Canadian privacy class actions used to orbit one convenient theory: intrusion upon seclusion. It sounded right after a breach. Someone got into personal data. People felt violated. Certify the class, argue aggregate harm, settle under pressure.
Then appellate courts started asking a basic doctrinal question. Who did the intruding?
In Del Giudice v Thompson, 2024 ONCA 70, the Court of Appeal for Ontario reinforced a hard limit. An organization that suffers a third-party cyberattack is not, without more, an “intruder” for the purpose of the tort. The classic intrusion claim targets intentional, highly offensive privacy invasions by the defendant. A failure to stop a criminal outsider may be negligent. It is not the same legal wrong.
Why this ruling landed the way it did
The tort has always had elements. Intention matters. Offensiveness matters. The defendant’s conduct matters. Stretching those elements to cover every ransomware crew or credential-stuffing campaign turns a privacy tort into strict liability for being targeted.
Ontario courts, including the line of thinking visible in large breach files involving major commercial databases, have resisted that stretch. Del Giudice is part of that resistance. It tells plaintiffs: if your theory is “you got hacked,” you need a cause of action that fits those facts.
Negligence is harder—and that is the point
After intrusion becomes unavailable in pure third-party hack scenarios, attention shifts to negligence, contract, statute, and sometimes consumer protection theories. Negligence is not impossible. It is simply more demanding.
Plaintiffs generally need duty, breach, causation, and compensable damages. Courts have been skeptical of claims built only on an increased risk of future fraud or a general sense of vulnerability. That does not mean no one is harmed by breaches. It means harm must be pleaded and proven with more care than a boilerplate affidavit about stress.
From a governance perspective, I welcome the discipline even when I dislike the human cost of breaches. Speculative mass claims can distort settlement economics without improving security. Fact-based claims push organizations to document real safeguards and real response quality.
What this does not mean
It does not mean breach victims have no remedies. It does not mean poor security is free. It does not mean regulators will stay quiet. And it does not mean every privacy class action is dead.
Internal misuse, deceptive collection, unauthorized secondary use, and deliberate corporate overreach are different fact patterns. Those cases can still support intentional privacy theories and statutory claims. External criminal intrusion and internal commercial abuse are not moral twins, and courts are increasingly treating them differently.
It also does not mean notification fatigue is a strategy. PIPEDA breach obligations, provincial duties, contractual notice clauses, and reputational reality still apply. The OPC’s breach guidance and your provincial regulator materials still matter on day one of an incident. Winning a pleadings motion years later is not a substitute for competent incident response this week.
How I change the breach playbook after Del Giudice
I ask security and counsel to prepare as if negligence will be the live theory.
That means evidence of risk assessments before the incident, not reconstructed after. Patch and access-control history. Vendor due diligence files. MFA coverage. Logging that can show detection time. Decision records for containment. Clear timelines for notification. Offer letters and credit-monitoring choices that match the actual risk profile.
I also push product owners to reduce data holdings. You cannot disclose what you never retained. Minimization is still the cheapest defence.
Finally, I separate communications tracks: regulator notice, individual notice, and litigation hold. Mixing those tracks creates inconsistent statements that later appear in discovery.
The strategic reading for boards
Boards sometimes hear “intrusion claims are harder” and translate it into budget cuts for security. That is a misread. The jurisprudence reduces one inflated pleading path. It increases the importance of proving reasonable care. Under-investing in safeguards makes the remaining theories easier for plaintiffs and harder for you.
If anything, Del Giudice should improve the quality of privacy risk conversation. Less mythology about automatic class-wide privacy torts. More attention to control design, residual risk acceptance, and post-incident proof.
There is a communications angle too. Overconfident public statements after a breach become painful exhibits. Understated, accurate updates age better than bravado. Stick to verified facts, known containment steps, and support offers that match the data actually exposed. If negligence is the live theory, the quality of your investigation file matters—do not invent governance after plaintiffs already have your timeline.
Building a “prove it under oath” file before the crisis
I keep a short evidence list for privacy and security leaders:
- Last enterprise risk assessment that covered the compromised system
- Access reviews and privileged-account inventory
- Patch SLAs versus actual patch age at incident time
- Vendor SOC reports and residual-risk acceptances
- Backup and restoration tests (not only backup configuration screenshots)
- Decision log from the first 72 hours of the incident
- Notification analysis: who was told, when, and why the threshold was or was not met
If those items live only in people’s heads, you do not have a defence file. You have a storytelling problem. Quebec-facing organizations should also keep CAI notification and safeguard expectations in the same binder; multi-jurisdictional incidents do not wait for doctrinal purity.
Actionable takeaway
Update your cyber incident legal strategy memo in plain language: list which claims are fact-dependent after Del Giudice, identify the evidence you would need to defend a negligence theory, and assign owners to collect that evidence continuously—not after the breach call. Review the memo with security and privacy together at least twice a year. Pair it with one tabletop that ends in a mock discovery request for safeguard proof, not only a mock press release.