ClearBreach
⚠

Sample assessment, fictional organization

ACME Dental does not exist. The staff, the contact address and every answer are invented. What is real is the assessment: this page shows the output ClearBreach produced from those answers, generated by the same engine a subscriber uses.

← How ClearBreach works·See a breach assessment verdict →

ClearBreach Compliance Assessment

ACME Dental

A two-location dental practice in Alberta. Eleven staff, about 4,000 patient records, one cloud practice-management vendor and one payroll provider.

Issued 2026-09-01 · Reference CR-ACMEDE-20260901 · AB_PIPA and PIPEDA

Where this organization stands

Shown in full. This is the whole result, not a preview. It is about one fictional clinic’s answers, so there is nothing in it to hold back.

At risk

Where they stand

24

questions scored

14

gaps found

7

documents produced

The clinic operates in one province, so two frameworks reach it. The areas below are the ten this assessment covers; the ones marked not applicable were ruled out by the answers rather than skipped.

Every area, applicable or not

Shown in full. All ten, including those that came out clean.

AreaIn placePartlyNot startedGaps
Accountability and Governance1101
Privacy Policy and External Communication2213
Consent and Collection2101
Retention and Disposal0011
Security Safeguards100none
Access and Correction0134
Training and Awareness0101
Service Provider Management0011
Incident Management0022
Commercial Email (CASL)not applicable to this organizationn/an/an/an/a

What is missing, and what to do about it

Shown in full. Every gap the assessment found, with the wording the subscriber receives.

Critical, 14

Does your organization have a written privacy policy that staff can find and read?

Partly · accountability · moderate effort

Write down how your own people should handle personal information. Put it where they can read it, and set one date a year to look at it again. PIPEDA clause 4.1.4 lists what it has to cover. Procedures to protect the information, procedures for complaints and inquiries, training staff on those policies, and information explaining your procedures. The annual look is the 2012 guidance’s oversight and review plan, which revisits the policies, the training, the breach response and the vendor arrangements.

Does your published privacy policy say what personal information you collect and why, for each kind of information?

Partly · policy · moderate effort

List the kinds of personal information you hold, and what each is used for. PIPEDA clause 4.8.2(c) requires a description of the type of information held, including a general account of its use. Kind by kind, not one sentence covering everything.

Does your published privacy policy name the countries your information goes to, and what the provider there may do with it?

Not started · policy · moderate effort

Name the countries in your policy, and say what the provider there is authorized to do with the information. Alberta PIPA s.6(2) requires both, wherever a service provider outside Canada collects, uses, discloses or stores personal information for you. Neither PIPEDA nor BC PIPA imposes this, so it is an Alberta duty. The federal Commissioner's cross-border guidelines ask for more than Alberta does, and that is asked separately.

Does your published privacy policy explain how someone can ask to see their information, and who to complain to?

Partly · policy · moderate effort

Say how someone asks for their information, and name who complaints and inquiries go to. PIPEDA clause 4.8.2(b) puts the means of gaining access into what you make available. Clause 4.8.2(a) requires the name or title and address of the person complaints go to. Clause 4.10.2 requires the complaint procedures themselves to exist. That they also be "easily accessible and simple to use" is a should under s.5(2), and worth doing anyway.

Do you have consent, or an exception in the Act, for every place you collect personal information?

Partly · consent · significant effort

Go through each place you collect personal information. Write down whether you are relying on consent, or on an exception in the Act. AB s.7(1), BC s.6(1) and PIPEDA clause 4.3 all require consent unless the Act provides otherwise. It is the organization that has to say which applies.

Is personal information securely destroyed once it is no longer needed?

Not started · retention · moderate effort

Destroy or anonymize the information once its purpose is finished and no legal or business reason to keep it remains. Write down the procedure for doing it. AB s.35(2) and BC s.35(2) both make the destruction itself a duty in those terms. The word "securely" is part of the duty, not our addition. PIPEDA clause 4.7.5 requires care "in the disposal or destruction of personal information, to prevent unauthorized parties from gaining access". A recycling bin is not disposal. Clause 4.5.3 then makes the guidelines and procedures a duty, even though it phrases the destruction itself as a recommendation.

Do you have a set way of handling it when someone asks to see their own information?

