Anonymised, illustrative composite. An agent's laptop was stolen with 47 clients' identification and financial records on it. PIPEDA drew two separate duties from the same breach — reporting one, recording the other.
At a glance
An agent’s laptop was stolen from a parked car outside an open house in Kitchener-Waterloo. The laptop was not encrypted, and it held active files for 47 clients — signed agreements, mortgage pre-approval financial details, and government-issued ID scans collected as part of the brokerage’s FINTRAC identification duties.
PIPEDA requires an organization to report a breach of security safeguards to the Privacy Commissioner where it is reasonable to believe the breach creates a real risk of significant harm — and, separately, to notify the affected individuals on the same trigger. Both duties carry the same timing standard, quoted directly from the Act: “as soon as feasible after the organization determines that the breach has occurred.”
The Act itself defines significant harm to include “identity theft” by name. An unencrypted device carrying government ID scans and financial records is close to the paradigm case that language was written for — the brokerage’s privacy officer did not need to wait for evidence of actual misuse before concluding the risk threshold was met.
47 client files were on the device. The privacy officer confirmed the theft, assessed the device as unencrypted, and concluded a real risk of significant harm existed by day 2. Reports to the Privacy Commissioner and notification letters to all 47 affected clients went out by day 6 — inside the “as soon as feasible” standard, though the Act sets no fixed number of days against which to measure that.
Separately, PIPEDA’s Breach of Security Safeguards Regulations require a written record of the breach to be kept for 24 months from the day the organization determines it occurred — a duty that runs independently of whatever conclusion is reached about reporting.
This case turns on two distinct duties inside the same section of the Act, and conflating them is the most common mistake. Section 10.1 requires reporting and notification once the significant-harm threshold is met. Section 10.3 requires something different and broader: “An organization shall… keep and maintain a record of every breach of security safeguards,” full stop — a duty the Act itself states is independent of whether the reporting threshold is met.
The regulations attach a specific number to that second duty: a record of every breach must be kept for 24 months after the day the organization determines the breach occurred. Even a breach a privacy officer correctly judges too minor to report to the Commissioner still has to be logged for two years — a step many agents assume is unnecessary the moment they decide not to report.
The brokerage reported and notified inside the “as soon as feasible” window and separately logged the breach in its own compliance file, satisfying both duties rather than treating the reporting decision as the end of the matter. No client reported actual misuse of their information in the months that followed, which the brokerage treated as good fortune, not as evidence the original risk assessment had been wrong.
For the risk standard itself, see the real and significant harm glossary entry, and for the information at stake, the personal information glossary entry. For a related access-rights question on the same category of client file, see a client who asked to see their own file.
Knowingly contravening the reporting duty in section 10.1 or the record-keeping duty in section 10.3 carries its own penalty under section 28: a fine of up to $10,000 on summary conviction, or up to $100,000 on indictment. The more common failure mode is not a knowing violation of either duty — it is assuming a decision not to report also closes out the record-keeping duty, when the two are legally independent. A brokerage that correctly decided a minor breach did not cross the significant-harm threshold, but never logged it for the required 24 months, has still failed a separate obligation under the same Act.
The tell is definitional: treating “no evidence of misuse yet” as the same thing as “no real risk of significant harm.” The statutory test is forward-looking and probabilistic — reasonable grounds to believe a real risk exists — not a wait-and-see standard that requires proof of actual harm before it applies. An unencrypted device carrying ID scans and financial records crosses that line on its own, before any client ever reports a problem.
Encryption is not a legal requirement stated anywhere in the sections cited here, but it changes the practical analysis: a properly encrypted device stolen under identical circumstances would give the privacy officer a materially different, and likely lower, risk assessment to work from.
A 30-minute call is enough to tell you whether AI pays for itself here.