Organizations must report breach details in writing, notify affected individuals with specific content, keep breach records for 24 months, and may use secure communication or send later updates.
Breach of Security Safeguards Regulations Her Excellency the Governor General in Council, on the recommendation of the Minister of Industry, pursuant to subsection 26(1)a of the Personal Information Protection and Electronic Documents Actb, makes the annexed Breach of Security Safeguards Regulations. S.C. 2015, c. 32, s. 21 S.C. 2000, c. 5 Definition of Act In these Regulations, Act means the Personal Information Protection and Electronic Documents Act. Report — content, form and manner A report of a breach of security safeguards referred to in subsection 10.1(2) of the Act must be in writing and must contain a description of the circumstances of the breach and, if known, the cause; the day on which, or the period during which, the breach occurred or, if neither is known, the approximate period; a description of the personal information that is the subject of the breach to the extent that the information is known; the number of individuals affected by the breach or, if unknown, the approximate number; a description of the steps that the organization has taken to reduce the risk of harm to affected individuals that could result from the breach or to mitigate that harm; a description of the steps that the organization has taken or intends to take to notify affected individuals of the breach in accordance with subsection 10.1(3) of the Act; and the name and contact information of a person who can answer, on behalf of the organization, the Commissioner’s questions about the breach. New information An organization may submit to the Commissioner any new information referred to in subsection (1) that the organization becomes aware of after having made the report. Means of communication The report may be sent to the Commissioner by any secure means of communication. Contents of notification A notification provided by an organization, in accordance with subsection 10.1(3) of the Act, to an affected individual with respect to a breach of security safeguards must contain a description of the circumstances of the breach; the day on which, or period during which, the breach occurred or, if neither is known, the approximate period; a description of the steps that the organization has taken to reduce the risk of harm that could result from the breach; a description of the steps that affected individuals could take to reduce the risk of harm that could result from the breach or to mitigate that harm; and contact information that the affected individual can use to obtain further information about the breach. Direct notification — form and manner For the purposes of subsection 10.1(5) of the Act, direct notification must be given to the affected individual in person, by telephone, mail, email or any other form of communication that a reasonable person would consider appropriate in the circumstances. Indirect notification — circumstances For the purposes of subsection 10.1(5) of the Act, indirect notification must be given by an organization in any of the following circumstances: direct notification would be likely to cause further harm to the affected individual; direct notification would be likely to cause undue hardship for the organization; or the organization does not have contact information for the affected individual. Indirect notification — form and manner For the purposes of subsection 10.1(5) of the Act, indirect notification must be given by public communication or similar measure that could reasonably be expected to reach the affected individuals. Record-keeping requirements For the purposes of subsection 10.3(1) of the Act, an organization must maintain a record of every breach of security safeguards for 24 months after the day on which the organization determines that the breach has occurred. Compliance The record referred to in subsection 10.3(1) of the Act must contain any information that enables the Commissioner to verify compliance with subsections 10.1(1) and (3) of the Act. S.C. 2015, c. 32 These Regulations come into force on the day on which section 10 of the Digital Privacy Act comes into force, but if they are registered after that day, they come into force on the day on which they are registered. [Note: Regulations in force November 1, 2018, see SI/2018-32.]