Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Guide · Updated 30 Sep 2026

PIPEDA: what a firm has to do after a breach

Canada’s federal private-sector privacy law requires a firm to report some breaches, tell the people affected, and keep a record of every breach. Here is what that means in practice.

Updated 30 Sep 2026Reading time 6 minBy LeakTrace

Who it applies to

PIPEDA applies to private-sector organisations that collect, use or disclose personal information in the course of commercial activity. Some provinces have their own substantially similar laws for activity inside the province; PIPEDA still applies to information that crosses provincial or national borders. For most firms the safe assumption is that it applies.

When a breach must be reported

Since 1 November 2018, a breach of security safeguards involving personal information must be reported when it creates a real risk of significant harm to an individual. Significant harm includes identity theft, financial loss, humiliation, damage to reputation or relationships, loss of employment, and damage to or loss of property.

When the threshold is met, the firm must:

  1. Report the breach to the Office of the Privacy Commissioner of Canada.
  2. Notify the people affected.
  3. Notify any other organisation that may be able to reduce the harm.

Each must be done as soon as feasible after the firm determines that the breach has occurred. There is no fixed number of hours.

The record every firm must keep

A firm must keep a record of every breach of security safeguards, whether or not it met the reporting threshold, for 24 months. The Privacy Commissioner can ask to see it at any time.

Penalties

Knowingly failing to report a breach, notify individuals or keep the record is an offence, with fines of up to $100,000 per offence.

The safeguards principle

PIPEDA also requires security safeguards appropriate to the sensitivity of the information held: physical, organisational and technical. Knowing what your firm exposes from outside, such as staff passwords in breach data or email that can be forged in your name, is part of showing the safeguards are reasonable.

Firms that also work in the United States

There is no single federal equivalent of PIPEDA in the United States. Each state has its own breach-notification law, with different definitions and timelines. Firms working in both countries usually build one process around the strictest rule that applies to them.

Our PIPEDA reference page lists the provisions and recent amendments, with a link to the authoritative text.

Sources
  1. Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, ss. 10.1 to 10.3 and 28, Government of Canada
  2. Breach of Security Safeguards Regulations, SOR/2018-64
  3. Office of the Privacy Commissioner of Canada, guidance on mandatory breach reporting