Free breach-response planning tool
Breach notification: when the clock actually starts
PIPEDA and Quebec’s Law 25 give you no 72-hour, 30-day, or other fixed deadline for breach notification. They use judgment-based standards: “as soon as feasible,” “with diligence.” This tool walks you through the trigger, the clock, and who gets notified under each regime – then builds a draft incident-register entry covering the elements both laws expect you to keep. Review it against your own register procedure before filing.
Privacy promise: everything you type stays in this browser tab. No accounts, no cookies for your inputs, no network calls, nothing sent anywhere. The register generator keeps nothing – save its output into your own secure records.
Step 1 · the calculator
Do I have to notify, and when?
The legal clock starts when your organization determines the breach occurred (not when the risk assessment finishes); discovery time anchors your response timeline and your register entry.
Step 2 · the register generator
Build the incident-register entry
Both regimes expect a written record: PIPEDA’s Breach of Security Safeguards Regulations require a record of every breach (even below the notification threshold), kept for 24 months; Quebec’s Law 25 requires a register of all confidentiality incidents involving personal information, kept for five years from the date the organization became aware of the incident and available to the Commission on request. Fill in what you know – the entry stays in this tab until you save it.
Quebec expects the register to record the elements supporting the serious-injury conclusion.
Record the facts behind your conclusion. The risk factors you checked in Step 1 are added to the entry automatically.
Notification dates
Fill in the fields, then press “Generate register entry.”
Retention reminder: keep PIPEDA breach records for at least 24 months after the day you determine the breach occurred. Keep Quebec’s register up to date and retain each entry for five years from the date you became aware of the incident; the Commission can request a copy at any time. Store the saved entry in your own secure records – this page retains nothing.
Show your work
Methodology and sources
Every rule on this page comes from the statute or the regulator’s own guidance – not from blog summaries:
- PIPEDA, s. 10.1: an organization must report a breach of security safeguards to the Privacy Commissioner where it is reasonable to believe the breach creates a real risk of significant harm, “as soon as feasible after the organization determines that the breach has occurred” – and must notify the affected individual on the same standard (laws-lois.justice.gc.ca). The assessment weighs the sensitivity of the information and the probability of misuse.
- Breach of Security Safeguards Regulations (SOR/2018-64):require a written record of every breach involving personal information – threshold or not – kept for 24 months after the day the organization determines the breach occurred, producible to the Commissioner on request (ss. 10.3, 6).
- Quebec, Act respecting the protection of personal information in the private sector (RLRQ c. P-39.1), ss. 3.5–3.8 (as amended by Bill 64):where a confidentiality incident presents a risk of serious injury, the organization must notify the Commission avec diligence (with diligence / promptly) and notify each affected person, unless doing so would hamper an investigation. Every organization must keep a register of allconfidentiality incidents involving personal information; a copy goes to the Commission on request. See the Commission’s own guidance at cai.gouv.qc.ca.
- Alberta PIPA, ss. 34.1 and 37.1: an organization must notify the Commissioner “without unreasonable delay” where a reasonable person would consider there is a real risk of significant harm; the Commissioner may then require the organization to notify affected individuals (oipc.ab.ca).
- The 72-hour myth, killed with sources: the 72-hour number is GDPR Article 33(1) – EU controllers notify their supervisory authority within 72 hours of becoming aware of a breach. It is not Canadian law. Federal government institutions under Canada’sPrivacy Act work to yet another rule: report material breaches to the OPC and the Treasury Board Secretariat as soon as practically possible and no later than 7 days after determining the breach is material (TBS Privacy Implementation Notice 2024-02). If you are a private-sector organization under PIPEDA or Law 25, neither of those clocks applies to you.
Regulator context behind the strictness: the OPC’s 2025 23andMe findings criticized thetiming of notifications to affected Canadians, and Quebec’s Commission has made incident-reporting one of its visible enforcement themes. Treat “as soon as feasible” as a working standard, not a grace period.
Common questions
Before you act
- Is there a 72-hour deadline under PIPEDA or Law 25?
- No. The 72-hour figure is from the EU’s GDPR. Canadian private-sector law uses “as soon as feasible” (PIPEDA), “with diligence” (Quebec Law 25), and “without unreasonable delay” (Alberta PIPA).
- When does the clock start?
- When your organization determines the breach occurred. PIPEDA ties “as soon as feasible” to that determination; the real-risk-of-significant-harm test decides whether you must notify and must be run promptly inside the window. A slow investigation is not a pause button.
- Do below-threshold incidents go in the register?
- Yes. Record every breach: PIPEDA requires records of all breaches (24-month retention), and Quebec’s register covers all confidentiality incidents involving personal information (five-year retention from awareness).
- Should I also notify the police or my cyber insurer?
- Often yes, and your incident-response plan should say so – but those are separate decisions from the statutory duties above. Notify law enforcement where a crime is suspected, and loop in your insurer early if the policy requires it. Neither replaces the regulator and individual notifications.
Want a second pair of eyes on your response plan?
A tabletop walkthrough of your breach-response plan – roles, clocks, and the register – before an incident forces you to improvise.
Discuss your privacy needsDisclaimer: this tool is an educational planning aid, not legal advice and not a substitute for counsel. Breach-notification duties depend on your facts, your sector, and your jurisdiction; statutes and regulator guidance change. Confirm your response plan with qualified legal counsel before acting. This tool is maintained by Mohammad Movahedi.