Vancouver · Closed, opens 09:00604-324-5711Delta · Closed, opens 09:00604-635-0890Surrey · Closed, opens 09:00604-319-1000
Business Insurance BC  /  Cyber Insurance for Business BC  /  Data Breach Duties for BC Firms
Client data · breach duties · professional firms

A breach is not only an IT problem. It is a reporting duty.

Firms that hold client records – accountants, consultants, engineers, brokers, clinics – think of a breach as something the IT person fixes. Canadian privacy law turns it into a set of legal duties that start running the moment you know. Those duties cost real money whether or not a single client ever sues you.

Build the cyber file The short answer
Duty one

Report it to the Privacy Commissioner where the harm test is met

Duty two

Tell the people whose information it was, as soon as feasible

Duty three

Keep a record of every breach, including the small ones

The short answer

What does a professional firm have to do after a data breach?

Three things, and only the first is optional depending on severity. Report the breach to the Office of the Privacy Commissioner of Canada where it is reasonable to believe it creates a real risk of significant harm. Notify the affected individuals as soon as feasible. And keep a record of every breach of security safeguards, including the ones that did not meet the harm test.

The record-keeping duty is the one firms are most often unaware of, because it applies to breaches that were never serious enough to report. The Commissioner can ask to see those records. The exact requirements are set out by the regulator and are worth reading directly rather than second-hand: Office of the Privacy Commissioner of Canada, mandatory reporting of breaches of security safeguards.

What it costs you

Legal advice on whether the harm test is met, a forensic report to work out what actually left, notification to everyone affected, and the time of whoever runs the firm. All of that happens before anyone decides whether you were negligent.

Two different policies

Errors and omissions does not answer this.

Errors and omissions

Answers when your professional work or advice causes a client a financial loss. A mistake in the thinking, or a step that was missed.

Cyber

Answers the breach itself – the forensics, the legal advice on your duties, the notification, the credit monitoring, the business interruption while systems are down, and an extortion demand if one arrives.

What firms get wrong

Three assumptions that cost money.

“We are too small to be a target”

Most breaches at small firms are not targeted. They arrive through a compromised email account or a supplier, and the attacker finds out who you are afterwards. Size affects how much is taken, not whether it happens.

“Our IT company handles it”

An IT provider restores systems. It does not decide whether the harm test is met, does not draft the notification, and does not carry the cost of getting either wrong. Those are legal and financial questions, and the duty sits with the firm holding the data.

“The data was the client’s, not ours”

The duty follows whoever holds the information, not whoever originally collected it. A firm holding client records on behalf of a client generally has its own obligations, and its own exposure to that client for failing them.

Common questions

What professional firms ask us about this.

Nothing was stolen. An employee just emailed a file to the wrong person. Does that count?

It can. A breach of security safeguards is not limited to hacking, and misdirected information is one of the most common causes. Whether it has to be reported turns on the harm test, but the record-keeping duty applies either way.

Does cyber cover pay a ransom?

Many wordings include extortion cover, and what it will and will not do varies a great deal between them. It is one of the sections most worth reading before you buy rather than during an incident, when the timeline is measured in hours.

We are cloud based. Is the provider responsible?

Their contract governs what they owe you. Your privacy duties to the individuals stay with you. Firms are often surprised how little a standard cloud agreement shifts, and it is worth reading alongside the insurance rather than instead of it.

Our client contract requires cyber cover at a set limit. Does the wording matter as much as the number?

More, usually. Two policies at the same limit can respond very differently on notification costs, business interruption and the waiting period before it starts. Send us the clause and the policy and we will tell you where they do not line up.

Will a claim on this affect our professional liability?

They are separate policies with separate histories, and a serious incident can affect how both are underwritten at renewal. Reporting properly and early tends to help on both sides.

Not the question you had? Build the cyber file and set out your own situation in plain words. A licensed broker reads it and replies in writing.

Tell us what you hold, and for whom.

We will tell you which duties land on your firm, what a cyber policy would actually answer for, and where your client contracts already commit you. Next business day, and usually the same day.