Sample assessments, fictional organizations
Neither organization exists and neither incident happened. What is real is the assessment: these are the verdicts ClearBreach produced from those facts, by the same engine a subscriber uses.
← How ClearBreach works·Compliance assessment →·Privacy impact assessment →
Two breach assessments
The first is the ordinary case: one province, one regulator, and a verdict in a few minutes. The second is the one that is hard to do by hand, the same kind of incident at an organization operating in four provinces, where the answer is different under each Act that reaches them.
ACME Dental
A laptop left in a car
The same fictional Alberta clinic as the compliance and PIA samples. A staff laptop holding an appointment export was stolen from a car overnight. One province, no encryption, and nobody knows whether the file was opened.
AB · 340 individuals affected
What happened
A staff laptop was taken from a locked car overnight. It held a spreadsheet exported for a recall campaign: patient names, phone numbers, email addresses and appointment types. The laptop had a login password and the file was not separately encrypted.
What is owed, under each Act that reaches them
Shown in full. Every framework the engine assessed, with the explanation it gave.
Alberta PIPA
Report required
Office of the Information and Privacy Commissioner of Alberta
The breach was caused by deliberate theft of a device or records, and personal information capable of enabling phishing or identity theft was reached. Regulators treat deliberate unauthorized access as reportable regardless of how few individuals were affected or how quickly the breach was contained. Unauthorized access could not be ruled out, and the assessment therefore assumes it occurred. No mitigating factor reduced the risk.
The documents it produced

Structure only. Section headings, so you can see what is in each one. The drafted text is what the subscription provides.
Verdict
11 sections
- Report to the Office of the Information and Privacy Commissioner of Alberta (OIPC AB)
- Notify Affected Individuals (Alberta PIPA)
- Step 1 · Contain the breach
- Step 2 · Activate the Internal Incident Record
- Step 3 · Notify your cyber liability insurer
- Step 4 · File the OIPC Alberta PIPA Report and send the Individual Notification Letter simultaneously
- Step 5 · Conduct a post-incident review
- Assessment Verdict Card
- Internal Privacy Incident Record
- Individual Notification Letter
- OIPC Alberta PIPA Regulator Report
InternalRecord
5 sections
- Incident summary
- Description
- Additional incident details
- Independent grounds for this determination (4)
- Pre-submission checklist
NotificationLetter
8 sections
- Pre-submission checklist
- What happened
- What information was involved
- What we are doing
- What you can do
- Your privacy rights and how to file a complaint
- Alberta PIPA
- Contact us
OIPC AB Report
7 sections
- Pre-submission checklist
- A1, Reporting organization
- A2, Third-party notifier (if applicable)
- B11, Description of the breach
- C1, RROSH determination
- C2, Specific risk factors and harms identified
- C3, Risk factors checklist
The same engine, a harder question
Four provinces. Two of them have their own private-sector privacy Act, one is covered federally, and Quebec has an Act this product does not assess and says so. Working that out is the part nobody can do from a checklist.
ACME Retail
One incident, four provinces
A national retailer whose loyalty database was accessed through a compromised vendor account. Customers in Alberta, British Columbia, Ontario and Quebec. One incident, and the obligations are not the same in each.
AB · BC · ON · QC · 18,400 individuals affected
What happened
A vendor account with access to the loyalty database was compromised in a phishing attack. Access logs show the customer table was queried and exported over four days before the account was disabled. The export included names, dates of birth, email addresses and the last four digits of saved payment cards.
What is owed, under each Act that reaches them
Shown in full. Every framework the engine assessed, with the explanation it gave.
Alberta PIPA
Report required
Office of the Information and Privacy Commissioner of Alberta
The breach was caused by external hacking or unauthorized system access, and personal information capable of enabling phishing or identity theft was reached. Regulators treat deliberate unauthorized access as reportable regardless of how few individuals were affected or how quickly the breach was contained. Unauthorized access to that information was confirmed. No mitigating factor reduced the risk.
BC PIPA
Reporting voluntary
Office of the Information and Privacy Commissioner for British Columbia
The breach was caused by external hacking or unauthorized system access, and personal information capable of enabling phishing or identity theft was reached. Regulators treat deliberate unauthorized access as reportable regardless of how few individuals were affected or how quickly the breach was contained. Unauthorized access to that information was confirmed. No mitigating factor reduced the risk. British Columbia's Personal Information Protection Act does not impose a mandatory notification requirement on private-sector organizations, so reporting here is recommended rather than legally required.
PIPEDA (federal)
Report required
Office of the Privacy Commissioner of Canada
The breach was caused by external hacking or unauthorized system access, and personal information capable of enabling phishing or identity theft was reached. Regulators treat deliberate unauthorized access as reportable regardless of how few individuals were affected or how quickly the breach was contained. Unauthorized access to that information was confirmed. No mitigating factor reduced the risk.
One incident, 3 answers. The obligations differ because the Acts differ, not because anything about the breach changed between them.
The documents it produced

Structure only. Section headings, so you can see what is in each one. The drafted text is what the subscription provides.
Verdict
19 sections
- Report to the Office of the Information and Privacy Commissioner of Alberta (OIPC AB)
- Notify Affected Individuals (Alberta PIPA)
- Report to the Office of the Information and Privacy Commissioner of British Columbia (OIPC BC), Voluntary
- Report to the Office of the Privacy Commissioner of Canada (OPC)
- Notify Affected Individuals (PIPEDA)
- Step 1 · Contain the breach
- Step 2 · Activate the Internal Incident Record
- Step 3 · Contact the third-party vendor
- Step 4 · Notify your cyber liability insurer
- Step 5 · File the OPC PIPEDA Breach Report and notify affected individuals (PIPEDA)
- Step 6 · File the OIPC Alberta PIPA Report and send the Individual Notification Letter simultaneously
- Step 7 · Consider voluntary report to the OIPC BC
- Step 8 · Conduct a post-incident review
- Assessment Verdict Card
- Internal Privacy Incident Record
- Individual Notification Letter
- OIPC Alberta PIPA Regulator Report
- OIPC BC PIPA Report (Voluntary)
- OPC PIPEDA Breach Report
InternalRecord
8 sections
- Incident summary
- Description
- Additional incident details
- Independent grounds for this determination (5)
- Independent grounds for this determination (5)
- Independent grounds for this determination (5)
- Framework comparison
- Pre-submission checklist
NotificationLetter
9 sections
- Pre-submission checklist
- What happened
- What information was involved
- What we are doing
- What you can do
- Your privacy rights and how to file a complaint
- Alberta PIPA
- PIPEDA (federal)
- Contact us
OIPC AB Report
7 sections
- Pre-submission checklist
- A1, Reporting organization
- A2, Third-party notifier (if applicable)
- B11, Description of the breach
- C1, RROSH determination
- C2, Specific risk factors and harms identified
- C3, Risk factors checklist
OIPC BC Report
2 sections
- Pre-submission checklist
- Description of the breach
OPC Report
3 sections
- Pre-submission checklist
- Description of the breach
- Specific risk factors and cause-and-effect analysis
Where these figures come from
Both assessments were produced by the same engine a subscriber uses, from committed scenarios. Nothing on this page was written by hand or chosen to look good. Engine version pathway-1.5. When the product changes, this page is produced again from it.

This verdict came from three answers. Change them yourself and watch the obligations move →