Not started · access · moderate effort

Write down who receives an access request, what they check, and how the information is provided. BC s.23(1) asks for three things, not one. The information itself, how it has been used, and who it was disclosed to. PIPEDA clause 4.9 imposes the same right, and AB s.24(1.1) and s.24(1.2) do the same in Alberta.

Are access requests answered within the deadline the law gives you?

Not started · access · quick effort

Put the deadline on the request the day it arrives, and give it an owner. The periods are not the same: PIPEDA s.8(3) gives 30 days, BC s.29(1) gives 30, and Alberta PIPA s.28(1)(a) gives 45. An extension of up to 30 more days is available in stated circumstances, under PIPEDA s.8(4), AB s.31 and BC s.31. Missing the deadline is treated as a refusal. PIPEDA s.8(5) deems it one, and AB s.28(2.1) treats it as a decision to refuse. Either way the person gets a complaint to the Commissioner.

When someone shows you their information is wrong, is it corrected and are the people you gave it to told?

Partly · access · moderate effort

Correct it as soon as you reasonably can. Then tell the organizations you already sent the wrong information to. The two Acts bound that differently. BC s.24(2)(b) covers organizations it went to during the year before the correction. AB s.25(2)(b) covers them where it is reasonable to do so. Where you decide the information is not wrong, AB s.25(3) and BC s.24(3) require the request to be annotated on the record instead. The individual's account of it stays with the file. PIPEDA clause 4.9.5 requires the amendment, and its transmission to third parties where appropriate.

Is there a set way for someone to complain about how you handled their personal information, and does someone answer?

Not started · access · quick effort

Decide who receives a privacy complaint, how they can be reached, and what happens next. Then write those three things down. PIPEDA clause 4.10.2 requires procedures to receive and respond to complaints or inquiries. Both halves are the duty: a way in, and an answer. Clause 4.10.3 requires telling people who ask that the procedures exist. BC s.5(b) requires a process to respond to complaints, and s.5(c) requires information about it on request. AB s.6(1) carries it as part of the policies and practices duty.

Have the people who handle personal information been trained on how to handle it?

Partly · training · moderate effort

Walk the people who handle personal information through your own policy. What they may collect, who they may give it to, and what to do when something goes wrong. Then repeat it once a year, and keep a list of who has done it. PIPEDA clause 4.1.4(c) makes training staff part of the policies-and-practices duty. Clause 4.7.4 requires making employees aware of the importance of confidentiality. The repetition and the record are asked for in the 2020 joint self-assessment, at ss.4.5 and 4.6.

Do your arrangements with them require comparable protection of that information?

Not started · vendors · significant effort

Get two things into the contract at once, because you will only negotiate it once. Comparable protection of the information, and a requirement that they tell you promptly if they are breached. PIPEDA clause 4.1.3 requires "contractual or other means to provide a comparable level of protection" while a third party is processing it. Comparable to your own, not merely something in writing. The 2020 joint self-assessment covers protection at s.4.17 and breach reporting at s.4.18. The second matters to you directly: your reporting clock runs on information they hold as well as yours.

If you had a reportable breach, would the report reach the right regulator in time?

Not started · incident · moderate effort

Know which regulator applies before you need to. PIPEDA s.10.1(1) requires a report to the federal Commissioner where the breach creates a real risk of significant harm. Alberta PIPA s.34.1(1) requires notice to the Alberta Commissioner without unreasonable delay, on the same test. British Columbia imposes no breach-notification duty at all under PIPA. A BC organization reports only where PIPEDA reaches it.

Do you keep a record of every privacy incident, including the ones you decided not to report?

Not started · incident · moderate effort

Keep a record of every incident, including the ones you decided not to report. PIPEDA s.10.3(1) says "every breach of security safeguards", and the ones you assessed and let go are the half people miss. SOR/2018-64 s.6 requires the records to be kept 24 months, and s.10.3(2) lets the Commissioner ask to see them.

The documents this produced

Structure only. The headings of each document are listed so you can see what is in it. The text is not shown: these are the drafted documents the subscription provides.

The first page of the generated gap remediation roadmap for ACME Dental, listing the gaps found in priority order with what closes each one.
The first page of one of them. The rest are shown by their headings below, because they are the documents the subscription provides.

