Law / Canada

PIPEDA breach of security safeguards regime

S.C. 2000, c. 5, ss. 10.1-10.3

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 November 2018.

A breach notification rule binding private bodies.

As of 2 September 2026.

What it requires

  • Report any breach of security safeguards involving personal information under the organization's control to the Privacy Commissioner as soon as feasible, if it is reasonable to believe the breach creates a real risk of significant harm to an individual.
  • Notify each affected individual directly, in a conspicuous form, with enough information to let them understand the significance of the breach and take steps to reduce or mitigate the resulting harm.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Requires an organization to report to the Privacy Commissioner, and to notify the affected individual directly, any breach of security safeguards involving personal information under its control where it is reasonable to believe the breach creates a real risk of significant harm. Significant harm includes bodily harm, humiliation, damage to reputation, financial loss and identity theft; relevant factors include the sensitivity of the information and the probability of misuse. Added to PIPEDA by the 2015 Digital Privacy Act, with the reporting duty itself brought into force November 1, 2018.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_voice
  • processes_biometrics
  • operates_social_platform
  • serves_minors
  • operates_app_store
  • ships_mobile_app

Read the law

official consolidated statute text, Department of Justice Canada Justice Laws Website

Back to the example  ·  Lint your app