Canada To Fine Companies For Not Reporting Data Breaches
The news of Canada to fine companies for not reporting data breaches is making headlines these days. Know what it means for your business.

On Sept. 2, the Canadian Government announced an update to the Digital Privacy Act (June 2015) that will make it mandatory for all Canadian companies to report if their data has been breached. Currently, Alberta is the only province where companies are required to report breaches by law. This change makes this a requirement across the country.
Under the new proposed rules, any company that has a data breach will be required to do a risk assessment to determine if the breach poses a “Risk of significant harm”. If so, they’re required to notify all individuals that are affected and also report the breach to the Canadian Privacy Commissioner’s Office.
A 2017 study by the Ponemon Institute found data breaches are most expensive in the United States and Canada. The average per capita cost of a data breach was $225 in the United States and $190 in Canada. However, because breach reporting is not mandatory, it’s difficult to get a full picture of the number of breaches. Still, over the last few years, there have been a number of high-profile data breaches where the personal information of Canadians was stolen. It’s hoped that mandatory reporting will create an incentive for organizations to take information security more seriously.
The consequences for organizations that decide not to comply with the new rules are two-fold. First of all, is the public relations nightmare that occurs when knowledge of the breach eventually becomes public. Typically this comes in the form of loss of confidence in the brand and will result in loss of customers; up to a third of customers will leave after a breach. Second, are the fines for non-compliance under the proposed new rules; up to $10,000 for a summary offense and up to $100,000 for an indictable offense.
A capable CIAM platform makes it far easier to manage and secure customer profile data, which is the most reliable way to stay ahead of these rules.
More like this
All Scams & Cybersecurity- Scams & CybersecurityThe AT&T Breach Lifecycle: Why Your 'Old' Data Is Getting More DangerousAT&T's $177M settlement covers 73M customers, but the real story is how breach data from 2019 just resurfaced in 2026 with fully…
- Scams & CybersecurityThe Instagram API Scraping Crisis: When 'Public' Data Becomes a 17.5 Million User Breach17.5 million Instagram accounts leaked through API scraping. Meta denies breach, but your data is on the dark web. Here's what actually…
- Scams & CybersecurityWhen the Data Breach Alarm Fails: A Global Guide to Who Should Tell You and How to Protect YourselfYour data is constantly at risk, but who's required to tell you when it's compromised?
Get new Scams & Cybersecurity writing
Enjoyed this? Subscribe and tell us what you read most. Scams & Cybersecurity is already ticked for you. No tracking pixels, unsubscribe with one click.