Gap Remediation Roadmap

15 sections

  • Required by privacy law
  • 1. Are access requests answered within the deadline the law gives you?
  • 2. Is there a set way for someone to complain about how you handled their personal information, and does someone answer?
  • 3. Do you have a set way of handling it when someone asks to see their own information?
  • 4. When someone shows you their information is wrong, is it corrected and are the people you gave it to told?
  • 5. Does your organization have a written privacy policy that staff can find and read?
  • 6. If you had a reportable breach, would the report reach the right regulator in time?
  • 7. Do you keep a record of every privacy incident, including the ones you decided not to report?
  • 8. Does your published privacy policy say what personal information you collect and why, for each kind of information?
  • 9. Does your published privacy policy name the countries your information goes to, and what the provider there may do with it?
  • 10. Does your published privacy policy explain how someone can ask to see their information, and who to complain to?
  • 11. Is personal information securely destroyed once it is no longer needed?
  • 12. Have the people who handle personal information been trained on how to handle it?
  • 13. Do you have consent, or an exception in the Act, for every place you collect personal information?
  • 14. Do your arrangements with them require comparable protection of that information?

Incident Response Plan

25 sections

  • 1. Purpose and scope
  • 2. Immediate actions
  • 3. Roles and responsibilities
  • 4. First response by incident type
  • Ransomware or other malware
  • Lost or stolen device
  • Email sent to the wrong recipient
  • Phishing or a compromised mailbox
  • Cloud storage or website left open
  • An employee looked at records they should not have
  • A supplier or service provider was breached
  • Paper records lost, taken or wrongly disposed of
  • 5. Response steps
  • 5.1 Assess the risk
  • 5.2 Report to the regulator where required
  • 5.3 Notify affected individuals where required
  • 5.4 Notify other organizations where required
  • 5.5 Record the incident
  • 5.6 Learn from the incident
  • 6. Records
  • 7. Regulatory notification
  • Office of the Information and Privacy Commissioner of Alberta
  • Office of the Privacy Commissioner of Canada
  • 8. Common errors
  • 9. Review

Privacy Management Program

19 sections

  • Part A: Organizational commitment
  • A.1 Senior support
  • A.2 The person accountable
  • A.3 Reporting
  • Part B: Program controls
  • B.1 Personal information inventory
  • B.2 Policies
  • B.3 Risk assessment
  • B.4 Training and education
  • B.5 Breach and incident management
  • B.6 Service provider management
  • B.7 External communication
  • B.8 Safeguards
  • Part C: Ongoing assessment and revision
  • C.1 Review plan
  • Part D: This year's assessment
  • D.1 Standing
  • D.2 What this assessment covered
  • D.3 Area by area

Personal Information Inventory

4 sections

  • 1. What this is for
  • 2. The inventory
  • 3. Filling in each column
  • 4. Keeping it current

Privacy Registers

6 sections

  • 1. Access and correction requests
  • 2. Privacy complaints
  • 3. Privacy incidents
  • 4. Privacy training
  • 5. Commercial email consent
  • 6. Unsubscribe requests

Internal Privacy Policy

10 sections

  • 1. Who this applies to
  • 2. Who is accountable
  • 3. Collecting personal information
  • 4. Using it and sharing it
  • 5. Keeping it safe
  • 6. Getting rid of it
  • 7. When somebody asks for their own information
  • 8. When something goes wrong
  • 9. If this policy is not followed
  • 10. Review

Complaint Handling Procedure

9 sections

  • 1. Purpose
  • 2. Scope
  • 3. How to make a complaint
  • 4. Acknowledgement
  • 5. Investigation
  • 6. Response
  • 7. Escalation to a privacy commissioner
  • 8. Records
  • 9. Review

Offered, and not included by default

You already make your privacy practices available, so a template would invite you to replace a working policy with a generic one. It is below if you want to compare.

Where these figures come from

Every number on this page was produced by the same assessment engine a subscriber uses. Nothing here was written by hand or chosen to look good. Issued 2026-09-01, package reference CR-ACMEDE-20260901, the same reference the clinic’s own documents carry. When the product changes, this page is produced again from it.

The ClearBreach compliance results screen for ACME Dental: an overall status of At Risk, a summary of fourteen outstanding duties, and every one of the ten areas scored separately.
The result screen. Every area scored on its own, and the overall status against all three so it can be placed.
These findings came from answers to twenty five questions. Change four of them yourself and watch the findings move →