Handle a breach calmly,
with the clock tracked for you
Breach Triage guides your team through a privacy incident end to end: it runs the real-risk-of-significant-harm assessment, tracks your statutory notification deadline, drafts the regulator report and individual notices, and assembles the evidence package — so nothing slips on your worst day.
how long PIPEDA requires you to keep a record of every breach — reportable or not
1 PIPEDA Breach of Security Safeguards Regulations
Start Free AssessmentThe OPC clock starts at breach, not discovery.
The 72-hour notification window under PIPEDA begins when the breach occurs — not when you realize it happened. Valdra starts the clock automatically and walks you through every required step before the deadline.
Request a demoSubject: Important notice about your personal information
Dear [First Name],
We are writing to inform you of a security incident that may have affected your personal information held by [Company].
What happened: On [Date], we discovered that...
Every letter, every document, generated.
OPC notification letters, affected party notifications, and internal incident reports are auto-generated from your incident data. Plain language, legally reviewed templates — done in minutes, not hours.
Request a demoAdditional features
Request a demoGuided Intake
Log an incident in minutes — what happened, what data, how many people — and the agent structures it into a defensible record from the first minute.
RROSH Determination
Works through the real-risk-of-significant-harm test that decides whether you must notify, and explains its reasoning so you can stand behind it.
Deadline Tracking
Once notification is required, Valdra tracks the statutory clock and counts down the hours remaining so a reporting window never quietly passes.
Regulator Report Drafting
Drafts the breach report for the OPC (and CAI for Quebec) from the incident details — review, adjust, and file instead of starting from a blank page.
Notification Letters
Generates plain-language notices to affected individuals, worded to meet the requirement, ready to review and send.
Evidence & Register
Every action is timestamped into your breach register and kept the way the law expects — your defensible record if a regulator asks.
Frequently asked questions
What is RROSH?
Real Risk of Significant Harm — the legal test under PIPEDA (SOR/2018-64) that determines whether a breach must be reported to the OPC and affected individuals. Breach Triage works through it with you and records the reasoning.
Does it file to the regulator automatically?
No. It drafts the regulator report and notices from your incident so you can review and file. You stay in control of what is submitted.
Does it cover Quebec Law 25 breaches?
Yes. It supports the federal OPC process and Quebec CAI notices; the workflow, deadline tracking, letters, and audit trail apply regardless of regulator.
Learn more about Valdra
Get compliant and build trust
Join hundreds of Canadian organizations using Valdra to automate their privacy obligations — no consultants required.
🍁 Canadian data residency · PIPEDA compliant · SOC 2 in progress