A Canadian business discovers that an employee emailed a spreadsheet of customer records to the wrong address. It contains names and order histories, nothing financial. Management concludes, reasonably, that this does not warrant telling a regulator. They are probably right about reporting and almost certainly wrong about their obligations, because the duty they just engaged was not the duty to report.

Key Takeaway

PIPEDA requires organizations to report breaches of security safeguards to the Privacy Commissioner and notify affected individuals where there is a real risk of significant harm, and separately to keep records of all breaches regardless of whether that threshold is met, for 24 months, in sufficient detail for the OPC to verify compliance. Where a breach was not reported, the OPC states the record should include a brief explanation of why the threshold was determined not to be met. Quebec's Law 25 has applied since September 22, 2022 using a different concept, the confidentiality incident, and a different threshold, risk of serious injury, with a register of all incidents retained for five years. Alberta's PIPA has required mandatory reporting since 2010. Routing depends on where affected individuals reside rather than where the business operates, and the penalty gap is extreme: PIPEDA's section 28 offences reach $100,000 per offence while Quebec's administrative monetary penalties reach the greater of $10 million or 2% of worldwide turnover.

The Inversion

The organising insight of this article is that the reporting threshold and the compliance obligation are different things, and businesses conflate them.

PIPEDA requires an organization to report to the OPC any privacy breaches that pose a real risk of significant harm to an individual, notify affected individuals and relevant third parties of such breaches, and keep records of all breaches, regardless of whether they present a real risk of significant harm[1].

The third duty is unconditional. It is not triggered by severity, it does not depend on any assessment, and it applies to every incident the organization becomes aware of. One commentary draws the operational conclusion precisely: if your incident log only contains the big breaches, your process is already weaker than it needs to be[2].

Sharpen that. A log containing only serious breaches is not merely incomplete evidence of compliance. It is affirmative evidence of non-compliance, because it demonstrates that minor incidents were occurring and not being recorded. An organization that has never logged a misdirected email, a lost laptop or a mistaken disclosure is describing either an implausible operational record or a failure of the record-keeping duty.

That is the inversion. Most businesses treat the log as the by-product of the reporting decision. The statute treats the log as the primary continuous obligation and reporting as the exception triggered within it.

What Counts As A Breach

The definition is broader than the word suggests, and breadth is where most under-recording originates.

A privacy breach occurs when there is a loss, unauthorized access to, use or disclosure of personal information[1].

Four verbs, only one of which describes what people picture when they hear "data breach."

Loss covers a misplaced device, a missing file, a destroyed record. No attacker required. Unauthorized access covers an employee viewing records they had no business reason to see, which is an internal event with no external actor. Unauthorized use covers personal information being used for a purpose outside what was authorised. Unauthorized disclosure covers the misdirected email, the document left visible, the file shared with the wrong recipient.

The population of qualifying incidents in any organization handling personal information is therefore considerably larger than the population of incidents most organizations would describe as breaches. An employee accessing a colleague's file out of curiosity is a breach. A courier losing a package of documents is a breach. Sending a client's statement to another client is a breach.

Each of those must be recorded, and only some must be reported. A business that calibrates its record-keeping to its intuitive sense of what counts as a breach will systematically under-record, and the under-recording is itself the contravention.

The Four Duties

Set out separately, because they have different triggers and are frequently collapsed into one.

Report to the OPC. Required where the breach poses a real risk of significant harm[1].

Notify affected individuals. Required on the same threshold[1].

Notify third parties. Where the organization determines it must notify individuals, it must also notify any other organization or public body, such as law enforcement, that may be able to reduce or mitigate the risk[3]. The OPC frames this as notifying other organizations or government institutions if they may help reduce the risk of harm[4].

Keep records. Required for all breaches, whether or not they meet the threshold, for 24 months, in sufficient detail to enable the OPC to verify that the organization has complied with the mandatory reporting requirements[3]. The OPC can request access to, or a copy of, breach records, which must contain enough detail to allow it to determine whether the organization has properly assessed the risk of harm and met its obligations[1].

Note what the fourth duty makes possible. The OPC does not need to learn of a breach from the organization's report, from a complainant, or from the press. It can ask to see the log, and the log is required to be complete.

The RROSH Threshold

The test that determines whether the reporting duties engage.

Under PIPEDA, an organization must report to the OPC and notify affected individuals if it is reasonable to believe the breach creates a real risk of significant harm[2]. One source characterises the assessment operationally as determining the sensitivity of the data and the probability of misuse, offering the example that a leaked password database is an immediate RROSH[5].

