PIPEDA Breach Response: Your First 72 Hours
The moment you find a breach, the clock and the questions start together. Here's the test PIPEDA actually applies — and a calm, ordered plan for the first 72 hours.
Under PIPEDA you have to report a breach to the Office of the Privacy Commissioner and notify affected individuals "as soon as feasible" once it creates a "real risk of significant harm" — measured by how sensitive the information is and how likely it is to be misused. There's no fixed 72-hour clock (that's the EU's GDPR), but the first 72 hours are what decide whether you get ahead of a breach or spend weeks chasing it.
The day you discover a privacy breach is a terrible day to start learning what PIPEDA asks of you. The obligations land immediately, the decisions come fast, and the two natural instincts — panic, or quietly downplay it — both lead somewhere bad. This is the plan worth having ready before you ever need it.
First, a myth to put down: PIPEDA doesn't give you 72 hours. That's the EU's GDPR. The PIPEDA rule is that you report to the Office of the Privacy Commissioner (OPC) and notify affected individuals "as soon as feasible" after determining a breach creates a real risk of significant harm. No countdown clock — but "as soon as feasible" is not a licence to wait, and those first three days are where you either get ahead of the breach or fall behind it.
The test that decides everything: real risk of significant harm
Not every breach gets reported. The trigger under PIPEDA is a breach of security safeguards that creates a "real risk of significant harm" to a person — often shortened to RROSH. Get this one assessment right and the rest of your decisions fall into place behind it.
"Significant harm" is defined broadly. It reaches bodily harm, humiliation, damage to reputation or relationships, loss of employment or business or professional opportunities, financial loss, identity theft, a hit to a credit record, and damage to or loss of property. That's a wide net — reputational harm and humiliation sit inside it, not just dollars lost.
To decide whether the risk is "real," PIPEDA points to two factors above the rest: how sensitive the personal information is, and how probable it is that the information has been, is being, or will be misused. A spreadsheet of names and store loyalty points sits low on both axes; a file of health records or banking credentials sits high. You weigh the two together — highly sensitive data with a slim chance of misuse can still clear the bar, and so can middling data that's plainly in the wrong hands.
What should you do in the first 72 hours?
At a glance, the first three days break down like this:
| Window | Focus | Key action |
|---|---|---|
| Hours 0-4 | Contain | Stop access, isolate systems, preserve logs |
| Hours 4-24 | Establish facts | Determine what, whose, how much, and how |
| Hours 24-48 | Assess | Run the real-risk-of-significant-harm test, document reasoning |
| Hours 48-72 | Notify | Report to the OPC and affected individuals if the threshold is met |
Hours 0-4: contain, don't erase. Stop the bleeding — revoke access, kill the compromised account, isolate the affected system. Just don't destroy the evidence while you're at it. Preserve the logs; you'll need them to understand scope and to defend your assessment later. Pull together a small response team and give one person clear ownership.
Hours 4-24: establish the facts. What information was involved, how much, whose, and how did it get exposed? Was it encrypted? Is there any sign it was actually accessed or misused, or only that it could have been? Write down what you know — and, just as important, what you don't know yet. Start the breach record now, while memories are fresh.
Hours 24-48: run the RROSH assessment. With the facts in hand, work through sensitivity and probability of misuse. Document your reasoning, because the OPC — and, in a dispute, a court — will care as much about how you reasoned as about where you landed. If the risk clears the threshold, you're reporting. If it's genuinely borderline, lean toward reporting; under-reporting is the more dangerous mistake.
Hours 48-72: notify. If the threshold's met, report to the OPC and notify affected individuals as soon as feasible. The OPC gives you a breach report form; your report should describe the circumstances, the personal information involved, the number of people affected if you know it, what you've done to reduce the harm, and how you're notifying people. Notice to individuals should be direct where possible, and it has to give them enough to grasp the risk and act on it — monitoring accounts, changing passwords, that sort of thing.
Don't forget the notifications you might owe others
PIPEDA also expects you to notify other organizations or government institutions when doing so could reduce the risk of harm — think a payment processor that can flag compromised cards, or the police in a case of theft. And if your breach touches the personal information of Quebec residents, Quebec's Law 25 carries its own confidentiality-incident duties to the Commission d'accès à l'information and to the people affected, on its own terms. One incident can set off obligations under more than one law at once.
The register you must keep either way
Here's the requirement that catches people off guard: under PIPEDA you have to keep a record of every breach of security safeguards — not just the ones you reported. The OPC can ask to see this breach register, and you have to hold it for a set period. Logging even the small incidents pays off twice: it satisfies the legal obligation, and it builds the pattern-recognition that helps you head off the next one.
After the fire is out
Once the notifications are done, run a real post-incident review — not a box-ticking one. What let the breach happen? What did the response get right, and where did it stall? Update your safeguards and your plan to match. A breach handled well and genuinely learned from is survivable; the reputational damage almost always comes from a slow, defensive, or dishonest response rather than from the incident itself.
The businesses that come out of a breach with their credibility intact are nearly always the ones that decided, in advance and while calm, exactly what they'd do in the first 72 hours.
*This article is general information, not legal advice; consult a qualified professional about your specific situation.*
At Canuckt we build privacy-first tools for Canadian businesses, and Valdra gives you a breach-response workflow and an incident register built around the RROSH test — while a PIPEDA readiness assessment helps you close the safeguards gaps before they become the breach you have to report.
Frequently asked questions
Does PIPEDA give you 72 hours to report a breach?+
No — that 72-hour deadline belongs to the EU's GDPR. PIPEDA requires you to report to the OPC and notify individuals "as soon as feasible" once you've determined a breach creates a real risk of significant harm. There's no fixed clock, but "as soon as feasible" isn't permission to drag your feet.
What is the "real risk of significant harm" test?+
It's PIPEDA's trigger for mandatory breach reporting. You weigh two things: how sensitive the personal information is, and how likely it is to be misused. Significant harm is broad — it covers financial loss, identity theft, humiliation, and reputational damage, among others.
Do you have to report every privacy breach to the OPC?+
No. You have to report and notify only when a breach creates a real risk of significant harm. But you must still log every breach of security safeguards in a register the OPC can ask to see — even the ones that never met the reporting threshold.
Who must you notify after a PIPEDA breach?+
If the threshold is met, you notify the OPC and the affected individuals as soon as feasible. You also have to notify other organizations or government institutions where doing so could reduce the harm. And if Quebec residents are involved, Law 25 layers on its own duties to the Commission d'accès à l'information.
How long must you keep a breach record under PIPEDA?+
PIPEDA requires you to keep a register of every breach of security safeguards for a set period, whether or not it was reported. The OPC can request it, so logging even minor incidents is a legal obligation — not just tidy practice.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Explore Valdra