Skip to main content
All of CanadaUpdated September 2026

Individual Breach Response Playbook

A complete checklist for what to do when your personal information has been exposed in a data breach.

TL;DR

The first 24 hours after a breach notice are usually about account security (passwords and multi-factor authentication); the first week is about credit protection (fraud alerts at Equifax and TransUnion, any credit monitoring the organization offers). Records of the notice and of time and costs matter later if a complaint or a certified class action follows.

Hour 0 to 24

Steps commonly taken in the first day:

  • Change passwords on affected and reused accounts.
  • Enable multi-factor authentication everywhere possible.
  • Check statements for unauthorized transactions.
  • Screenshot and save all breach notifications.

Day 1 to 7

Steps commonly taken in the first week:

  • Fraud alerts on the credit files at Equifax and TransUnion (free for reported victims, six years).
  • Enrolment in any credit monitoring offered by the breached organization.
  • A report to the Canadian Anti-Fraud Centre where fraud has occurred.
  • A police report where identity theft has occurred; the file number is what banks and bureaus ask for.

Ongoing monitoring

Free credit reports are available from Equifax and TransUnion; annual checks are the usual practice.

Unfamiliar mail (new accounts, change-of-address confirmations) is a common first sign of misuse.

Multi-factor authentication and unique passwords remain the main protection afterwards.

Legal options

The legal routes are a complaint to the OPC or provincial commissioner, a civil claim, or a certified class action. Ontario courts have held that intrusion upon seclusion does not lie against an organization that was itself hacked by a third party (Owsianik v. Equifax, 2022 ONCA 813), so claims against breached organizations usually rest on negligence or contract. Records of time and costs incurred are what damages claims rely on.

Related topics

Ask AI