Canadian Privacy
Featured
Part of the PIPEDA guide

Data Breach Notification Canada: Step-by-Step Response Guide for the First 72 Hours

What to do in the first 72 hours of a privacy breach in Canada: contain, assess real risk of significant harm, notify, and record what you did.

Canada Compliance AI• Compliance Team
January 6, 2026
Updated September 15, 2026
17 min read
Data Breach
Breach Notification
PIPEDA
Law 25
Breach Response Plan

When a data breach occurs, every minute counts. With PIPEDA's mandatory breach reporting and Law 25's requirement to notify "promptly", having a tested response plan isn't optional—it's business-critical.

This comprehensive guide walks you through exactly what to do in the first 72 hours after discovering a breach, including assessment frameworks, notification requirements, documentation procedures, and communication templates for Canadian businesses.

Note: The 72-hour structure in this guide is a practical internal response timeline, not a statutory deadline. Where a breach creates a real risk of significant harm, PIPEDA (s. 10.1) requires reporting "as soon as feasible" after you determine the breach occurred; where a confidentiality incident presents a risk of serious injury, Quebec's private sector Act (s. 3.5) requires the enterprise to notify the CAI "promptly". Neither sets a fixed number of hours. (The 72-hour rule is from the EU GDPR, Article 33.)

Understanding Data Breaches Under Canadian Law

What Constitutes a "Breach of Security Safeguards"?

PIPEDA Definition:

"A breach of security safeguards means the loss of, unauthorized access to, or unauthorized disclosure of, personal information resulting from a breach of an organization's security safeguards or from a failure to establish those safeguards."

Three Types of Breaches:

1. Unauthorized Access

  • Hacker gains access to database
  • Employee views records without authorization
  • Third party accesses data improperly
  • Stolen laptop with unencrypted data

2. Unauthorized Disclosure

  • Email sent to wrong recipient
  • Data published publicly by mistake
  • Vendor shares data without authorization
  • Ransomware exfiltration (data stolen)

3. Loss of Personal Information

  • Lost laptop or mobile device
  • Stolen backup tapes
  • Improper disposal (documents not shredded)
  • Cloud misconfiguration exposing data

Canadian Breach Notification Laws Overview

JurisdictionLawThresholdDeadlineRegulator
FederalPIPEDAReal Risk of Significant HarmAs soon as feasible after determining the breach occurred (no fixed hours)OPC
QuebecLaw 25Risk of Serious InjuryPromptly (no fixed hours)CAI
OntarioPHIPA (health)Theft/loss/unauthorized use or disclosureIndividuals at the first reasonable opportunity (s. 12(2)); IPC where prescribed (s. 12(3))IPC
AlbertaPIPAReal Risk of Significant HarmWithout unreasonable delay (s. 34.1)OIPC

Hour 0-1: Initial Breach Discovery

Immediate Actions (First 60 Minutes)

Step 1: Confirm the Breach (5 minutes)

✅ Verify it's actually a breach:

  • Don't panic over false alarms
  • Confirm unauthorized access/disclosure/loss occurred
  • Gather initial details

Questions to Answer:

  • What happened?
  • When did it occur?
  • What systems/data affected?
  • Is it still ongoing?

Step 2: Alert Breach Response Team (10 minutes)

✅ Notify designated personnel:

  • Privacy Officer (lead)
  • IT Security team
  • Legal counsel
  • Executive leadership
  • Communications/PR (if needed)

Step 3: Activate Incident Response Plan (5 minutes)

✅ Retrieve and follow plan:

  • Access breach response documentation
  • Assign roles and responsibilities
  • Set initial response meeting time
  • Begin incident log

Step 4: Preserve Evidence (10 minutes)

✅ Critical for investigation:

  • Don't delete logs
  • Take system snapshots
  • Preserve email evidence
  • Document initial observations

What NOT to do: ❌ Shut down systems impulsively (destroys evidence) ❌ Attempt fixes before documenting ❌ Communicate externally before assessment ❌ Delete anything

Step 5: Initial Documentation (15 minutes)

✅ Start incident log:

BREACH INCIDENT LOG

Incident ID: [YYYY-MM-DD-###]
Discovery Date/Time: [Date] [Time] [Timezone]
Discovered By: [Name, Role]
Discovery Method: [How discovered]

Initial Assessment:
- Systems Affected: [List]
- Data Potentially Affected: [Types]
- Approximate Records: [Estimate]
- Ongoing: [Yes/No]
- Initial Severity: [Low/Medium/High/Critical]

