Data Breach Notification Canada: Step-by-Step Response Guide for the First 72 Hours
What to do in the first 72 hours of a privacy breach in Canada: contain, assess real risk of significant harm, notify, and record what you did.
When a data breach occurs, every minute counts. With PIPEDA's mandatory breach reporting and Law 25's requirement to notify "promptly", having a tested response plan isn't optional—it's business-critical.
This comprehensive guide walks you through exactly what to do in the first 72 hours after discovering a breach, including assessment frameworks, notification requirements, documentation procedures, and communication templates for Canadian businesses.
Note: The 72-hour structure in this guide is a practical internal response timeline, not a statutory deadline. Where a breach creates a real risk of significant harm, PIPEDA (s. 10.1) requires reporting "as soon as feasible" after you determine the breach occurred; where a confidentiality incident presents a risk of serious injury, Quebec's private sector Act (s. 3.5) requires the enterprise to notify the CAI "promptly". Neither sets a fixed number of hours. (The 72-hour rule is from the EU GDPR, Article 33.)
Understanding Data Breaches Under Canadian Law
What Constitutes a "Breach of Security Safeguards"?
PIPEDA Definition:
"A breach of security safeguards means the loss of, unauthorized access to, or unauthorized disclosure of, personal information resulting from a breach of an organization's security safeguards or from a failure to establish those safeguards."
Three Types of Breaches:
1. Unauthorized Access
- Hacker gains access to database
- Employee views records without authorization
- Third party accesses data improperly
- Stolen laptop with unencrypted data
2. Unauthorized Disclosure
- Email sent to wrong recipient
- Data published publicly by mistake
- Vendor shares data without authorization
- Ransomware exfiltration (data stolen)
3. Loss of Personal Information
- Lost laptop or mobile device
- Stolen backup tapes
- Improper disposal (documents not shredded)
- Cloud misconfiguration exposing data
Canadian Breach Notification Laws Overview
| Jurisdiction | Law | Threshold | Deadline | Regulator |
|---|---|---|---|---|
| Federal | PIPEDA | Real Risk of Significant Harm | As soon as feasible after determining the breach occurred (no fixed hours) | OPC |
| Quebec | Law 25 | Risk of Serious Injury | Promptly (no fixed hours) | CAI |
| Ontario | PHIPA (health) | Theft/loss/unauthorized use or disclosure | Individuals at the first reasonable opportunity (s. 12(2)); IPC where prescribed (s. 12(3)) | IPC |
| Alberta | PIPA | Real Risk of Significant Harm | Without unreasonable delay (s. 34.1) | OIPC |
Hour 0-1: Initial Breach Discovery
Immediate Actions (First 60 Minutes)
Step 1: Confirm the Breach (5 minutes)
✅ Verify it's actually a breach:
- Don't panic over false alarms
- Confirm unauthorized access/disclosure/loss occurred
- Gather initial details
Questions to Answer:
- What happened?
- When did it occur?
- What systems/data affected?
- Is it still ongoing?
Step 2: Alert Breach Response Team (10 minutes)
✅ Notify designated personnel:
- Privacy Officer (lead)
- IT Security team
- Legal counsel
- Executive leadership
- Communications/PR (if needed)
Step 3: Activate Incident Response Plan (5 minutes)
✅ Retrieve and follow plan:
- Access breach response documentation
- Assign roles and responsibilities
- Set initial response meeting time
- Begin incident log
Step 4: Preserve Evidence (10 minutes)
✅ Critical for investigation:
- Don't delete logs
- Take system snapshots
- Preserve email evidence
- Document initial observations
What NOT to do: ❌ Shut down systems impulsively (destroys evidence) ❌ Attempt fixes before documenting ❌ Communicate externally before assessment ❌ Delete anything
Step 5: Initial Documentation (15 minutes)
✅ Start incident log:
BREACH INCIDENT LOG
Incident ID: [YYYY-MM-DD-###]
Discovery Date/Time: [Date] [Time] [Timezone]
Discovered By: [Name, Role]
Discovery Method: [How discovered]
Initial Assessment:
- Systems Affected: [List]
- Data Potentially Affected: [Types]
- Approximate Records: [Estimate]
- Ongoing: [Yes/No]
- Initial Severity: [Low/Medium/High/Critical]
Response Team Activated: [Time]
Hours 1-4: Containment and Assessment
Hour 1: Emergency Response Meeting
Agenda (30 minutes):
- Situation Brief (5 minutes) - IT Security presents what's known
- Immediate Containment Plan (10 minutes) - Decisions on system isolation
- Role Assignments (5 minutes) - Investigation lead, communication coordinator
- Initial Assessment (10 minutes) - Severity level, preliminary RROSH assessment
Hours 1-2: Immediate Containment Actions
Technical Containment:
✅ For Unauthorized Access:
- Isolate affected systems from network
- Reset all potentially compromised credentials
- Revoke API keys and access tokens
- Enable MFA if not already
- Block attacker IP addresses
- Close vulnerability (patch, configuration fix)
✅ For Ransomware:
- Isolate infected systems immediately
- DO NOT pay ransom (yet - legal advice needed)
- Disconnect backups to prevent encryption
- Preserve encrypted systems for forensics
- Assess if data was exfiltrated (often is)
✅ For Physical Loss (laptop/device):
- Remote wipe if capability exists
- Deactivate credentials for that device
- Monitor for suspicious access
- Report theft to law enforcement
✅ For Misdirected Email/Disclosure:
- Recall email if possible (limited success)
- Contact recipient requesting deletion
- Document recall attempts
Hours 2-4: Detailed Breach Assessment
Investigation Questions:
What data was affected?
