Update

Your 10-Step Guide to New Mandatory Breach Reporting Regulations

Ruth E. Promislow and Katherine Rusk
October 17, 2018
Social Media
Download
Download
Read Mode
Subscribe
Summarize
 Your 10-Step Guide to New Mandatory Breach Reporting Regulations

This 10-step guide will walk you through the upcoming changes to the Personal Information Protection and Electronic Documents Act (PIPEDA), the factors to consider in being prepared under PIPEDA and other related considerations. This guide is no replacement for targeted legal advice. If you are an organization affected by the changes to PIPEDA, please contact us to determine what you need to do to be prepared and how you can minimize your organization’s potential legal exposure. There is no “one size fits all” when it comes to managing compliance with privacy regulation.

The biggest changes, which will be coming into force on November 1, 2018, are:

  1. Mandatory breach reporting to the Office of the Privacy Commissioner (OPC).
  2. Mandatory breach notification to impacted individuals.
  3. Mandatory breach record-keeping.
  4. Financial penalties of up to $100,000 for non-compliance with items 1 to 3.
Social Media
Download
Download
Subscribe
Republishing Requests

For permission to republish this or any other publication, contact Amrita Kochhar at kochhara@bennettjones.com.

For informational purposes only

This publication provides an overview of legal trends and updates for informational purposes only. For personalized legal advice, please contact the authors.

From the Same Authors

See All
Right to Have Your Information De-Listed
Blog

Right to Have Your Information De-Listed? The Federal Privacy Commissioner Issues Decision

August 28, 2025
Ruth E. PromislowCaroline PoirierSuzie Suliman
Ruth E. Promislow, Caroline Poirier & Suzie Suliman
23andMes Data Breach
Blog

23andMe's Data Breach: Key Takeaways

June 26, 2025
Stephen D. BurnsRuth E. PromislowJ. Sébastien A. Gittens
& 7 more