With security breaches regularly affecting millions (or even billions) of people, effective security breach disclosure rules are an essential part of a modern privacy law framework. It may surprise many to learn that Canada still does not have mandatory security breach disclosure rules that require companies to notify affected individuals in effect. Rules were passed in 2015, but the accompanying regulations were puzzlingly slow to emerge. The government finally released proposed regulations late in the summer with a consultation that closed earlier this week. My submission, which focused on implementation, content of notices, and proposed “indirect” notification, is posted below.
Archive for October 4th, 2017

Law Bytes
Episode 261: Ian Goldberg on the Privacy Risks of Age Assurance Technologies
byMichael Geist

March 16, 2026
Michael Geist
March 2, 2026
Michael Geist
February 23, 2026
Michael Geist
February 9, 2026
Michael Geist
Search Results placeholder
Recent Posts
The Lawful Access Privacy Risks: Unpacking Bill C-22’s Expansive Metadata Retention Requirements
The Law Bytes Podcast, Episode 261: Ian Goldberg on the Privacy Risks of Age Assurance Technologies
Government Enacts Political Party Anti-Privacy Rules With Bill C-4 Royal Assent Sprint
A Tale of Two Bills: Lawful Access Returns With Changes to Warrantless Access But Dangerous Backdoor Surveillance Risks Remain
Words Are Not Enough: Countering Relentless Antisemitic Violence in Canada With Action