Two components have to be satisfied together. The harm must be significant, which speaks to what could happen to the individual. And the risk of it must be real, which speaks to likelihood rather than theoretical possibility. A highly sensitive dataset disclosed to a party with no capacity or motive to misuse it, and recovered promptly, may fail the second limb even though it plainly satisfies the first.

The commentary emphasises that this demands process rather than judgment in the moment: an organization needs a disciplined threshold determination process, not just general incident activity[2].

Our view, and it follows from the record-keeping duty rather than from the threshold itself, is that the determination should be documented on a consistent framework applied to every incident. Consistency matters more than sophistication here, because the OPC's review is of whether the organization properly assessed the risk, and an assessment that varies in structure from incident to incident is difficult to defend as a process at all.

The Record Of A Decision Not To Report

The single most under-appreciated requirement in the Canadian regime, and the reason this article is titled as it is.

The OPC states that if the breach was not reported and individuals were not notified, the record also should include a brief explanation of why it was determined that the risk threshold was not met[3].

Read that carefully. The decision not to report is not the end of the matter; it is itself a documented, auditable act. The organization must record the incident, record its assessment, and record its reasoning for concluding the threshold was not crossed.

Three consequences follow, and together they change how an incident process should be designed.

The reasoning must exist at the time. An explanation reconstructed months later, when the OPC requests records, is weaker evidence and may be impossible to produce accurately if the relevant facts were never captured.

The reasoning must be defensible. Recording "not significant" is not an explanation. What was the information, who received it, was it recovered, what could plausibly be done with it, and why does that not amount to a real risk of significant harm.

And a pattern of borderline calls all resolving in the organization's favour, each thinly reasoned, is visible in a way that no individual call would be. The log aggregates the judgment calls, which is precisely what makes it valuable to a regulator assessing whether an organization is genuinely applying a threshold or routinely finding reasons not to report.

As Soon As Feasible

The timing standard, and a practical point that is frequently misunderstood in a way that causes delay.

PIPEDA guidance requires that individuals be notified as soon as feasible after the organization has determined that a breach with real risk of significant harm has occurred[2]. One source reports that the OPC expects reports within days to a few weeks rather than months, and states plainly that an organization does not need to complete its full investigation before reporting, but should submit what it knows and update as more information becomes available[6].

That last point matters because the instinct in most organizations runs the other way. Faced with an incomplete picture, management wants to establish the facts before contacting a regulator, both to avoid alarming anyone unnecessarily and to avoid saying something that later proves wrong. That instinct produces delay, and delay is itself a compliance failure independent of the underlying breach.

The clock also has a specific starting point. The obligation runs from determining that a qualifying breach occurred, not from the breach itself, which means the assessment step is inside the timeline rather than before it. An organization that takes six weeks to assess an incident has not preserved its position by declining to start the clock.

For Quebec, one source reports that the CAI expects notification within days[6], and the statutory language is that notification must be prompt[7].

The Duty Nobody Remembers

The third notification obligation, which is easy to overlook because it is conditional on the second.

Where an organization determines it must notify individuals, it must also notify any other organization or public body that may be able to reduce or mitigate the risk[3].

The category is defined by capability rather than by relationship. Candidates include law enforcement where criminal activity is suspected, a payment processor or financial institution that could monitor or block compromised payment credentials, a credit bureau, another organization whose systems or customers are implicated, and a professional regulator where the information concerns regulated activity.

The practical difficulty is that this determination requires knowing who could act, which is not obvious under time pressure and is not a question most incident response plans prompt. A plan that lists the OPC and the affected individuals and stops there has omitted a statutory duty.

The remedy is inexpensive: a standing list, prepared in advance, of the third parties who might be able to reduce risk given the categories of personal information the organization actually holds. That list can be assembled calmly, in advance, by people who know the data.

Quebec: A Different Test And A Different Register

Not a provincial variation on the federal rule but a parallel regime with its own vocabulary.

Since September 22, 2022, Quebec has implemented a mandatory breach reporting regime under which an organization must promptly report to the Quebec privacy commissioner and notify affected individuals of any confidentiality incident involving personal information if the incident presents a risk of serious injury[7].

The threshold turns on stated factors: whether a particular incident presents a risk of serious injury depends on the sensitivity of the information, the anticipated consequences of its use, and the likelihood that the information will be used for injurious purposes[8]. Where the threshold is met, the organization must take reasonable measures to reduce the risk of injury and to prevent new incidents of the same nature, which includes promptly notifying the Commission d'accès à l'information du Québec and all affected individuals[8].

