Context
Despite reasonable measures, controls designed to prevent breaches or IT security incidents and protect OIPC Information may fail. In addition, human errors and exploitation of security vulnerabilities can lead to breaches and IT security incidents. Therefore, it is critical to ensure plans are in place at the Office of the Information and Privacy Commissioner (OIPC) to manage these breaches and IT security incidents when they occur.
Purpose
To limit the effects of breaches involving OIPC Information or of IT security incidents involving OIPC IT resources, by appropriately managing breaches and IT security incidents.
Application
This directive applies to all OIPC Employees and Third-Party Service Providers.
References
POPA, POPR, Information Risk Management Policy, Information Security Classification Directive
Directive Statements
IT security incidents
Containment
- OIPC Employees must immediately report any suspected IT security incident to their supervisor, or in their absence, to any member of the Senior Leadership Team (SLT).
- On receiving a report of an IT security incident, the supervisor or SLT member must act promptly to:
- contain the IT security incident to the degree possible, and
- report the IT security incident to the Director, IM/IT.
Risk Assessment
- On receiving a report of an IT security incident, the Director, IM/IT is to:
- assess the containment measures taken, and supplement them as needed,
- investigate the cause and effect of the IT security incident on OIPC IT Resources,
- assess the risk to OIPC IT Resources and applicable mitigation measures, and
- document these activities in an incident report.
Reporting
- The incident report created by the Director IM/IT must be shared with the CIO, or the Commissioner in the absence of the CIO.
- On receiving a copy of the incident report, the CIO, or the Commissioner, as applicable, must review and sign off on the incident report and forward a signed copy for filing to the Director, IM/IT.
Prevention
- The Director, IM/IT is responsible for ensuring the identified mitigation measures to prevent recurrence are implemented. Once these activities have concluded, a note must be added to the incident report detailing the mitigation measures taken along with the completion date and any other relevant information.
- OIPC employees are required to participate in any activities arising from an IT security incident to the extent that they are involved in that IT security incident.
Breaches
Containment
- OIPC Employees must immediately report any suspected breach to their supervisor, or in their absence, to any member of the Senior Leadership Team (SLT).
- On receiving a report of a breach, the supervisor or SLT member must act promptly to:
- contain the breach to the degree possible, and
- report the breach to the Privacy Officer.
Risk Assessment
- On receiving a report of a breach, the Privacy Officer is to:
- identify any affected individuals or bodies and assess the risk of harm from the breach to these individuals or bodies,
- for any breach of Business Information, identify any affected individuals or bodies and assess the risk of harm to these individuals or bodies and determine whether there is a real risk of significant harm to the affected individuals as required by section 10(2) of POPA and in accordance with sections 4(1) and (2) of the POP (Ministerial) Regulation,
- Where it is determined by the Privacy Officer that there is a risk of harm to individuals or bodies as a result of the breach, the Privacy Officer shall inform the Commissioner or in the absence of the Commissioner, the Access/Privacy Coordinator.
Notification
- As soon as it is practicable thereafter, the Privacy Officer must prepare and issue notices to the affected individuals or bodies about the breach.
- For any breaches of Business Information, the notice requirements in sections 4(3) and (5) of the POP (Ministerial) Regulation must be complied with.
Reporting
- The investigation conducted by the Privacy Officer must be documented with mitigation measures to prevent recurrence. A copy of the investigation report must be shared with the Commissioner, or in the absence of the Commissioner, with the Access/Privacy Coordinator.
- On receiving a copy of the investigation report, the Commissioner or the Access/Privacy Coordinator, as applicable, must review and sign the investigation report and forward a signed copy for filing to the Privacy Officer.
Prevention
- The Privacy Officer is responsible for ensuring the identified mitigation measures to prevent recurrence are implemented. Once these activities have concluded, a note must be added to the investigation report along with the completion date and any other relevant information.
- OIPC Employees are required to participate in any activities arising from a breach to the extent that they are involved in that breach.
Third-Party Service Providers
- Third-Party Service Providers must immediately report any suspected or confirmed breach or IT security incident to the appropriate OIPC contract manager.
- Upon receiving a breach or IT security incident report from a Third-Party Service Provider, the OIPC contract manager is to follow the steps above, as applicable.
Third-Party Service Providers are required to participate in any activities arising from a breach or IT security incident to the extent that they are involved in that breach or IT security incident.
Roles and Responsibilities
OIPC Employees
Must immediately report potential breaches and IT security incidents to their supervisor.
Must participate in or cooperate with the investigation of the breach or IT security incident, as applicable, to the extent they are involved in a breach or an IT security incident.
Supervisors
Must immediately report potential breaches or IT security incidents to the Privacy Officer or the Director IM/IT, as applicable.
Must participate in or cooperate with the investigation of the breach or IT security incident, as applicable, to the extent they are involved in a breach or an IT security incident.
Third-Party Service Providers
Must immediately report breaches or IT security incidents to the appropriate OIPC contract manager.
Must participate in or cooperate with the investigation of the breach or IT security incident, as applicable, to the extent they are involved in a breach or an IT security incident.
Privacy Officer
Responsible for investigation and management of breaches in relation to OIPC Information.
As applicable, participates to any initiative aimed at preventing the re-occurrence of a breach.
Director IM/IT
Responsible for investigation and management of IT security incidents that impact or potentially impact OIPC IT resources.
As applicable, participates to any initiative aimed at preventing the re-occurrence of an IT security incident.
Monitoring and review period
This directive will be reviewed and updated every two years or as required.
Approval
This directive was approved by the Information and Privacy Commissioner on September 21, 2026 and is in effect.






