Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
When must you notify a PIPEDA breach of security safeguards?
Updated
PIPEDA s. 10.1: if it is reasonable to believe a breach of security safeguards creates a real risk of significant harm, report to the Commissioner and notify the individual as soon as feasible after the organization determines the breach occurred. Not legal advice; does not start a clock.
Canada PIPEDA jurisdiction guide, last verified 8 September 2026 against PIPEDA ss. 2, 4, and 10.1–10.3 (laws-lois.justice.gc.ca; Act current to 21 June 2026, last amended 4 March 2025; HTML date modified 20 August 2026), the Breach of Security Safeguards Regulations SOR/2018-64 (current to 21 June 2026, last amended 1 November 2018; HTML date modified 20 August 2026), OPC mandatory-reporting guidance and the OPC report-a-privacy-breach-at-your-business page, Quebec's Act respecting the protection of personal information in the private sector (CQLR c. P-39.1) ss. 3.5–3.8 as updated to 7 April 2026, and CAI confidentiality-incident pages actually fetched. OPC and CAI pages are regulator materials, not the Act. It is not legal advice, not a filing, not a RROSH determination, and not a substitute for counsel.
This is PIPEDA ss. 10.1–10.3, not YOUR determination
Audience: a founder, CISO, privacy officer, or counsel at an organization that may collect, use, or disclose personal information in the course of commercial activities with a real and substantial connection to Canada, triaging an incident that may sit under PIPEDA Division 1.1. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that PIPEDA applies, that a breach of security safeguards occurred, that a real risk of significant harm (RROSH) exists, that 'as soon as feasible' has started, or that you must file.
Sections 10.1–10.3 and SOR/2018-64 are legal requirements only if PIPEDA applies to YOUR facts. PIPEDA s. 4(1): this Part applies to every organization in respect of personal information that the organization collects, uses or discloses in the course of commercial activities, or that is about an employee of, or an applicant for employment with, the organization and that the organization collects, uses or discloses in connection with the operation of a federal work, undertaking or business. This page does not decide that YOU are such an organization. Last verified 8 September 2026. Not legal advice.
- Statute versus guidance: PIPEDA ss. 10.1–10.3 and SOR/2018-64 are legal requirements only if they apply. OPC 'What you need to know about mandatory reporting of breaches of security safeguards' (date modified 11 August 2025) and the OPC report-a-privacy-breach-at-your-business page (date modified 23 June 2025) are OPC materials; they are not the Act. This page quotes which kind of text it is relying on.
- This page does not start 'as soon as feasible', does not convert that phrase into a number of hours, and does not paste GDPR 72 hours, CRA 24-hour / 72-hour marks, or HIPAA 60 days onto PIPEDA s. 10.1.
- The reporting-deadlines page on this site is the statute table of clocks. The who-to-notify page on this site is the recipient-class map. The which-jurisdictions-apply page on this site is the applicability map. The document-your-decision page on this site is the decision record. The HIPAA breach-notification guide on this site.
- The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is not a PIPEDA clock, and it does not file with the OPC. The CRA Article 14 reporting guide on this site is that ladder's statute.
RROSH is the notice threshold — not a determination this page makes
PIPEDA s. 10.1(1) is the Commissioner's notice. Section 10.1(3) is the individual's notice. Both fire only if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual. This page does not find RROSH on YOUR facts. An assessment aid is not a determination. Counsel applies the test. Last verified 8 September 2026. Not legal advice.