The two tests are similar in structure and different in emphasis. One commentary observes that the Quebec concept bears resemblance to PIPEDA's breach of security safeguards, but that PIPEDA places greater emphasis on the likelihood of harm rather than injury[8]. Another notes that although the terminology differs from PIPEDA's RROSH standard, the substantive information required is generally aligned with the federal regime[7].

The register requirement diverges more sharply. Quebec's regulation requires organizations to maintain a register of all confidentiality incidents for a period of five years, regardless of whether the risk of serious injury test is met[7], against PIPEDA's 24 months.

An organization holding personal information about residents of both jurisdictions therefore has a single practical answer: retain for the longer period. Building two retention schedules for one incident log is an unnecessary source of error.

Alberta Got There First

A third regime, and a useful corrective to the assumption that this is a recent development.

Alberta's Personal Information Protection Act has required mandatory breach reporting since 2010, eight years before PIPEDA caught up, with reporting to the Office of the Information and Privacy Commissioner of Alberta[6].

The relevance for a national business is that Alberta is a distinct reporting destination with its own commissioner and its own requirements, and has been for over a decade. British Columbia also operates its own private-sector privacy statute, and organizations should confirm the current position in every province where they hold personal information rather than assuming the federal regime covers them.

The general structure across Canada is therefore federal legislation applying to organizations in most provinces, with substantially similar provincial legislation displacing it for intra-provincial activity in certain provinces, and a separate health-information layer in several jurisdictions that this article does not address.

The Routing Problem

The operational consequence of multiple regimes, and the point at which most incident plans fail.

One source describes the step directly: determine where the affected users reside to trigger the correct regulatory notification, whether OPC, CAI or OIPC[5].

Residence of the affected individuals, not the location of the business, drives the routing. A company headquartered in Ontario with customers across Canada does not have one regulator; it has as many as its customer base implicates, and a single incident can therefore trigger obligations under multiple regimes simultaneously with different thresholds, different timelines and different notice content requirements.

This has a data architecture implication that is worth acting on before an incident rather than during one. The organization must be able to answer, quickly, which affected individuals reside in which province. If province of residence is not a reliable field in the customer record, or if the compromised dataset does not carry it, the routing determination becomes an extraction and matching exercise performed under a days-long clock.

Our recommendation is to test this capability in advance by asking a simple question of the systems: for any given customer table, can we produce a count by province in minutes. If not, that is a gap to close now, and it is a data question rather than a legal one.

The Penalty Gap

The asymmetry that should determine where compliance investment is directed.

Under PIPEDA it is an offence to knowingly contravene the reporting, notification and record-keeping requirements relating to breaches of security safeguards, and doing so could lead to fines, though the OPC does not prosecute offences or issue fines itself[1]. The section 28 framework is reported as summary conviction fines up to $10,000 per offence and indictable offence fines up to $100,000 per offence[9].

Quebec is a different order of magnitude. Maximum administrative monetary penalties may reach the greater of CAD $10 million or 2% of worldwide turnover for the preceding fiscal year, while penal fines for more serious offences may reach higher[7], reported elsewhere as up to $25 million or 4% of turnover[6]. Quebec's privacy commissioner may impose these penalties for specified contraventions including failures to report qualifying incidents, notify affected individuals, or maintain the required register[7].

Two observations. The Quebec penalties attach expressly to the register requirement, not only to failures to report, which means the record-keeping duty this article emphasises carries direct financial exposure in that province rather than merely evidentiary consequence.

And one source notes that beyond fines, the OPC can publicly name non-compliant organisations[6]. For most Canadian businesses the reputational consequence of being named is a larger practical risk than a $100,000 federal maximum, which is worth weighing when assessing whether the federal regime is toothless.

The Private Right Of Action

A Quebec feature that changes the risk calculus independently of regulatory action.

Law 25 provides a private right of action with minimum $1,000 punitive damages[9].

The significance is arithmetic rather than doctrinal. A statutory minimum award, available to individuals, applied across a large affected population, produces an aggregate exposure that scales with the number of records rather than with the severity of the incident or the regulator's appetite. A breach affecting ten thousand Quebec residents carries a different profile under that provision than the same breach affecting ten thousand residents elsewhere.

We note that we have not established the precise conditions under which the minimum award applies, and readers should not treat the arithmetic above as a prediction of outcome. The point is directional: Quebec exposure is not confined to what the CAI decides to do.

Why The First Hours Decide The Notice

The operational insight that connects incident response to notice quality, and it is well put in the commentary.

Quebec's regulation specifies detailed content requirements for notices to the CAI, which means notice quality depends on how well the incident record captures facts during the investigation, not on what people can reconstruct from memory two or three days later. The incident record should be designed to support legal notices from the first few hours of investigation onward, rather than as a last-minute administrative exercise[2].

