A breach must be reported to the Privacy Commissioner and to affected individuals where it creates a real risk of significant harm. Separately, records of every breach must be kept for two years regardless of severity.

What changed and who it covers

Since November 2018, organisations subject to federal private-sector privacy legislation have had mandatory breach obligations rather than voluntary ones.

There is no small business exemption. If you collect customer names, addresses, payment information or employee records in the course of commercial activity, this applies.

Three duties, and they are separate:

The third catches people out. The record-keeping duty is unconditional.

What counts as a breach

Broader than a hack.

The loss of, unauthorised access to, or unauthorised disclosure of personal information resulting from a failure of your safeguards.

So: a stolen laptop, an email sent to the wrong customer, a misconfigured folder, a former employee still holding a client list, a paper file left somewhere, or a supplier's system being compromised while holding your data.

That last one matters. Where information has been transferred to a third party for processing, the accountability principle means you remain responsible for it.

The threshold

Whether it is reasonable in the circumstances to believe the breach creates a real risk of significant harm to an individual.

Significant harm is defined broadly and includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on a credit record, and damage to or loss of property.

Real risk turns on two stated factors: how sensitive the information is, and the probability it has been, is being, or will be misused.

Two points worth internalising. Sensitivity is contextual rather than fixed, so a list of names alone may be low risk while the same names attached to a medical service are not. And the absence of misuse so far is not reassurance, because identity theft can follow years after a breach.

A deliberate intrusion tends to raise the probability assessment, since somebody chose to take it.

What reporting involves

The report goes to the Privacy Commissioner as soon as feasible after you conclude the breach has occurred and meets the threshold.

Notification to affected individuals has to be direct where possible, and has to contain enough for them to understand the significance and take protective steps.

There is a third notification duty people miss: if another organisation or a government institution could reduce the risk, you have to tell them too. A bank where financial details were exposed, a credit bureau, or law enforcement where the breach involved criminal activity.

Failure to notify relevant third parties has been flagged as a compliance deficiency in investigations, so it is not a formality.

The record-keeping duty

The one to set up before anything happens.

Records of all breaches must be kept for two years, in enough detail for the regulator to verify that you assessed them properly.

Which means a minor breach you correctly decided not to report still needs a record, including your reasoning for that conclusion.

A simple log is sufficient: the date, what happened, what information was involved, how many people, what you did, your assessment against the threshold, and the decision with its reasoning.

That log is also what demonstrates you were taking the obligation seriously, which matters if a later breach is examined.

The first hour

  1. Contain it. Revoke access, change credentials, take the system offline.
  2. Record the time and what you know.
  3. Work out what information was involved, and whose.
  4. Assess against the threshold, writing down the reasoning.
  5. Report and notify if it meets it, and tell any third party who could help.
  6. Log it either way.

Do not delay containment to investigate, and do not delay the record because the picture is incomplete. Both can be updated.

Provinces and sectors

British Columbia, Alberta and Quebec have their own private-sector privacy statutes, and Quebec's requirements have moved substantially in recent years.

Health information carries its own regimes provincially, with their own reporting rules and frequently a lower threshold.

Which means a business handling health information, or operating in a province with its own statute, should confirm its position rather than assume the federal picture is the whole one.

The point worth ending on

Most small business breaches are ordinary: a wrong recipient, a lost device, a shared folder. They are not dramatic and they are still breaches.

Having a log and a short procedure before one happens turns a stressful hour into a checklist. Not having one means making judgement calls about legal obligations while dealing with the incident itself.

This is general information rather than legal advice, and the privacy commissioner publishes guidance and a reporting form. The preventive half is knowing what you hold in the first place, as covered in knowing what customer data you actually hold.


Frequently asked questions

Is there a small business exemption?

No. If you collect customer or employee personal information in the course of commercial activity, the breach obligations apply.

What counts as a breach?

Loss of, unauthorised access to, or unauthorised disclosure of personal information. A stolen laptop, a misdirected email, or a supplier compromise all qualify.

What is the reporting threshold?

A real risk of significant harm, assessed on the sensitivity of the information and the probability of misuse. Harm includes humiliation, reputational damage, financial loss and identity theft.

Does the absence of misuse mean no risk?

No. Identity theft can follow years later, and a deliberate intrusion raises the probability assessment because somebody chose to take the information.

Do I keep records of breaches I do not report?

Yes. Records of all breaches must be kept for two years, including your reasoning for concluding a breach did not meet the threshold.

Who else might need telling?

Any organisation or government institution that could reduce the risk, such as a bank, a credit bureau, or law enforcement. This has been flagged as a common deficiency.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

No breach log and no procedure?

We set up the short version now, which is the difference between a checklist and improvising legal judgements mid-incident.

Start a Conversation