Breach Response Policy

BREACH RESPONSE POLICY

[Name of Charity]

Approved by the Board of Directors: [Date]
Next scheduled review: [Date, no later than 12 months from approval]
Policy owner: [Executive Director / Privacy Officer]

1. Purpose

This Policy sets out how [Name of Charity] (the "Charity") identifies, responds to, contains, investigates, reports, and remediates data breaches involving personal information, confidential information, or the Charity's information systems.

The Charity holds information about donors, beneficiaries, members, employees, volunteers, and partners. That information must be protected in accordance with the Charity's legal obligations, including under the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (Law 25), Alberta's Personal Information Protection Act (PIPA), British Columbia's PIPA, Ontario's Personal Health Information Protection Act (PHIPA) where applicable, and other applicable federal and provincial legislation.

A breach that is well-handled is a manageable event. A breach that is poorly handled is a crisis. This Policy exists to make sure the Charity is prepared before the breach happens, because after is too late.

2. Scope

This Policy applies to all directors, officers, employees, volunteers, contractors, and other representatives of the Charity ("Personnel") and to all information held by or on behalf of the Charity, regardless of format (electronic, paper, verbal) or location.

This Policy operates alongside the Charity's Privacy Policy, AI Policy, Acceptable Use of Technology Policy, Records Retention Policy, and Crisis Management Plan. Where a breach also triggers those policies, all applicable requirements apply.

3. Definitions

"Breach" means the loss of, unauthorized access to, or unauthorized use or disclosure of personal information or confidential information held by the Charity, including through theft, hacking, misdirected communication, loss of a device, employee error, third-party compromise, or unauthorized action by an AI tool.

"Personal information" has the meaning given in PIPEDA and applicable provincial privacy legislation.

"Real risk of significant harm" (RROSH) is the threshold under PIPEDA that triggers reporting and notification obligations. Significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on credit records, and damage to or loss of property.

"Sensitive personal information" includes health information, information about children, financial account information, government identifiers, information about vulnerable individuals, and any other information that a reasonable person would consider sensitive.

"Breach Response Team" is defined in Section 6.

4. Prevention (before the breach)

Prevention is the first line of defence. Personnel are expected to:

(a) complete privacy and security training at onboarding and at least annually thereafter;

(b) follow the Acceptable Use of Technology Policy, the AI Policy, and other applicable Charity policies;

(c) use approved tools and systems for handling personal information and confidential information;

(d) apply multi-factor authentication and strong passwords on all Charity accounts;

(e) report suspected vulnerabilities to the [Executive Director / Privacy Officer / IT lead] promptly; and

(f) never share credentials or leave devices unattended in insecure locations.

The Charity conducts periodic security reviews of its systems, vendors, and processes, and updates its safeguards as risks evolve.

5. Detection and initial reporting

5.1 Duty to report. Any Personnel member who becomes aware of a suspected or actual breach must report it immediately to the [Executive Director / Privacy Officer]. "Immediately" means without delay, without stopping to investigate first, and regardless of whether the reporting Personnel member believes the breach is serious.

5.2 What to report. The initial report should include, to the extent known:

(a) what happened;
(b) when the incident occurred and when it was discovered;
(c) what information may be involved;
(d) who is affected;
(e) what systems are affected; and
(f) any immediate steps already taken.

Personnel are not expected to have all the answers. They are expected to raise the flag.

5.3 No penalty for good-faith reporting. Personnel who report a suspected breach in good faith, including one they may have caused, will not be disciplined for the act of reporting. Personnel who fail to report a breach they knew or should have known about may face disciplinary action.

5.4 Preservation. Personnel must not delete, alter, or "clean up" evidence of a suspected breach. Do not attempt to remediate on your own before the Breach Response Team is engaged.

6. The Breach Response Team

6.1 Composition. On notification of a suspected breach, the [Executive Director / Privacy Officer] convenes the Breach Response Team, which includes, at minimum:

(a) the Executive Director;
(b) the Privacy Officer (if different);
(c) the IT lead or contractor responsible for affected systems;
(d) senior staff responsible for the affected program or function;
(e) legal counsel; and
(f) the Board Chair or a designated Board member, for material breaches.

The Team may include external forensic investigators, communications advisors, and insurance representatives as required.

6.2 Authority. The Breach Response Team has authority to take reasonable steps to contain and respond to the breach, including engaging external professionals, notifying affected individuals and regulators, and making public statements, subject to Board oversight for material matters.

7. The four-phase response

The Charity follows a four-phase response: contain, assess, notify, and remediate. Phases may overlap or run in parallel where circumstances require.

7.1 Phase 1: Contain

The immediate priority is to stop the breach from continuing or worsening. Depending on the nature of the breach, containment may involve:

(a) disconnecting affected systems from the network;
(b) revoking compromised credentials and issuing new ones;
(c) suspending AI agents or automated processes involved in the breach;
(d) recovering lost or stolen devices where safely possible;
(e) contacting third-party recipients of misdirected communications and requesting deletion;
(f) preserving evidence (logs, screenshots, physical materials);
(g) engaging external forensic support where needed; and
(h) documenting the containment steps taken.

