ClearBreach

← Guides·All compliance guides →

PIPEDAAB PIPABC PIPAAll sectors

What ClearBreach Generates

By Yong DuPublished Reviewed

Three assessments: a breach produces six documents, an annual compliance assessment seven, and a privacy impact assessment one PIA.

Evaluate ClearBreach before your next breach

Breach documents, an annual compliance assessment and privacy impact assessments, generated from your own answers in your browser.

Get early access →
On this page

What does ClearBreach generate?

Three assessments, and each one ends with documents rather than a score. Everything below is pre-populated from your own answers and yours to keep as the record that you did the work.

A breach assessment produces six breach documents: an Assessment Verdict Card, an OPC Breach Report (PIPEDA), an OIPC Alberta Breach Report (Alberta PIPA), an OIPC BC Voluntary Breach Report (BC PIPA), an Individual Notification Letter, and an Internal Incident Record. Three are produced for every assessment, and three depend on which obligations fired. No breach details are transmitted to ClearBreach servers.

An annual compliance assessment produces seven documents, from a gap remediation roadmap to an incident response plan, plus an eighth offered where you need it. This is the work done before anything goes wrong, and it is what an insurer or a client security questionnaire is asking about.

A privacy impact assessment produces one completed PIA, the record that you looked before you signed up for a new system or a new use of personal information.

This page describes what each document contains, the legal fields required by Canadian law, and how ClearBreach generates it. If you are evaluating ClearBreach before a breach occurs, this is the right starting point.

On this page:

The breach assessment, six documents

The other two assessments


Assessment Verdict Card

The Assessment Verdict Card is the output of ClearBreach's rules-engine assessment. It shows one of three findings, Reporting required, Voluntary report recommended or No reporting obligation, under each applicable framework (PIPEDA, Alberta PIPA, BC PIPA), and lists the specific obligations triggered under each framework where RROSH is present.

The Verdict Card is the first document ClearBreach generates and the one that determines which of the remaining five documents you need. If RROSH is below the threshold, only the Internal Incident Record is required. If RROSH is present under any framework, the remaining documents are generated for that framework.

What the Assessment Verdict Card contains

  • A finding per framework: reporting required, voluntary report recommended, or no reporting obligation, under PIPEDA, Alberta PIPA and BC PIPA separately
  • Assessment factor summary: how the four RROSH factors (sensitivity, misuse probability, scale, recovery status) drove the finding
  • Obligations triggered: specific reporting and notification obligations activated under each applicable framework
  • Framework applicability: which frameworks apply to your organization based on your assessment answers

A completed sample Verdict Card is available at /features/sample-breach-verdict/. For a detailed explanation of how the four RROSH factors are assessed, see What Is RROSH?


OPC Breach Report, PIPEDA

The OPC Breach Report is filed with the Office of the Privacy Commissioner of Canada when a breach poses a real risk of significant harm under PIPEDA. Filing is mandatory when RROSH is present, and must be made as soon as feasible after the RROSH determination, in practice, days, not weeks.

ClearBreach generates the OPC report pre-populated with your breach facts, formatted to match the required fields under the Breach of Security Safeguards Regulations (SOR/2018-64). The draft is ready for review and submission via the OPC's online breach portal at priv.gc.ca.

What the OPC breach report form must contain

The Breach of Security Safeguards Regulations specify the mandatory fields for the OPC report:

  • Description of the breach: circumstances of how the breach occurred
  • Date or estimated date: when the breach occurred or was discovered
  • Personal information involved: a description of the type and nature of the personal information affected
  • Number of individuals affected: actual count or a reasonable estimate
  • Steps taken or to be taken: measures your organization has taken or plans to take to reduce the risk of harm to affected individuals
  • Individual notification steps: what you have done or plan to do to notify affected individuals directly
  • Contact information: name and contact details for a person in your organization who can answer questions from the OPC

ClearBreach pre-populates all seven required fields from your assessment answers. You review, edit if needed, and submit.