| Question | What the cited text says | What this page does not do | Kind of text |
|---|---|---|---|
| Does PIPEDA apply to this organization and this information? | PIPEDA s. 4(1): commercial activities, or employee / applicant information in connection with a federal work, undertaking or business. OPC 'PIPEDA requirements in brief' (OPC guidance) restates that Alberta, British Columbia, and Quebec have private-sector privacy laws deemed substantially similar, and that organizations subject to such a law are generally exempt from PIPEDA for collection, use, or disclosure that occurs within that province; interprovincial and international handling in the course of commercial activities remains under PIPEDA. That OPC page is not s. 4. | Does not decide that YOU are subject to PIPEDA, to Quebec's P-39.1, or to Alberta or British Columbia PIPA. Does not start a clock. | Legal requirement — PIPEDA s. 4(1), only if it applies. Substantially-similar restatement is OPC guidance. |
| Was there a breach of security safeguards? | PIPEDA s. 2(1): 'breach of security safeguards' means the loss of, unauthorized access to or unauthorized disclosure of personal information resulting from a breach of an organization's security safeguards that are referred to in clause 4.7 of Schedule 1 or from a failure to establish those safeguards. | Does not decide that YOUR event is a breach of security safeguards. Does not start a clock. | Legal requirement — PIPEDA s. 2(1). |
| Is it reasonable to believe the breach creates a real risk of significant harm? | PIPEDA s. 10.1(7): significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record and damage to or loss of property. Section 10.1(8): relevant factors include (a) the sensitivity of the personal information involved in the breach; (b) the probability that the personal information has been, is being or will be misused; and (c) any other prescribed factor. Last verified 8 September 2026, SOR/2018-64 prescribed no additional factor under (c). | Does not find RROSH on YOUR facts. A decision aid is not a determination. The OPC privacy-breach risk self-assessment tool is OPC guidance, not the Act. | Legal requirement — PIPEDA s. 10.1(1), (3), (7), and (8). OPC RROSH tool is OPC guidance. |
| If RROSH — report to the Commissioner and notify the individual | Section 10.1(1) and (2): report to the Commissioner as soon as feasible after the organization determines that the breach has occurred. Section 10.1(3) and (6): unless otherwise prohibited by law, notify the individual as soon as feasible after that same determination. Those two notices are different recipient classes. They share the RROSH threshold and the same timing words. They are not GDPR Article 33 versus Article 34. | Does not start 'as soon as feasible'. Does not file. Does not convert the phrase into hours. | Legal requirement — PIPEDA s. 10.1(1)–(3) and (6). |
| If no RROSH — the record-keeping duty still exists | PIPEDA s. 10.3(1): keep and maintain a record of every breach of security safeguards involving personal information under its control. SOR/2018-64 s. 6(1): maintain that record for 24 months after the day on which the organization determines that the breach has occurred. Notice can be off the table; the record is not. | Does not keep YOUR register. Does not find that YOUR no-notice decision was correct. | Legal requirement — PIPEDA s. 10.3(1) and SOR/2018-64 s. 6. |
'As soon as feasible' is not 72 hours
PIPEDA s. 10.1(2) and (6) use the same timing words: as soon as feasible after the organization determines that the breach has occurred. That phrase is not GDPR Article 33(1)'s 'without undue delay and, where feasible, not later than 72 hours after having become aware'. It is not 'without undue delay' from GDPR. It is not 30 days, not 60 days, and not a number of hours this page invents. Last verified 8 September 2026. Not legal advice.
