How ClearBreach works
Canadian privacy law places identical obligations on a two-person clinic and a two-thousand-person corporation. Most small businesses and professional practices face those obligations without a privacy officer or legal team to navigate them. ClearBreach applies the legal interpretation for you, answer questions about your situation and receive every required document automatically.
Answer questions about your breach, your compliance program, or a planned project. ClearBreach generates every report, policy, and assessment Canadian privacy law requires, built on OPC and OIPC published guidance.
Breach assessment
A guided assessment against PIPEDA, Alberta PIPA and BC PIPA, answering each separately. Up to 6 documents generated automatically, the verdict card, an internal incident record, a notification letter, and reports for OPC, OIPC Alberta and OIPC BC.
Annual compliance assessment
Gap identification across 10 compliance areas. Generates 7 documents from your own answers, a remediation roadmap, an incident response plan, a privacy management programme, a personal information inventory, privacy registers, an internal privacy policy and a complaint handling procedure.
Privacy impact assessment
Structured PIA wizard for new projects, systems, or data uses. Walks your organization through the assessment and produces a completed PIA document ready to retain or file with your regulator.
Compliance guides
Free step-by-step guides covering proactive obligations under PIPEDA, Alberta PIPA, and BC PIPA, privacy officer designation, complaint handling, PIAs, and the legislative requirements under each jurisdiction.
Three workflows, one record
The three assessments are not three products. They are one account, and signing in lands on it. Every assessment you have run stays there with its date and what it came back as, the compliance result stays on the page area by area, and the next annual re-assessment carries the date it falls due.
That matters after the incident rather than during it. A regulator asking what you had in place, an insurer at renewal, or a client’s security questionnaire are all answered from the same page, months later, by whoever is in the chair that day.
The counts are all it holds. How many duties are unmet in each area, never which ones. Your answers stay in your browser and in the answer file you download, and the page says so itself underneath the table.
Breach assessment
You found out this morning. Somebody needs to know whether this has to be reported, to whom, and by when, and the answer has to be defensible later, when nobody remembers what was known at nine o'clock.
A structured wizard of 28 to 36 questions walks you through your breach. The rules engine evaluates every answer against applicable legislation and produces your full document set.
Answer questions about your breach
Data types involved, number of individuals affected, whether the breach was isolated or systemic, and your operating jurisdiction. Question count varies by province due to conditional routing.
The rules engine evaluates in real time
ClearBreach applies the Real Risk of Significant Harm (RROSH) test under PIPEDA, and the equivalent thresholds under Alberta PIPA and BC PIPA. Where more than one applies, each is assessed on its own, one answer per framework, and a single combined obligation set built from all of them.
All required documents generated automatically
Every required document is produced from your answers, nothing to draft manually. Download and use immediately.
Up to six documents. Zero drafting.
Every document required to respond to a Canadian privacy breach is generated automatically from your assessment answers. Three documents are always produced, up to four additional regulator reports are generated based on which obligations are triggered.

Try it on a real breach → and the compliance assessment is here →
3 documents always generated · up to 3 more, one per regulator whose reporting obligation is triggered
Assessment Verdict Card
AlwaysThe determination under each framework that applies to you, in the same three words the assessment itself uses, with the reasoning behind it and the obligations it triggers, the primary record of your assessment.
Internal Incident Record
AlwaysInternal documentation required for your compliance file. Includes full incident details, assessment results, and a response log.
Individual Notification Letter
AlwaysDraft notification to affected individuals, one section per applicable framework. Where Alberta PIPA applies it also carries the PIPA Regulation s.19.1 content, cited heading by heading, so a single letter satisfies both.
OPC PIPEDA Breach Report
ConditionalPre-drafted submission to the Office of the Privacy Commissioner of Canada. Generated when PIPEDA reporting obligations are triggered.
OIPC Alberta PIPA Report
ConditionalMirrors the official April 2024 OIPC Alberta form, Sections A through E. Generated when AB PIPA reporting obligations are triggered.
