What to do if a customer's information is exposed

Report to the Privacy Commissioner only when there is a real risk of significant harm. Keep a record of every breach regardless, for two years. The second obligation is the one nobody knows about.

A breach does not require a hacker. A laptop left in a van, an invoice emailed to the wrong homeowner, a spreadsheet of customer addresses shared with a supplier who did not need it — each is a breach of security safeguards, and the obligations below attach to all of them.

The reporting threshold

You must report a breach to the Privacy Commissioner where it creates a real risk of significant harm to an individual. Not every breach meets that bar; the assessment turns on two things.

  • How sensitive the information is. Medical and financial records sit at the sensitive end. Context matters — an address alone is ordinary, an address combined with the fact that a house is empty for three weeks is not.
  • How likely it is to be misused. Who saw it, how long it was exposed, whether there is any sign of malicious intent, whether several pieces of information were exposed together, and whether it reached someone likely to cause harm.

Where that threshold is met you must also notify the affected individuals directly, and both the report and the notification must happen as soon as feasible after you determine the risk exists.

The obligation almost nobody knows about

You must keep a record of every breach of security safeguards — including the ones you assessed as harmless and did not report — and keep those records for two years.

This catches small businesses out, because the intuition is that a breach you decided not to report is a breach that is over. It is not. The Commissioner can ask to see your breach records, and "we judged it harmless" is a defensible position only if you wrote down the judgement at the time.

A record should capture the date, the circumstances, what kinds of information were involved, and whether you reported or notified. For most plumbing companies a single dated document is enough. The point is that it exists.

The order to do things in

  • Contain it. Get the laptop back, revoke the access, recall what can be recalled.
  • Work out what was exposed, and whose. You cannot assess risk without knowing the scope.
  • Assess real risk of significant harm against sensitivity and probability of misuse.
  • Report and notify if the threshold is met — as soon as feasible, not at the end of the month.
  • Write the record either way, and keep it two years.

Reducing how much you hold in the first place is the only measure that shrinks every one of these steps at once. A breach of records you deleted on schedule is not a breach at all — which is the practical argument for taking retention seriously before anything goes wrong.

This is a plain-language summary of published guidance, not legal advice. Every claim above is sourced below. For a decision that carries real consequence for your business, talk to a lawyer who practises privacy law in your province.

Sources

Checked against the Office of the Privacy Commissioner of Canada on .

Related