A breach is not only an IT problem. The first question is which privacy law covers you.
Firms that hold client records, from accountants and consultants to engineers and clinics, think of a breach as something the IT person fixes. Which privacy law covers you decides what you have to do next, and in British Columbia that answer is worth knowing before anything goes wrong. Either way the response costs real money whether or not a single client ever sues you.
Build the cyber file The short answerWork out which privacy law covers you. BC’s own Act, the federal one, or both.
There is no duty to report a breach or to notify the people affected. That does not make it the wrong thing to do.
Report, notify where the harm test is met, and keep a record of every breach.
What does a professional firm have to do after a data breach?
It depends on which privacy law covers you. A BC firm handling personal information inside British Columbia is generally under BC’s Personal Information Protection Act, and its regulator is the Office of the Information and Privacy Commissioner for BC. That Act does not require you to report a breach or to notify the people affected. The federal law, PIPEDA, does require both, and it still reaches a BC firm when personal information crosses a provincial or national border. It always covers federally regulated businesses such as banks, airlines and telecoms. Where the federal law applies, the same test decides two of the three duties. Report the breach to the Office of the Privacy Commissioner of Canada, and tell the people affected, where it is reasonable to believe the breach creates a real risk of significant harm. The record-keeping duty applies either way.
Where the federal law applies, the record-keeping duty is easy to miss, because it covers breaches that were never serious enough to report. The record has to be kept for a set period, and the Commissioner can ask to see it. The exact requirements are set out by the regulator and are worth reading directly rather than second-hand: Office of the Privacy Commissioner of Canada, mandatory reporting of breaches of security safeguards (opens in a new tab).
Legal advice on whether the harm test is met, a forensic report to work out what actually left, notification to everyone affected, and the time of whoever runs the firm. All of that happens before anyone decides whether you were negligent.
Errors and omissions does not answer this.
Errors and omissions
Answers when your professional work or advice causes a client a financial loss. A mistake in the thinking, or a step that was missed.
Cyber
Answers the breach itself: the forensics, the legal advice on your duties, the notification, the credit monitoring, the business interruption while systems are down, and an extortion demand if one arrives.
Three assumptions that cost money.
“We are too small to be a target”
A breach at a small firm does not have to be aimed at the firm at all. They arrive through a compromised email account or a supplier, and the attacker finds out who you are afterwards. Size affects how much is taken, not whether it happens.
“Our IT company handles it”
An IT provider restores systems. It does not decide whether the harm test is met, does not draft the notification, and does not carry the cost of getting either wrong. Those are legal and financial questions, and the duty sits with the firm holding the data.
“The data was the client’s, not ours”
The duty follows whoever holds the information, not whoever originally collected it. A firm holding client records on behalf of a client generally has its own obligations, and its own exposure to that client for failing them.
What professional firms ask us about this.
Nothing was stolen. An employee just emailed a file to the wrong person. Does that count?
It can. A breach of security safeguards is not limited to hacking, and misdirected information is a common cause. Whether it has to be reported turns on the harm test, but the record-keeping duty applies either way.
Does cyber cover pay a ransom?
Many wordings include extortion cover, and what it will and will not do varies a great deal between them. It is one of the sections most worth reading before you buy rather than during an incident, when the timeline is measured in hours.
We are cloud based. Is the provider responsible?
Their contract governs what they owe you. Your privacy duties to the individuals stay with you. A standard cloud agreement may shift less than it appears to, and it is worth reading alongside the insurance rather than instead of it.
Our client contract requires cyber cover at a set limit. Does the wording matter as much as the number?
More, usually. Two policies at the same limit can respond very differently on notification costs, business interruption and the waiting period before it starts. Send us the clause and the policy and we will tell you where they do not line up.
Will a claim on this affect our professional liability?
They are separate policies with separate histories, and a serious incident can affect how both are underwritten at renewal. Reporting properly and early tends to help on both sides.
Not the question you had? Build the cyber file and set out your own situation in plain words. A licensed broker reads it and replies in writing.
Tell us what you hold, and for whom.
We will tell you which duties land on your firm, what a cyber policy would actually answer for, and where your client contracts already commit you. Next business day.