The sequencing problem is real. In the first hours of an incident the priority is containment, and the people doing the work are technical staff whose attention is on stopping the exposure. The facts a regulatory notice requires, precisely what information was involved, how many individuals, when it began, when it was discovered, what has been done, are being established in exactly that window and are rarely being recorded in a form the notice can use.

One incident response outline recommends containment in the first 24 hours including taking snapshots of compromised systems for forensic analysis, then assessing the threshold in the following day[5].

The practical fix is a structured incident record opened at the moment of discovery, with fields corresponding to what the notices will require, completed contemporaneously as facts are established. That converts the notice from a drafting exercise into an extraction, and it is the difference between a defensible notice and a reconstructed one.

A Worked Case: One Incident, Three Regulators

A Canadian services business suffers unauthorised access to a customer database. The reconstruction illustrates the routing rather than reporting a specific engagement.

The compromised records cover customers in Ontario, Quebec and Alberta, and contain names, contact details and service histories. No payment credentials are involved.

The business must assess the federal RROSH threshold for the Ontario customers and report to the OPC if met. It must separately assess Quebec's risk of serious injury standard, considering sensitivity, anticipated consequences of use, and likelihood of injurious use, and notify the CAI promptly if met. It must consider Alberta's regime for its Alberta customers, reporting to the OIPC.

Regardless of any of those determinations, it must record the incident, retain that record for 24 months federally and enter it in a register retained for five years in Quebec, and if it concludes that a threshold was not met, record a brief explanation of why[3].

It must also identify whether any third party could reduce the risk and notify them if it is notifying individuals[3].

The binding constraint in practice is none of the legal tests. It is whether the business can determine, within days, how many affected individuals reside in each province, and whether it captured enough contemporaneous fact to complete notices with detailed content requirements. Both are systems questions answered long before the incident.

What To Build

A log that records everything. Every loss, unauthorised access, use or disclosure, regardless of severity. A log containing only serious incidents is evidence of a record-keeping failure.

A structured reasoning field for non-reported incidents. The OPC expects a brief explanation of why the threshold was determined not to be met, recorded contemporaneously and specific enough to defend.

A consistent threshold assessment framework. Applied identically to every incident, so the pattern of decisions is defensible as a process.

Retention to the longest applicable period. Five years covers Quebec's register and comfortably exceeds PIPEDA's 24 months. Running two schedules invites error.

Province-of-residence as a reliable, queryable field. Routing depends on where affected individuals live. Test now whether you can produce counts by province in minutes.

An incident record designed around notice content. Fields matching what the regulators require, completed as facts emerge, so the notice is extracted rather than reconstructed.

A pre-built third-party list. Who could reduce risk given the categories of information you hold, assembled calmly in advance.

A bias toward reporting early and updating. The OPC does not require a completed investigation before a report, and delay is its own failure.

The Limits Of This Analysis

Several caveats matter. This article draws on OPC guidance together with legal and commercial commentary rather than the statutory text and regulations directly, and readers should consult PIPEDA, the Breach of Security Safeguard Regulations, Quebec's legislation and regulation, and Alberta's PIPA for authoritative requirements. Penalty figures are reported from secondary sources and differ between them, particularly on Quebec's penal maximums; we have reported the range rather than resolving it. We have not established the precise conditions governing Quebec's private right of action or its minimum punitive damages award, and the arithmetic illustration in that section is directional rather than predictive. Several cited sources are compliance software or advisory vendors with a commercial interest in the subject. This article does not address British Columbia's PIPA in any detail, provincial health information statutes, the federal Digital Privacy Act's interaction with sector regulators, cross-border transfer obligations, privacy impact assessment requirements, consent standards, or the reform proposals that have been under discussion federally. Nothing here is legal advice; an organization facing an actual or suspected breach should obtain Canadian privacy counsel immediately, and the decision on whether a threshold is met should not be made from a general article.