OIPC BC PIPA Report
ConditionalVoluntary report to the OIPC BC. Generated when BC PIPA obligations are identified.
Three answers, one per framework
Every framework that applies to you is assessed separately and returns its own answer. There is no overall score and no risk rating. Canadian privacy law asks whether a real risk of significant harm exists, not whether risk passes some threshold, so the assessment answers that question, once per framework, and says what follows from it.
Reporting required
A real risk of significant harm was identified and this framework imposes a mandatory duty. Regulator reporting and individual notification obligations apply, and the reports are generated for you.
Voluntary report recommended
There is a real signal here, but this framework does not compel a report. BC PIPA has no mandatory breach-notification trigger, so a breach that is mandatory federally comes back as recommended in British Columbia. The report is still prepared for you.
No reporting obligation
No mandatory duty was triggered under this framework. That is not the same as safe: you are still required to keep a record of the breach, and it is generated for you.
Why the same breach can end in two different answers
ACME Retail has customers in Alberta, British Columbia, Ontario and Quebec. One incident, 18,400 people affected, the same facts assessed under every framework that applies. Quebec has its own Act, which ClearBreach does not assess, so it returns nothing here:
British Columbia differs because BC PIPA has no mandatory breach-notification trigger, not because the breach is less serious there. Missing that distinction is exactly what an obligation set per framework is for.
Jurisdiction coverage
PIPEDA
Federal private sector privacy legislation. Applies to all organizations operating across provincial borders or in non-PIPA provinces.
Alberta PIPA
Alberta's provincial privacy legislation. Applies to private sector organizations operating in Alberta.
BC PIPA
British Columbia's provincial privacy legislation. Applies to private sector organizations operating in BC.
Multi-jurisdiction assessment
PIPEDA, Alberta PIPA, and BC PIPA assessed simultaneously in one workflow. All applicable frameworks evaluated together, producing a single combined obligation set.
Out of scope: Quebec Law 25 is permanently outside ClearBreach scope and is not assessed.
Built for privacy
Breach details never leave your browser
Your answers about the breach are processed entirely client-side. Only anonymous metadata is recorded (the verdict tier, the province count and the framework count) never the breach details themselves. The compliance assessment records a score per area. A PIA does store the initiative and privacy officer names, because it is a document you file and return to.
Canadian data residency
Production infrastructure is hosted in Canada. Your organization data stays in Canada.
Grounded in Canadian law
Assessment logic is built on the text of PIPEDA, Alberta PIPA, and BC PIPA and published OPC and OIPC guidance. ClearBreach produces a preliminary risk assessment, not a legal opinion. Engage a privacy lawyer before submitting reports to regulators.
Why most privacy compliance resources require expertise to use →
Compliance guides
Alongside the assessment workflows, ClearBreach publishes practical step-by-step guides covering proactive privacy obligations under PIPEDA, Alberta PIPA, and BC PIPA, privacy officer designation, complaint handling procedures, privacy impact assessments, and the legislative requirements under each jurisdiction.
Browse compliance guides →Annual compliance assessment
The insurance renewal questionnaire asks whether you have a privacy policy, a named privacy officer, and a retention schedule. So does the security review your largest client sends every year. Both are answered from one document set you already have, and the year you cannot answer them is the year somebody asks why.
A structured assessment maps your privacy practices across 10 areas, tells you which duties you are not meeting, and writes the documents that close them.
Answer questions about how you actually work
Who is accountable, what you collect and why, how long you keep it, who your vendors are, and what happens when something goes wrong. Questions that cannot apply to you are not asked, and questions that cannot be scored are not counted against you.
Every area is scored on its own
Each area is measured against the duties the legislation actually imposes on you, in your province and your sector. A gap is recorded with the provision behind it, so the finding can be traced rather than taken on trust.
