ClearBreach

How ClearBreach works

Canadian privacy law places identical obligations on a two-person clinic and a two-thousand-person corporation. Most small businesses and professional practices face those obligations without a privacy officer or legal team to navigate them. ClearBreach applies the legal interpretation for you, answer questions about your situation and receive every required document automatically.

Answer questions about your breach, your compliance program, or a planned project. ClearBreach generates every report, policy, and assessment Canadian privacy law requires, built on OPC and OIPC published guidance.

Three workflows, one record

The three assessments are not three products. They are one account, and signing in lands on it. Every assessment you have run stays there with its date and what it came back as, the compliance result stays on the page area by area, and the next annual re-assessment carries the date it falls due.

That matters after the incident rather than during it. A regulator asking what you had in place, an insurer at renewal, or a client’s security questionnaire are all answered from the same page, months later, by whoever is in the chair that day.

The counts are all it holds. How many duties are unmet in each area, never which ones. Your answers stay in your browser and in the answer file you download, and the page says so itself underneath the table.

Breach assessment

You found out this morning. Somebody needs to know whether this has to be reported, to whom, and by when, and the answer has to be defensible later, when nobody remembers what was known at nine o'clock.

A structured wizard of 28 to 36 questions walks you through your breach. The rules engine evaluates every answer against applicable legislation and produces your full document set.

An assessment from the questions to the documents. The questions are sped up and the clip says so while it does it; from the verdict onward it runs at real speed. Recorded from the product. No sound.
01

Answer questions about your breach

Data types involved, number of individuals affected, whether the breach was isolated or systemic, and your operating jurisdiction. Question count varies by province due to conditional routing.

02

The rules engine evaluates in real time

ClearBreach applies the Real Risk of Significant Harm (RROSH) test under PIPEDA, and the equivalent thresholds under Alberta PIPA and BC PIPA. Where more than one applies, each is assessed on its own, one answer per framework, and a single combined obligation set built from all of them.

03

All required documents generated automatically

Every required document is produced from your answers, nothing to draft manually. Download and use immediately.

Up to six documents. Zero drafting.

Every document required to respond to a Canadian privacy breach is generated automatically from your assessment answers. Three documents are always produced, up to four additional regulator reports are generated based on which obligations are triggered.

The first page of a generated OIPC Alberta PIPA breach notification report for ACME Retail, showing the submission address, the counsel-review notice, and a panel listing the form fields the Commissioner will also ask for.
A page of one of them, the OIPC Alberta report, on the regulator's own April 2024 form. This is the file, converted to a picture, not a drawing of it.

Try it on a real breach → and the compliance assessment is here →

3 documents always generated · up to 3 more, one per regulator whose reporting obligation is triggered

1.

Assessment Verdict Card

Always

The determination under each framework that applies to you, in the same three words the assessment itself uses, with the reasoning behind it and the obligations it triggers, the primary record of your assessment.

2.

Internal Incident Record

Always

Internal documentation required for your compliance file. Includes full incident details, assessment results, and a response log.

3.

Individual Notification Letter

Always

Draft notification to affected individuals, one section per applicable framework. Where Alberta PIPA applies it also carries the PIPA Regulation s.19.1 content, cited heading by heading, so a single letter satisfies both.

4.

OPC PIPEDA Breach Report

Conditional

Pre-drafted submission to the Office of the Privacy Commissioner of Canada. Generated when PIPEDA reporting obligations are triggered.

5.

OIPC Alberta PIPA Report

Conditional

Mirrors the official April 2024 OIPC Alberta form, Sections A through E. Generated when AB PIPA reporting obligations are triggered.

6.

OIPC BC PIPA Report

Conditional

Voluntary report to the OIPC BC. Generated when BC PIPA obligations are identified.

Three answers, one per framework

Every framework that applies to you is assessed separately and returns its own answer. There is no overall score and no risk rating. Canadian privacy law asks whether a real risk of significant harm exists, not whether risk passes some threshold, so the assessment answers that question, once per framework, and says what follows from it.

