Under PIPEDA, organisations must report qualifying breaches to the Privacy Commissioner and notify affected individuals as soon as feasible, and must keep records of all breaches regardless of whether they are reportable.
Why it matters: the record-keeping duty applies to every breach, not only reportable ones, and failing to report a qualifying breach carries its own consequences.