Valdra/Breach & Incidents

Know within minutes whether
you must notify the OPC

The PIPEDA RROSH (real risk of significant harm) test determines if an OPC report is mandatory. Our AI assessment walks through all six harm factors and produces a defensible written determination.

app.valdra.ai/rrosh-assessment
Section 6 of 7RROSH Assessment37%
11 of 30 questions answered · Estimated: 7 min remaining
Question 11
Does your organization collect personal information from individuals in Quebec?
AI Insight

Based on your answers, you may need a Privacy Impact Assessment under Law 25 §12.

Relevant legislation:
PIPEDA §4.3
Law 25 §12
CAI Guidance
Built for Canadian businesses
421+Entity Types
95%+F1 Accuracy
0 bytesData Retained
🍁Canadian Servers
PIPEDACertified
$100K

maximum fine per violation under PIPEDA

1 PIPEDA, s.28

Start Free Assessment
Gap Analysis Results
PIPEDA — April 2026
3 gaps found
Data Retention Policy
Critical
Consent Mechanisms
Compliant
Breach Response Plan
High
Access & Correction
Compliant
Third-Party Agreements
Critical

AI guidance at every step.

As you answer each question, our Claude-powered AI explains the relevant statutory requirement in plain English, flags your risk level, and suggests remediation steps — so your team learns while they comply.

Request a demo
Valdra
Compliance Certificate
OrganizationAcme Corp Ltd.
Assessment DateApril 14, 2026
Valid UntilApril 14, 2027
Frameworks CoveredPIPEDA · Law 25 · CASL
Overall Score
91/100Compliant
Remediation Roadmap1 of 4 done
Publish bilingual privacy policy
Legal
Critical
Designate a Privacy Officer (Law 25)
Exec
Critical
Add consent timestamps to signup
Eng
High
Document data retention schedule
Ops
Medium

From gap to resolved, automatically.

Every identified gap automatically creates a prioritized task with suggested remediation, assigned to the right team member. Track closure rates and demonstrate continuous improvement to your regulator.

Request a demo

Additional features

Request a demo

Six-Factor Harm Analysis

Evaluates sensitivity of information, probability of misuse, number of affected individuals, severity of harm, and vulnerability of individuals.

OPC Guidance Alignment

Each factor is assessed against current OPC RROSH guidance and enforcement decisions to ensure your determination reflects best practice.

Written Determination

Produces a signed, dated RROSH determination document suitable for your breach register and regulatory defense.

Mandatory Notification Trigger

If RROSH is confirmed, automatically triggers the OPC notification workflow, incident log, and 72-hour countdown.

Non-Notification Documentation

If RROSH is not met, generates documentation of why notification was not required — essential for your breach register.

Legal Review Integration

Flag the assessment for outside counsel review with a single click. Legal feedback is captured in the audit trail.

Get compliant and build trust

Join hundreds of Canadian organizations using Valdra to automate their privacy obligations — no consultants required.

Start Free — No credit card required

🍁 Canadian data residency · PIPEDA compliant · SOC 2 in progress

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

RROSH Assessment Tool | Valdra