- Specific databases, files, systems
- Types of personal information
- Sensitivity level
- Number of individuals
- Geographic location of individuals
Data Sensitivity Assessment:
| Data Type | Sensitivity | Potential Harm |
|---|---|---|
| Health records | Critical | Identity theft, discrimination, emotional distress |
| Financial accounts | Critical | Direct financial loss, fraud |
| SIN/Passport | Critical | Identity theft, fraud |
| Biometric data | Critical | Permanent compromise (can't change) |
| Credit card (with CVV) | High | Financial fraud |
| Date of birth + address | High | Identity theft combination |
| Name + email | Medium | Phishing, spam (lower harm) |
| Email only | Low | Spam, minimal harm |
Engaging External Experts
When to Call External Help:
✅ Immediately call for:
- Ransomware attacks
- Sophisticated cyber attacks
- Large-scale breaches (>10,000 records)
- Healthcare data breaches
- Financial data breaches
- When internal expertise insufficient
Forensic Investigation Firms: Scope the investigation and cost with the firm Legal Counsel (Privacy Specialist): Assess legal obligations, guide notification decisions Cyber Insurance: Notify immediately (coverage requirement)
Hours 4-12: Internal Team Activation
Hour 4: Second Response Meeting
Agenda (45 minutes):
- Containment Update (10 minutes) - Breach stopped? Systems secured?
- Investigation Findings (15 minutes) - What data affected, how many individuals
- RROSH Preliminary Assessment (10 minutes) - Likely meets threshold?
- Notification Planning (5 minutes) - OPC/CAI notification timeline
- Next 8 Hours Plan (5 minutes) - Investigation tasks
Hours 4-8: Data Inventory
Critical Task: Determine exactly what data was compromised
For each system, document:
System: Customer Database
Tables Accessed: customers, orders, payments
Fields Compromised:
- customer_id
- first_name, last_name
- email, phone
- address (street, city, province, postal)
- date_of_birth
- credit_card_last4
Sensitivity: MEDIUM-HIGH
Records Affected: 47,832 individuals
Hours 8-12: Root Cause Analysis
Common Attack Vectors:
- Phishing: Employee clicked malicious link/attachment
- Vulnerability Exploitation: Unpatched software, misconfiguration
- Stolen Credentials: Password reuse, weak passwords
- Insider Threat: Malicious or negligent employee
- Physical Theft: Lost/stolen device
- Third-Party: Vendor breach affecting your data
Hours 12-24: Risk of Significant Harm Assessment
Understanding RROSH - Real Risk of Significant Harm
PIPEDA Threshold for Mandatory Notification
Must notify if breach creates "real risk of significant harm" to individuals.
