Resources · Compliance & Privacy

Breach Notification Requirements by Jurisdiction

Who you must notify and by when after a privacy breach, across PIPEDA, Quebec Law 25, Alberta PIPA, PHIPA, HIPAA, CCPA, CPRA and US Privacy Law

The clock starts before you know what happened. Every privacy regime in Canada and the United States requires you to notify someone after a breach, and each sets its own trigger, threshold, recipient and deadline. Most of them start counting from discovery, not from the day your investigation finishes. This page sets out who must be told and by when, in the jurisdictions our clients actually operate in.

Positioning Written by a SOC 2 Type II certified MSSP with offices in Toronto and Miami, for organizations that answer to regulators on both sides of the border.

The deadline is not the hard part

Organizations that miss a notification deadline rarely miss it because nobody knew the number. They miss it because the work that has to happen before the clock is useful was never done.

Notification is the last step in a sequence. Before you can notify, you have to know what personal information was in the affected system, whose it was, which jurisdictions those people live in, and whether the exposure meets the threshold that triggers the duty. That requires a data inventory, a documented risk assessment methodology and a decision-maker named in advance. Assembled during an incident, it takes days you do not have. Assembled beforehand, the notification itself is paperwork.

The sequence, in order

  1. Contain and preserve. Stop the exposure, preserve the evidence, and record the time of discovery, because most clocks run from that moment.
  2. Establish scope. What data, whose, how much, and where those individuals are resident. The data inventory does this work; without one you are reconstructing it under pressure.
  3. Assess the threshold. Canadian regimes turn on a real risk of significant harm or a risk of serious injury. US state statutes generally turn on unauthorized acquisition of defined categories of personal information, with some allowing a documented risk of harm analysis.
  4. Decide and document. A named decision-maker records the determination and the reasoning, whether or not notification follows. The record matters as much as the decision.
  5. Notify, in the right order. Regulators, individuals, and in some cases credit reporting agencies, media or other organizations able to reduce the harm.
  6. Log it. Several statutes require a register of all incidents, including those that did not meet the notification threshold.

Canada

Canadian regimes share a harm-based trigger: the duty attaches when the breach creates a real risk of significant harm, or under Quebec Law 25 a risk of serious injury. The assessment considers the sensitivity of the information and the probability of misuse.

RegimeWho must be notifiedTiming and record-keeping
PIPEDA (federal)The Office of the Privacy Commissioner of Canada and affected individuals, plus any other organization or government institution that may be able to reduce the risk of harm.As soon as feasible after determining that a breach creating a real risk of significant harm has occurred. Records of every breach of security safeguards must be kept for 24 months, including those that did not trigger notification.
Quebec Law 25The Commission d’accès à l’information and affected individuals. Any person or body able to reduce the risk may also be notified.With diligence, where the incident presents a risk of serious injury. A register of confidentiality incidents must be maintained and may be requested by the CAI.
Alberta PIPAThe Office of the Information and Privacy Commissioner of Alberta. The Commissioner then decides whether the organization must notify individuals.Without unreasonable delay, where a reasonable person would consider a real risk of significant harm exists. Alberta has required breach reporting since 2010, longer than any other Canadian private-sector regime.
British Columbia PIPANo general mandatory breach notification duty for private-sector organizations, though notification is often advisable and may be required by contract or sector rules.Not prescribed. Organizations operating in BC still commonly fall under PIPEDA for interprovincial or international activity, which does impose the duty.
PHIPA (Ontario)Affected individuals, and the Information and Privacy Commissioner of Ontario in prescribed circumstances such as theft, use or disclosure without authority, or a pattern of similar breaches.Individuals at the first reasonable opportunity. Annual breach statistics must be reported to the IPC for the preceding calendar year.
Provincial health privacy lawThe applicable provincial commissioner and affected individuals, on terms that vary by province.Confirmed per province. Custodians and their service providers are frequently both in scope.

