The Digital Privacy Act (DPA), passed in June 2015, was an official announcement by the Canadian federal government that cyber-security had crossed over into...
Reporting breaches under the Digital Privacy Act becomes complicated if a company doesn’t know when it was breached or how much data was touched by a bad actor
The Digital Privacy Act has amended some aspects of Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), including introducing a new data breach notification requirement that is not yet in force
Canadian Privacy Commissioner Daniel Therrien recommends the Privacy Act be updated to require federal institutions to report data breaches. He also wants broader powers to take things to court.
While there are many aspects to the new Digital Privacy Act, one that is not on most IT groups radar, and will likely impact IT the most, is the requirement to establish and maintain a record of breaches of the security controls protecting personal information