What happened to your data? Start here.
Pick what happened and see the deadline that matters, what to do first, and the privacy law that applies.
A company had a data breach
PIPEDA s. 10.1 (breach of security safeguards)
The deadline that matters
Do this first
- 1Get the breach details in writingAsk what data was exposed, when, and what protective steps the organization is taking.
- 2Protect your accountsChange passwords, enable two-factor, and watch for fraud on affected accounts.
- 3You can complain to the OPCIf the response is inadequate, the Office of the Privacy Commissioner accepts complaints.
The law that protects you
"An organization shall report to the Commissioner any breach of security safeguards⦠if it is reasonable⦠to believe that the breach creates a real risk of significant harm to an individual."
Legal information, not legal advice. Privacy law varies by sector and province and is being reformed; confirm what is in force against the current statute or a licensed professional.
Protections that apply to your data
You can ask what personal information a company holds about you and how it was used β usually answered within 30 days.
Breaches posing a real risk of significant harm must be reported to the Commissioner and to you.
Commercial messages generally require your consent and a working unsubscribe honoured within 10 business days.
Provincial health-privacy law gives strong rights to see your records and request corrections.
Did This Help You?
MyPrivacyRights.ca is free for every Canadian. Your support helps keep legal information accessible to everyone.
Donations processed securely via KnowMyRights.ca