What happened to your data? Start here.
Pick what happened and see the deadline that matters, what the process involves, and the privacy law that applies.
A company had a data breach
PIPEDA s. 10.1 (breach of security safeguards)
The deadline that matters
What the process involves
- 1The breach details, in writingThe notice has to say what data was exposed, when, and what protective steps the organization is taking.
- 2Account protectionNew passwords, two-factor authentication, and monitoring of the affected accounts are the usual first steps.
- 3A complaint to the OPCIf the response is inadequate, the Office of the Privacy Commissioner accepts complaints.
The law that protects you
"An organization shall report to the Commissioner any breach of security safeguards⦠if it is reasonable⦠to believe that the breach creates a real risk of significant harm to an individual."
Legal information, not legal advice. Privacy law varies by sector and province and is being reformed; confirm what is in force against the current statute or a licensed professional.
Protections that apply to your data
You can ask what personal information a company holds about you and how it was used β usually answered within 30 days.
Breaches posing a real risk of significant harm must be reported to the Commissioner and to you.
Commercial messages generally require your consent and a working unsubscribe honoured within 10 business days.
Provincial health-privacy law gives strong rights to see your records and request corrections.
Did This Help You?
MyPrivacyRights.ca is free for every Canadian. Your support helps keep legal information accessible to everyone.
Donations processed securely via KnowMyRights.ca