Two-Part Test:
1. Real Risk = Probable
- Not just theoretical possibility
- Reasonable probability harm will occur
2. Significant Harm = Serious
- Bodily harm
- Humiliation
- Damage to reputation or relationships
- Loss of employment, business, or professional opportunities
- Financial loss
- Identity theft
- Negative effects on credit record
- Damage to or loss of property
RROSH Assessment Factors
Factor 1: Sensitivity of Information
- High Sensitivity: Health, financial, SIN, passport, biometric, children's data
- Lower Sensitivity: Name and email only, business contact info
Factor 2: Probability of Misuse
- Higher: Data accessed by malicious actor, published online, sold on dark web
- Lower: Misdirected email to trusted party (who deleted), lost encrypted device
Factor 3: Nature and Extent
- Large number of individuals (>1,000) = Higher risk
- Complete profiles vs. single data element
- Long-term exposure vs. quick remediation
Factor 4: Individuals' Vulnerability
- Children, elderly, individuals with disabilities = Higher risk
- High-profile individuals = Higher risk
RROSH Decision Matrix
| Scenario | RROSH? |
|---|---|
| Lost encrypted laptop, no evidence accessed | ❌ NO |
| Phishing attack, email list stolen (name+email) | ⚠️ MAYBE |
| Ransomware, customer DB (name+DOB+address+CC) | ✅ YES |
| Misdirected email to wrong client (1 person) | ❌ NO |
| Health records accessed by ex-employee | ✅ YES |
Key Principle: When in doubt, notify. Over-notification is better than under-notification.
Hours 24-36: OPC Notification Decision (PIPEDA)
If RROSH = YES, Notification Required
Two Required Notifications:
- Office of the Privacy Commissioner (OPC)
- Affected individuals
OPC Notification Requirements
Deadline: As soon as feasible after the organization determines that the breach has occurred (PIPEDA s. 10.1). Many organizations use 72 hours as an internal target — PIPEDA itself sets no fixed number of hours.
Method: OPC Breach Reporting Portal (online)
Required Information:
- Organization details and contact person
- Breach details (dates, circumstances, how it happened)
- Personal information affected (types, number of individuals, provinces)
- RROSH assessment explanation
- Containment steps and notification plan
Notifying Relevant Organizations
Required if organization can reduce risk of harm:
- Credit card breach: Notify payment card companies (Visa, Mastercard)
- Banking info breach: Notify banks
- Email credentials breach: Notify email service providers
Hours 36-48: Individual Notification Preparation
Individual Notification Requirements (PIPEDA)
Who to Notify: All individuals affected by RROSH breach
Deadline: As soon as feasible after determining RROSH
Required Content:
- Explanation of Breach - What happened, when it occurred
- Personal Information Affected - What types of data compromised
- Steps Taken - Contain breach, prevent recurrence, mitigate harm
- Potential Harms and Mitigation - What harms are possible, steps individual can take
- Contact Information - Privacy Officer contact, toll-free number
- Reporting Options - How to contact OPC if not satisfied
Individual Notification Letter Template
[ORGANIZATION LETTERHEAD]
[Date]
IMPORTANT: DATA SECURITY INCIDENT NOTIFICATION
Dear [Name / Valued Customer],
We are writing to inform you of a data security incident that may affect your personal information.
WHAT HAPPENED
On [date], we discovered that [brief description of breach]. We immediately took steps to secure our systems and began an investigation.
WHAT INFORMATION WAS INVOLVED
The personal information that may have been accessed includes:
- [List specific data types]
WHAT WE ARE DOING
We have taken the following steps:
- Secured our systems and closed the vulnerability
- Engaged cybersecurity experts to investigate
- Notified law enforcement
- Reported to the Office of the Privacy Commissioner
WHAT YOU CAN DO
- Monitor your accounts for suspicious activity
- Change passwords on other sites if you use the same password
- Be alert for phishing attempts
- Consider placing a fraud alert on your credit file:
- Equifax Canada: 1-800-465-7166
- TransUnion Canada: 1-800-663-9980
FOR MORE INFORMATION
Contact our Privacy Officer:
- Email: privacy@[organization].ca
- Phone: 1-800-[NUMBER]
REPORTING TO PRIVACY COMMISSIONER
If you are not satisfied, you may contact:
- Office of the Privacy Commissioner: 1-800-282-1376 or priv.gc.ca
Sincerely,
[Name, Title]
Hours 48-60: External Notifications (If Required)
Credit Bureaus (If Financial Data Compromised)
Who to contact:
- Equifax Canada: 1-800-465-7166
- TransUnion Canada: 1-800-663-9980
Law Enforcement
When to notify:
- Criminal activity (hacking, theft, fraud)
- Ransomware attacks
- Ongoing investigation needed
Who to contact:
- Local police (for physical theft)
- RCMP Cybercrime (for sophisticated attacks)
- Canadian Anti-Fraud Centre: 1-888-495-8501
Insurance Company
When to notify: Immediately
Check whether your cyber insurance policy requires:
- Notification within a set period
- Use of approved vendors
- Cooperation with investigation
Hours 60-72: CAI Notification (Law 25 Quebec — required "promptly"; no fixed number of hours)
Quebec Law 25 Requirements
Key Differences from PIPEDA:
Threshold:
- Law 25: "Risk of serious injury"
- PIPEDA: "Real risk of significant harm"
Timing:
- The CAI must be notified promptly where an incident presents a risk of serious injury (s. 3.5)
- Law 25 sets no fixed number of hours — the 72-hour rule is GDPR, not Quebec law
- Affected individuals must also be notified
CAI Notification Requirements
Who must notify: Any organization handling Quebec residents' personal information
Deadline: Promptly (s. 3.5) — no fixed number of hours
Method: CAI online portal
Required Information:
- Organization details and contact person
- Incident description (date, how discovered, circumstances)
- Personal information compromised (types, number affected)
- Risk assessment (why "risk of serious injury")
- Containment and mitigation steps
- Individual notification plan
Penalties for Late/Missing Notification
Failing to report a confidentiality incident to the Commission or to the persons concerned, where required, can lead to an administrative monetary penalty (s. 90.1) of up to $10,000,000 or, if greater, 2% of worldwide turnover for enterprises (s. 90.12), and is also a penal offence (s. 91) carrying fines for enterprises of up to $25,000,000 or, if greater, 4% of worldwide turnover. Source: LégisQuébec, P-39.1.
