Policies Internal operating policies
Privacy Breach Policy
How Map.ca detects, contains, reports, and learns from privacy breaches — aligned with PIPEDA's breach reporting framework.
- Version
- 0.1.0
- Effective
- May 20, 2026
- Last reviewed
- May 20, 2026
- Review cycle
- every 3 months
- Master Policy Index entry
- §4 #64
Policy text
Under PIPEDA, organizations must report breaches of security safeguards involving personal information to the Office of the Privacy Commissioner of Canada and notify affected individuals where there is a real risk of significant harm. The Privacy Breach Policy operationalizes that within Map.ca: detection, containment, evaluation of real-risk-of-significant-harm, notification timelines, and the post-breach review that feeds back into the Security Policy and the Incident Response Policy. Three-month review cycle, deliberately short.
It applies to Map.ca security, privacy, legal, and communications teams.
Principles this policy enforces
- Consent must be meaningful
- Collect less, protect more
- Public data and personal data are not the same thing
- Community benefit must survive scale
What it requires
- Evaluate real-risk-of-significant-harm on every detected breach.
- Notify the Office of the Privacy Commissioner of Canada and affected individuals within required timelines.
What it forbids
- Do not delay notification to manage public perception.
- Do not close a breach without a post-incident review.
How it applies
- Map.ca security, privacy, legal, and communications teams
References
- PIPEDA — Breach of security safeguards reporting
- Office of the Privacy Commissioner of Canada — Breach notification guidance
Related policies
Incident Response Policy
How Map.ca classifies, responds to, and communicates about security and operational incidents.
Security Policy
How Map.ca protects accounts, infrastructure, secrets, and operational data day to day.
Privacy Policy
What Map.ca collects, why, how long it is kept, who it is shared with, and what rights people have.