Policies Internal operating policies

Privacy Breach Policy

How Map.ca detects, contains, reports, and learns from privacy breaches — aligned with PIPEDA's breach reporting framework.

Version
0.1.0
Effective
May 20, 2026
Last reviewed
May 20, 2026
Review cycle
every 3 months
Master Policy Index entry
§4 #64

Policy text

Under PIPEDA, organizations must report breaches of security safeguards involving personal information to the Office of the Privacy Commissioner of Canada and notify affected individuals where there is a real risk of significant harm. The Privacy Breach Policy operationalizes that within Map.ca: detection, containment, evaluation of real-risk-of-significant-harm, notification timelines, and the post-breach review that feeds back into the Security Policy and the Incident Response Policy. Three-month review cycle, deliberately short.

It applies to Map.ca security, privacy, legal, and communications teams.

Principles this policy enforces

  • Consent must be meaningful
  • Collect less, protect more
  • Public data and personal data are not the same thing
  • Community benefit must survive scale

What it requires

  • Evaluate real-risk-of-significant-harm on every detected breach.
  • Notify the Office of the Privacy Commissioner of Canada and affected individuals within required timelines.

What it forbids

  • Do not delay notification to manage public perception.
  • Do not close a breach without a post-incident review.

How it applies

References