Speed matters. So does not making things worse. The Breach Response Team weighs both.

7.2 Phase 2: Assess

The Charity assesses:

(a) What information is involved (personal information, sensitive personal information, financial information, employee information, donor information, beneficiary information, other confidential information, AI training data).

(b) How many individuals are affected, and who they are.

(c) The cause of the breach (external attack, employee error, vendor compromise, lost device, misdirected communication, AI-related incident, other).

(d) Whether the breach is ongoing or contained.

(e) The risk of harm to affected individuals, applying the RROSH threshold under PIPEDA and equivalent tests under provincial legislation. Factors include the sensitivity of the information, the probability of misuse, the number of individuals affected, and the identity and intentions of any recipient.

(f) Reporting and notification obligations under PIPEDA, Quebec's Law 25 (which has a lower notification threshold than PIPEDA), provincial legislation, sector-specific regulation (including PHIPA), and any applicable contractual obligations (funders, partners, insurers).

(g) Whether the breach is likely to attract regulatory, media, or public attention, and any reputational risk.

Legal counsel is engaged to advise on the assessment. Documentation of the assessment is created and preserved.

7.3 Phase 3: Notify

7.3.1 Regulator notification. Where the RROSH threshold is met under PIPEDA, or the corresponding provincial threshold is met, the Charity reports the breach to the Office of the Privacy Commissioner of Canada (OPC) and any applicable provincial privacy commissioner as soon as feasible. Under Quebec's Law 25, the Commission d'accès à l'information is notified where the breach presents a risk of serious injury.

Sector-specific regulators are also notified where required (for example, the Information and Privacy Commissioner of Ontario under PHIPA, or the Canada Revenue Agency where the breach involves information subject to CRA reporting obligations).

7.3.2 Individual notification. Affected individuals are notified where notification is required by law, or where notification is otherwise reasonable in the circumstances. Notification is provided directly to individuals where feasible, and includes:

(a) a description of what happened;
(b) the information involved;
(c) the steps the Charity is taking to address the breach;
(d) the steps the individual can take to protect themselves;
(e) contact information for the Charity's Privacy Officer; and
(f) contact information for the relevant privacy commissioner.

Language, tone, and channel of notification are chosen with care. The Charity does not minimize or obscure what happened.

7.3.3 Other notifications. The Charity considers notification to:

(a) law enforcement, where criminal activity is suspected;
(b) the Charity's insurer, in accordance with the applicable policy;
(c) funders and grantors, where required by funding agreements;
(d) partner organizations whose information or beneficiaries are affected;
(e) other organizations that may be able to reduce risk of harm (for example, credit reporting agencies); and
(f) the Board of Directors, in accordance with Section 8.

7.3.4 Record-keeping. PIPEDA requires organizations to keep records of all breaches of security safeguards involving personal information for 24 months, whether or not notification is triggered. The Charity maintains a breach register for this purpose (see Section 9).

7.4 Phase 4: Remediate

The Charity takes steps to prevent recurrence, which may include:

(a) technical remediation (patching vulnerabilities, replacing systems, strengthening access controls);
(b) policy updates (revising this Policy, the AI Policy, the Acceptable Use of Technology Policy, or others);
(c) additional training for affected Personnel or all Personnel;
(d) changes to vendor relationships or contracts;
(e) additional monitoring or auditing;
(f) reassessment of the Charity's overall privacy and security posture; and
(g) offering credit monitoring, identity protection services, or other support to affected individuals where appropriate.

Remediation is documented, and the Board receives a summary as part of the post-incident review (Section 8).

8. Board reporting

8.1 Material breaches. The Board of Directors is informed promptly of any breach that:

(a) meets the RROSH threshold or a corresponding provincial threshold;
(b) triggers regulator notification;
(c) affects a significant number of individuals;
(d) involves sensitive personal information;
(e) attracts or is likely to attract media attention; or
(f) could reasonably affect the Charity's operations, funding, or reputation.

8.2 Post-incident review. For every material breach, the Breach Response Team provides the Board with a written post-incident review addressing what happened, why, how the Charity responded, what was learned, and what has been changed as a result.

8.3 Aggregate reporting. The Board receives an aggregate summary of all breaches (including non-material breaches) at least [annually / semi-annually] as part of the Board's oversight of privacy and information governance.

9. Breach register

The Charity maintains a breach register recording, for each breach:

(a) the date of the breach and the date of discovery;
(b) the nature of the breach;
(c) the information involved and the number of individuals affected;
(d) the assessment of risk;
(e) notifications made (regulator, individual, other);
(f) remediation steps taken; and
(g) the location of related documentation.

