Sections marked as location-specific are showing the position in Ontario. Rules change — confirm current deadlines before relying on them.
Identify what actually happened
Privacy disputes take a few recognisable forms, and each has a different route. Being precise about which one applies saves time, because the regulator and the remedies differ.
| Situation | Usual first route |
|---|---|
| A security breach exposed your data | The organisation's breach notification, then the regulator |
| Someone inside an organisation looked at your file | Internal privacy officer complaint, then the regulator |
| Your information was shared without consent | Complaint to the organisation, then the regulator |
| An access or correction request was refused | Internal review, then the regulator or tribunal |
| Information posted about you online | Platform removal routes, and possibly defamation or privacy claims |
The first steps that protect you
Immediately
Change passwords, enable multi-factor authentication, and review account activity.
Same week
Place fraud alerts or a credit freeze where financial data was involved.
In writing
Ask the organisation what data was involved, when, and what they are doing.
Keep
A log of every notification, call, cost and hour spent dealing with it.
Regulators in Ontario
Ontario's Information and Privacy Commissioner oversees provincial and municipal public bodies and personal health information, including access and correction requests and complaints about how health records were handled. Private-sector commercial activity generally remains under the federal regime.
Deadlines and reporting dutiesOntario
Organisations often have mandatory breach reporting duties measured in days. From your side, complaint windows to regulators are usually measured in months from when you became aware, and any civil claim runs on the ordinary limitation period.
Documents to gather
- The breach notification letter or email you received
- Your complaint to the organisation and its response
- Any access or correction request you made, and the reply
- The organisation's privacy policy in force at the relevant time
- Bank, credit and account statements showing suspicious activity
- Receipts for monitoring services, replacement documents or other costs
Evidence that carries weight
- A dated log of everything you did in response and how long it took
- Screenshots of the exposed information where it was published
- Correspondence identifying who accessed the information and when
- Credit reports before and after the incident
- Medical or counselling records where distress is claimed
Want both lists in one printable page?
Common mistakes
- Going straight to a regulator without complaining to the organisation first
- Not making a written access request to find out what was actually held
- Failing to record time and costs spent responding
- Accepting a free monitoring offer without checking whether it releases claims
- Letting the regulator complaint window pass while waiting for a response
Frequently asked
Can I find out exactly what data they hold about me?
Most privacy regimes give individuals a right to request access to their own personal information, usually with a defined response deadline and limited grounds for refusal.
Will the regulator get me compensation?
Generally no. Regulators investigate and can make findings or order changes, but compensation typically comes from a separate civil claim or a class proceeding.
What if the breach was caused by an employee snooping?
Unauthorised internal access is treated seriously in most systems and is usually handled first through the organisation's privacy officer, then the regulator.
Should I join a class action?
Large breaches often attract class proceedings. Joining one is usually low effort but limits individual control, and any settlement typically releases individual claims.
Nothing has happened yet — is it too early to act?
The protective steps are worth taking immediately, and keeping records from the start is what makes a later claim provable. Complaint windows can begin running from awareness rather than from harm.
Assess my situation
Concaso turns what you already know into a structured, confidential report — strengths, weaknesses, missing evidence, and the deadlines that matter. We will start you in the right place based on this guide, in Ontario.
Assess my situationAssessment topics related to this guide
Topics in this guide
Related guides
Recommended next read
Breach of Contract
What has to be shown in a contract dispute, how losses are usually measured, and the records that carry the most weight.
Recommended next read
Administrative Appeals
How decisions by public bodies, tribunals and regulators are reviewed, why the record matters more than new arguments, and why the deadlines are so short.
Recommended next read
Defamation and Online Reputation
What separates a damaging statement from an actionable one, how online posts and reviews are handled, and why the clock is unusually short.
Related reading
Human Rights and Discrimination Complaints
How discrimination and accommodation complaints are usually assessed, where they are filed, and what evidence tends to matter.
This guide is general information, not legal advice, and Concaso is not a law firm. Reading it does not create a lawyer–client relationship. Deadlines and procedures differ by jurisdiction and change over time — confirm anything you intend to rely on.