The Breach Register PIPEDA Demands: Every Incident You Have to Keep
PIPEDA makes you keep a record of every breach you suffer, even the harmless ones. Most Canadian businesses never learn this rule exists until the OPC asks to see the log.
By Valdra Team
A laptop disappears from a sales rep's car in a Mississauga parking lot. It was encrypted, password-protected, powered off. The company decides, reasonably, that no one faces a real risk of significant harm. No report to the Office of the Privacy Commissioner. No notification to the people whose data sat on that drive. A defensible call.
Here is what most owners get wrong. That decision does not close the file. You still have to write the incident down, keep the record for at least two years, and hand it over if the OPC ever asks.
This is the quiet half of PIPEDA's breach regime, and it catches far more companies than the reporting rules do. Everyone has heard that serious breaches must be reported. Almost nobody has absorbed the second sentence: you record every breach, full stop.
What the law actually says
The duty lives in section 10.3 of PIPEDA and in the Breach of Security Safeguards Regulations (SOR/2018-64), in force since November 1, 2018. The wording is short and unforgiving:
"An organization shall keep and maintain a record of every breach of security safeguards involving personal information under its control."
Every breach. Not every *reportable* breach. Not every breach that clears a harm threshold. Every one.
The distinction matters because PIPEDA runs two separate tests. The first is the real risk of significant harm (RROSH) test in section 10.1, which decides whether you report to the OPC and notify individuals. Bodily harm, humiliation, reputational damage, financial loss, identity theft, lost employment or business opportunity, the regulator weighs each against the sensitivity of the data and the probability of misuse. Clear the threshold and you report "as soon as feasible."
The record-keeping duty in 10.3 sits apart from that test. A breach that fails RROSH, that you correctly never report, still goes in the log. The encrypted laptop goes in the log. The email sent to the wrong client goes in the log. The misconfigured folder that exposed three records for an hour before someone caught it goes in the log.
Why a breach register PIPEDA requires exists at all
If a breach is harmless enough that you tell no one, why does Ottawa care that you wrote it down?
Two reasons, both about the OPC's ability to check your work. The breach register PIPEDA demands gives the Commissioner a way to audit your *judgment*, not just your worst incidents. Section 10.3(2) is blunt: on request, you must give the Commissioner access to, or a copy of, the record. No threshold, no warrant, no investigation needed first. And the OPC is not only interested in the breaches you reported. It wants the ones you decided *not* to report, so it can test whether your RROSH assessments hold up.
There is the trap. A company that reports nothing might be genuinely clean, or it might be quietly lowballing every harm assessment to dodge the paperwork and the reputational hit. The register is how the regulator tells the two apart. An empty log from a 200-person firm handling health or financial data does not read as careful. It reads as nobody paying attention.
The second reason is pattern detection. Twelve "minor" misdirected emails in a quarter are not twelve trivial events. They are one broken process, and a kept register surfaces that long before it becomes a reportable catastrophe.
What every entry has to contain
The regulations set the floor. Each record must let the OPC verify you applied the RROSH test correctly, which in practice means every entry needs:
- The date or estimated date of the breach, plus when you became aware of it (often a different date)
- A description of the circumstances, what happened and how
- The nature of the information involved, the actual data elements exposed
- Whether the breach was reported to the Commissioner and whether individuals were notified
- Your assessment of the risk of harm, the reasoning behind the report-or-not decision
That last element is the one people skimp on and the one the OPC cares about most. "Decided not to report" is not a record. "Laptop encrypted AES-256 full-disk, powered off at time of loss, no evidence of compromise, contents limited to public-facing contact data, RROSH not met" is a record. The reasoning is the entire point.
You keep each record for at least 24 months after the day you determine the breach occurred. Twenty-four months is the floor, not the ceiling. PIPEDA complaints and class actions can surface long after the fact, so keeping records well past the minimum is the safer instinct.
The penalty most people miss
Failing to report a reportable breach gets the headlines. But knowingly failing to keep the record under 10.3(1) is itself an offence under section 28, an indictable offence carrying a fine of up to $100,000. You can be flawless on reporting, never suffer a single reportable incident, and still expose yourself to a six-figure penalty purely for not maintaining the log.
One detail to keep straight: the OPC does not levy that fine itself. It refers the matter to the Attorney General, and the Director of Public Prosecutions decides whether to prosecute. The word *knowingly* sets a real bar, intent rather than an honest slip. But "we never bothered to set up a register" starts to look a lot like knowing once you have ignored the obligation for years.
I have watched small companies treat this as theoretical. It is not. The OPC has run breach-record inspections precisely to test whether organizations keep the logs at all. And Bill C-27's proposed Consumer Privacy Protection Act, if it ever clears Parliament, lifts the ceilings into the tens of millions or a percentage of global revenue. Betting that today's regime is the strictest it will ever be is not a plan.
Quebec runs a parallel, stricter track
One employee or customer in Quebec and PIPEDA is no longer the whole story. Law 25 carries its own register requirement, enforced by the Commission d'accès à l'information (CAI), and it bites harder in two places. The "confidentiality incident" register must be maintained and produced to the CAI on demand. The notification trigger is a "risk of serious injury," weighed against the sensitivity of the data, the consequences of its use, and the likelihood it gets used for harm.
The sharper difference is retention. Quebec requires the incident register to be kept for five years after the organization becomes aware of the incident, more than double the federal 24 months. A company operating in both jurisdictions cannot keep one log and call it finished. The fields overlap heavily but not perfectly, and a Quebec auditor and a federal one will ask different questions of the same incident. Ontario health-sector organizations layer a third regime on top under PHIPA, with the IPC expecting its own documentation of breaches involving personal health information.
How to do this without losing your mind
The failure mode I see constantly is a register that lives in one person's head, or in a stray spreadsheet they update when they remember. That holds right up until they leave, or until the OPC gives you 30 days to produce two years of records you never actually wrote down.
A working register needs three things. A fixed template, so every entry captures the regulatory fields. A defined intake, so incidents reliably reach the log instead of getting handled by hallway conversation and forgotten. And automatic retention, so the 24-month clock (or Quebec's five years) does not depend on anyone remembering it. The reasoning behind each report-or-not call has to be written *at the time*, not reconstructed under audit pressure once memories have gone soft.
For most Canadian businesses, the ones without a $500K consultant on retainer, this is the obligation that is easy to defer and expensive to ignore. The harmless breach you skipped logging is the one the OPC asks about. If you would rather the log keep itself, capture each incident with the right fields, run the RROSH and Law 25 assessments, and hold everything for the full retention period, let Valdra keep your breach register for you.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Try Valdra