For the full PIPEDA reporting framework, see PIPEDA Breach Reporting Requirements.


OIPC Alberta Breach Report, Alberta PIPA

The OIPC Alberta Breach Report is filed with the Office of the Information and Privacy Commissioner of Alberta when a breach poses RROSH under Alberta PIPA. Filing is mandatory when RROSH is present and must be made without unreasonable delay.

ClearBreach generates the OIPC Alberta report pre-populated and mirroring the April 2024 official OIPC Alberta breach notification form. It is generated automatically when your assessment indicates Alberta PIPA applies, typically when the breach involves personal information about Alberta residents collected in the course of commercial activity within the province.

What the OIPC Alberta breach notification form must contain

Alberta PIPA requires the following fields in the breach report to the OIPC:

  • Description of the breach: how it occurred and what systems or processes were involved
  • Date or approximate date: when the breach occurred
  • Personal information involved: type and description of the personal information affected
  • Number of individuals affected: actual count or estimate
  • Steps to reduce risk of harm: containment and mitigation measures taken
  • Individual notification steps: what you have done or will do to notify affected individuals directly
  • Contact information: a person within your organization who can answer OIPC questions

When both Alberta PIPA and PIPEDA apply, ClearBreach generates separate OIPC Alberta and OPC reports automatically. Individual notification is generated once, a single letter satisfying both frameworks.

For the full Alberta PIPA framework, see Alberta PIPA Breach Notification Requirements.


Evaluate ClearBreach before your next breach. The six documents described on this page are generated automatically from a single 15-minute assessment, entirely in your browser. Get early access →


OIPC BC Voluntary Breach Report, BC PIPA

The OIPC BC Voluntary Breach Report is filed with the Office of the Information and Privacy Commissioner for BC. Unlike PIPEDA and Alberta PIPA, reporting to the OIPC BC under BC PIPA is voluntary, not legally mandatory. However, voluntary reporting demonstrates accountability and is considered best practice for any significant breach triggering BC PIPA obligations.

ClearBreach generates the OIPC BC report with voluntary reporting language when your assessment indicates BC PIPA applies, typically when the breach involves personal information about BC residents collected in the course of commercial activity within the province. The draft is ready for submission to the OIPC BC.

What the OIPC BC voluntary breach report should contain

The OIPC BC expects voluntary reports to include:

  • Description of the breach: circumstances and how it occurred
  • Date or approximate date: when the breach occurred
  • Personal information involved: type and description, and number of individuals affected
  • RROSH determination: your finding under BC PIPA
  • Containment steps: measures taken to stop and contain the breach
  • Individual notification steps: what you have done to notify affected BC individuals
  • Contact information: your privacy officer or responsible person

If the breach also triggers PIPEDA mandatory reporting, the OPC and OIPC BC coordinate directly. Filing with both avoids the appearance of selective disclosure to only one regulator.

For the full BC PIPA framework, see BC PIPA Breach Reporting Requirements.


Individual Notification Letter

The Individual Notification Letter is sent directly to every person whose personal information was involved in a breach that poses RROSH. Direct individual notification is mandatory under PIPEDA, Alberta PIPA, and BC PIPA when RROSH is present. A general public notice or website announcement does not satisfy this obligation unless direct contact is not reasonably possible.

ClearBreach generates one letter covering all applicable frameworks. The letter is drafted in plain language and satisfies the required contents of each framework that applies to your organization.