Response Team Activated: [Time]

Hours 1-4: Containment and Assessment

Hour 1: Emergency Response Meeting

Agenda (30 minutes):

  1. Situation Brief (5 minutes) - IT Security presents what's known
  2. Immediate Containment Plan (10 minutes) - Decisions on system isolation
  3. Role Assignments (5 minutes) - Investigation lead, communication coordinator
  4. Initial Assessment (10 minutes) - Severity level, preliminary RROSH assessment

Hours 1-2: Immediate Containment Actions

Technical Containment:

✅ For Unauthorized Access:

  • Isolate affected systems from network
  • Reset all potentially compromised credentials
  • Revoke API keys and access tokens
  • Enable MFA if not already
  • Block attacker IP addresses
  • Close vulnerability (patch, configuration fix)

✅ For Ransomware:

  • Isolate infected systems immediately
  • DO NOT pay ransom (yet - legal advice needed)
  • Disconnect backups to prevent encryption
  • Preserve encrypted systems for forensics
  • Assess if data was exfiltrated (often is)

✅ For Physical Loss (laptop/device):

  • Remote wipe if capability exists
  • Deactivate credentials for that device
  • Monitor for suspicious access
  • Report theft to law enforcement

✅ For Misdirected Email/Disclosure:

  • Recall email if possible (limited success)
  • Contact recipient requesting deletion
  • Document recall attempts

Hours 2-4: Detailed Breach Assessment

Investigation Questions:

What data was affected?

  • Specific databases, files, systems
  • Types of personal information
  • Sensitivity level
  • Number of individuals
  • Geographic location of individuals

Data Sensitivity Assessment:

Data TypeSensitivityPotential Harm
Health recordsCriticalIdentity theft, discrimination, emotional distress
Financial accountsCriticalDirect financial loss, fraud
SIN/PassportCriticalIdentity theft, fraud
Biometric dataCriticalPermanent compromise (can't change)
Credit card (with CVV)HighFinancial fraud
Date of birth + addressHighIdentity theft combination
Name + emailMediumPhishing, spam (lower harm)
Email onlyLowSpam, minimal harm

Engaging External Experts

When to Call External Help:

✅ Immediately call for:

  • Ransomware attacks
  • Sophisticated cyber attacks
  • Large-scale breaches (>10,000 records)
  • Healthcare data breaches
  • Financial data breaches
  • When internal expertise insufficient

Forensic Investigation Firms: Scope the investigation and cost with the firm Legal Counsel (Privacy Specialist): Assess legal obligations, guide notification decisions Cyber Insurance: Notify immediately (coverage requirement)


Hours 4-12: Internal Team Activation

Hour 4: Second Response Meeting

Agenda (45 minutes):

  1. Containment Update (10 minutes) - Breach stopped? Systems secured?
  2. Investigation Findings (15 minutes) - What data affected, how many individuals
  3. RROSH Preliminary Assessment (10 minutes) - Likely meets threshold?
  4. Notification Planning (5 minutes) - OPC/CAI notification timeline
  5. Next 8 Hours Plan (5 minutes) - Investigation tasks

Hours 4-8: Data Inventory

Critical Task: Determine exactly what data was compromised

For each system, document:

System: Customer Database
Tables Accessed: customers, orders, payments
Fields Compromised:
- customer_id
- first_name, last_name
- email, phone
- address (street, city, province, postal)
- date_of_birth
- credit_card_last4

Sensitivity: MEDIUM-HIGH
Records Affected: 47,832 individuals

Hours 8-12: Root Cause Analysis

Common Attack Vectors:

  • Phishing: Employee clicked malicious link/attachment
  • Vulnerability Exploitation: Unpatched software, misconfiguration
  • Stolen Credentials: Password reuse, weak passwords
  • Insider Threat: Malicious or negligent employee
  • Physical Theft: Lost/stolen device
  • Third-Party: Vendor breach affecting your data

Hours 12-24: Risk of Significant Harm Assessment

Understanding RROSH - Real Risk of Significant Harm

PIPEDA Threshold for Mandatory Notification

Must notify if breach creates "real risk of significant harm" to individuals.