| Element | What the text says | Kind of text | Last verified |
|---|---|---|---|
| Commissioner report — duty | An organization shall report to the Commissioner any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual. | Legal requirement — PIPEDA s. 10.1(1). Only if PIPEDA applies. The recipient is the Privacy Commissioner of Canada, not an EU supervisory authority and not Quebec's Commission d'accès à l'information. | 8 September 2026 |
| Commissioner report — timing | The report shall contain the prescribed information and shall be made in the prescribed form and manner as soon as feasible after the organization determines that the breach has occurred. | Legal requirement — PIPEDA s. 10.1(2). 'As soon as feasible' is not converted here into hours. Determination that the breach has occurred is the start event named in that sentence — not GDPR-style awareness, not CRA manufacturer-awareness, not Form 8-K materiality. | 8 September 2026 |
| Individual notice — duty | Unless otherwise prohibited by law, an organization shall notify an individual of any breach of security safeguards involving the individual's personal information under the organization's control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to the individual. | Legal requirement — PIPEDA s. 10.1(3). Same RROSH threshold as s. 10.1(1). A different recipient class. | 8 September 2026 |
| Individual notice — timing | The notification shall be given as soon as feasible after the organization determines that the breach has occurred. | Legal requirement — PIPEDA s. 10.1(6). Same timing words as s. 10.1(2). This page does not invent a second, later start. | 8 September 2026 |
| What this page does not convert | 'As soon as feasible' is not 72 hours. It is not 24 hours. It is not 30 days. It is not 'without undue delay'. GDPR Article 33(1)'s 72-hour outer mark does not discharge PIPEDA, and PIPEDA does not borrow that mark. | This page. Not a filing. Not YOUR clock. | 8 September 2026 |
What the Commissioner report must contain — SOR/2018-64 s. 2
PIPEDA s. 10.1(2) points at prescribed information, form, and manner. SOR/2018-64 s. 2 is that prescription. Last verified 8 September 2026. Not legal advice. Not YOUR report.
- SOR/2018-64 s. 2(1): the report must be in writing and must contain (a) a description of the circumstances of the breach and, if known, the cause; (b) the day on which, or the period during which, the breach occurred or, if neither is known, the approximate period; (c) a description of the personal information that is the subject of the breach to the extent that the information is known; (d) the number of individuals affected by the breach or, if unknown, the approximate number; (e) a description of the steps that the organization has taken to reduce the risk of harm to affected individuals that could result from the breach or to mitigate that harm; (f) a description of the steps that the organization has taken or intends to take to notify affected individuals of the breach in accordance with subsection 10.1(3) of the Act; and (g) the name and contact information of a person who can answer, on behalf of the organization, the Commissioner's questions about the breach.
- SOR/2018-64 s. 2(2): an organization may submit to the Commissioner any new information referred to in subsection (1) that the organization becomes aware of after having made the report. That is not a licence to skip the first report.
- SOR/2018-64 s. 2(3): the report may be sent to the Commissioner by any secure means of communication.
- OPC report-a-privacy-breach-at-your-business page (OPC materials, date modified 23 June 2025): organizations should use the OPC's secure online breach reporting form; they request a link, then submit. Organizations can report in any format that captures the necessary information, including the OPC PIPEDA breach report form PDF. That page is OPC materials, not the Act. This page does not invent a public form URL beyond the pages actually fetched. A named human still submits.
Individual notice content, form, and manner — s. 10.1(4)–(5) and SOR ss. 3–5
Section 10.1(4) is the content standard. Section 10.1(5) is form and manner. SOR/2018-64 ss. 3–5 prescribe the list, direct notice, and the limited indirect-notice path. Last verified 8 September 2026. Not legal advice.
- PIPEDA s. 10.1(4): the notification shall contain sufficient information to allow the individual to understand the significance to them of the breach and to take steps, if any are possible, to reduce the risk of harm that could result from it or to mitigate that harm. It shall also contain any other prescribed information.
- SOR/2018-64 s. 3: the notification must contain (a) a description of the circumstances of the breach; (b) the day on which, or period during which, the breach occurred or, if neither is known, the approximate period; (c) a description of the personal information that is the subject of the breach to the extent that the information is known; (d) a description of the steps that the organization has taken to reduce the risk of harm that could result from the breach; (e) a description of the steps that affected individuals could take to reduce the risk of harm that could result from the breach or to mitigate that harm; and (f) contact information that the affected individual can use to obtain further information about the breach.
- PIPEDA s. 10.1(5): the notification shall be conspicuous and shall be given directly to the individual in the prescribed form and manner, except in prescribed circumstances, in which case it shall be given indirectly in the prescribed form and manner.
- SOR/2018-64 s. 4: direct notification must be given in person, by telephone, mail, email or any other form of communication that a reasonable person would consider appropriate in the circumstances.