Post-72-Hour: Investigation and Remediation
Weeks 1-2: Complete Investigation
Forensic Analysis:
- Complete timeline reconstruction
- Full scope of data compromised
- All attack vectors identified
- Evidence collection and preservation
Final RROSH Assessment:
- Update with complete information
- Confirm notification decisions were correct
- Document any changes
Weeks 2-4: Remediation Implementation
Immediate Fixes:
- Patch vulnerabilities
- Close attack vectors
- Implement compensating controls
- Enhanced monitoring
Long-term Improvements:
REMEDIATION PLAN
Immediate (Weeks 2-4):
1. Deploy MFA across all systems
2. Implement SIEM monitoring
3. Enhance email filtering
4. Mandatory security training
Short-term (Months 2-3):
5. Third-party security audit
6. Penetration testing
7. Incident response plan update
8. DLP implementation
Long-term (Months 4-6):
9. Zero-trust architecture
10. Enhanced encryption
11. Security awareness program
12. Vendor security review
Month 2: OPC/CAI Follow-up
OPC May Request:
- Additional information
- Clarification on RROSH assessment
- Evidence of notification
- Remediation plans
Ongoing: Lessons Learned
Conduct Post-Incident Review:
- What happened (complete timeline)
- What went well
- What didn't go well
- What we learned
- What we'll change
Provincial Variations in Breach Notification
Summary Table
| Province | Law | Threshold | Regulator | Deadline |
|---|---|---|---|---|
| Federal | PIPEDA | RROSH | OPC | As soon as feasible (no fixed hours) |
| Quebec | Law 25 | Risk of serious injury | CAI | Promptly (no fixed hours) |
| Ontario (Healthcare) | PHIPA | Theft/loss/unauthorized use or disclosure | IPC | Individuals at the first reasonable opportunity; IPC where prescribed |
| Alberta | PIPA | RROSH | OIPC | Without unreasonable delay |
Multi-Provincial Breaches
Challenge: Breach affects multiple provinces
Solution: Comply with most stringent requirements
Example:
- Breach affects customers in Quebec, Ontario, BC
- Quebec = "promptly" (no fixed clock)
- Notify: OPC, CAI, IPC (if healthcare)
- Many organizations treat 72 hours as an internal target for all notifications (a common internal target — PIPEDA and Law 25 set no fixed number of hours)
Best Practice: Treat all Canadian breaches as if Law 25 applies (strictest standard)
Breach Documentation Requirements
What Must Be Documented
All Breaches (Even Below RROSH Threshold):
PIPEDA Requirement:
- Must keep record of all breaches
- 24-month retention minimum
- Available for OPC inspection
Law 25 Requirement:
- Breach register mandatory
- All confidentiality incidents documented (no threshold) (s. 3.8)
- Kept at least 5 years after becoming aware of the incident (Regulation respecting confidentiality incidents, s. 8)
Breach Record Contents
BREACH RECORD
Incident ID: [Unique identifier]
Discovery Date: [Date/time]
Occurrence Date: [Date/time if known]
1. DESCRIPTION
- Circumstances of breach
- How discovered
- Type: [Unauthorized access / Disclosure / Loss]
2. PERSONAL INFORMATION AFFECTED
- Data types
- Sensitivity
- Number of individuals
- Provinces/countries
3. RROSH ASSESSMENT
- Assessment performed: [Date]
- Assessors: [Names]
- Conclusion: [Yes/No]
- Rationale: [Summary]
4. NOTIFICATIONS MADE
- OPC: [Yes/No] [Date]
- CAI: [Yes/No] [Date]
- Individuals: [Yes/No] [Date] [Method]
- Others: [List]
5. CONTAINMENT AND REMEDIATION
- Containment date: [Date]
- Containment actions: [Summary]
- Remediation plan: [Reference]
- Completion date: [Date]
6. LESSONS LEARNED
- Root cause: [Summary]
- Preventive measures: [List]
How Automation Speeds Breach Response
Breach Response Automation Tools
1. Automated Detection (SIEM)
- Real-time threat detection
- Automated alerting
2. Incident Response Orchestration
- Automated team notification
- Workflow triggering
- Evidence collection automation
- Timeline tracking
3. RROSH Assessment Automation