United States

The US has no single federal breach notification law for most organizations. Instead there is a sector-specific federal layer and a state layer covering every state, with the state of residence of each affected individual determining which rules apply. A single incident touching customers in fifteen states triggers fifteen analyses.

RegimeWho must be notifiedTiming and thresholds
HIPAA Breach Notification RuleAffected individuals, the Secretary of Health and Human Services, and prominent media outlets for larger breaches. Business associates must notify the covered entity.Individuals without unreasonable delay and no later than 60 calendar days from discovery. HHS within 60 days where 500 or more individuals are affected; smaller breaches are logged and submitted annually within 60 days of year end. Media notice where 500 or more residents of a single state or jurisdiction are affected.
State breach notification statutesAffected residents, and frequently the state attorney general, state regulators and the consumer reporting agencies where the incident exceeds a stated headcount.Every state imposes a duty, on differing triggers and clocks. Some set a fixed deadline as short as 30 days from discovery; others require notice without unreasonable delay. Definitions of personal information and the availability of a risk-of-harm exception also vary, so multi-state incidents are mapped before the first notice goes out.
California (CCPA, CPRA and Civil Code 1798.82)Affected California residents, and the Attorney General where the incident affects more than 500 California residents.Without unreasonable delay. California also creates a private right of action for certain breaches of unencrypted personal information, which makes documented safeguards materially valuable.
GLBA Safeguards RuleThe Federal Trade Commission, for non-bank financial institutions within scope.Within 30 days of discovering an incident involving the unencrypted information of 500 or more consumers.
SEC cybersecurity disclosureInvestors, via Form 8-K, for public companies.Within four business days of determining that an incident is material. The clock runs from the materiality determination, not from discovery, but that determination must be made without unreasonable delay.

If you hold data on people outside North America

RegimeWho must be notifiedTiming
GDPR and UK GDPRThe supervisory authority, and affected individuals where the breach is likely to result in a high risk to their rights and freedoms.Supervisory authority within 72 hours of becoming aware. Individuals without undue delay. Every breach must be documented internally whether or not it is reported.

One incident, several clocks These duties stack rather than replace one another. A Canadian company with US customers and an EU contact list can owe notice to the Privacy Commissioner of Canada, a provincial commissioner, several state attorneys general and an EU supervisory authority for the same incident, on four different deadlines and four different thresholds. The shortest clock governs your response planning.

Four things this table will not tell you

Whether your incident actually meets the threshold. Every Canadian regime and many US statutes turn on a judgment about harm, made on the facts and recorded at the time. Two organizations with identical technical incidents can reach different, equally defensible conclusions. What is not defensible is reaching a conclusion without a documented methodology.

Which jurisdictions you are in. It is determined by where the affected individuals live, not where your company or your servers are. Most organizations discover their true jurisdictional footprint during an incident, which is the worst moment to find out.

What your contracts require. Customer agreements, data processing agreements and cyber insurance policies routinely impose notification deadlines shorter than the statutory ones, often 24 or 48 hours. These are frequently the tightest clock you face and the one most often missed.

When the clock actually started. Discovery is usually defined as the point at which the organization knew or reasonably should have known. An alert that sat unreviewed in a queue for three weeks can move your start date backwards, which is why detection and triage practice is part of breach readiness rather than separate from it.

Could you run this sequence tomorrow?

Book a breach readiness review. We walk your data inventory, your assessment methodology, your decision rights and your notification templates against the jurisdictions you actually operate in, and tell you where the sequence breaks.

If you are in an incident right now Call the 24/7 line first and worry about this page later. Cyberwall provides incident response alongside privacy support, so the team establishing what happened and the team assessing notification thresholds are the same team.

Related services: Privacy Consulting, Incident Response, Compliance Services, and Risk Assessment.


Still stuck?

If this guide doesn't cover your situation, our team can walk you through it directly.