What a privacy breach notification letter must include

Under PIPEDA, the individual notification must:

  • Describe the circumstances of the breach
  • Identify the type of personal information involved
  • Describe steps your organization has taken to reduce risk of harm
  • Describe steps the individual can take to protect themselves
  • Include a toll-free number or other direct contact means for follow-up questions

Under Alberta PIPA, the individual notification must:

  • Describe the breach and the personal information involved
  • State the date or approximate date of the breach
  • Describe steps taken or to be taken to reduce harm to the individual
  • Include contact information so the individual can ask follow-up questions

Under BC PIPA, the individual notification must:

  • Describe the circumstances of the breach
  • Identify the personal information involved
  • Describe steps taken to reduce harm
  • Include contact information for the individual to ask questions

ClearBreach generates a single letter that satisfies the requirements of every applicable framework, identified from your assessment answers. You do not need to draft separate letters per jurisdiction.


Internal Incident Record

The Internal Incident Record is required for every breach of security safeguards, regardless of whether RROSH was present or any report was filed with a regulator. Under PIPEDA, the record must be retained for a minimum of 24 months. Alberta PIPA and BC PIPA also require organizations to maintain internal breach records. The OPC, OIPC Alberta, or OIPC BC may request access to this record.

ClearBreach generates the Internal Incident Record automatically at the end of every assessment, including assessments that result in a No reporting obligation finding.

What an internal breach record must document

  • Date and description: when the breach occurred and what happened
  • Nature of personal information involved: type, sensitivity, and estimated volume
  • Cause: root cause of the breach, if known at the time of assessment
  • Number of individuals affected: actual count or best estimate
  • The determination and its reasoning: the finding under each framework and the factor-by-factor analysis supporting it
  • Containment and remediation steps: actions taken to stop the breach, recover data, and prevent recurrence
  • Regulatory reporting: whether a report was filed with the OPC, OIPC Alberta, and/or OIPC BC, and the date filed
  • Individual notification: whether affected individuals were notified and when

The Internal Incident Record is your compliance file for the breach. Under PIPEDA, failure to maintain this record is an offence.


Which breach documents apply to your organization?

The breach documents ClearBreach generates depend on which frameworks apply to your organization and whether RROSH is present. The table below shows which documents are triggered under each scenario.

Document PIPEDA Alberta PIPA BC PIPA RROSH required?
Assessment Verdict Card Always Always Always No, generated for every assessment
OPC Breach Report ✓ n/a n/a Yes, mandatory when RROSH present
OIPC Alberta Breach Report n/a ✓ n/a Yes, mandatory when RROSH present
OIPC BC Voluntary Breach Report n/a n/a ✓ Recommended, voluntary under BC PIPA
Individual Notification Letter ✓ ✓ ✓ Yes, mandatory when RROSH present
Internal Incident Record Always Always Always No, required for every breach

ClearBreach identifies which frameworks apply to your organization based on your assessment answers, where your organization operates, whether commercial activity crosses provincial borders, and whether any federally regulated activities are involved. You do not need to pre-determine your framework obligations before starting the assessment.


Province-by-province breach document coverage

ClearBreach covers private-sector organizations in every Canadian province except Quebec. The applicable framework, and therefore the documents generated, depends on your province and whether your commercial activity is purely intraprovincial or crosses provincial or international borders.

Ontario, Saskatchewan, Manitoba, New Brunswick, Nova Scotia, Prince Edward Island, and Newfoundland and Labrador

These provinces have no substantially similar provincial privacy legislation. PIPEDA is the sole applicable framework for private-sector organizations in these provinces. ClearBreach generates three documents for a PIPEDA-only assessment:

  • Assessment Verdict Card: every assessment
  • OPC Breach Report: when RROSH is present (mandatory)
  • Individual Notification Letter: when RROSH is present (mandatory)
  • Internal Incident Record: every assessment (24-month retention required)

No provincial OIPC submission is required. There is one regulator: the OPC at priv.gc.ca.

