Canwest reports that the federal government plans to introduce new security breach disclosure legislation that will provide considerable discretion for when businesses disclose instances of security breaches. There are apparently no penalties for failure to disclose. Given the potential impact of identity theft and the incentives to keep breaches secret, the law sounds so weak as to be close to useless.
Security Breach Disclosure Bill May Fall Short
April 25, 2008
Share this post
One Comment

Law Bytes
Episode 259: The Privacy and Surveillance Risks of AI Chatbot Reporting to Police
byMichael Geist

March 2, 2026
Michael Geist
February 23, 2026
Michael Geist
February 9, 2026
Michael Geist
Episode 256: Jennifer Quaid on Taking On Big Tech With the Competition Act's Private Right of Access
February 2, 2026
Michael Geist
The Law Bytes Podcast, Episode 255: Grappling with Grok – Heidi Tworek on the Limits of Canadian Law
January 26, 2026
Michael Geist
Search Results placeholder
Recent Posts
More Transparency Not Police Reporting: Navigating the Safety-Privacy Balance for AI ChatBots
The Law Bytes Podcast, Episode 259: The Privacy and Surveillance Risks of AI Chatbot Reporting to Police
Nobody Wants This: Senate Rejects Government’s Anti-Privacy Plan for Political Parties By Sending Bill Back to the House With a Sunset Clause
The Law Bytes Podcast, Episode 258: Jaxson Khan With an Insider Perspective on AI Policy Development in Canada
Time for the Government to Fix Its Political Party Privacy Blunder: Kill Bill C-4’s Disastrous Privacy Rules

Only disclosure?
It seems to me that disclosure is not even the important issue. How come there is no liability? Could it be because personal information is being handled in a way that benefits the company or government and not the individuals concerned? A bank would be responsible if they left your money in a suitcase somewhere and someone walked off with it. “I left it on the bus” doesn’t cut it with money, why does it with information. Shouldn’t personal information be protected by the same rules? Whether loss or disclosure of personal information is deliberate or accidental doesn’t make any difference to the people effected.