- SOR/2018-64 s. 5(1): indirect notification is permitted only if (a) direct notification would be likely to cause further harm to the affected individual; (b) direct notification would be likely to cause undue hardship for the organization; or (c) the organization does not have contact information for the affected individual. Section 5(2): indirect notification must be given by public communication or similar measure that could reasonably be expected to reach the affected individuals. This page does not decide that YOUR facts meet those limbs.
Record-keeping exists even when there is no notice
PIPEDA s. 10.3(1) is a separate duty from s. 10.1 notice. It covers every breach of security safeguards involving personal information under the organization's control — not only the RROSH subset. Last verified 8 September 2026. Not legal advice. The product does not keep that register.
| Element | What the text says | Kind of text | What this page does not do |
|---|---|---|---|
| Duty | An organization shall, in accordance with any prescribed requirements, keep and maintain a record of every breach of security safeguards involving personal information under its control. | Legal requirement — PIPEDA s. 10.3(1). | Does not keep YOUR register. Does not treat a no-RROSH decision as a no-record decision. |
| Retention | For the purposes of subsection 10.3(1) of the Act, an organization must maintain a record of every breach of security safeguards for 24 months after the day on which the organization determines that the breach has occurred. | Legal requirement — SOR/2018-64 s. 6(1). OPC guidance restates this as two years; two years is that regulation's 24 months, not a different clock. | Does not convert 24 months into a notice clock. Does not start 24 months. |
| Content of the record | The record must contain any information that enables the Commissioner to verify compliance with subsections 10.1(1) and (3) of the Act. | Legal requirement — SOR/2018-64 s. 6(2). | Does not draft YOUR record. OPC guidance listing date, circumstances, nature of information, and whether notice was given is OPC guidance, not s. 6(2). |
| Commissioner access | An organization shall, on request, provide the Commissioner with access to, or a copy of, a record. | Legal requirement — PIPEDA s. 10.3(2). | Does not produce YOUR copy. Does not file. |
Notification to other organizations — s. 10.2 is not s. 10.1
PIPEDA s. 10.2 is a third notice class. It fires after individual notice under s. 10.1(3), not instead of it. Last verified 8 September 2026. Not legal advice.
- Section 10.2(1): an organization that notifies an individual of a breach of security safeguards under subsection 10.1(3) shall notify any other organization, a government institution or a part of a government institution of the breach if the notifying organization believes that the other organization or the government institution or part concerned may be able to reduce the risk of harm that could result from it or mitigate that harm, or if any of the prescribed conditions are satisfied. Last verified 8 September 2026, SOR/2018-64 prescribed no additional conditions under that 'or'.
- Section 10.2(2): the notification shall be given as soon as feasible after the organization determines that the breach has occurred. Same timing words as s. 10.1(2) and (6). This page does not convert them into hours.
- Sections 10.2(3)–(4) permit disclosure of personal information without knowledge or consent solely for reducing or mitigating that harm to the notified organization or institution. That permission is not the s. 10.1(1) Commissioner report.
- OPC guidance examples (law enforcement; a payments processor) are OPC materials, not the Act. This page does not find that YOUR facts require a s. 10.2 notice.
PIPEDA is not Quebec Law 25
Two different regimes. Do not paste PIPEDA RROSH onto Quebec, and do not treat an OPC filing as a CAI filing. Last verified 8 September 2026 against CQLR c. P-39.1 as updated to 7 April 2026. Not legal advice.
