With security breaches regularly affecting millions (or even billions) of people, effective security breach disclosure rules are an essential part of a modern privacy law framework. It may surprise many to learn that Canada still does not have mandatory security breach disclosure rules that require companies to notify affected individuals in effect. Rules were passed in 2015, but the accompanying regulations were puzzlingly slow to emerge. The government finally released proposed regulations late in the summer with a consultation that closed earlier this week. My submission, which focused on implementation, content of notices, and proposed “indirect” notification, is posted below.
Archive for October 4th, 2017

Law Bytes
Episode 253: Guy Rub on the Unconvincing Case for a New Canadian Artists' Resale Right
byMichael Geist

December 8, 2025
Michael Geist
December 1, 2025
Michael Geist
November 24, 2025
Michael Geist
November 17, 2025
Michael Geist
November 10, 2025
Michael Geist
Search Results placeholder
Recent Posts
Confronting Antisemitism in Canada: If Leaders Won’t Call It Out Without Qualifiers, They Can’t Address It
“Shock” and the Bondi Beach Chanukah Massacre
The Catch-22 of Canadian Digital Sovereignty
The Law Bytes Podcast, Episode 253: Guy Rub on the Unconvincing Case for a New Canadian Artists’ Resale Right
The Most Unworkable Internet Law in the World: Quebec Opens the Door to Mandating Minimum French Content Quotas for User Generated Content on Social Media