Alberta

Alberta organizations are subject to Alberta PIPA for purely intraprovincial commercial activity, and also subject to PIPEDA when commercial activity crosses provincial or international borders. Most Alberta small businesses are subject to both. ClearBreach generates:

  • Assessment Verdict Card: every assessment
  • OPC Breach Report: when RROSH is present and PIPEDA applies (mandatory)
  • OIPC Alberta Breach Report: when RROSH is present and Alberta PIPA applies (mandatory)
  • Individual Notification Letter: when RROSH is present (one letter satisfying both frameworks)
  • Internal Incident Record: every assessment

When both frameworks apply, ClearBreach generates separate OPC and OIPC Alberta reports automatically. For the full Alberta PIPA framework, see Alberta PIPA Breach Notification Requirements.

British Columbia

BC organizations are subject to BC PIPA for purely intraprovincial commercial activity, and also subject to PIPEDA when commercial activity crosses provincial or international borders. Most BC small businesses are subject to both. ClearBreach generates:

  • Assessment Verdict Card: every assessment
  • OPC Breach Report: when RROSH is present and PIPEDA applies (mandatory)
  • OIPC BC Voluntary Breach Report: when RROSH is present and BC PIPA applies (recommended)
  • Individual Notification Letter: when RROSH is present (one letter satisfying both frameworks)
  • Internal Incident Record: every assessment

For the full BC PIPA framework, see BC PIPA Breach Reporting Requirements.

Quebec

ClearBreach does not currently cover Quebec. Quebec private-sector organizations are governed by Quebec's Act respecting the protection of personal information in the private sector (Law 25), which operates under a separate framework administered by the Commission d'accès à l'information (CAI). Law 25 breach reporting obligations differ materially from PIPEDA, Alberta PIPA, and BC PIPA. ClearBreach support for Law 25 is planned for a future release.


The annual compliance assessment

The breach documents answer a question nobody chooses to be asked. The compliance assessment answers the one that arrives on a schedule: an insurance renewal, a client security questionnaire, or a regulator asking what your privacy programme actually is.

A structured assessment maps your privacy practices across ten areas and returns one of three statuses, On Track, Needs Attention, or At Risk. Every area is scored separately, and every gap names the provision that requires the thing you are missing, so a finding can be checked rather than trusted.

Seven documents are generated from your own answers:

  • Gap remediation roadmap: every gap found, in priority order, each with what is missing, what closes it, and the provision that requires it.
  • Incident response plan: what your organization does when a breach happens, written before you need it.
  • Privacy management programme: the programme documentation a regulator asks for: who is accountable, what the policies are, and how they are kept current.
  • Personal information inventory: what personal information you hold, where it lives, why you have it, and how long you keep it.
  • Privacy records and registers: the running records (access requests, complaints, breaches, vendors, training) that turn a policy into evidence you followed it.
  • Internal privacy policy: how your own staff must handle personal information, in words they can act on.
  • Complaint handling procedure: how a privacy complaint reaches the right person and what happens next, which every Canadian framework requires you to have.

An eighth, a public privacy policy template, depends on your situation. It is offered where you do not already publish one. Where you do, it is withheld and the reason is given rather than inviting you to replace a working policy with a generic one.

A completed sample assessment, generated by the same engine a subscriber uses, is at /features/sample-compliance-assessment/.


The privacy impact assessment

You are about to sign up for something: a booking system, a payroll provider, a tool that reads your customer list. Nobody thinks of that as a privacy decision until afterwards. Some of those choices carry duties that arrive from the shape of what you are doing rather than from a box anybody remembers to tick, and information leaving Canada is the clearest one.

A privacy impact assessment is the record that you looked before you signed. It is cheap to produce beforehand and impossible to produce afterwards.

The assessment produces one completed PIA document, ready to retain or to file where a regulator asks for one. It contains:

  • Every movement of information, placed under an Act: each flow is assessed on its own, because the governing Act follows the activity rather than the organization. A clinic in Alberta is under Alberta PIPA for what it does in Alberta, whatever else it does elsewhere.
  • The scope, stated and held to: what you excluded is written down as excluded, so the assessment cannot later be read as covering more than it did.
  • Duties you have not met yet: listed as open findings, each carrying the provision it comes from and the action that closes it.
  • Risk that remains after mitigation: each risk scored on what is left once your own controls are counted, and banded, so effort goes where the residual risk actually is.