| Limb | PIPEDA (federal private sector) | Quebec P-39.1 (Law 25 amendments) | Do not |
|---|---|---|---|
| Instrument | Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, Division 1.1 (ss. 10.1–10.3) plus SOR/2018-64. Legal requirement only if PIPEDA applies. | Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, ss. 3.5–3.8, introduced by 2021, c. 25 (commonly called Law 25 / Loi 25). Legal requirement only if that Act applies. A person carrying on an enterprise within the meaning of article 1525 of the Civil Code. | Do not collapse federal and provincial private-sector statutes. Filing one never discharges the other. |
| What is a breach / incident | s. 2(1) 'breach of security safeguards': loss of, unauthorized access to or unauthorized disclosure of personal information resulting from a breach of clause 4.7 safeguards or a failure to establish them. | s. 3.6 'confidentiality incident': (1) access not authorized by law to personal information; (2) use not authorized by law; (3) communication not authorized by law; or (4) loss of personal information or any other breach of the protection of such information. | Do not paste the PIPEDA definition onto s. 3.6. Quebec's list includes unauthorized use; PIPEDA's definition as fetched does not use that word. |
| Notice threshold | Real risk of significant harm (RROSH). s. 10.1(7)–(8): significant harm includes the listed harms; factors include sensitivity and probability of misuse. | s. 3.5 second paragraph: if the incident presents a risk of serious injury. s. 3.7: in assessing the risk of injury, consider in particular the sensitivity of the information concerned, the anticipated consequences of its use and the likelihood that such information will be used for injurious purposes, and consult the person in charge of the protection of personal information. | Do not paste RROSH onto 'risk of serious injury'. The factors are not the same sentence. |
| Timing words | 'As soon as feasible after the organization determines that the breach has occurred' (s. 10.1(2) and (6)). Not a number of hours. | s. 3.5: 'must promptly notify' the Commission d'accès à l'information (English official text). French official text: 'avec diligence'. This page does not convert 'promptly' or 'avec diligence' into 72 hours or into any other number. | Do not paste GDPR 72 hours onto either statute. Do not paste 'as soon as feasible' onto s. 3.5. |
| Regulator recipient | The Privacy Commissioner of Canada (the Commissioner). OPC report-a-privacy-breach-at-your-business is OPC materials describing a filing path. | The Commission d'accès à l'information established by section 103 of CQLR c. A-2.1. CAI confidentiality-incident pages (CAI materials) describe a written notice using the CAI form. CAI pages are not P-39.1. | Do not treat an OPC submission as a CAI notice. Do not treat a CAI notice as an OPC report. |
| Record / register | s. 10.3(1) plus SOR/2018-64 s. 6: every breach of security safeguards, 24 months from determination. | s. 3.8: a person carrying on an enterprise must keep a register of confidentiality incidents. A government regulation may determine the content. A copy must be sent to the Commission at its request. This page does not paste PIPEDA's 24 months onto s. 3.8. | Do not treat the PIPEDA record as the Quebec register. The product keeps neither. |
Legal requirement versus OPC guidance
This page labels each cited text. Last verified 8 September 2026. Not legal advice.
| Text | Kind | What it is not |
|---|---|---|
| PIPEDA ss. 2, 4, 10.1, 10.2, 10.3, and 28 | Legal requirement, only if PIPEDA applies. | Not OPC guidance. Not a RROSH determination on YOUR facts. |
| Breach of Security Safeguards Regulations, SOR/2018-64 | Legal requirement, only if PIPEDA applies. In force 1 November 2018 (SI/2018-32). Last amended 1 November 2018. | Not OPC guidance. s. 2 is report content. ss. 3–5 are individual-notice content and manner. s. 6 is the 24-month record. |
| OPC mandatory-reporting guidance; OPC report-a-privacy-breach-at-your-business page; OPC RROSH self-assessment tool; OPC 'PIPEDA requirements in brief' | OPC materials. Regulator guidance and how-to pages. Date modified on the pages fetched: mandatory reporting 11 August 2025; report-at-your-business 23 June 2025. | Not the Act. Not SOR/2018-64. The RROSH tool does not find RROSH on YOUR facts. The online form path is OPC materials describing how to submit, not s. 10.1 itself. |
| CQLR c. P-39.1 ss. 3.5–3.8 (Law 25 amendments) | Legal requirement, only if that Act applies. Updated to 7 April 2026 on the Légis Québec text fetched. | Not PIPEDA. Not RROSH. Not an OPC filing. |
| CAI confidentiality-incident pages and CAI forms | CAI materials. The CAI site states that its web texts vulgarize the laws and do not have the force of law. | Not P-39.1. Not a 72-hour clock. |
What this page did not fetch — provincial and sector statutes
Canada is not one statute. This page treats PIPEDA Division 1.1 and, as a contrast, Quebec P-39.1 ss. 3.5–3.8. It does not invent a thirteen-jurisdiction table. Last verified 8 September 2026. Not legal advice.
