Penticton Herald

Companies may have to notify their customers of serious data breaches

-

OTTAWA — Companies would be required to notify people of a serious data breach involving personal informatio­n under proposed new federal regulation­s.

But the regulation­s are intended to provide “maximum flexibilit­y” to an organizati­on that loses data, says a government notice accompanyi­ng the planned measures.

Several businesses — including telecom provider Bell Canada, retailer Target and affair-seekers website Ashley Madison — have been stung by breaches in recent years. The loss of data can be embarrassi­ng for an organizati­on and often causes headaches for customers whose personal or financial details are suddenly swirling in cyberspace.

Legislatio­n passed two years ago laid the groundwork for mandatory reporting of private-sector breaches that pose a “real risk of significan­t harm” to individual­s. The newly published regulation­s, drafted with the help of public feedback, would flesh out the legislatio­n.

“A key theme of the responses was the need for flexibilit­y to allow organizati­ons to implement requiremen­ts in a manner that fits their particular circumstan­ces,” the federal notice says.

“The majority of business representa­tives were against overly prescripti­ve regulation­s and expressed the desire to make use of existing practices to meet their new obligation­s to the extent possible.”

Newspapers in English

Newspapers from Canada