Two-Part Test:

1. Real Risk = Probable

  • Not just theoretical possibility
  • Reasonable probability harm will occur

2. Significant Harm = Serious

  • Bodily harm
  • Humiliation
  • Damage to reputation or relationships
  • Loss of employment, business, or professional opportunities
  • Financial loss
  • Identity theft
  • Negative effects on credit record
  • Damage to or loss of property

RROSH Assessment Factors

Factor 1: Sensitivity of Information

  • High Sensitivity: Health, financial, SIN, passport, biometric, children's data
  • Lower Sensitivity: Name and email only, business contact info

Factor 2: Probability of Misuse

  • Higher: Data accessed by malicious actor, published online, sold on dark web
  • Lower: Misdirected email to trusted party (who deleted), lost encrypted device

Factor 3: Nature and Extent

  • Large number of individuals (>1,000) = Higher risk
  • Complete profiles vs. single data element
  • Long-term exposure vs. quick remediation

Factor 4: Individuals' Vulnerability

  • Children, elderly, individuals with disabilities = Higher risk
  • High-profile individuals = Higher risk

RROSH Decision Matrix

ScenarioRROSH?
Lost encrypted laptop, no evidence accessed❌ NO
Phishing attack, email list stolen (name+email)⚠️ MAYBE
Ransomware, customer DB (name+DOB+address+CC)✅ YES
Misdirected email to wrong client (1 person)❌ NO
Health records accessed by ex-employee✅ YES

Key Principle: When in doubt, notify. Over-notification is better than under-notification.


Hours 24-36: OPC Notification Decision (PIPEDA)

If RROSH = YES, Notification Required

Two Required Notifications:

  1. Office of the Privacy Commissioner (OPC)
  2. Affected individuals

OPC Notification Requirements

Deadline: As soon as feasible after the organization determines that the breach has occurred (PIPEDA s. 10.1). Many organizations use 72 hours as an internal target — PIPEDA itself sets no fixed number of hours.

Method: OPC Breach Reporting Portal (online)

Required Information:

  • Organization details and contact person
  • Breach details (dates, circumstances, how it happened)
  • Personal information affected (types, number of individuals, provinces)
  • RROSH assessment explanation
  • Containment steps and notification plan

Notifying Relevant Organizations

Required if organization can reduce risk of harm:

  • Credit card breach: Notify payment card companies (Visa, Mastercard)
  • Banking info breach: Notify banks
  • Email credentials breach: Notify email service providers

Hours 36-48: Individual Notification Preparation

Individual Notification Requirements (PIPEDA)

Who to Notify: All individuals affected by RROSH breach

Deadline: As soon as feasible after determining RROSH

Required Content:

  1. Explanation of Breach - What happened, when it occurred
  2. Personal Information Affected - What types of data compromised
  3. Steps Taken - Contain breach, prevent recurrence, mitigate harm
  4. Potential Harms and Mitigation - What harms are possible, steps individual can take
  5. Contact Information - Privacy Officer contact, toll-free number
  6. Reporting Options - How to contact OPC if not satisfied

Individual Notification Letter Template

[ORGANIZATION LETTERHEAD]

[Date]

IMPORTANT: DATA SECURITY INCIDENT NOTIFICATION

Dear [Name / Valued Customer],

We are writing to inform you of a data security incident that may affect your personal information.

WHAT HAPPENED
On [date], we discovered that [brief description of breach]. We immediately took steps to secure our systems and began an investigation.

WHAT INFORMATION WAS INVOLVED
The personal information that may have been accessed includes:
- [List specific data types]

WHAT WE ARE DOING
We have taken the following steps:
- Secured our systems and closed the vulnerability
- Engaged cybersecurity experts to investigate
- Notified law enforcement
- Reported to the Office of the Privacy Commissioner

WHAT YOU CAN DO
- Monitor your accounts for suspicious activity
- Change passwords on other sites if you use the same password
- Be alert for phishing attempts
- Consider placing a fraud alert on your credit file:
  - Equifax Canada: 1-800-465-7166
  - TransUnion Canada: 1-800-663-9980

FOR MORE INFORMATION
Contact our Privacy Officer:
- Email: privacy@[organization].ca
- Phone: 1-800-[NUMBER]

REPORTING TO PRIVACY COMMISSIONER
If you are not satisfied, you may contact:
- Office of the Privacy Commissioner: 1-800-282-1376 or priv.gc.ca

Sincerely,
[Name, Title]

Hours 48-60: External Notifications (If Required)

Credit Bureaus (If Financial Data Compromised)

Who to contact:

  • Equifax Canada: 1-800-465-7166
  • TransUnion Canada: 1-800-663-9980

Law Enforcement

When to notify:

