Canada

PIPEDA and Law 25, documented as you onboard.

Canada layers federal privacy law, Quebec's stricter Law 25 and sector rules like OSFI B-13, with the CCSPA under Bill C-26 set to add critical infrastructure obligations. Blueprint generates the evidence pack alongside the onboarding itself.

What applies in Canada

PIPEDA requires reporting breaches posing a real risk of significant harm to the OPC and affected individuals as soon as feasible. Quebec's Law 25 adds its own notification duty to the CAI, mandatory privacy impact assessments and, for Quebec-facing services, French-language obligations. OSFI B-13 gives federally regulated financial institutions a 72-hour incident reporting window.

The CCSPA under Bill C-26 will add mandatory incident reporting for designated critical infrastructure operators once in force, and CASL already constrains commercial electronic messages.

What the generated pack covers

Each Canadian onboarding pack includes the IR framework with the OPC, CAI and OSFI notification chains listed separately, a risk register, detection priorities per sector, and source runbooks with the retention your frameworks require. Quebec engagements flag Law 25's PIA and French-language requirements explicitly.

Statutory notification deadlines

TriggerDeadlineReport to
Breach of security safeguards with real risk of significant harmAs soon as feasibleOPC and affected individuals
High or critical severity technology or cyber incident72 hoursOSFI
Cyber security incident at a designated operatorPrescribed timelines under CCSPACanadian Centre for Cyber Security
Confidentiality incident presenting risk of serious injuryWith diligenceCAI and affected individuals

Frequently asked questions

What is the PIPEDA breach reporting deadline?
As soon as feasible after determining a breach poses a real risk of significant harm, to the OPC and affected individuals, with mandatory record keeping of all breaches.
Does the pack handle Quebec Law 25?
Yes. Law 25's CAI notification duty and privacy impact assessment requirement are part of the Canadian mapping, and Quebec engagements are flagged for French-language obligations.
What about banks and insurers?
Federally regulated financial institutions fall under OSFI B-13, including its 72-hour technology incident reporting window. The generated IR framework lists it as a separate chain.

Partner with us

Blueprint is white-label first: your branding on every generated pack, your domain on the client portal. We are looking for our first delivery partner in Canada.

Apply as a partner