Federal law requires reporting a breach to the Privacy Commissioner and notifying affected people where there is a real risk of significant harm, and requires a record of every breach regardless. Provincial private-sector laws differ, so the first question is which applies to you.

What counts as a breach

Broader than most people assume.

The concept is the loss of, unauthorised access to, or unauthorised disclosure of personal information, resulting from a failure of security safeguards or from not having established them.

That covers a compromised website with customer enquiries in its database. It also covers an email sent to the wrong recipient, a stolen laptop with unencrypted files, a misconfigured storage location, and ransomware that encrypts customer records.

Access alone is enough. Somebody reaching personal information counts even if nothing was published or used.

Which law applies to you

The first question, and it is not the same answer for everybody.

The federal Personal Information Protection and Electronic Documents Act applies to organisations under federal jurisdiction and to commercial activity in provinces without their own substantially similar legislation.

British Columbia, Alberta, and Quebec each have their own private-sector privacy statutes covering organisations operating within those provinces, and their breach requirements are not identical to the federal ones or to each other.

That variation matters. A business should establish which applies before assuming a particular obligation, and the relevant privacy commissioner is the authority rather than a general article.

The federal position

Stated because it is the most demanding and because many businesses fall under it.

Report to the Privacy Commissioner where it is reasonable to believe the breach creates a real risk of significant harm to an individual.

Notify the affected individuals in those cases, as soon as feasible after determining the breach occurred.

Notify other organisations that could reduce the risk, where relevant.

Keep a record of every breach, whether or not it met that threshold, and retain it for two years.

That last obligation is the one most small businesses have never heard of, and it applies to incidents that were never reportable.

The harm threshold

What real risk of significant harm actually means, since it is doing all the work.

Significant harm is broad and includes humiliation, damage to reputation or relationships, identity theft, fraud, financial loss, and loss of employment or business opportunities.

Whether the risk is real depends principally on how sensitive the information is and how likely it is to be misused. Financial and health information is obviously sensitive. Less obviously, a birth date or an address can be sensitive where combined with other information it enables fraud.

Even one affected person meets the threshold if the risk is there. Volume is not the test.

The record, which applies regardless

Worth setting up because it is required federally whether or not anything was reportable, and it is good practice anywhere.

What it should contain: the date or period, a description of the circumstances, what information was involved, roughly how many people, what you did to reduce the harm, and whether it was reported.

Where you decided it was not reportable, the record should say why, since that reasoning is what demonstrates you applied the threshold rather than ignored it.

A simple document is sufficient. The requirement is that it exists and can be produced.

What to tell affected people

The notification should be direct and useful rather than defensive.

The fifth item is what makes a notification useful rather than a disclosure. Somebody told their details were exposed wants to know what action to take.

Notifying when you are not required to

The separate and simpler question.

Where a breach does not meet the threshold, you may still choose to tell people. That is frequently the right call, because customers who learn about an incident from you react differently from customers who learn about it another way.

The calculation is not really legal. A business that handled something small transparently is in a better position than one that said nothing and is later asked why.

Where it is genuinely trivial and telling people would cause alarm disproportionate to the risk, saying nothing is defensible. That judgement should be recorded either way.

What to do in the moment

  1. Contain it, which comes before anything else.
  2. Work out what information was actually involved, since the notification decision depends on it.
  3. Record what you know, from the start rather than reconstructing later.
  4. Assess the harm against the threshold, and document the reasoning.
  5. Get advice where the answer is not obvious, which for anything involving financial or health information it usually is not.
  6. Notify, where required or where you have decided to.

The second step is the one that takes longest and cannot be skipped, since notifying people without knowing what was exposed produces a message that helps nobody.

The preparation worth doing

Knowing in advance what personal information you actually hold and where.

For most small businesses that is enquiry records, customer details, possibly payment references, and email. Knowing that before an incident is what makes the assessment possible in hours rather than days.

This is a general description rather than legal advice, requirements differ by jurisdiction and change, and the applicable privacy commissioner is the authority. The technical side of the same incident is covered in when your backup is also compromised.


Frequently asked questions

What counts as a privacy breach?

The loss of, unauthorised access to, or unauthorised disclosure of personal information. That includes a compromised site, an email to the wrong recipient, a stolen laptop, or ransomware.

Which privacy law applies to my business?

It depends on jurisdiction. The federal law applies to federally regulated organisations and to provinces without substantially similar legislation, while BC, Alberta, and Quebec have their own with differing breach requirements.

When must a breach be reported federally?

Where it is reasonable to believe there is a real risk of significant harm to an individual. Affected people must also be notified, as soon as feasible.

What does significant harm include?

Humiliation, damage to reputation or relationships, identity theft, fraud, financial loss, and loss of employment or business opportunities. Even one affected person meets the threshold.

Do I have to record breaches that were not reportable?

Federally, yes. A record of every breach must be kept for two years regardless of whether it met the threshold, including why you decided it did not.

Should I tell people even when not required?

Frequently yes. Customers who learn about an incident from you react differently from those who learn about it another way, and the record should note the decision either way.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Had an incident and unsure what you have to do?

We help establish what was actually exposed and which framework applies, so the notification decision is made on facts rather than guesswork.

Start a Conversation