  • Criminal activity (hacking, theft, fraud)
  • Ransomware attacks
  • Ongoing investigation needed

Who to contact:

  • Local police (for physical theft)
  • RCMP Cybercrime (for sophisticated attacks)
  • Canadian Anti-Fraud Centre: 1-888-495-8501

Insurance Company

When to notify: Immediately

Check whether your cyber insurance policy requires:

  • Notification within a set period
  • Use of approved vendors
  • Cooperation with investigation

Hours 60-72: CAI Notification (Law 25 Quebec — required "promptly"; no fixed number of hours)

Quebec Law 25 Requirements

Key Differences from PIPEDA:

Threshold:

  • Law 25: "Risk of serious injury"
  • PIPEDA: "Real risk of significant harm"

Timing:

  • The CAI must be notified promptly where an incident presents a risk of serious injury (s. 3.5)
  • Law 25 sets no fixed number of hours — the 72-hour rule is GDPR, not Quebec law
  • Affected individuals must also be notified

CAI Notification Requirements

Who must notify: Any organization handling Quebec residents' personal information

Deadline: Promptly (s. 3.5) — no fixed number of hours

Method: CAI online portal

Required Information:

  1. Organization details and contact person
  2. Incident description (date, how discovered, circumstances)
  3. Personal information compromised (types, number affected)
  4. Risk assessment (why "risk of serious injury")
  5. Containment and mitigation steps
  6. Individual notification plan

Penalties for Late/Missing Notification

Failing to report a confidentiality incident to the Commission or to the persons concerned, where required, can lead to an administrative monetary penalty (s. 90.1) of up to $10,000,000 or, if greater, 2% of worldwide turnover for enterprises (s. 90.12), and is also a penal offence (s. 91) carrying fines for enterprises of up to $25,000,000 or, if greater, 4% of worldwide turnover. Source: LégisQuébec, P-39.1.


Post-72-Hour: Investigation and Remediation

Weeks 1-2: Complete Investigation

Forensic Analysis:

  • Complete timeline reconstruction
  • Full scope of data compromised
  • All attack vectors identified
  • Evidence collection and preservation

Final RROSH Assessment:

  • Update with complete information
  • Confirm notification decisions were correct
  • Document any changes

Weeks 2-4: Remediation Implementation

Immediate Fixes:

  • Patch vulnerabilities
  • Close attack vectors
  • Implement compensating controls
  • Enhanced monitoring

Long-term Improvements:

REMEDIATION PLAN

Immediate (Weeks 2-4):
1. Deploy MFA across all systems
2. Implement SIEM monitoring
3. Enhance email filtering
4. Mandatory security training

Short-term (Months 2-3):
5. Third-party security audit
6. Penetration testing
7. Incident response plan update
8. DLP implementation

Long-term (Months 4-6):
9. Zero-trust architecture
10. Enhanced encryption
11. Security awareness program
12. Vendor security review

Month 2: OPC/CAI Follow-up

OPC May Request:

  • Additional information
  • Clarification on RROSH assessment
  • Evidence of notification
  • Remediation plans

Ongoing: Lessons Learned

Conduct Post-Incident Review:

  1. What happened (complete timeline)
  2. What went well
  3. What didn't go well
  4. What we learned
  5. What we'll change

Provincial Variations in Breach Notification

Summary Table

ProvinceLawThresholdRegulatorDeadline
FederalPIPEDARROSHOPCAs soon as feasible (no fixed hours)
QuebecLaw 25Risk of serious injuryCAIPromptly (no fixed hours)
Ontario (Healthcare)PHIPATheft/loss/unauthorized use or disclosureIPCIndividuals at the first reasonable opportunity; IPC where prescribed
AlbertaPIPARROSHOIPCWithout unreasonable delay

Multi-Provincial Breaches

Challenge: Breach affects multiple provinces

Solution: Comply with most stringent requirements

Example:

  • Breach affects customers in Quebec, Ontario, BC
  • Quebec = "promptly" (no fixed clock)
  • Notify: OPC, CAI, IPC (if healthcare)
  • Many organizations treat 72 hours as an internal target for all notifications (a common internal target — PIPEDA and Law 25 set no fixed number of hours)

Best Practice: Treat all Canadian breaches as if Law 25 applies (strictest standard)


Breach Documentation Requirements

What Must Be Documented

All Breaches (Even Below RROSH Threshold):

