Who you must notify and by when after a privacy breach, across PIPEDA, Quebec Law 25, Alberta PIPA, PHIPA, HIPAA, CCPA, CPRA and US Privacy Law
The clock starts before you know what happened. Every privacy regime in Canada and the United States requires you to notify someone after a breach, and each sets its own trigger, threshold, recipient and deadline. Most of them start counting from discovery, not from the day your investigation finishes. This page sets out who must be told and by when, in the jurisdictions our clients actually operate in.
Positioning Written by a SOC 2 Type II certified MSSP with offices in Toronto and Miami, for organizations that answer to regulators on both sides of the border.
Organizations that miss a notification deadline rarely miss it because nobody knew the number. They miss it because the work that has to happen before the clock is useful was never done.
Notification is the last step in a sequence. Before you can notify, you have to know what personal information was in the affected system, whose it was, which jurisdictions those people live in, and whether the exposure meets the threshold that triggers the duty. That requires a data inventory, a documented risk assessment methodology and a decision-maker named in advance. Assembled during an incident, it takes days you do not have. Assembled beforehand, the notification itself is paperwork.
Canadian regimes share a harm-based trigger: the duty attaches when the breach creates a real risk of significant harm, or under Quebec Law 25 a risk of serious injury. The assessment considers the sensitivity of the information and the probability of misuse.
| Regime | Who must be notified | Timing and record-keeping |
|---|---|---|
| PIPEDA (federal) | The Office of the Privacy Commissioner of Canada and affected individuals, plus any other organization or government institution that may be able to reduce the risk of harm. | As soon as feasible after determining that a breach creating a real risk of significant harm has occurred. Records of every breach of security safeguards must be kept for 24 months, including those that did not trigger notification. |
| Quebec Law 25 | The Commission d’accès à l’information and affected individuals. Any person or body able to reduce the risk may also be notified. | With diligence, where the incident presents a risk of serious injury. A register of confidentiality incidents must be maintained and may be requested by the CAI. |
| Alberta PIPA | The Office of the Information and Privacy Commissioner of Alberta. The Commissioner then decides whether the organization must notify individuals. | Without unreasonable delay, where a reasonable person would consider a real risk of significant harm exists. Alberta has required breach reporting since 2010, longer than any other Canadian private-sector regime. |
| British Columbia PIPA | No general mandatory breach notification duty for private-sector organizations, though notification is often advisable and may be required by contract or sector rules. | Not prescribed. Organizations operating in BC still commonly fall under PIPEDA for interprovincial or international activity, which does impose the duty. |
| PHIPA (Ontario) | Affected individuals, and the Information and Privacy Commissioner of Ontario in prescribed circumstances such as theft, use or disclosure without authority, or a pattern of similar breaches. | Individuals at the first reasonable opportunity. Annual breach statistics must be reported to the IPC for the preceding calendar year. |
| Provincial health privacy law | The applicable provincial commissioner and affected individuals, on terms that vary by province. | Confirmed per province. Custodians and their service providers are frequently both in scope. |
The US has no single federal breach notification law for most organizations. Instead there is a sector-specific federal layer and a state layer covering every state, with the state of residence of each affected individual determining which rules apply. A single incident touching customers in fifteen states triggers fifteen analyses.
| Regime | Who must be notified | Timing and thresholds |
|---|---|---|
| HIPAA Breach Notification Rule | Affected individuals, the Secretary of Health and Human Services, and prominent media outlets for larger breaches. Business associates must notify the covered entity. | Individuals without unreasonable delay and no later than 60 calendar days from discovery. HHS within 60 days where 500 or more individuals are affected; smaller breaches are logged and submitted annually within 60 days of year end. Media notice where 500 or more residents of a single state or jurisdiction are affected. |
| State breach notification statutes | Affected residents, and frequently the state attorney general, state regulators and the consumer reporting agencies where the incident exceeds a stated headcount. | Every state imposes a duty, on differing triggers and clocks. Some set a fixed deadline as short as 30 days from discovery; others require notice without unreasonable delay. Definitions of personal information and the availability of a risk-of-harm exception also vary, so multi-state incidents are mapped before the first notice goes out. |
| California (CCPA, CPRA and Civil Code 1798.82) | Affected California residents, and the Attorney General where the incident affects more than 500 California residents. | Without unreasonable delay. California also creates a private right of action for certain breaches of unencrypted personal information, which makes documented safeguards materially valuable. |
| GLBA Safeguards Rule | The Federal Trade Commission, for non-bank financial institutions within scope. | Within 30 days of discovering an incident involving the unencrypted information of 500 or more consumers. |
| SEC cybersecurity disclosure | Investors, via Form 8-K, for public companies. | Within four business days of determining that an incident is material. The clock runs from the materiality determination, not from discovery, but that determination must be made without unreasonable delay. |
| Regime | Who must be notified | Timing |
|---|---|---|
| GDPR and UK GDPR | The supervisory authority, and affected individuals where the breach is likely to result in a high risk to their rights and freedoms. | Supervisory authority within 72 hours of becoming aware. Individuals without undue delay. Every breach must be documented internally whether or not it is reported. |
One incident, several clocks These duties stack rather than replace one another. A Canadian company with US customers and an EU contact list can owe notice to the Privacy Commissioner of Canada, a provincial commissioner, several state attorneys general and an EU supervisory authority for the same incident, on four different deadlines and four different thresholds. The shortest clock governs your response planning.
Whether your incident actually meets the threshold. Every Canadian regime and many US statutes turn on a judgment about harm, made on the facts and recorded at the time. Two organizations with identical technical incidents can reach different, equally defensible conclusions. What is not defensible is reaching a conclusion without a documented methodology.
Which jurisdictions you are in. It is determined by where the affected individuals live, not where your company or your servers are. Most organizations discover their true jurisdictional footprint during an incident, which is the worst moment to find out.
What your contracts require. Customer agreements, data processing agreements and cyber insurance policies routinely impose notification deadlines shorter than the statutory ones, often 24 or 48 hours. These are frequently the tightest clock you face and the one most often missed.
When the clock actually started. Discovery is usually defined as the point at which the organization knew or reasonably should have known. An alert that sat unreviewed in a queue for three weeks can move your start date backwards, which is why detection and triage practice is part of breach readiness rather than separate from it.
Book a breach readiness review. We walk your data inventory, your assessment methodology, your decision rights and your notification templates against the jurisdictions you actually operate in, and tell you where the sequence breaks.
If you are in an incident right now Call the 24/7 line first and worry about this page later. Cyberwall provides incident response alongside privacy support, so the team establishing what happened and the team assessing notification thresholds are the same team.
Related services: Privacy Consulting, Incident Response, Compliance Services, and Risk Assessment.
If this guide doesn't cover your situation, our team can walk you through it directly.