Reporting required

A real risk of significant harm was identified and this framework imposes a mandatory duty. Regulator reporting and individual notification obligations apply, and the reports are generated for you.

Voluntary report recommended

There is a real signal here, but this framework does not compel a report. BC PIPA has no mandatory breach-notification trigger, so a breach that is mandatory federally comes back as recommended in British Columbia. The report is still prepared for you.

No reporting obligation

No mandatory duty was triggered under this framework. That is not the same as safe: you are still required to keep a record of the breach, and it is generated for you.

Why the same breach can end in two different answers

ACME Retail has customers in Alberta, British Columbia, Ontario and Quebec. One incident, 18,400 people affected, the same facts assessed under every framework that applies. Quebec has its own Act, which ClearBreach does not assess, so it returns nothing here:

Alberta PIPAReporting required
BC PIPAVoluntary report recommended
PIPEDAReporting required

British Columbia differs because BC PIPA has no mandatory breach-notification trigger, not because the breach is less serious there. Missing that distinction is exactly what an obligation set per framework is for.

See the full verdict for this incident →

Jurisdiction coverage

PIPEDA

Federal private sector privacy legislation. Applies to all organizations operating across provincial borders or in non-PIPA provinces.

Alberta PIPA

Alberta's provincial privacy legislation. Applies to private sector organizations operating in Alberta.

BC PIPA

British Columbia's provincial privacy legislation. Applies to private sector organizations operating in BC.

Multi-jurisdiction assessment

PIPEDA, Alberta PIPA, and BC PIPA assessed simultaneously in one workflow. All applicable frameworks evaluated together, producing a single combined obligation set.

Out of scope: Quebec Law 25 is permanently outside ClearBreach scope and is not assessed.

Built for privacy

Breach details never leave your browser

Your answers about the breach are processed entirely client-side. Only anonymous metadata is recorded (the verdict tier, the province count and the framework count) never the breach details themselves. The compliance assessment records a score per area. A PIA does store the initiative and privacy officer names, because it is a document you file and return to.

Canadian data residency

Production infrastructure is hosted in Canada. Your organization data stays in Canada.

Grounded in Canadian law

Assessment logic is built on the text of PIPEDA, Alberta PIPA, and BC PIPA and published OPC and OIPC guidance. ClearBreach produces a preliminary risk assessment, not a legal opinion. Engage a privacy lawyer before submitting reports to regulators.

Why most privacy compliance resources require expertise to use →

Compliance guides

Alongside the assessment workflows, ClearBreach publishes practical step-by-step guides covering proactive privacy obligations under PIPEDA, Alberta PIPA, and BC PIPA, privacy officer designation, complaint handling procedures, privacy impact assessments, and the legislative requirements under each jurisdiction.

Browse compliance guides →

Annual compliance assessment

The insurance renewal questionnaire asks whether you have a privacy policy, a named privacy officer, and a retention schedule. So does the security review your largest client sends every year. Both are answered from one document set you already have, and the year you cannot answer them is the year somebody asks why.

A structured assessment maps your privacy practices across 10 areas, tells you which duties you are not meeting, and writes the documents that close them.

01

Answer questions about how you actually work

Who is accountable, what you collect and why, how long you keep it, who your vendors are, and what happens when something goes wrong. Questions that cannot apply to you are not asked, and questions that cannot be scored are not counted against you.

02

Every area is scored on its own

Each area is measured against the duties the legislation actually imposes on you, in your province and your sector. A gap is recorded with the provision behind it, so the finding can be traced rather than taken on trust.

03

The documents that close the gaps are generated

Not a list of things to go and write. The privacy policy, the incident response plan, the registers and the rest are produced from your own answers, with your organization named in them.

The 10 areas

Two of them are critical: an area with nothing in place under Security Safeguards or Incident Management sets your overall status on its own, however well the rest is going.

Accountability and Governance
Privacy Policy and External Communication
Consent and Collection
Retention and Disposal
Security SafeguardsCritical
Access and Correction
Training and Awareness
Service Provider Management
Incident ManagementCritical
Commercial Email (CASL)

Where you stand, and against what

The assessment returns one of three statuses. You are shown all three, because a status with nothing to compare it against tells you nothing.

