DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Mandatory data breach notification law proposed in Canada

Posted on February 28, 2013 by Dissent

Nestor E. Arellano reports:

With the Conservative government’s privacy reform bill sitting untouched after being introduced about two years ago, New Democractic Party MP Charmain Borg has introduced a private member’s bill that that would make it mandatory for organizations to report data breach incidents.

Bill C-475, Borg’s proposed amendment to the federal Personal Information Protection and Electronics Document Act (PIPEDA), echoes what Canadian consumer and privacy advocacy groups have been clamoring for – more teeth to the existing privacy legislation that only requires voluntary reporting of breaches.

Read more on IT World Canada.

You can read the text of the bill here.  The language of the proposed bill is generally stronger than what we have seen proposed here in Congress:

10.01 (1) For the purposes of this section and section 10.02, “harm” includes bodily harm, humiliation, embarrassment, injury to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, identity fraud, negative effects on credit rating and damage to or loss of property.

(2) An organization having personal information under its control shall notify the Commissioner of any incident involving the loss or disclosure of, or unauthorized access to, personal information, where a reasonable person would conclude that there exists a possible risk of harm to an individual as a result of the loss or disclosure or unauthorized access.

It also contains a provision that the entity can be ordered to stop collecting personal information:

12.11 Upon completion of an investigation of a complaint, the Commissioner may order the organization that is the object of the complaint to take the necessary actions to comply with this Act, which may include
(a) correcting its practices in order to comply with sections 5 to 10, including by

(i) fulfilling any obligation under the Act,
(ii) destroying data,
(iii) ceasing to collect, use or disclose personal information, and
(iv) deleting or adding a record; and

(b) publishing a notice of any action taken or proposed to be taken to correct its practices, whether or not ordered to correct them under paragraph (a).

Michael Geist comments on it:

Bill C-475 is a far better proposal with amendments to PIPEDA with more clear cut security breach disclosure requirements along with order making power that is backed by significant penalties for compliance failures. Those provisions would do far to ensure greater respect for Canadian privacy law and give Canadians the assurance of notifications in the event of security breaches. What the bill does not do, however, is address the other side of the privacy coin, namely the failure of government to hold itself accountable for the personal information it collects and now regularly seems to fail to safeguard.

Category: Breach LawsLegislationNon-U.S.Of Note

Post navigation

← ABC Australia confirms data breach, target was old micro-site
AU: Soldiers' medical records found on road →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Turkish Group Hacks Zero-Day Flaw to Spy on Kurdish Forces
  • Cyberattacks on Long Island Schools Highlight Growing Threat
  • Dior faces scrutiny, fine in Korea for insufficient data breach reporting; data of wealthy clients in China, South Korea stolen
  • Administrator Of Online Criminal Marketplace Extradited From Kosovo To The United States
  • Twilio denies breach following leak of alleged Steam 2FA codes
  • Personal information exposed by Australian Human Rights Commission data breach
  • International cybercrime tackled: Amsterdam police and FBI dismantle proxy service Anyproxy
  • Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency
  • N.W.T.’s medical record system under the microscope after 2 reported cases of snooping
  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows
  • FTC dismisses privacy concerns in Google breakup
  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.