With security breaches regularly affecting millions (or even billions) of people, effective security breach disclosure rules are an essential part of a modern privacy law framework. It may surprise many to learn that Canada still does not have mandatory security breach disclosure rules that require companies to notify affected individuals in effect. Rules were passed in 2015, but the accompanying regulations were puzzlingly slow to emerge. The government finally released proposed regulations late in the summer with a consultation that closed earlier this week. My submission, which focused on implementation, content of notices, and proposed “indirect” notification, is posted below.
Archive for October 4th, 2017

Law Bytes
Episode 276: Information Commissioner Caroline Maynard on Canada’s Access to Information Failures and Why Access Delayed is Access Denied
byMichael Geist

June 22, 2026
Michael Geist
Search Results placeholder
Michael Geist on Substack
Recent Posts
The Law Bytes Podcast, Episode 276: Information Commissioner Caroline Maynard on Canada’s Access to Information Failures and Why Access Delayed is Access Denied
Why the Government’s Plan for a Social Media Ban in Bill C-34 Is Unconstitutional
Outdated Data and Dubious Comparisons: Digging into the Government’s AI Strategy Adoption Claims
Why Being Locked Out of Frontier AI is The Sovereignty Threat Canada Missed
Blocked Twice: How Bill C-34’s Kids’ Social Media Ban Would Compound the Online News Act’s Harm to Young Canadians’ News Access

