Back to Blog
Incident Response
4 min read

Breach Notification in Canada: Who You Must Tell, and How Fast

Federal, Alberta, Quebec, Ontario and the health statutes all set different triggers and different recipients. A single map of who gets told what.

GuardsArm Team

Security Experts

September 25, 2026

Privacy breach notification requirements across Canada

An organisation operating in three provinces with both employee and customer data can be subject to four or five breach notification regimes at once. They share a general shape — assess harm, tell the regulator, tell the people — and differ in the details that matter at 2am: who decides, who is told, and how fast.

The practical answer is not to run five processes. It is to run one, built to the strictest applicable requirement.

Up to five regimes at once
Federal, provincial, and health-specific in parallel
Alberta PIPA inverts it
The Commissioner decides on individual notice, not you
Alberta HIA adds the Minister
A third recipient unique to that Act

Who must be told, by regime

RegimeRegulatorIndividualsAnyone else
PIPEDAPrivacy Commissioner of CanadaYes, where real risk of significant harmOther organisations that can reduce harm
Alberta PIPACommissioner — who then decides on individual noticeWhere the Commissioner requires it—
Alberta HIACommissioner and the MinisterYes—
Quebec Law 25Commission d'accès à l'informationYes, where risk of serious injury—
Ontario PHIPAIPC in defined circumstances, plus an annual returnYes, at first reasonable opportunityThe professional College in specified cases
Manitoba PHIAOmbudsmanYes—

Two entries in that table surprise people. Alberta PIPA inverts the usual order: you report to the Commissioner, and the Commissioner decides whether individuals must be notified. Alberta HIA requires the Minister as well as the Commissioner — a third recipient no other regime has.


The harm thresholds are worded differently and mean nearly the same thing

Harm thresholds across the regimesThe wording differs but the assessments converge; an incident clearing one threshold generally clears the others.Real risk of significant harmPIPEDA — sensitivity plus probability of misuseRisk of serious injuryQuebec Law 25Risk of harmThe health statutes, with local variationRecord everything regardlessPIPEDA register covers non-reportable breaches too
The wording varies more than the outcome does.

The federal test is a real risk of significant harm, assessed on sensitivity and probability of misuse. Quebec's is risk of serious injury. The health statutes use variations on risk of harm. In practice an assessment that would clear one threshold generally clears the others, which is what makes a single process viable.

What differs more than the wording is who bears the judgement. Under PIPEDA you assess and decide. Under Alberta PIPA you report and the regulator decides. Your runbook needs to encode that difference, because it changes what you do on day one.


Build one process to the strictest standard

One process, built to the strictest applicable standardOne process, built to the strictest applicable standard1Contain and logHour 0Stop the exposure and start the incident record immediately.2ScopeHours 0-24Establish what information, whose, and how much. Usually the slowest step.3Assess against the strictest testDay 1One assessment, applied to the most demanding standard in scope.4Notify regulatorsPer the shortest applicable clockIncluding the Minister in Alberta HIA, and the College where PHIPA applies.5Notify individualsWithout unreasonable delayUsing templates prepared in advance.6Record and closeWithin 30 daysInto the register, whether or not it was reportable.
Scoping is where the time goes, and logging is what determines how long it takes.

The design principles:

  • Assess once, against the strictest test that could apply to the affected population, then notify everyone entitled
  • Default to notifying where the assessment is genuinely borderline; under-notification is the failure that generates enforcement
  • Maintain the register regardless — PIPEDA requires records of every breach, including the ones you correctly decided not to report
  • Template the notifications in advance, including the required content (what happened, what information, what you are doing, what they can do, how to complain)
  • Name the decision-maker and a deputy, reachable out of hours

What slows real organisations down

Not the legal analysis. It is almost always one of these:

  1. Establishing scope. Which records were actually accessed? Without adequate logging this can take weeks, and the clock does not pause. See logging strategy.
  2. Finding current contact details for affected individuals.
  3. Deciding who signs off, when nobody was designated in advance.
  4. Drafting under pressure, with legal and communications reviewing in series rather than in parallel.

Each of those is fixable before an incident and nearly unfixable during one. See incident communications.


What the notification has to say

Content requirements vary in wording but converge on the same five elements. Draft the template now, with blanks:

  1. What happened, in plain language and without minimising
  2. What information was involved, specifically
  3. What you have done to contain it and reduce the risk
  4. What the individual can do — concrete steps, not general advice
  5. How to reach you, and their right to complain to the regulator

Two judgement calls recur. Credit monitoring is not legally required in Canada, but offering it is now close to an expectation where financial identifiers were exposed, and declining to offer it becomes a story in itself. Timing against the investigation is the harder one: regimes generally require notification without unreasonable delay rather than waiting for a complete picture, so a first notification that is honest about what is still unknown beats a late one that is comprehensive.


Where to start

Write down, on one page, which regimes apply to your organisation and who the decision-maker is under each. Most organisations have never done this, and it takes an afternoon. It is also the first thing you will wish you had when an incident starts.

GuardsArm builds breach response processes that satisfy multiple Canadian regimes at once. See multi-province compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.