- Alberta's Personal Information Protection Act and British Columbia's Personal Information Protection Act have been deemed substantially similar to PIPEDA, as the OPC 'PIPEDA requirements in brief' page (OPC guidance) restates. This page did not fetch those provincial Acts' breach-notification sections and does not invent their clocks, thresholds, or recipients.
- Ontario's Personal Health Information Protection Act (PHIPA) and other provincial health-information statutes are different instruments. This page did not fetch PHIPA and does not paste PIPEDA RROSH onto health custodians.
- Federal public-sector Privacy Act breach rules are a different regime from PIPEDA. The OPC report-a-privacy-breach-at-your-federal-institution path is not this page.
- The which-jurisdictions-apply page on this site is the applicability map. Counsel maps YOUR facts. This page does not.
HIPAA, SEC Item 1.05, and GDPR 72 hours do not discharge PIPEDA
Overlapping duties may all attach. Filing one never discharges the others. Last verified 8 September 2026. Not legal advice.
- GDPR Article 33(1)'s 72 hours from becoming aware is not PIPEDA s. 10.1's 'as soon as feasible' after determination that the breach has occurred. The GDPR breach-notification guide on this site is Articles 33–34 of EU GDPR. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner.
- Form 8-K Item 1.05 is securities-law disclosure to investors within four business days of a materiality determination. The SEC cyber-disclosure guide on this site is Item 1.05 and Item 106. An Item 1.05 filing does not discharge PIPEDA.
- HIPAA 45 CFR §§164.400–414, when it applies, is a different regime. The HIPAA breach-notification guide on this site. A HIPAA notice does not discharge PIPEDA.
- US-state individual, attorney-general, and credit-bureau notices are different recipient classes. The US-state-laws guide on this site is the representative high-variance comparison. Filing California does not discharge the OPC.
- Document the walk, including a no-notification decision. The document-your-decision page on this site is the decision record. This page does not keep YOUR file.
Offence maxima — not a typical fine, not an OPC levy
PIPEDA s. 28, last verified 8 September 2026: every organization that knowingly contravenes subsection 8(8), section 10.1 or subsection 10.3(1) or 27.1(1), or that obstructs the Commissioner or the Commissioner's delegate in the investigation of a complaint or in conducting an audit, is guilty of (a) an offence punishable on summary conviction and liable to a fine not exceeding $10,000; or (b) an indictable offence and liable to a fine not exceeding $100,000. Those figures are statutory maxima, not typical outcomes, not an average, and not an OPC-issued administrative penalty. OPC mandatory-reporting guidance (OPC materials): the OPC does not prosecute offences under PIPEDA or issue fines; it can refer information relating to a possible offence to the Attorney General of Canada. This page invents no typical OPC fine and no average Canadian breach cost. Not legal advice.
Checklist
This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The which-jurisdictions-apply page on this site is the applicability map. The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table. The document-your-decision page on this site is the decision record.
- Does PIPEDA s. 4 apply to this organization and this personal information? Substantially similar provincial law for in-province activity? This page does not run that test.
- Was there a breach of security safeguards as s. 2(1) defines it? This page does not find it.
- Is it reasonable in the circumstances to believe the breach creates a real risk of significant harm? Quote s. 10.1(7)–(8). Counsel applies the test. The OPC RROSH tool is OPC guidance, not the Act. This page does not find RROSH.
- If RROSH: Commissioner report (s. 10.1(1)–(2); SOR/2018-64 s. 2) and individual notice (s. 10.1(3)–(6); SOR ss. 3–5), as soon as feasible after the organization determines that the breach has occurred. Do not convert that phrase into 72 hours.