Frequently Asked Questions

Do I have to report every breach?
No, but you must record every breach. Reporting to the OPC and notifying individuals is required only where there is a real risk of significant harm. Record-keeping applies to all breaches regardless of threshold, for 24 months federally, in sufficient detail for the OPC to verify you assessed risk properly.
What if I decide not to report?
The OPC states the record should then include a brief explanation of why it was determined that the risk threshold was not met. So the decision not to report is itself a documented, auditable act, and the reasoning needs to exist contemporaneously and be specific enough to defend.
What actually counts as a breach?
A loss, unauthorized access to, use or disclosure of personal information. That includes a misdirected email, a lost device, and an employee viewing records without a business reason. No external attacker is required, which is why the population of recordable incidents is much larger than most organizations assume.
How does Quebec differ?
Different vocabulary, threshold, register and penalties. Since September 22, 2022, a confidentiality incident presenting a risk of serious injury must be promptly reported to the CAI and notified to affected individuals, with a register of all incidents retained for five years regardless of threshold, and administrative monetary penalties reaching the greater of $10 million or 2% of worldwide turnover.
Which regulator do I report to?
It depends on where the affected individuals reside, not where your business is located. A single incident can engage the OPC, Quebec's CAI and Alberta's OIPC simultaneously. That makes province of residence a field your systems need to be able to query quickly, which is a data architecture question to solve before an incident.
How fast must I move?
As soon as feasible after determining a qualifying breach occurred, with reporting reportedly expected within days to a few weeks rather than months, and days for Quebec's CAI. You do not need to finish investigating before reporting; submit what you know and update. Waiting for a complete picture is a common and avoidable failure.
IB

About The Insight Bureau Research Desk

The Insight Bureau is GSH Financial's research publication, written for Canadian business owners and the students who will eventually advise them. This article reports a divergence between its sources on Quebec's penal maximums rather than resolving it, and flags which of its sources are vendors. See References below.

References

  1. Office of the Privacy Commissioner of Canada. What You Need to Know About Mandatory Reporting of Breaches of Security Safeguards, on the definition of a privacy breach, the three obligations, the OPC's ability to request breach records, and the offence provision. priv.gc.ca/en/privacy-topics/business-privacy/breaches-and-safeguards/privacy-breaches-at-your-business/gd_pb_201810
  2. Canadian Cyber. (2026, March 16). Breach Reporting in Canada: PIPEDA and Law 25 Guide, on the RROSH standard, the need for a disciplined threshold determination process, the incident log observation, and the point that notice quality depends on contemporaneous capture. Note: published by a cybersecurity advisory business. canadiancyber.ca/breach-reporting-canada
  3. LexisNexis Canada. Complying with PIPEDA's New Breach Reporting Rules, on the third-party notification duty, the 24-month record retention requirement and sufficiency standard, and the OPC's position that non-reported breaches should record why the threshold was not met. lexisnexis.com/en-ca/ihc/complying-with-PIPEDAs-new-breach-reporting-rule
  4. McCarthy Tétrault. (2026, May 7). Navigating the Legislative Landscape on Data Breaches: 2026 Data Breach Insights, Part 3, on the federal notification obligations once RROSH is met. mccarthy.ca/en/insights/publications/navigating-the-legislative-landscape-on-data-breaches-2026-data-breach-insights-part-3
  5. Vucense. (2026, July). Canada PIPEDA and Law 25 Guide 2026, on the containment and assessment sequence, the provincial routing step, and the record-keeping rule. Note: published by a technology guidance provider. vucense.com/tech-guides/security-101/canada-pipeda
  6. SmartSMSSolutions. (2026, May 25). Data Breach Notification Laws Canada 2026, on OPC timing expectations, CAI expectations, Alberta PIPA's 2010 mandatory reporting, the penalty comparison and the OPC's ability to name organizations. Note: published by a compliance software vendor. smartsmssolutions.com/resources/blog/ca/data-breach-notification-laws-canada-2026
  7. McCarthy Tétrault. (2026, May 7). 2026 Data Breach Insights, Part 3, on Quebec's regime since September 22, 2022, the confidentiality incident concept, the five-year register requirement, and administrative monetary penalties reaching the greater of $10 million or 2% of worldwide turnover. mccarthy.ca/en/insights/publications/navigating-the-legislative-landscape-on-data-breaches-2026-data-breach-insights-part-3
  8. Gowling WLG. (2022, December 14). The ABCs of Reporting a Privacy Breach Under Quebec's New Law 25, on the risk of serious injury factors, the duty to take reasonable measures, and the comparison with PIPEDA's emphasis on likelihood of harm. gowlingwlg.com/en/insights-resources/articles/2022/the-abcs-of-reporting-a-privacy-breach-law-25
  9. Recording Law. (2026, May 20). Canada Data Privacy Laws: PIPEDA and Provincial Guide 2026, on section 28 penalty levels and Quebec's private right of action with minimum punitive damages. recordinglaw.com/world-laws/world-data-privacy-laws/canada-data-privacy-laws

This article discusses privacy breach obligations and is provided for general informational purposes. It is not legal advice. Requirements derive from federal and provincial statutes and regulations that should be consulted directly. Penalty figures are reported from secondary sources that differ. Obtain Canadian privacy counsel immediately in respect of any actual or suspected breach.