Mandatory Privacy Breach Reporting Rules Take Effect In November

TL
Torys LLP

Contributor

Torys LLP is a respected international business law firm with a reputation for quality, innovation and teamwork. Our experience, our collaborative practice style, and the insight and imagination we bring to our work have made us our clients' choice for their largest and most complex transactions as well as for general matters in which strategic advice is key.
In 2015, the federal government amended the PIPEDA to require organizations to report certain serious breaches of personal information to the OPC and to affected individuals.
Canada Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

In 2015, the federal government amended the Personal Information Protection and Electronic Documents Act (PIPEDA) to require organizations to report certain serious breaches of personal information to the Office of the Privacy Commissioner (OPC) and to affected individuals. The government recently announced that these breach reporting requirements will come into force on November 1, 2018. The final text of the Breach of Security Safeguards Regulations (Regulations), which sets out the required content of both the report to the OPC and the notice to individuals, will be published on April 18, 2018 (see our 2017 analysis of the draft Regulations here).

What You Need to Know

  • Organizations will be required to 1. report to the OPC, and 2. notify affected individuals of breaches of security safeguards involving personal information where the breach creates a real risk of significant harm to individuals.
  • The final text of the Regulations will likely include additional guidance on the content and format of breach notifications, and may address suggestions from industry, the public and the OPC during the draft Regulations' comment period in 2017.
  • Companies can prepare for mandatory breach reporting by:

    • updating internal breach response protocols, record retention procedures and personal information handling and complaint policies;
    • establishing legal and fact-gathering frameworks  for determining whether a privacy breach meets the "real risk of significant harm" reporting threshold;
    • designating a privacy breach response team, including internal stakeholders and external advisers and service providers;
    • designing templates for reports to the OPC and notices to customers, employees and other individuals;
    • drafting templates for retaining records of all breaches, whether they meet the reporting threshold or not; and
    • updating employee training materials to ensure stakeholders understand the organization's approach to complying with the new breach reporting requirements.

Additional Insights

Although the breach reporting requirements have been part of PIPEDA since 2015 and the implementing Regulations were broadly expected to be finalized this spring, the coming into force date was not expected to be announced until after the final Regulations had been released. The announcement of a November 2018 implementation date suggests that the final Regulations will not be significantly different than the draft published in September 2017. Rather, the relatively short deferral indicates a government view that the private sector will require little time to bring their breach response practices into compliance with the new regulatory requirements.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More