A privacy breach occurs when personal information is lost, stolen, accessed without authority, or disclosed to the wrong party. Common breach scenarios in insurance include: a laptop with unencrypted client files is stolen, a document containing medical information is sent to the wrong email address, or a paper file is left accessible in a public area.
Under PIPEDA (as amended by the Digital Privacy Act, in force since 2018), organizations must:
- Assess whether the breach creates a real risk of significant harm to any individual
- Report the breach to the Office of the Privacy Commissioner of Canada if the real-risk-of-significant-harm threshold is met
- Notify affected individuals whose information was involved in the breach where the real-risk test is met
- Maintain a breach log of all breaches, regardless of whether the risk threshold is met, and retain records for at least 24 months
Significant harm includes bodily harm, humiliation, damage to reputation or relationships, financial loss, identity theft, and negative effects on employment or insurance coverage.
Quebec's Law 25 imposes additional obligations, including notifying the Commission d'acces a l'information du Quebec and affected individuals regardless of the harm threshold in certain circumstances.
Common mistake: waiting to report a breach while investigating. The notification obligation runs from the time the breach is discovered, not from when investigation is complete.
Recall: Name the three steps an agent or their brokerage must take after a privacy breach that meets the real-risk-of-significant-harm threshold.