ClearBreach
⚠

Sample assessments, fictional organizations

Neither organization exists and neither incident happened. What is real is the assessment: these are the verdicts ClearBreach produced from those facts, by the same engine a subscriber uses.

← How ClearBreach works·Compliance assessment →·Privacy impact assessment →

Two breach assessments

The first is the ordinary case: one province, one regulator, and a verdict in a few minutes. The second is the one that is hard to do by hand, the same kind of incident at an organization operating in four provinces, where the answer is different under each Act that reaches them.

ACME Dental

A laptop left in a car

The same fictional Alberta clinic as the compliance and PIA samples. A staff laptop holding an appointment export was stolen from a car overnight. One province, no encryption, and nobody knows whether the file was opened.

AB · 340 individuals affected

What happened

A staff laptop was taken from a locked car overnight. It held a spreadsheet exported for a recall campaign: patient names, phone numbers, email addresses and appointment types. The laptop had a login password and the file was not separately encrypted.

What is owed, under each Act that reaches them

Shown in full. Every framework the engine assessed, with the explanation it gave.

Alberta PIPA

Report required

Office of the Information and Privacy Commissioner of Alberta

The breach was caused by deliberate theft of a device or records, and personal information capable of enabling phishing or identity theft was reached. Regulators treat deliberate unauthorized access as reportable regardless of how few individuals were affected or how quickly the breach was contained. Unauthorized access could not be ruled out, and the assessment therefore assumes it occurred. No mitigating factor reduced the risk.

The documents it produced

The ClearBreach download screen after an assessment: each generated document listed by name, with the regulator reports the answers triggered.
The download screen at the end of the assessment. Every document named, and the regulator reports are the ones these answers triggered.

Structure only. Section headings, so you can see what is in each one. The drafted text is what the subscription provides.

Verdict

11 sections

  • Report to the Office of the Information and Privacy Commissioner of Alberta (OIPC AB)
  • Notify Affected Individuals (Alberta PIPA)
  • Step 1 · Contain the breach
  • Step 2 · Activate the Internal Incident Record
  • Step 3 · Notify your cyber liability insurer
  • Step 4 · File the OIPC Alberta PIPA Report and send the Individual Notification Letter simultaneously
  • Step 5 · Conduct a post-incident review
  • Assessment Verdict Card
  • Internal Privacy Incident Record
  • Individual Notification Letter
  • OIPC Alberta PIPA Regulator Report

InternalRecord

5 sections

  • Incident summary
  • Description
  • Additional incident details
  • Independent grounds for this determination (4)
  • Pre-submission checklist

NotificationLetter

8 sections

  • Pre-submission checklist
  • What happened
  • What information was involved
  • What we are doing
  • What you can do
  • Your privacy rights and how to file a complaint
  • Alberta PIPA
  • Contact us

OIPC AB Report

7 sections

  • Pre-submission checklist
  • A1, Reporting organization
  • A2, Third-party notifier (if applicable)
  • B11, Description of the breach
  • C1, RROSH determination
  • C2, Specific risk factors and harms identified
  • C3, Risk factors checklist

The same engine, a harder question

Four provinces. Two of them have their own private-sector privacy Act, one is covered federally, and Quebec has an Act this product does not assess and says so. Working that out is the part nobody can do from a checklist.

ACME Retail

One incident, four provinces

A national retailer whose loyalty database was accessed through a compromised vendor account. Customers in Alberta, British Columbia, Ontario and Quebec. One incident, and the obligations are not the same in each.

AB · BC · ON · QC · 18,400 individuals affected

What happened

A vendor account with access to the loyalty database was compromised in a phishing attack. Access logs show the customer table was queried and exported over four days before the account was disabled. The export included names, dates of birth, email addresses and the last four digits of saved payment cards.

What is owed, under each Act that reaches them

Shown in full. Every framework the engine assessed, with the explanation it gave.

Alberta PIPA

Report required

Office of the Information and Privacy Commissioner of Alberta

The breach was caused by external hacking or unauthorized system access, and personal information capable of enabling phishing or identity theft was reached. Regulators treat deliberate unauthorized access as reportable regardless of how few individuals were affected or how quickly the breach was contained. Unauthorized access to that information was confirmed. No mitigating factor reduced the risk.