- s. 10.2 other-organization / government-institution notice, if s. 10.1(3) notice is given and the belief limb is met.
- Record every breach of security safeguards for 24 months from determination (s. 10.3; SOR/2018-64 s. 6), including a documented no-RROSH decision. Notice can be off; the record is not.
- Does Quebec P-39.1 also sit on the facts? Different threshold (risk of serious injury), different clock ('promptly' / 'avec diligence'), different recipient (CAI). Filing OPC does not discharge CAI.
- Who is authorised to file, and who is not. A named human files. The product does not. This page does not file.
Where this shows up in ShipReady Metrics
The signed-in app does not decide that PIPEDA or Quebec Law 25 applies, does not run a RROSH assessment, does not start an 'as soon as feasible' clock, does not keep a PIPEDA s. 10.3 register or a Quebec s. 3.8 register, does not file with the OPC, and does not file with the CAI. None of the surfaces below is a s. 10.1 report, an individual notice, a confidentiality-incident notice, or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a PIPEDA 'as soon as feasible' clock, not a RROSH assessment, and not an OPC filing. It tracks a clock the organization already recorded. It is not a determination that CRA applies. The CRA Article 14 reporting guide on this site is that ladder's statute. A named human still submits.
The obligation map lists frameworks the organization has marked in-scope. That in-scope mark is not a determination that PIPEDA applies, not a determination that Quebec P-39.1 applies, and not a legal opinion that a breach of security safeguards or a confidentiality incident has occurred. There is no `pipeda` key in the bundled framework catalog. GDPR (`gdpr`), HIPAA (`hipaa`), and CCPA/CPRA (`ccpa`) are bundled starter subsets; marking any of them in-scope is not a PIPEDA analysis and is not an OPC filing. The cyber risk register lives under Security. It is a cyber risk register. It is not a s. 10.3 record, not a Quebec s. 3.8 register, and not a RROSH worksheet. There is no OPC reporting ladder and no CAI filing surface. A named human / counsel still files.
Key terms used on this page
Short labels. They are not a glossary of every privacy-law term. Last verified 8 September 2026. Not legal advice.
| Term | How this page uses it |
|---|---|
| RROSH | Real risk of significant harm. PIPEDA s. 10.1(1) and (3) notice threshold. Defined via s. 10.1(7) (significant harm) and s. 10.1(8) (factors). Not Quebec's 'risk of serious injury'. Not GDPR Article 33(1)'s 'unlikely to result in a risk'. |
| As soon as feasible | PIPEDA s. 10.1(2) and (6) timing words, from the organization's determination that the breach has occurred. Not 72 hours. Not a number this page invents. |
| Breach of security safeguards | PIPEDA s. 2(1) definition. Loss, unauthorized access, or unauthorized disclosure of personal information from a clause 4.7 safeguard breach or a failure to establish those safeguards. |
| Commissioner / OPC | The Privacy Commissioner of Canada. s. 10.1(1) recipient. OPC pages are OPC materials, not the Act. |
| Law 25 / P-39.1 | Quebec's 2021, c. 25 amendments to the Act respecting the protection of personal information in the private sector. Confidentiality-incident rules in ss. 3.5–3.8. Recipient: Commission d'accès à l'information (CAI). Clock: 'promptly' / 'avec diligence'. Not PIPEDA. |
| Record-keeping | PIPEDA s. 10.3(1) plus SOR/2018-64 s. 6: every breach, 24 months from determination, even when there is no s. 10.1 notice. |
Primary sources (last verified 8 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
PIPEDA (S.C. 2000, c. 5) ss. 2, 4, 10.1, 10.2, 10.3, and 28 (laws-lois.justice.gc.ca; Act current to 21 June 2026, last amended 4 March 2025; HTML date modified 20 August 2026) are legal requirements only when PIPEDA applies. s. 10.1 is Commissioner and individual notice at the RROSH threshold, as soon as feasible after the organization determines that the breach has occurred. s. 10.2 is notice to other organizations or government institutions. s. 10.3 is the record of every breach. s. 28 maxima are $10,000 (summary) and $100,000 (indictable) for a knowing contravention of s. 10.1 or s. 10.3(1), among other limbs — maxima, not typical fines. Breach of Security Safeguards Regulations, SOR/2018-64 (current to 21 June 2026, last amended 1 November 2018; in force 1 November 2018; HTML date modified 20 August 2026) prescribe report content (s. 2), individual-notice content and manner (ss. 3–5), and 24-month record-keeping (s. 6). OPC mandatory-reporting guidance (date modified 11 August 2025) and the OPC report-a-privacy-breach-at-your-business page (date modified 23 June 2025) are OPC materials, not the Act. CQLR c. P-39.1 ss. 3.5–3.8 (Légis Québec, updated to 7 April 2026) are Quebec's private-sector confidentiality-incident rules; CAI pages are CAI materials. These are the Canadian provisions this page treats, not a complete world list of breach laws. Not legal advice.
