Valdra/AI Agents

Handle a breach calmly,
with the clock tracked for you

Breach Triage guides your team through a privacy incident end to end: it runs the real-risk-of-significant-harm assessment, tracks your statutory notification deadline, drafts the regulator report and individual notices, and assembles the evidence package — so nothing slips on your worst day.

app.valdra.ai/incidents/breach-triage
Incident INC-2026-060
Breach Triage
CRITICAL
OPC Notification Required In
29:23:11
Hours : Minutes : Seconds
Incident Timeline
1. Incident Detected
2. Investigation Started
3. OPC Notification
4. Parties Notified
OPC ReportDRAFT
Organization: Acme Corp
Date of breach: Apr 12, 2026
Individuals affected: 928
Data types: Name, SIN, DOB
RROSH assessment: ✓
Built for Canadian businesses
421+Entity Types
95%+F1 Accuracy
0 bytesData Retained
🍁Canadian Servers
PIPEDACertified
24 mo

how long PIPEDA requires you to keep a record of every breach — reportable or not

1 PIPEDA Breach of Security Safeguards Regulations

Start Free Assessment
OPC Breach Notification — Draft
47h 23m left
Incident Summary
Unauthorized access to customer database on April 12, 2026. Approximately 1,200 records including names, emails, and account numbers affected.
Records Affected
1,200
Data Types
Name, Email, Account #
Risk Level
Real Risk of Harm
OPC Report
Required

The OPC clock starts at breach, not discovery.

The 72-hour notification window under PIPEDA begins when the breach occurs — not when you realize it happened. Valdra starts the clock automatically and walks you through every required step before the deadline.

Request a demo
Affected Party NotificationTemplate · En/Fr

Subject: Important notice about your personal information

Dear [First Name],

We are writing to inform you of a security incident that may have affected your personal information held by [Company].

What happened: On [Date], we discovered that...

Legally reviewed · Meets OPC plain language standards
Breach Response Timeline47h 23m to deadline
Breach detected14:02
Contained15:18
RROSH assessed — reportable16:40
OPC notifiedpending
Individuals notifiedpending

Every letter, every document, generated.

OPC notification letters, affected party notifications, and internal incident reports are auto-generated from your incident data. Plain language, legally reviewed templates — done in minutes, not hours.

Request a demo

Additional features

Request a demo

Guided Intake

Log an incident in minutes — what happened, what data, how many people — and the agent structures it into a defensible record from the first minute.

RROSH Determination

Works through the real-risk-of-significant-harm test that decides whether you must notify, and explains its reasoning so you can stand behind it.

Deadline Tracking

Once notification is required, Valdra tracks the statutory clock and counts down the hours remaining so a reporting window never quietly passes.

Regulator Report Drafting

Drafts the breach report for the OPC (and CAI for Quebec) from the incident details — review, adjust, and file instead of starting from a blank page.

Notification Letters

Generates plain-language notices to affected individuals, worded to meet the requirement, ready to review and send.

Evidence & Register

Every action is timestamped into your breach register and kept the way the law expects — your defensible record if a regulator asks.

Frequently asked questions

What is RROSH?

Real Risk of Significant Harm — the legal test under PIPEDA (SOR/2018-64) that determines whether a breach must be reported to the OPC and affected individuals. Breach Triage works through it with you and records the reasoning.

Does it file to the regulator automatically?

No. It drafts the regulator report and notices from your incident so you can review and file. You stay in control of what is submitted.

Does it cover Quebec Law 25 breaches?

Yes. It supports the federal OPC process and Quebec CAI notices; the workflow, deadline tracking, letters, and audit trail apply regardless of regulator.

Get compliant and build trust

Join hundreds of Canadian organizations using Valdra to automate their privacy obligations — no consultants required.

Start Free — No credit card required

🍁 Canadian data residency · PIPEDA compliant · SOC 2 in progress

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

Breach Triage — AI Breach Response & RROSH | Valdra