BC PIPA

Reporting voluntary

Office of the Information and Privacy Commissioner for British Columbia

The breach was caused by external hacking or unauthorized system access, and personal information capable of enabling phishing or identity theft was reached. Regulators treat deliberate unauthorized access as reportable regardless of how few individuals were affected or how quickly the breach was contained. Unauthorized access to that information was confirmed. No mitigating factor reduced the risk. British Columbia's Personal Information Protection Act does not impose a mandatory notification requirement on private-sector organizations, so reporting here is recommended rather than legally required.

PIPEDA (federal)

Report required

Office of the Privacy Commissioner of Canada

The breach was caused by external hacking or unauthorized system access, and personal information capable of enabling phishing or identity theft was reached. Regulators treat deliberate unauthorized access as reportable regardless of how few individuals were affected or how quickly the breach was contained. Unauthorized access to that information was confirmed. No mitigating factor reduced the risk.

One incident, 3 answers. The obligations differ because the Acts differ, not because anything about the breach changed between them.

The documents it produced

The ClearBreach download screen after an assessment: each generated document listed by name, with the regulator reports the answers triggered.
The download screen at the end of the assessment. Every document named, and the regulator reports are the ones these answers triggered.

Structure only. Section headings, so you can see what is in each one. The drafted text is what the subscription provides.

Verdict

19 sections

  • Report to the Office of the Information and Privacy Commissioner of Alberta (OIPC AB)
  • Notify Affected Individuals (Alberta PIPA)
  • Report to the Office of the Information and Privacy Commissioner of British Columbia (OIPC BC), Voluntary
  • Report to the Office of the Privacy Commissioner of Canada (OPC)
  • Notify Affected Individuals (PIPEDA)
  • Step 1 · Contain the breach
  • Step 2 · Activate the Internal Incident Record
  • Step 3 · Contact the third-party vendor
  • Step 4 · Notify your cyber liability insurer
  • Step 5 · File the OPC PIPEDA Breach Report and notify affected individuals (PIPEDA)
  • Step 6 · File the OIPC Alberta PIPA Report and send the Individual Notification Letter simultaneously
  • Step 7 · Consider voluntary report to the OIPC BC
  • Step 8 · Conduct a post-incident review
  • Assessment Verdict Card
  • Internal Privacy Incident Record
  • Individual Notification Letter
  • OIPC Alberta PIPA Regulator Report
  • OIPC BC PIPA Report (Voluntary)
  • OPC PIPEDA Breach Report

InternalRecord

8 sections

  • Incident summary
  • Description
  • Additional incident details
  • Independent grounds for this determination (5)
  • Independent grounds for this determination (5)
  • Independent grounds for this determination (5)
  • Framework comparison
  • Pre-submission checklist

NotificationLetter

9 sections

  • Pre-submission checklist
  • What happened
  • What information was involved
  • What we are doing
  • What you can do
  • Your privacy rights and how to file a complaint
  • Alberta PIPA
  • PIPEDA (federal)
  • Contact us

OIPC AB Report

7 sections

  • Pre-submission checklist
  • A1, Reporting organization
  • A2, Third-party notifier (if applicable)
  • B11, Description of the breach
  • C1, RROSH determination
  • C2, Specific risk factors and harms identified
  • C3, Risk factors checklist

OIPC BC Report

2 sections

  • Pre-submission checklist
  • Description of the breach

OPC Report

3 sections

  • Pre-submission checklist
  • Description of the breach
  • Specific risk factors and cause-and-effect analysis

Where these figures come from

Both assessments were produced by the same engine a subscriber uses, from committed scenarios. Nothing on this page was written by hand or chosen to look good. Engine version pathway-1.5. When the product changes, this page is produced again from it.

The first page of the generated individual notification letter for ACME Retail, addressed to affected customers, with a section for each framework that applies.
The first page of the notification letter this assessment produced, one section per framework that applies, so a single letter satisfies each duty.

This verdict came from three answers. Change them yourself and watch the obligations move →