- Guided assessment questionnaire
- Automated risk scoring
- Jurisdiction-specific logic (PIPEDA, Law 25)
- Documentation generation
4. Notification Automation
- Template library (jurisdiction-specific)
- Mail merge for individual notifications
- Multi-channel deployment (email, mail, SMS)
- Tracking and confirmation
Frequently Asked Questions
Q: What if we can't determine the exact number of individuals affected within 72 hours? Provide your best estimate to regulators with explanation of uncertainty. Update them once exact count is known. Don't delay notification waiting for perfect count.
Q: Can we wait to notify individuals until after we notify the OPC/CAI? You should notify regulators first (or simultaneously), but don't delay individual notification significantly. Aim for individuals within 1-2 days of regulator notification.
Q: What if some data was encrypted but the encryption key was also compromised? Treat as if data was not encrypted. Encryption only mitigates if key remains secure.
Q: Do we need to notify for every minor incident? No. Only breaches meeting RROSH (PIPEDA) or risk of serious injury (Law 25) require notification. But ALL breaches must be documented in breach register.
Q: What if CAI notification is delayed? Notify immediately with explanation for delay. Document reason for delay.
Q: Can we use indirect notification (public notice) instead of individual notification? Under PIPEDA, only in the circumstances set out in the Breach of Security Safeguards Regulations, s. 5: direct notification would be likely to cause further harm to the individual, would be likely to cause undue hardship for the organization, or you have no contact information for the individual. Otherwise, notification must be direct.
Q: What if the breach only affected encrypted backup tapes that were lost? If encryption is strong and no evidence tapes accessed, likely no RROSH. But must assess based on encryption strength, key security, and circumstances.
Q: What if we're not sure if personal information was actually accessed in a hack? Err on side of caution. If attacker had access to systems containing personal information, presume they accessed it unless evidence proves otherwise.
Prepare Your Breach Response Today
The time to prepare for a breach is before it happens.
Key Takeaways
✅ First Hour: Confirm breach, alert team, preserve evidence, document everything ✅ Hours 1-4: Contain breach, assess scope, engage experts if needed ✅ Hours 4-12: Inventory data, analyze root cause, prepare RROSH assessment ✅ Hours 12-24: Complete RROSH assessment, make notification decision ✅ Hours 24-72: Notify OPC, CAI (Quebec), prepare individual notifications (internal target — the legal standards are "as soon as feasible" under PIPEDA and "promptly" under Law 25) ✅ Post-72: Complete investigation, remediate, conduct lessons learned
Related Articles
- PIPEDA Compliance Checklist 2026
- Quebec Law 25 Penalties: Maximum Fines and How Penalties Are Set
- Privacy Officer Requirements in Canada
- Cross-Border Data Transfers: US Cloud Storage
About Canada Compliance AI
We help Canadian businesses prepare for and respond to data breaches with automated tools, guided workflows, and expert support. Our breach response module includes 72-hour internal-target countdown tracking, RROSH assessment automation, and multi-jurisdiction notification management.
Last Updated: January 6, 2026 Next Review: April 2026
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Cross-Border Data Transfers: How Canadian Businesses Can Legally Store Data in US Cloud Servers
Sending personal information outside Canada: what PIPEDA requires of transfers, what Quebec Law 25 a...
Privacy Officer Requirements in Canada: Do You Need One? (Province-by-Province Guide)
Who must appoint a privacy officer in Canada, what the role is accountable for under PIPEDA and Law ...