With security breaches regularly affecting millions (or even billions) of people, effective security breach disclosure rules are an essential part of a modern privacy law framework. It may surprise many to learn that Canada still does not have mandatory security breach disclosure rules that require companies to notify affected individuals in effect. Rules were passed in 2015, but the accompanying regulations were puzzlingly slow to emerge. The government finally released proposed regulations late in the summer with a consultation that closed earlier this week. My submission, which focused on implementation, content of notices, and proposed “indirect” notification, is posted below.
Archive for October 4th, 2017

Law Bytes
Episode 278: Ben Waldman on Gander Social and the Challenges of Building a Sovereign Social Network
byMichael Geist

August 10, 2026
Michael Geist
Search Results placeholder
Michael Geist on Substack
Recent Posts
Digital Trade Alignment: What May Be in Play in the Canada-U.S. Trade Deal
TMU Picks Damage Control Over Fixing the Damage: Behind Its Shameful Response to the Devastating Benotto Report on Campus Antisemitism
Thanks For Joining the Movement: French Constitutional Council Strikes Down Kids’ Social Media Ban
Denial, Hate, and Silence: The Three Responses to Overwhelming Evidence of Canada’s Campus Antisemitism Crisis
The Law Bytes Podcast, Episode 278: Ben Waldman on Gander Social and the Challenges of Building a Sovereign Social Network

