Rules
Company Lost Your Data in Canada? PIPEDA Steps to Take Now
Company lost my data in Canada? PIPEDA sets the notification duties, the OPC takes the complaints, and credit freezes sit with Equifax and TransUnion.
What to take away
- A company that suffers a breach of personal information must report it to the Office of the Privacy Commissioner of Canada when there is a real risk of significant harm, and must notify affected people.
- You complain to the OPC, not to a court, as your first route. The OPC can investigate, publish findings and push the company to change its practices.
- Credit freezes in Canada are voluntary products from Equifax Canada and TransUnion Canada. There is no single national freeze law.
- Quebec, Alberta and British Columbia have their own private-sector privacy statutes, so the regulator depends on where the company operates.
- Compensation usually comes from a negotiated settlement or a court action, not from the breach report itself.
Who has jurisdiction over your complaint
PIPEDA covers private-sector organizations that collect, use or disclose personal information in the course of commercial activity. That includes retailers, banks, telecoms, insurers and most online services. The Office of the Privacy Commissioner of Canada is the regulator. The office explains the statute and its breach duties on its PIPEDA overview page.
Federal works, undertakings and businesses fall under the Canada Labour Code side of the same statute. Airlines, banks, telecoms and interprovincial trucking are common examples. If your employer is federally regulated, the same commissioner handles the complaint.
Three provinces run their own private-sector regimes. Quebec has the strongest, with breach notification and a duty to report to the Commission d'acces a l'information. Alberta and British Columbia each have a Personal Information Protection Act. A company operating mainly in one of those provinces answers to the provincial commissioner first.
Health information sits outside PIPEDA in most provinces. Each province has health privacy legislation and its own commissioner. A hospital breach in Ontario goes to the Information and Privacy Commissioner of Ontario, not to Ottawa.
What a breach notice must contain
The company must report to the commissioner as soon as feasible after it determines a breach occurred. The report must describe the circumstances, the personal information involved, the number of people affected, and the steps taken to reduce harm.
A notice to affected individuals must be clear and plain. It should say what happened, when it happened, what information was involved, and what the person can do to reduce the risk. That includes watching for phishing and checking accounts.
The company must also keep a record of every breach, including ones it decides not to report. Those records go to the commissioner on request. The full text of the duty sits in the PIPEDA statute.
The test is real risk of significant harm, not the size of the breach. A small leak of health or financial details can meet it. A large leak of email addresses alone may not.
Records the company must keep, and what you should keep
Organizations must maintain a breach log for 24 months after the day they determined a breach occurred. Investigators use those logs to see whether a company has a pattern of weak controls.
You should build your own file. It carries weight in a complaint and in any later settlement.
- The breach notice, saved as a PDF with the date received
- Screenshots of any account changes you did not make
- A written timeline of calls, emails and reference numbers
- Receipts for costs you can tie to the breach, such as a credit monitoring subscription
- The company's response if you asked what data was taken
What happens if the company does not comply
The commissioner can investigate on complaint or on its own initiative. If it finds a violation, it can make findings public and name the organization. That public naming is the main consequence, and it lands on the company's reputation and its contracts.
The commissioner cannot fine a private-sector organization under PIPEDA. It can apply to the Federal Court for an order compelling compliance, and the court can award damages to a complainant. That path is slow and rare.
You file through the OPC complaint process. Complaints generally must be filed within one year of the act you are complaining about. The office will tell you if it will investigate or refer you elsewhere.
A company that ignores the notification duty can also face a civil claim. Plaintiffs argue negligence and breach of confidence. Certification of a class is the hard part, and most Canadian data breach settlements are modest per person.
Where the rules differ by place
Quebec requires organizations to report breaches to the provincial commission and to notify affected people when there is a risk of serious injury. The province also sets confidentiality duties that survive a contract ending.
Alberta and British Columbia require notification to the provincial commissioner when there is a real risk of significant harm. Alberta adds a duty to notify the commissioner of any breach involving personal information, even without significant harm, in some cases.
Ontario's health privacy law requires hospitals and clinics to notify the provincial commissioner and affected patients. Financial institutions also answer to the Office of the Superintendent of Financial Institutions for operational risk, which is separate from privacy.
Canadian credit freezes are not government-run. Equifax Canada and TransUnion Canada each offer a freeze or lock product, and you must request it from each bureau separately. A freeze blocks most new lenders from pulling your file. It does not stop a fraudster from using your existing accounts.
If the breach involved Interac e-Transfer fraud or a fake lender, report it to the RCMP scam and fraud page and to your bank's fraud line the same day. Speed matters more than paperwork in those cases.
Common questions
Does a company have to tell me about every breach? No. It must notify you only when there is a real risk of significant harm. It must still report to the commissioner and keep a record either way.
Can I get compensation from the OPC? Not directly. The commissioner can apply to Federal Court for damages, but that is uncommon. Most money comes from a class action or a settlement.
Is a credit freeze free in Canada? Equifax Canada and TransUnion Canada offer freezes or locks, but the terms and any fees differ by product and change over time. Check both bureaus directly before you rely on one.
What if the company is based outside Canada? PIPEDA still applies if the company handles personal information of Canadians in commercial activity. The OPC can investigate, though enforcement against a foreign firm is limited.