The reporting-deadlines page on this site is the statute table of clocks. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The failure-to-report-consequences page on this site is the maxima table. The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. The who-to-notify page on this site is the recipient-class map. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. The prepare-regulatory-report page on this site is the field checklist. The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record. The GDPR breach-notification guide on this site is Articles 33–34 of EU GDPR. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. The US-state-laws guide on this site is the representative high-variance comparison. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106. The HIPAA breach-notification guide on this site. A dedicated Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link.
Frequently asked questions
When must you notify a PIPEDA breach of security safeguards?
PIPEDA s. 10.1(1)–(3) and (6): if it is reasonable in the circumstances to believe a breach of security safeguards creates a real risk of significant harm, report to the Commissioner and notify the individual as soon as feasible after the organization determines that the breach has occurred. That phrase is not 72 hours. Last verified 8 September 2026. Not legal advice.
Is this legal advice?
No. It is a Canada PIPEDA jurisdiction guide distilled from PIPEDA ss. 10.1–10.3, SOR/2018-64, OPC materials labelled as OPC guidance, and Quebec P-39.1 ss. 3.5–3.8. Whether PIPEDA applies, whether a breach of security safeguards occurred, whether RROSH exists, and whether 'as soon as feasible' has started are legal questions for counsel on your facts. This page does not start a reporting clock.
Does ShipReady file with the OPC?
No. The signed-in app does not file with the OPC, does not file with the CAI, does not run a RROSH assessment, does not start an 'as soon as feasible' clock, and does not keep a s. 10.3 register. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for findings the org classified as CRA-in-scope — one product tracker, not PIPEDA. The obligation map is frameworks marked in-scope; there is no `pipeda` catalog key. A named human still submits.
Is 'as soon as feasible' the same as GDPR 72 hours?
No. PIPEDA s. 10.1(2) and (6) say as soon as feasible after the organization determines that the breach has occurred. GDPR Article 33(1) says without undue delay and, where feasible, not later than 72 hours after having become aware. This page does not convert 'as soon as feasible' into a number of hours. Filing GDPR does not discharge PIPEDA. Not legal advice.
Do you keep a record even when there is no notice?
Yes, if PIPEDA applies. s. 10.3(1) requires a record of every breach of security safeguards involving personal information under the organization's control. SOR/2018-64 s. 6(1) keeps that record for 24 months after the day the organization determines that the breach has occurred. RROSH is the notice threshold, not the record threshold. The product does not keep that register. Not legal advice.
Does filing with the OPC discharge Quebec Law 25?
No. Quebec's P-39.1 ss. 3.5–3.8 is a different provincial regime: confidentiality incident, risk of serious injury, promptly / avec diligence, Commission d'accès à l'information. PIPEDA RROSH is not that test. Filing OPC does not discharge CAI, and filing CAI does not discharge OPC. Not legal advice.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.