harvey Weinstein and to seek to illustrate the magnitude of the problem. Within 24 hours, the tweet generated more than 12 million […]

read more

Up Close and Personal…Guarantees

Securing bank financing could very well be the springboard to take your business to the next exciting level. A personal guarantee may be a condition of that financing, but don’t be scared off. Knowledge and experienced guidance can help you work with the lender to take the business successfully forward.

read more
view all
Cox & Palmer publications are intended to provide information of a general nature only and not legal advice. The information presented is current to the date of publication and may be subject to change following the publication date.