The breach register is retained for at least 24 months (PIPEDA minimum) and longer where required by other legislation, funder requirements, or the Charity's Records Retention Policy.

10. Vendor and third-party breaches

Where a breach occurs at a vendor, service provider, or partner organization holding Charity information:

(a) the Charity treats the vendor breach as its own for reporting and notification purposes, unless the vendor is separately obligated;

(b) the Charity engages the vendor promptly to obtain information about the breach, the vendor's response, and the vendor's own notification obligations;

(c) the Charity assesses whether the vendor relationship should continue or change; and

(d) the Charity considers whether the vendor's contract adequately allocated responsibility and, if not, updates it.

Vendor contracts should require prompt notification of breaches. If the current contract does not, this is addressed at the next renewal.

11. AI-related breaches

AI tools introduce new breach vectors, including:

(a) confidential information exposed through prompts to AI tools;

(b) unauthorized action by AI agents;

(c) AI-generated content that discloses information the AI inferred or retained from other sources; and

(d) compromise of AI accounts or credentials.

AI-related breaches are handled under this Policy and, where applicable, under the AI Policy. The Breach Response Team includes the AI Policy owner where the breach involves an AI tool.

12. Training and preparedness

12.1 Training. Personnel receive breach-response training at onboarding and at least annually thereafter. Training covers recognition of breach indicators, immediate reporting obligations under Section 5, and preservation of evidence under Section 5.4.

12.2 Tabletop exercises. The Charity conducts a tabletop breach response exercise at least [annually / every 18 months] to test this Policy under simulated conditions. Findings are documented and used to update the Policy.

13. Review

This Policy is reviewed at least annually, and sooner if:

(a) applicable law changes materially;
(b) an incident indicates a gap in the Policy;
(c) the Charity's operations, systems, or vendors change materially; or
(d) the Board directs a review.

14. Contact

Suspected breaches should be reported immediately to [name / role / phone / email]. Outside business hours: [after-hours contact].

Version: 1.0
Approved: [Date]
Next review: [Date]

Why this Policy matters now.

PIPEDA has required mandatory breach reporting since 2018. Quebec's Law 25 tightened requirements significantly in 2022 and 2023, with a lower notification threshold and stricter timelines than the federal regime. Provincial commissioners are actively investigating breaches at organizations of all sizes, and the days when charities could quietly manage a breach internally are over. Regulators expect a documented response plan. So do insurers, funders, and, increasingly, donors.

What the charity needs to do before adopting.

  1. Identify the Privacy Officer. PIPEDA requires every organization to designate an individual accountable for privacy compliance. This role is central to the Policy. For most charities, it is the Executive Director or a senior manager. Make sure the person named actually knows they hold the role.
  2. Confirm the after-hours contact. Breaches don't happen during business hours. Section 14 requires an after-hours contact. Choose one before the Policy is adopted.
  3. Map your data. Before adopting the Policy, the charity should have at least a rough inventory of what personal information it holds, where it is stored, and who has access. Without this, the Section 7.2 assessment is guesswork under pressure.
  4. Confirm the review cycle. The Policy defaults to annual review and semi-annual or annual Board reporting. If the charity has a different cadence, adjust before adopting.
  5. Line up legal counsel. Section 6 assumes counsel will be engaged during a breach. If the charity does not have a relationship with counsel familiar with Canadian privacy law, establish one before you need to.
  6. Confirm insurance coverage. Check whether the charity's directors and officers, general liability, or cyber policies cover breach response costs, notification costs, credit monitoring for affected individuals, and regulatory defence. Coverage varies enormously.

How to roll it out.

  1. Board adoption at a meeting where the Policy can be discussed, not just approved.
  2. Communication to all Personnel, ideally paired with training.
  3. Initial breach-response training within 60 days of adoption.
  4. Tabletop exercise within six months. This is the single most valuable thing charities do to prepare, and it consistently reveals gaps that no amount of policy review would catch.
  5. Vendor contract review to confirm breach notification requirements are in place with critical vendors (payment processors, CRM providers, cloud storage, email services, AI tools).

What to watch for.

The Policy assumes a mid-sized charity with some IT capacity and access to counsel. If the charity is very small, some elements (the Breach Response Team composition, the tabletop exercise cadence) should be scaled down. If the charity is larger or operates in Quebec, the notification obligations under Law 25 warrant close attention, including the reporting to the Commission d'accès à l'information and the requirement to notify affected individuals of specific rights.

The Policy is deliberately conservative on regulator notification. In practice, the RROSH threshold under PIPEDA gives organizations room to conclude that notification is not required. Charities should exercise that judgment carefully and always with counsel. Under-reporting is the failure mode that gets organizations in trouble; over-reporting rarely does.

When to update. Any time the charity adopts a new major system or vendor, launches AI tools, changes its Privacy Officer, or experiences a breach. The Policy also needs a review when Canadian privacy law changes materially, which is expected in the next 12 to 24 months as federal reform advances.