ClearBreach

Built for Canadian privacy law

Everything Canadian privacy law requires, generated automatically.

Answer questions about your breach, your compliance program, or a planned project. ClearBreach produces the reports, policies, and assessments your organization needs, built on OPC and OIPC published guidance.

Every document the law requires. $799/year.

Breach details are assessed in your browser and never sent to us. Canadian hosting. How we handle your information →

Our mission

ClearBreach makes privacy expertise affordable and accessible to Canadian small businesses.

Three tracks. All outputs generated automatically.

Every example below is real output from the assessment engine, not a mock-up.

Breach response

You found out this morning.

A guided assessment against PIPEDA, Alberta PIPA and BC PIPA, each answered separately. Up to 6 documents generated, the verdict card, an internal incident record, a notification letter, and the regulator reports your answers trigger.

See a real verdict →

Compliance programme

The insurance renewal asks whether you have a privacy policy.

An annual assessment across 10 areas, telling you which duties you are not meeting. 7 documents generated from your own answers, from the privacy policy to the incident response plan.

See a complete assessment →

Privacy impact assessment

You are about to sign up for something.

Each movement of information placed under the Act that governs it, with the duties you have not met listed against the provision behind each. One completed PIA, ready to retain or file.

See a completed PIA →

One breach. Three different answers.

ACME Retail had one incident affecting 18,400 people, with customers in Alberta, British Columbia, Ontario and Quebec. The same facts, assessed under every framework that applies to them:

Alberta PIPA

Reporting required

BC PIPA

Voluntary report recommended

PIPEDA

Reporting required

British Columbia differs because BC PIPA has no mandatory breach-notification trigger, not because the breach is less serious there. Quebec has its own Act, which ClearBreach does not assess. Getting that wrong in either direction is the thing an obligation set per framework exists to prevent.

The ClearBreach verdict screen for ACME Retail: Alberta PIPA reporting required, British Columbia PIPA voluntary report recommended, PIPEDA reporting required, with the reasoning under the Alberta determination and the four obligations it triggers.
The screen itself, from the product. The three answers above are the ones it returned for this incident.

See the full verdict for this incident →

Or answer this assessment yourself →

Built for privacy

Breach details never leave your browser

Your answers about the breach are assessed entirely in the browser. What is recorded is the provinces, how many frameworks applied, and the outcome, never what happened or to whom.

What the other two workflows keep

The compliance assessment records a score per area and nothing else. A privacy impact assessment does store the name of the initiative and of your privacy officer, because it is a document you file and return to a year later.

Canadian data residency

Production infrastructure is hosted in Canada, and your organization data stays in Canada.

The assessment logic is built on the text of PIPEDA, Alberta PIPA and BC PIPA and on published OPC and OIPC guidance, not a generic privacy checklist. ClearBreach produces the documents a legal conversation needs. It is not legal advice, and a privacy lawyer should see anything before it goes to a regulator.

What it requires of your profession

The law does not have a chapter for dentists and another for mortgage brokers. It has one set of obligations that lands differently depending on what you hold.

Privacy law by industry →

For IT Service Providers

Your client just called. They had a breach.

PIPEDA, Alberta PIPA, BC PIPA, different thresholds, different timelines, different regulators. ClearBreach MSP gives you and your clients one structured assessment and generates every required document from it automatically. You look like the expert in the room.

See how ClearBreach works for MSPs →

Who builds it

ClearBreach is built by Yong Du, founder and privacy officer, after more than a decade in enterprise cybersecurity and IT operations in western Canada. The assessment framework and every document it produces are his work, built on published OPC and OIPC guidance and enforcement findings.

About ClearBreach, and who is behind it →

Ready to get started?

From breach response to annual program management, everything Canadian privacy law requires, generated from your answers.

Get early access

MSP plans available. See pricing.