PIPEDA Requirement:

  • Must keep record of all breaches
  • 24-month retention minimum
  • Available for OPC inspection

Law 25 Requirement:

Breach Record Contents

BREACH RECORD

Incident ID: [Unique identifier]
Discovery Date: [Date/time]
Occurrence Date: [Date/time if known]

1. DESCRIPTION
   - Circumstances of breach
   - How discovered
   - Type: [Unauthorized access / Disclosure / Loss]

2. PERSONAL INFORMATION AFFECTED
   - Data types
   - Sensitivity
   - Number of individuals
   - Provinces/countries

3. RROSH ASSESSMENT
   - Assessment performed: [Date]
   - Assessors: [Names]
   - Conclusion: [Yes/No]
   - Rationale: [Summary]

4. NOTIFICATIONS MADE
   - OPC: [Yes/No] [Date]
   - CAI: [Yes/No] [Date]
   - Individuals: [Yes/No] [Date] [Method]
   - Others: [List]

5. CONTAINMENT AND REMEDIATION
   - Containment date: [Date]
   - Containment actions: [Summary]
   - Remediation plan: [Reference]
   - Completion date: [Date]

6. LESSONS LEARNED
   - Root cause: [Summary]
   - Preventive measures: [List]

How Automation Speeds Breach Response

Breach Response Automation Tools

1. Automated Detection (SIEM)

  • Real-time threat detection
  • Automated alerting

2. Incident Response Orchestration

  • Automated team notification
  • Workflow triggering
  • Evidence collection automation
  • Timeline tracking

3. RROSH Assessment Automation

  • Guided assessment questionnaire
  • Automated risk scoring
  • Jurisdiction-specific logic (PIPEDA, Law 25)
  • Documentation generation

4. Notification Automation

  • Template library (jurisdiction-specific)
  • Mail merge for individual notifications
  • Multi-channel deployment (email, mail, SMS)
  • Tracking and confirmation

Frequently Asked Questions

Q: What if we can't determine the exact number of individuals affected within 72 hours? Provide your best estimate to regulators with explanation of uncertainty. Update them once exact count is known. Don't delay notification waiting for perfect count.

Q: Can we wait to notify individuals until after we notify the OPC/CAI? You should notify regulators first (or simultaneously), but don't delay individual notification significantly. Aim for individuals within 1-2 days of regulator notification.

Q: What if some data was encrypted but the encryption key was also compromised? Treat as if data was not encrypted. Encryption only mitigates if key remains secure.

Q: Do we need to notify for every minor incident? No. Only breaches meeting RROSH (PIPEDA) or risk of serious injury (Law 25) require notification. But ALL breaches must be documented in breach register.

Q: What if CAI notification is delayed? Notify immediately with explanation for delay. Document reason for delay.

Q: Can we use indirect notification (public notice) instead of individual notification? Under PIPEDA, only in the circumstances set out in the Breach of Security Safeguards Regulations, s. 5: direct notification would be likely to cause further harm to the individual, would be likely to cause undue hardship for the organization, or you have no contact information for the individual. Otherwise, notification must be direct.

Q: What if the breach only affected encrypted backup tapes that were lost? If encryption is strong and no evidence tapes accessed, likely no RROSH. But must assess based on encryption strength, key security, and circumstances.

Q: What if we're not sure if personal information was actually accessed in a hack? Err on side of caution. If attacker had access to systems containing personal information, presume they accessed it unless evidence proves otherwise.


Prepare Your Breach Response Today

The time to prepare for a breach is before it happens.

Key Takeaways

✅ First Hour: Confirm breach, alert team, preserve evidence, document everything ✅ Hours 1-4: Contain breach, assess scope, engage experts if needed ✅ Hours 4-12: Inventory data, analyze root cause, prepare RROSH assessment ✅ Hours 12-24: Complete RROSH assessment, make notification decision ✅ Hours 24-72: Notify OPC, CAI (Quebec), prepare individual notifications (internal target — the legal standards are "as soon as feasible" under PIPEDA and "promptly" under Law 25) ✅ Post-72: Complete investigation, remediate, conduct lessons learned

Related Articles


About Canada Compliance AI

We help Canadian businesses prepare for and respond to data breaches with automated tools, guided workflows, and expert support. Our breach response module includes 72-hour internal-target countdown tracking, RROSH assessment automation, and multi-jurisdiction notification management.

Last Updated: January 6, 2026 Next Review: April 2026

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.