← Back to Insights
Compliance Education

What to Do in the First 72 Hours of a Data Breach in Canada

A practical, first-person account of the first 72 hours after a breach — what our office actually did, in order, and what turned out not to matter.

By Augure·
a sign on a door that says open business hours

The breach didn't stop us cold. What stopped us was figuring out, inside the first few hours, whether we had a "real and significant risk of harm" under PIPEDA or whether we were still just guessing. Those are two different obligations with two different clocks, and nobody on our team could say with confidence which one we were in.

We're a mid-size professional services firm. We hold client files, HR records, some payment data. We're small enough that a breach isn't background noise, and there's enough personal information sitting on our servers that it was never going to stay hypothetical. What follows is what we actually did, in order, including the parts that wasted time.

The First Call Was Not to the Regulator

Our security reviewer's first move was to isolate the affected system, not to figure out what to say publicly. That surprised a couple of people in the room who expected disclosure to come first. It has to come second — you can't describe a breach accurately to anyone, including yourself, until you've stopped it from continuing.

We pulled the affected server off the network within about ninety minutes of confirmation. Confirmation took longer than I expected, close to four hours, because the first alert looked like a false positive from our email filtering. Someone had to manually check log timestamps against login records before anyone would say the word "breach" out loud.

Who Do We Actually Have to Tell, and When

This is where the PIPEDA and Law 25 lines diverge, and it mattered more than I expected going in.

Under PIPEDA, the obligation is to report to the Office of the Privacy Commissioner of Canada "as soon as feasible" after determining there's a real risk of significant harm. No fixed hour count. That sounds like relief until you realize "as soon as feasible" is a standard your counsel has to defend later, not a deadline you can just meet and move past.

Law 25 is more specific for firms with a Quebec footprint. Section 3.5 of the Act respecting the protection of personal information in the private sector requires notifying the Commission d'accès à l'information without delay once there are reasonable grounds to believe an incident presents a risk of serious injury. We had two Quebec clients in the exposed dataset, which is what pulled Law 25 into the room at all. If that number had been zero, our counsel's read was that PIPEDA alone would have governed, and the whole shape of the first day would have looked different.

"Risk of serious injury" is a defined threshold, not a vibe. That's the piece of statutory language our counsel would not paraphrase loosely.

The List of Questions We Actually Asked

Before anyone touched a notification draft, our privacy lead ran through a short list, out loud, in a room with security and counsel both present:

  • What data categories were exposed, and can we say that with evidence rather than assumption?
  • Is there a real and significant risk of harm, per the PIPEDA standard, or are we still speculating?
  • Does the affected population include Quebec residents, which triggers Law 25's separate notice obligation?
  • What's our earliest defensible date for "reasonable grounds to believe," since that's when the clock legally starts, not when we feel ready?
  • Who internally is authorized to sign a regulator notification, and is that person available in the next 24 hours?

That fifth question ate more time than it should have. Our sign-off chain assumed availability that didn't exist on a Saturday, and we lost close to six hours locating the one person who could authorize outside counsel to file on our behalf.

The Detail That Turned Out Not to Matter

We spent an embarrassing amount of energy early on debating whether our cyber insurance policy's own notification clock — 48 hours to notify the insurer — would somehow shorten our regulatory deadline. It doesn't. The insurer clock and the regulator clock run independently. Conflating them just added stress without changing a single decision we made. I'd skip that whole conversation if I were doing this again.

Where AI Tools Fit, If They Fit at All

Somewhere around hour thirty, with a stack of exposed files that needed reading and categorizing fast, someone floated the idea of running the document set through an AI tool to speed up triage — figuring out which files contained names, which contained SIN numbers, which were just internal memos with nothing sensitive in them.

Jurisdiction stopped being an abstract compliance topic right about here and became an operational question with a clock attached. Feeding client files, mid-breach, into a US-hosted AI tool felt like stacking one exposure on top of another, and our security reviewer said as much almost immediately. The CLOUD Act point is the one our counsel would not move on: US authorities have a legal pathway to customer content handled by US-jurisdiction providers, regardless of where the servers physically sit, and during an active breach that's not a risk anyone wanted to add on purpose.

We looked at three options that week, and Augure was one of them, mostly because it kept surfacing in searches for Canadian AI tools built with PIPEDA and Law 25 in mind rather than bolted on after the fact. What we tested was the Knowledge Base feature against a sample batch of the exposed files, uploaded under a controlled, non-production account. It correctly flagged document types containing SIN-pattern strings in about the time it took to review the summary output — maybe four minutes for sixty files. It's not a substitute for legal judgment about what counts as personal information under the Act, and it didn't pretend to be. At C$80 a month for the tier with the document allowance we needed, cost wasn't the deciding factor either way.

The bigger reason a Canadian AI platform mattered here wasn't speed. Augure stores customer data in Canada. Inference for certain model tiers runs on Canadian infrastructure, with vetted EU partners handling other tiers and failover under zero-data-retention agreements, and none of it is routed to US providers. Augure has no US corporate parent, and customer conversations and documents aren't handled by US-jurisdiction providers, so the CLOUD Act's reach over US-controlled providers doesn't extend to that content. That's narrower than "everything stays in Canada" — payment processing and email delivery still involve US-based services, per their privacy policy — and I'd rather state it that narrowly than have someone catch us overselling it later.

What I'd Redo

I think we over-invested in polishing public messaging before we'd even nailed down the affected data categories. My read now is that internal accuracy should come before external tone, every time, even when someone senior is anxious about optics. We were not sure, in the first six hours, whether we were looking at a few dozen records or a few thousand. That uncertainty should have driven urgency toward data scoping, not toward drafting a client-facing statement we ended up rewriting twice anyway.

The other thing I'd change: we didn't loop in the eventual notification-drafting lawyer until day two. Bringing counsel in at hour one instead of hour thirty would have saved us at least one dead-end conversation about deadlines that turned out to be governed by an entirely different statute than the one we were reading from.

If you're staring down something similar right now, the short version is this. Contain first. Work out the legal threshold before you work out the message. And be honest with yourself about whether any tool you bring in mid-crisis is adding risk instead of cutting it. More on how Augure handles that document-review question, including what data stays where, is at augureai.ca.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started