Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn more

← Back to all insights

Incident Response

The First 24 Hours After a Privacy Breach: A Canadian Response Playbook

Privacy HorizonJune 22, 20268 min read
A cybersecurity incident-response team at work

The day everything depends on the next hour

Most privacy breaches do not announce themselves cleanly. A staff member forwards a file to the wrong distribution list. A laptop goes missing from a car. A monitoring alert flags an unfamiliar login at 2 a.m. By the time someone says the word "breach" out loud, the clock has usually been running for a while.

The first 24 hours rarely determine whether a breach happened, but they very often determine how bad it becomes, how a regulator views your conduct, and how much trust you keep with the people whose information you hold. The organizations that come through well are almost never the ones that react fastest. They are the ones that react in the right order.

This playbook walks through that order, written for Canadian organizations operating under PIPEDA and the provincial and sector regimes that sit alongside it. It is not legal advice, and it is not a substitute for a tested incident response plan. It is the calm version of what the first day should look like, so that when the day is anything but calm, you have a map.

Hour 0 to 1: Stabilize before you investigate

The instinct in the first moments is to find out exactly what happened. Resist it, slightly. The first job is not understanding, it is stabilizing, so the situation cannot quietly get worse while you investigate.

  • Open a single record. Start one timestamped log of what is known, who was told, and what was decided. Everything that follows depends on this log existing, and it is almost impossible to reconstruct after the fact.
  • Name an incident lead. One person owns coordination and decisions for the duration. Diffuse ownership is how steps get dropped and contradictory instructions go out.
  • Contain, do not erase. Disable the compromised account, revoke the shared link, isolate the affected system. Containment should stop the bleeding without destroying the scene.
  • Preserve evidence. Do not wipe, re-image, or clean up affected machines. Snapshot logs, capture system images where you can, and keep the mis-sent email rather than recalling and deleting it.

Hour 1 to 4: Scope what actually happened

Once the situation is stable, you can investigate without the pressure of an active, spreading incident. The goal is a defensible picture of scope, not a perfect one. You will refine it for days, but you need working answers to a few questions early.

What information was involved, and how sensitive is it? Names and business email addresses are a different conversation than health records, SINs, or financial details. Whose information is it, and roughly how many people? You do not need an exact count in hour two, but you need to know whether you are talking about three people or thirty thousand. Is the exposure ongoing or contained? An open misconfiguration that is still leaking is more urgent than a stolen laptop with full-disk encryption. And who else is involved? Vendors, processors, and partners may be the source, the affected party, or both, and their contracts often require you to notify them within a fixed window.

  • Distinguish data accessed from data exfiltrated, and say which one you actually know. "We cannot rule out access" is honest; "no data was taken" is a claim you usually cannot make on day one.
  • Check whether the data was encrypted, and whether the keys were also exposed. Strong encryption can meaningfully change your harm assessment and, in some cases, your notification obligations.
  • Pull your data inventory and your vendor list. If you have a record of processing or a data map, this is the moment it earns its keep.

Hour 4 to 8: Assess real risk of significant harm

Under PIPEDA, the trigger for mandatory action is whether a breach of security safeguards creates a real risk of significant harm to an individual. This is the single most consequential judgment of the first day, because it drives your reporting and notification duties. Make it deliberately, not by gut feel.

The Office of the Privacy Commissioner of Canada points to two broad factors: the sensitivity of the information involved, and the probability that it has been or will be misused. Significant harm is read broadly. It includes bodily harm, humiliation, damage to reputation or relationships, financial loss, identity theft, negative effects on credit, and loss of employment or business opportunity.

Sector and provincial rules can layer on top. Health information custodians under Ontario's PHIPA, public bodies under British Columbia's FOIPPA, and any organization handling the personal information of Quebec residents under Law 25 each carry their own breach obligations, thresholds, and timelines. Where more than one regime applies, plan to the strictest one.

  • Weigh sensitivity and probability together. Highly sensitive data with low probability of misuse, and lower-sensitivity data that is clearly in the wrong hands, can both clear the threshold.
  • Consider the recipient. Data sent to one known, trusted party who confirms deletion is a different risk than data posted publicly or sold.
  • When in doubt, document the doubt. Regulators are far more forgiving of a reasoned, recorded judgment than of a decision that appears to have skipped the analysis.

Hour 8 to 16: Get reporting and notification right

If a breach poses a real risk of significant harm, PIPEDA requires you to report it to the Privacy Commissioner and notify affected individuals as soon as feasible. You must also keep records of all breaches of security safeguards, even those that do not meet the reporting threshold. That recordkeeping duty catches many organizations off guard.

Notification is communication, not just compliance. People need to know what happened, what information was involved, what you are doing about it, and what they can do to protect themselves, such as monitoring accounts or changing credentials. Plain language, no spin, and a real point of contact go further than a polished statement that says nothing.

Mind the other obligations that surface on day one. Your cyber-insurance policy almost certainly requires prompt notice, and late notice can jeopardize coverage. Contracts with enterprise or healthcare customers frequently specify notification windows measured in hours. And if there is any sign of criminal activity, such as ransomware or theft, law enforcement may belong in the loop.

  • Map every clock at once: PIPEDA, the applicable provincial or sector regime, your insurer, and your key customer contracts. They rarely share the same deadline.
  • Draft notifications early, even before you are certain you will send them. It is easier to refine a draft than to write under deadline pressure later.
  • Avoid premature certainty in public statements. Walking back "no data was accessed" is far more damaging than having said "our investigation is ongoing."

Hour 16 to 24: Know when to bring in outside help

By the end of the first day, you should have a stable environment, a working scope, a documented harm assessment, and a notification plan in motion. You should also have an honest answer to a question many teams avoid: are we out of our depth?

There is no shame in being out of depth during a breach. It is a rare event for most organizations, and the people handling it are usually doing so on top of their normal jobs and without sleep. Outside breach response support, whether forensic, legal, or privacy advisory, earns its cost by keeping the response defensible and the timeline on track.

Signs it is time to call for help include uncertainty about your reporting obligations, suspected criminal activity or extortion, sensitive data such as health or financial records, a multi-jurisdiction footprint, or simply an incident larger than your team can run while keeping the business operating. If you are weighing this in real time, our answer on when to hire a breach response consultant lays out the decision points in more detail.

  • Decide before you are desperate. The best time to identify your forensic, legal, and advisory contacts is during planning, not at hour twenty.
  • A retainer or a named partner removes the procurement delay that costs you on day one.
  • Outside help does not replace your incident lead. It supports them.

The real lesson of the first 24 hours

The hardest truth about breach response is that the first 24 hours are mostly won or lost before the breach ever happens. The organizations that respond calmly are the ones that wrote down their plan, named their people, mapped their data, and practised the steps while nothing was on fire.

If reading this raised more questions than it answered, that is useful. It means the time to act is now, in the quiet, not at 2 a.m. during an incident. Start with a clear, tested incident response plan, a current data inventory, and a short list of who you call. For a tighter checklist of the immediate steps, see our answer on what to do after a data breach.

Privacy Horizon helps Canadian organizations build response plans they can actually execute, and stands beside them when the plan is put to the test. The goal is simple: when the first 24 hours arrive, you already know what the next hour looks like.

  • What to do after a data breach
  • When should you hire a breach response consultant

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.