What a privacy breach actually costs a small Canadian business
A breach costs more than a fine. Real numbers on notification, lost clients, and cleanup — and what Canadian AI tools can do to lower the odds.
A privacy breach at a small business rarely means a dramatic fine. It usually means two weeks of your time, a few thousand dollars in cleanup, and a handful of clients who quietly stop calling. Most people asking about breach costs are picturing a headline-size number. The real number is smaller and stranger, and it hits nine-person companies just as hard as it hits big ones.
What actually happens after a breach
Say an employee's laptop gets stolen, or a phishing email tricks someone into handing over a client list. Here is the sequence, roughly, for a small operation.
First, you figure out what happened. That takes a day or three, depending on how good your records are. Then you decide who needs to be told. Quebec's privacy law and the federal privacy law, called PIPEDA, both require you to notify people if the breach creates a real risk of harm. You draft a letter. You probably call a lawyer to check the letter, because getting the wording wrong can make things worse.
Then you notify. Some clients call back annoyed. A few ask to end the relationship. You spend real hours on this instead of billing hours, and for a nine-person shop, that gap shows up on the bottom line fast.
There's also a step people forget: you have to decide whether to tell the regulator, not just the affected clients. Quebec's privacy law requires you to report certain breaches to the provincial regulator, and the federal regulator has its own separate reporting line if PIPEDA applies. These are two different letters, sometimes two different timelines, and missing one because you assumed the other covered it is a common, avoidable mistake.
How much does this cost in dollars
There's no single number, because it depends on what was taken and how many people were affected. But the components are predictable:
- Investigation and IT cleanup: often C$2,000 to C$10,000, more if a forensic specialist is needed
- Legal review of your notification letter: a few hundred to a couple thousand dollars for a couple hours of a privacy lawyer's time
- Notification costs themselves: postage, a call centre if volumes are high, sometimes credit monitoring for affected clients
- Lost business: the hardest to measure, often the largest, and the one nobody puts on an invoice
Add it up and a modest breach at a small company can easily run C$15,000 to C$50,000 once lost clients are counted. That's before any fine.
A breach doesn't have to make headlines to cost you a month's revenue.
The fines exist too, and they're not small. Quebec's privacy law allows penalties that scale with the size of the offence, and they apply to businesses of any size, not just large ones. But fines are the tail end of a bad process. Most small businesses that get hit never see a fine at all, because regulators generally go after companies that ignored the problem, not ones that reported honestly and fixed it.
A skeptical owner might ask: if fines are rare, why bother with any of this? Because the regulator's leniency depends on you having something to show them. A company that can prove it encrypted its laptops and notified promptly gets treated differently than one that discovers the breach from a client's angry email. The paperwork you do now is the evidence you'd need later.
Why do small businesses think they're too small to target
This is the part that trips people up. Owners assume attackers want big fish. In practice, small businesses are easier targets precisely because they don't have a security team, and criminals know it. A nine-person accounting firm holding client SINs and banking details is worth exactly as much to a data thief as a five-hundred-person one, arguably more, because the defences are thinner.
The federal privacy regulator has said publicly that small and medium businesses report a disproportionate share of breaches relative to their size. You don't need a citation to believe that. You've probably had a phishing attempt in your own inbox this month.
Where do AI tools fit into this risk
Here's the part people don't expect: the AI tool you use for drafting emails or summarizing contracts is itself a privacy exposure point. If you're pasting client names, case details, or financial data into a US-based chatbot, that data may be stored on servers governed by US law, and it may be used to train someone else's model. That's a second breach waiting to happen, layered on top of your first one.
This is where a Canadian AI platform changes the math. Augure stores customer data in Canada, as Canadian privacy law requires. Its AI inference runs on Canadian infrastructure and, for certain model tiers and during failover, with vetted EU partners under zero-data-retention agreements — never on US servers. Customer data is never used to train models. Augure has no US corporate parent and no US investors, so customer conversations and documents aren't handled by companies answerable to US disclosure laws. Payment processing and email delivery still involve US providers, which Augure discloses in its privacy policy, but no customer content touches them. Using Augure doesn't erase your own compliance obligations. It does mean the tool you use every day isn't adding a new place for client data to leak.
Augure is Canadian and starts free, which matters for a business trying to lower risk without adding a new line item. The free tier gives you 50 messages a day and basic document search, enough for a small team to stop using riskier consumer tools without spending anything.
What actually lowers your odds this year
Cost control here isn't about buying insurance and hoping. It's about the boring stuff: knowing what data you hold, encrypting laptops, and picking tools that don't make your risk worse. A privacy breach almost always starts with something ordinary — a lost device, a reused password, a spreadsheet emailed to the wrong person. None of that requires a compliance officer to fix. It requires someone deciding this week that it matters.
Some businesses do need more than the basics. Law firms handling client contracts, for instance, need tools built for that specific risk. Augure Legal does contract review and compliance checks against Quebec's privacy law and PIPEDA for C$149 a month for a solo practitioner, cheaper than the legal review fee after a single breach.
What to do this week
- List where client data actually lives — laptops, shared drives, and any AI tool your team uses. If you don't know, ask everyone by Friday.
- Turn on device encryption on every laptop and phone that touches client information. This is free and takes twenty minutes per device.
- Move sensitive drafting off consumer AI tools. Set up a free Augure account this week and see if it covers what your team actually needs before you pay for anything.
Start at augureai.ca.
Where this comes from: Quebec's privacy law is formally An Act respecting the protection of personal information in the private sector (Law 25).
About Augure
Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.
More insights
View all →The Consent Question Small Businesses Keep Getting Wrong
Law 25 penalties: will a C$25M fine actually hit a nine-person business?
PIPEDA in plain language: what Canadian business owners actually owe their customers
Put this to work: Augure Chat, Canadian-hosted AI →