The documents that close the gaps are generated
Not a list of things to go and write. The privacy policy, the incident response plan, the registers and the rest are produced from your own answers, with your organization named in them.
The 10 areas
Two of them are critical: an area with nothing in place under Security Safeguards or Incident Management sets your overall status on its own, however well the rest is going.
Where you stand, and against what
The assessment returns one of three statuses. You are shown all three, because a status with nothing to compare it against tells you nothing.
On Track
No unmet legal duty, no area unaddressed, and at most one area substantially incomplete.
Needs Attention
At least one unmet legal duty, or an area with nothing in place, or two areas substantially incomplete.
At Risk
A critical area with nothing in place, or three or more areas substantially incomplete.
7 documents. Zero drafting.
7 are always produced. One more is offered where you need it, and withheld with a reason where you do not.
Gap remediation roadmap
AlwaysEvery gap found, in priority order, each with what is missing, what closes it, and the provision that requires it.
Incident response plan
AlwaysWhat your organization does when a breach happens, written before you need it, the plan the breach workflow assumes you already have.
Privacy management programme
AlwaysThe programme documentation a regulator asks for: who is accountable, what the policies are, and how they are kept current.
Personal information inventory
AlwaysWhat personal information you hold, where it lives, why you have it, and how long you keep it.
Privacy registers
AlwaysThe running records (access requests, complaints, breaches, vendors) that turn a policy into evidence you followed it.
Internal privacy policy
AlwaysHow your own staff must handle personal information, in words they can act on.
Complaint handling procedure
AlwaysHow a privacy complaint reaches the right person and what happens next, which every Canadian framework requires you to have.
Public privacy policy template
ConditionalOffered where you do not already publish one. Where you do, it is withheld and the reason is given, rather than inviting you to replace a working policy with a generic one.

Privacy impact assessment
You are about to sign up for something, a booking system, a payroll provider, a tool that reads your customer list. Nobody thinks of that as a privacy decision until afterwards. Some of those choices carry duties that arrive from the shape of what you are doing, not from a box anybody remembers to tick, information leaving Canada is the clearest one.
A privacy impact assessment is the record that you looked before you signed. It is cheap to produce beforehand and impossible to produce afterwards.
Describe the initiative and what it touches
What you are planning, what personal information it needs, who it comes from, and where it goes. The scope is stated and held to: what you exclude is written down as excluded, so the assessment cannot quietly be read as covering more than it did.
Each movement of information is placed under an Act
Every flow is assessed on its own, because the governing Act follows the activity rather than the organization. A clinic in Alberta is under Alberta PIPA for what it does in Alberta, whatever else it does elsewhere.
Risks are scored, and the completed PIA is generated
Duties you have not met are listed as open findings with the provision behind each. Risks that remain after your own mitigations are scored and banded. The finished assessment is a document you retain, or file where a regulator asks for one.
What it produces
Every flow, placed under an Act
2 movements of information in the sample assessment, each named, each with the Act that governs it and the reason that Act applies.
Duties you have not met yet
8 open findings in the sample, each carrying the provision it comes from and the action that closes it.
Risk that remains after mitigation
Each risk is scored on what is left once your own controls are counted, and banded, so effort goes where the residual risk actually is.
One completed PIA document is generated, ready to retain or to file. The sample below is a real one, produced by the same engine a subscriber uses.
Why a PIA is not optional as often as people think
ACME Dental planned one ordinary thing: online appointment booking. The vendor hosts it outside Canada, and that single fact is what makes the assessment compulsory rather than advisable.
A patient books or reschedules an appointment through the website
Alberta PIPA · leaves Canada for United States
The booking system sends the appointment to the practice-management software
Alberta PIPA · stays in Canada
Both movements sit under the provincial Act, not the federal one, because the activity happens in Alberta. Which Act applies follows what you are doing and where you are doing it, not where the business is registered.

Ready to run your assessment?
Know what you owe. Know it now.
Get early accessMSP plans available. See what MSPs get or see pricing.