
Breach Notification in Canada: Who You Must Tell, and How Fast
Federal, Alberta, Quebec, Ontario and the health statutes all set different triggers and different recipients. A single map of who gets told what.
GuardsArm Team
Security Experts

An organisation operating in three provinces with both employee and customer data can be subject to four or five breach notification regimes at once. They share a general shape — assess harm, tell the regulator, tell the people — and differ in the details that matter at 2am: who decides, who is told, and how fast.
The practical answer is not to run five processes. It is to run one, built to the strictest applicable requirement.
Who must be told, by regime
| Regime | Regulator | Individuals | Anyone else |
|---|---|---|---|
| PIPEDA | Privacy Commissioner of Canada | Yes, where real risk of significant harm | Other organisations that can reduce harm |
| Alberta PIPA | Commissioner — who then decides on individual notice | Where the Commissioner requires it | — |
| Alberta HIA | Commissioner and the Minister | Yes | — |
| Quebec Law 25 | Commission d'accès à l'information | Yes, where risk of serious injury | — |
| Ontario PHIPA | IPC in defined circumstances, plus an annual return | Yes, at first reasonable opportunity | The professional College in specified cases |
| Manitoba PHIA | Ombudsman | Yes | — |
Two entries in that table surprise people. Alberta PIPA inverts the usual order: you report to the Commissioner, and the Commissioner decides whether individuals must be notified. Alberta HIA requires the Minister as well as the Commissioner — a third recipient no other regime has.
The harm thresholds are worded differently and mean nearly the same thing
The federal test is a real risk of significant harm, assessed on sensitivity and probability of misuse. Quebec's is risk of serious injury. The health statutes use variations on risk of harm. In practice an assessment that would clear one threshold generally clears the others, which is what makes a single process viable.
What differs more than the wording is who bears the judgement. Under PIPEDA you assess and decide. Under Alberta PIPA you report and the regulator decides. Your runbook needs to encode that difference, because it changes what you do on day one.
Build one process to the strictest standard
The design principles:
- Assess once, against the strictest test that could apply to the affected population, then notify everyone entitled
- Default to notifying where the assessment is genuinely borderline; under-notification is the failure that generates enforcement
- Maintain the register regardless — PIPEDA requires records of every breach, including the ones you correctly decided not to report
- Template the notifications in advance, including the required content (what happened, what information, what you are doing, what they can do, how to complain)
- Name the decision-maker and a deputy, reachable out of hours
What slows real organisations down
Not the legal analysis. It is almost always one of these:
- Establishing scope. Which records were actually accessed? Without adequate logging this can take weeks, and the clock does not pause. See logging strategy.
- Finding current contact details for affected individuals.
- Deciding who signs off, when nobody was designated in advance.
- Drafting under pressure, with legal and communications reviewing in series rather than in parallel.
Each of those is fixable before an incident and nearly unfixable during one. See incident communications.
What the notification has to say
Content requirements vary in wording but converge on the same five elements. Draft the template now, with blanks:
- What happened, in plain language and without minimising
- What information was involved, specifically
- What you have done to contain it and reduce the risk
- What the individual can do — concrete steps, not general advice
- How to reach you, and their right to complain to the regulator
Two judgement calls recur. Credit monitoring is not legally required in Canada, but offering it is now close to an expectation where financial identifiers were exposed, and declining to offer it becomes a story in itself. Timing against the investigation is the harder one: regimes generally require notification without unreasonable delay rather than waiting for a complete picture, so a first notification that is honest about what is still unknown beats a late one that is comprehensive.
Where to start
Write down, on one page, which regimes apply to your organisation and who the decision-maker is under each. Most organisations have never done this, and it takes an afternoon. It is also the first thing you will wish you had when an incident starts.
GuardsArm builds breach response processes that satisfy multiple Canadian regimes at once. See multi-province compliance or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