A completed sample PIA is at /features/sample-pia/.


Generate the documents automatically. A breach assessment takes 15 minutes in your browser and produces all six breach documents, pre-populated and ready for review. The annual compliance assessment and the privacy impact assessment run the same way, from your own answers. Get early access →

Frequently asked questions

Is there a PIPEDA breach notification template?

ClearBreach generates a pre-populated OPC breach report draft, the functional equivalent of a PIPEDA breach notification template, directly from your assessment answers. Rather than a blank template you fill out manually, the report is auto-populated with your breach facts and formatted to match the OPC's required fields under the Breach of Security Safeguards Regulations. The same assessment simultaneously generates an OIPC Alberta submission, OIPC BC voluntary report, individual notification letter, and internal incident record.

What does a PIPEDA breach report form include?

The OPC breach report under PIPEDA must include: a description of the circumstances of the breach; the date or estimated date; a description of the personal information involved; the number of individuals affected or an estimate; the steps your organization has taken or will take to reduce risk of harm; the steps taken or to be taken to notify affected individuals; and contact information for a person in your organization who can answer OPC questions. ClearBreach pre-populates all required fields from your 15-minute assessment.

What goes in a privacy breach notification letter in Canada?

Under PIPEDA, the individual notification letter must describe the circumstances of the breach, identify the type of personal information involved, describe steps your organization has taken to reduce harm, describe steps the individual can take to protect themselves, and include contact information for follow-up questions. Alberta PIPA and BC PIPA have the same core requirements. ClearBreach generates a single letter covering all applicable frameworks from your assessment.

What is an internal breach record under PIPEDA?

PIPEDA requires organizations to maintain an internal record of every breach of security safeguards, regardless of whether it reached the RROSH threshold, for a minimum of 24 months. The record must document: the date and description of the breach, the nature of the personal information involved, the cause (if known), the number of individuals affected, the RROSH determination and reasoning, containment and remediation steps, and whether the breach was reported to the OPC and individuals notified. ClearBreach generates this record automatically.

What does an RROSH assessment tool produce?

An RROSH assessment tool evaluates the four RROSH factors, sensitivity of personal information, probability of misuse, number of individuals affected, and whether data was recovered, and produces a binary finding: No reporting obligation (no mandatory reporting obligations) or RROSH (mandatory reporting obligations apply). ClearBreach runs this assessment under PIPEDA, Alberta PIPA, and BC PIPA simultaneously and produces a Verdict Card showing the finding and specific obligations triggered under each applicable framework, plus five additional breach documents.

What does the annual compliance assessment produce?

The compliance assessment maps your privacy practices across ten areas and returns one of three statuses: On Track, Needs Attention, or At Risk. Every area is scored separately and every gap carries the provision behind it. Seven documents are generated from your own answers: gap remediation roadmap, incident response plan, privacy management programme, personal information inventory, privacy records and registers, internal privacy policy, complaint handling procedure. An eighth, a public privacy policy template, is offered only where you do not already publish one.

What does a privacy impact assessment produce?

One completed PIA document, ready to retain or to file where a regulator asks for one. Every movement of personal information in the initiative is assessed on its own and placed under the Act that governs it, because the governing Act follows the activity rather than the organization. Duties you have not met are listed as open findings with the provision behind each, and risks are scored on what remains after your own mitigations.

This guide is educational and does not constitute legal advice. It is grounded in the text of PIPEDA, Alberta PIPA, and BC PIPA and published guidance from the OPC, OIPC Alberta, and OIPC BC. If your situation involves regulatory investigation, litigation risk, or circumstances not addressed here, engage a qualified privacy lawyer.

See what a compliance assessment finds

A real assessment for a small clinic: every area scored, every gap against the provision behind it, and the documents that close them.

See a complete assessment →

Get early access →