When must a breach be reported
Under PIPEDA, a breach must be reported to the OPC and notified to affected individuals if it creates a real risk of significant harm (RROSH). Factors include:
- The sensitivity of the information involved.
- The likelihood the information has been or will be misused.
- Other relevant factors (e.g., the cause of the breach, who obtained the information).
What notification must contain
Notifications must be conspicuous, given as soon as feasible, and must contain enough information to help you understand the significance of the breach and to reduce the risk or mitigate the harm.
Provincial rules
Alberta PIPA requires mandatory notification to the OIPC since 2010.
Quebec's Law 25 requires notification to the CAI and affected individuals for any confidentiality incident that presents a risk of serious injury.
PHIPA, HIA, HIPA, and similar health-privacy laws have their own notification obligations for custodians.
Public bodies are now covered too: Ontario FIPPA institutions must report breaches with a real risk of significant harm to the IPC (since July 1, 2025) and Alberta public bodies must notify under the Protection of Privacy Act (since June 11, 2025).
What usually happens for affected people
The notification must describe what was exposed and the steps the organization is taking, and it usually lists protective steps for the individual.
Common protective steps are changing passwords and turning on multi-factor authentication on affected accounts.
Equifax and TransUnion place a free fraud alert on the credit file of someone who reports being a victim; the alert stays for six years.
Where the organization's response was inadequate, a complaint can be made to the OPC or the applicable provincial commissioner.