Canada
PIPEDA and Law 25, documented as you onboard.
Canada layers federal privacy law, Quebec's stricter Law 25 and sector rules like OSFI B-13, with the CCSPA under Bill C-26 set to add critical infrastructure obligations. Blueprint generates the evidence pack alongside the onboarding itself.
What applies in Canada
PIPEDA requires reporting breaches posing a real risk of significant harm to the OPC and affected individuals as soon as feasible. Quebec's Law 25 adds its own notification duty to the CAI, mandatory privacy impact assessments and, for Quebec-facing services, French-language obligations. OSFI B-13 gives federally regulated financial institutions a 72-hour incident reporting window.
The CCSPA under Bill C-26 will add mandatory incident reporting for designated critical infrastructure operators once in force, and CASL already constrains commercial electronic messages.
What the generated pack covers
Each Canadian onboarding pack includes the IR framework with the OPC, CAI and OSFI notification chains listed separately, a risk register, detection priorities per sector, and source runbooks with the retention your frameworks require. Quebec engagements flag Law 25's PIA and French-language requirements explicitly.
Statutory notification deadlines
| Trigger | Deadline | Report to |
|---|---|---|
| Breach of security safeguards with real risk of significant harm | As soon as feasible | OPC and affected individuals |
| High or critical severity technology or cyber incident | 72 hours | OSFI |
| Cyber security incident at a designated operator | Prescribed timelines under CCSPA | Canadian Centre for Cyber Security |
| Confidentiality incident presenting risk of serious injury | With diligence | CAI and affected individuals |
Frequently asked questions
Partner with us
Blueprint is white-label first: your branding on every generated pack, your domain on the client portal. We are looking for our first delivery partner in Canada.
Apply as a partner