On Track

No unmet legal duty, no area unaddressed, and at most one area substantially incomplete.

Needs Attention

At least one unmet legal duty, or an area with nothing in place, or two areas substantially incomplete.

At Risk

A critical area with nothing in place, or three or more areas substantially incomplete.

7 documents. Zero drafting.

7 are always produced. One more is offered where you need it, and withheld with a reason where you do not.

1.

Gap remediation roadmap

Always

Every gap found, in priority order, each with what is missing, what closes it, and the provision that requires it.

2.

Incident response plan

Always

What your organization does when a breach happens, written before you need it, the plan the breach workflow assumes you already have.

3.

Privacy management programme

Always

The programme documentation a regulator asks for: who is accountable, what the policies are, and how they are kept current.

4.

Personal information inventory

Always

What personal information you hold, where it lives, why you have it, and how long you keep it.

5.

Privacy registers

Always

The running records (access requests, complaints, breaches, vendors) that turn a policy into evidence you followed it.

6.

Internal privacy policy

Always

How your own staff must handle personal information, in words they can act on.

7.

Complaint handling procedure

Always

How a privacy complaint reaches the right person and what happens next, which every Canadian framework requires you to have.

8.

Public privacy policy template

Conditional

Offered where you do not already publish one. Where you do, it is withheld and the reason is given, rather than inviting you to replace a working policy with a generic one.

A ClearBreach compliance question with its authority panel open, showing the provision of the Act the question comes from and what to do if the answer is no.
Every question can show the provision it comes from. That is the difference between a finding you can check and one you have to take on trust.

See a complete compliance assessment →

Privacy impact assessment

You are about to sign up for something, a booking system, a payroll provider, a tool that reads your customer list. Nobody thinks of that as a privacy decision until afterwards. Some of those choices carry duties that arrive from the shape of what you are doing, not from a box anybody remembers to tick, information leaving Canada is the clearest one.

A privacy impact assessment is the record that you looked before you signed. It is cheap to produce beforehand and impossible to produce afterwards.

01

Describe the initiative and what it touches

What you are planning, what personal information it needs, who it comes from, and where it goes. The scope is stated and held to: what you exclude is written down as excluded, so the assessment cannot quietly be read as covering more than it did.

02

Each movement of information is placed under an Act

Every flow is assessed on its own, because the governing Act follows the activity rather than the organization. A clinic in Alberta is under Alberta PIPA for what it does in Alberta, whatever else it does elsewhere.

03

Risks are scored, and the completed PIA is generated

Duties you have not met are listed as open findings with the provision behind each. Risks that remain after your own mitigations are scored and banded. The finished assessment is a document you retain, or file where a regulator asks for one.

What it produces

Every flow, placed under an Act

2 movements of information in the sample assessment, each named, each with the Act that governs it and the reason that Act applies.

Duties you have not met yet

8 open findings in the sample, each carrying the provision it comes from and the action that closes it.

Risk that remains after mitigation

Each risk is scored on what is left once your own controls are counted, and banded, so effort goes where the residual risk actually is.

One completed PIA document is generated, ready to retain or to file. The sample below is a real one, produced by the same engine a subscriber uses.

Why a PIA is not optional as often as people think

ACME Dental planned one ordinary thing: online appointment booking. The vendor hosts it outside Canada, and that single fact is what makes the assessment compulsory rather than advisable.

A patient books or reschedules an appointment through the website

Alberta PIPA · leaves Canada for United States

The booking system sends the appointment to the practice-management software

Alberta PIPA · stays in Canada

Both movements sit under the provincial Act, not the federal one, because the activity happens in Alberta. Which Act applies follows what you are doing and where you are doing it, not where the business is registered.

See the completed assessment →

The ClearBreach privacy impact assessment flows screen: two movements of information for ACME Dental, each with the province it happens in and whether it can be reached from outside Canada.
Each movement is asked about one at a time, because where it happens decides which law applies to it.

Ready to run your assessment?

Know what you owe. Know it now.

Get early access

MSP plans available. See what MSPs get or see pricing.