Almost every Canadian organisation has an incident response plan for the technology. Far fewer have one for the privacy side of the same incident — who decides whether it has to be reported, what the regulator has to be told, what affected people have to be told, and where the record of it lives afterwards. That last part is not optional: PIPEDA requires you to keep a record of every breach of security safeguards, reportable or not, and Quebec requires a register of every confidentiality incident. Most organisations we assess cannot produce either.
This template is the privacy half of your response. Adapt it, put a name against every role, and keep it beside your technical runbook.
Before you adopt it
The clock starts when you find out, not when you finish deciding.
PIPEDA requires you to report a breach that poses a real risk of significant harm “as soon as feasible” after you determine it occurred. Quebec requires you to notify the Commission d’accès à l’information with diligence. Neither gives you a fixed number of days, and that is harder, not easier — you will be judged on how long you took and why. A template does not buy you that time. Naming the decision-maker in advance does.
This document is a starting point for your own legal and privacy advice. It is not legal advice, and adopting it does not make you compliant.
Privacy breach response policy
[ORGANISATION] · approved by [ROLE] · [DATE] · review annually
1. Purpose and scope
This policy sets out how [ORGANISATION] responds when personal information under our control is lost, accessed, used or disclosed without authorisation. It applies to every employee, contractor and director, to every system we run and every system a supplier runs on our behalf, and to information in any form — digital, paper or spoken.
It sits alongside our technical incident response procedure. Where the two overlap, the technical procedure governs containment and recovery; this policy governs assessment, notification and record keeping.
2. What counts as a breach
Under federal law (PIPEDA) a breach of security safeguards is the loss of, unauthorised access to, or unauthorised disclosure of personal information resulting from a failure of our safeguards, or from not having established them.
Under Quebec law (Law 25) a confidentiality incident is unauthorised access to, unauthorised use of, or unauthorised communication of personal information, or the loss of personal information or any other breach in its protection.
In practice, all of the following are reportable to [PRIVACY LEAD] immediately, whether or not anything was ultimately exposed:
- An email, letter or file sent to the wrong recipient
- A lost or stolen laptop, phone, USB drive or paper file
- A folder, mailbox, drive or database shared more widely than intended
- A password, token or account known or suspected to be compromised
- Personal information pasted into a public AI tool or any unapproved service
- A ransomware or intrusion event touching any system that holds personal information
- A supplier telling us they have had an incident affecting our data
Staff are not asked to judge severity. They are asked to report, quickly, and without fear of blame. Reporting an incident that turns out to be nothing is always the right call.
3. Who does what
- Anyone who becomes aware of an incident reports it to [PRIVACY LEAD] at [EMAIL] or [PHONE] without delay, and does not attempt to investigate or conceal it.
- [PRIVACY LEAD] owns this policy, records the incident in the register, coordinates the assessment, and drafts every notification.
- [ROLE — technical owner] contains the incident, preserves evidence and logs, and reports what was accessed and by whom.
- [ROLE — accountable executive] makes the final decision on whether the incident is notifiable and signs off every external communication. This decision is not delegated to the technical team.
- [ROLE — board or owner] is informed of every notifiable incident within [24 hours] of that determination, and receives a summary of all incidents at each [quarterly] meeting.
Deputies are named for each role above, because incidents do not wait for people to come back from leave.
4. The first hour
- Contain. Stop the exposure — recall the message, revoke the share, disable the account, isolate the device.
- Preserve. Do not delete anything. Do not wipe the device. Logs, headers and copies of the message are the evidence we will be asked for.
- Record. [PRIVACY LEAD] opens a register entry immediately, even before anyone knows how serious it is.
- Do not notify anyone externally yet. No email to customers, no post, no statement to a journalist, until section 6 and section 7 have been worked through and [ROLE — accountable executive] has approved the wording.
5. Assessing the risk
Two tests apply, and an incident can trigger one without the other.
Federal — real risk of significant harm. PIPEDA requires us to weigh the sensitivity of the information involved and the probability that it has been, is being, or will be misused. Significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or professional opportunity, financial loss, identity theft, negative effects on a credit record and damage to or loss of property.
Quebec — risk of serious injury. Law 25 requires us to weigh the sensitivity of the information, the apprehended consequences of its use, and the likelihood that it will be used for an injurious purpose.
The assessment is written down at the time, with the reasoning, whichever way it goes. A decision not to notify is the one most likely to be examined later, so it is the one that most needs a record.
6. Reporting to the regulator
Where the federal test is met, [ROLE — accountable executive] reports to the Office of the Privacy Commissioner of Canada as soon as feasible after we determine the breach occurred. The report describes the circumstances and, if known, the cause; when it happened; what personal information was involved; how many people are affected; what we have done to reduce the risk of harm; what we have done or intend to do to notify them; and who at [ORGANISATION] can answer the Commissioner’s questions.
Where the Quebec test is met, we notify the Commission d’accès à l’information with diligence, using its prescribed form.
Where the personal information belongs to another organisation, or where another organisation or a government institution may be able to reduce the risk of harm, we notify them too. Our contractual obligations to notify a customer, insurer or regulator in a set number of hours are listed in [APPENDIX A] and are usually tighter than the law.
7. Notifying the people affected
Where either test is met, affected individuals are notified as soon as feasible, directly, in language a person can act on. Indirect notification — a public notice — is used only where direct notification would cause further harm, would impose undue hardship on us, or where we do not have current contact details.
Each notification states what happened and when, what information about them was involved, what we have done to reduce the risk, what they can do to protect themselves, and how to reach a named person at [ORGANISATION] for more.
Notifications are drafted before they are needed. A template written under pressure reads like one.
8. The register
[PRIVACY LEAD] maintains a single register of every incident — not only the ones that were notifiable. Both regulators can ask to see it, and the register is the evidence that a decision not to notify was actually a decision.
Each entry records: a description of the personal information involved (or why that is not known); the circumstances; the date or period the incident occurred; the date or period we became aware of it; the number of people affected; the reasoning behind our risk assessment; if notifiable, the dates the regulator and the individuals were notified and whether a public notice was given; and the steps taken to reduce the risk of injury and to prevent a recurrence.
How long we keep it. Federal records are kept for at least 24 months from the day we determined the breach occurred. Quebec register entries are kept for at least five years from the date we became aware of the incident. Where both apply, we keep the entry for five years. Nothing in the register is deleted early to tidy it up.
9. Suppliers
Every contract under which a supplier handles personal information on our behalf requires them to notify [PRIVACY LEAD] of any incident affecting our data within [24 hours] of becoming aware of it, and to give us the information we need to make our own assessment. An incident at a supplier is our incident: the obligation to report and notify stays with us.
10. Learning and testing
Every incident is closed with a short written note of what allowed it to happen and what has changed as a result. [ORGANISATION] runs a walkthrough of this policy at least once a year, using a realistic scenario, with the people actually named in section 3 in the room. The date of the last walkthrough is [DATE].
This policy is reviewed annually and after any notifiable incident.
Practical tip
Denny Thompson
Before you write a privacy policy, write down what personal information you actually hold. Most organisations find the policy was describing a slightly different company.
Canadian privacy governance · the people who do the work
Send us your version. We will read it properly.
Adapt this to your organisation and we will review what you have written against PIPEDA, Law 25 and our control set, and tell you plainly where it would not hold up. No charge, no obligation, and we will not add you to anything.