Your data was in a breach — what to do now
Your data was in a breach — what to do now
Breach notifications are written by lawyers and tend to say very little clearly. The useful response depends entirely on what was exposed, so start there.
Step 1 — work out what was actually exposed
Read the notification for the specific list. Then match it:
| What was exposed | What it puts at risk | What to do |
|---|---|---|
| Email address only | Phishing targeted at you | Expect it. Be sceptical of mail about this company |
| Password | Every account where you reused it | Change it there and everywhere else you used it. Turn on 2FA |
| Payment card number | Fraudulent charges | Watch statements; ask for a replacement card |
| Address, phone, date of birth | Convincing impersonation and identity verification bypass | Be alert to callers who "already know" your details |
| SIN | Tax and benefit fraud, credit opened in your name | Fraud alert with both credit bureaus |
| ID document scans | Full identity theft | Fraud alert, plus consider replacing the documents |
| Health information | Insurance and benefit fraud, plus sensitivity | Contact the provider; check provincial health privacy rules |
The bottom three rows are the ones that justify real work. The top rows mostly justify vigilance.
Step 2 — passwords
If a password was exposed:
- Change it on the breached service.
- Change it everywhere you reused it. This is the whole ballgame — password reuse is how one breach at a forum becomes a compromised bank account.
- Start with your email account, which is the reset path for everything else.
- Turn on two-factor authentication on anything that matters — see Turn on two-factor authentication.
- Use passkeys where offered. They cannot be phished and there is no shared secret to steal — see Sign in with a passkey.
- Get a password manager, so uniqueness stops being something you have to remember to do.
Step 3 — identity data
If a SIN, date of birth, or ID document was exposed, this is the serious case.
- Place a fraud alert with both credit bureaus — Equifax Canada and TransUnion Canada, separately. An alert with one does not reach the other.
- Get your credit report and read it for accounts and inquiries you do not recognize.
- Watch your CRA account for a return or benefit claim filed in your name.
- Consider a credit freeze, where available, which is stronger than an alert.
Full detail: What to do if your SIN or ID is stolen.
Step 4 — the free credit monitoring
Companies almost always offer a year or two of free credit monitoring after a breach.
Take it. It costs nothing and adds a source of warning.
But understand what it is. Monitoring is detection, not prevention — it tells you after something has been opened in your name. A fraud alert or freeze is what makes opening the account harder in the first place. Do both; do not treat the free monitoring as the response.
Step 5 — expect the second wave
The most reliable consequence of a breach is not fraud. It is the follow-up scam, and it arrives within days.
The pattern: an email, text or call, referencing the breach you just heard about, offering help, compensation, or "verification". It is convincing precisely because the breach is real and the caller genuinely knows details about you.
Rules:
- Never click a link in a breach notification email. Navigate to the company yourself.
- Nobody legitimate calls to ask for your password, SIN, or a code sent to your phone. No bank, no government agency, no security team.
- A caller knowing your address and date of birth proves nothing — those are exactly what was breached.
- Hang up and call back on a number you looked up independently.
See How to spot a fake government website.
Your rights in Canada
Under PIPEDA, the federal private-sector privacy law, organizations must:
- report breaches of security safeguards that pose a real risk of significant harm to the Office of the Privacy Commissioner of Canada,
- notify affected individuals, and
- keep records of all breaches, whether or not they were reportable.
You can:
- request access to the personal information an organization holds about you,
- ask for corrections, and
- complain to the Office of the Privacy Commissioner of Canada about how an organization handled your information.
Some provinces have their own private-sector privacy laws deemed substantially similar, with their own commissioners, and health information is governed separately in most provinces. Provincial public bodies are covered by provincial legislation rather than PIPEDA.
Reducing your exposure going forward
You cannot stop other organizations from being breached. You can reduce how much of you is in each of them.
- Give less. Every optional field you skip is one that cannot leak — see Who can legally ask for your SIN.
- Use unique passwords everywhere, so a breach stays contained.
- Prefer passkeys where offered.
- Stop leaving documents in inboxes — see Is it safe to email your SIN, passport or ID?.
- Ask about retention. Data that has been deleted cannot be breached.
- Know where your data lives. Jurisdiction determines which laws apply — see Where your documents actually live when you upload them.
How my-id.ca helps
my-id.ca is a place your data is stored, so the honest framing is what we do to reduce your risk here — and what you can verify.
Data is encrypted and held on Canadian servers, which keeps it under Canadian privacy law. AI features run on my-id.ca's own infrastructure, so your documents are never sent to OpenAI, Google or Anthropic. Sign-in supports passkeys and TOTP two-factor authentication. Autofill is off on every website until you enable it there. You can export or delete everything at any time — no fee, no waiting period.
Trust and security sets out the security posture, the sub-processors, and the incident-response commitments — including what we do not currently hold, such as a third-party attestation. Read it before you decide.
Next steps
- What to do if your SIN or ID is stolen
- Where your documents actually live when you upload them
- Sign in with a passkey
- Export, correct, or delete your data
Important: this is general information, not legal advice
This article is general information — it is not legal, security, or financial advice, and my-id.ca does not provide legal or professional consultation. my-id.ca is not a government agency, law firm, lawyer, credit bureau, or licensed advisor, and is not affiliated with or endorsed by the Office of the Privacy Commissioner of Canada, the Government of Canada, Equifax, TransUnion, or any provincial commissioner.
Privacy legislation, breach-reporting obligations and your available remedies differ by province and sector and change over time. Always confirm the current rules with the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner. For advice about your individual circumstances, consult a qualified professional. If anything in this guide differs from an official source, the official source is correct.
Frequently asked questions
- Do Canadian companies have to tell me about a data breach?
- Under PIPEDA, organizations must report breaches of security safeguards that create a real risk of significant harm to the Office of the Privacy Commissioner of Canada, notify affected individuals, and keep records of all breaches. Some sectors and provinces have additional requirements.
- What should I do first after a breach notification?
- Identify what was exposed. Email addresses alone mean expect phishing. Passwords mean change them everywhere they were reused. Payment card details mean watch statements and consider replacement. SIN, date of birth or ID numbers mean place a fraud alert with both Canadian credit bureaus.
- Is the free credit monitoring worth accepting?
- Usually yes — it is free and it is one more source of warning. It is detection, not prevention: it tells you after something has happened. A fraud alert or credit freeze does more to stop credit being granted in your name.
- Should I change all my passwords?
- Change the breached account's password, and change it everywhere you reused it — reuse is what turns one breach into many. A password manager and unique passwords stop this from ever compounding again.
- Can I complain about a company that lost my data?
- Yes. You can complain to the Office of the Privacy Commissioner of Canada about an organization's handling of your personal information, and provincial commissioners handle complaints in provinces with substantially similar legislation.
- How do I find out if my data has been breached before?
- Reputable breach-notification services let you check whether an email address has appeared in known breaches. Use only well-established services, and never enter a password into a site to check whether it has been breached.