Ask Actually

Who reports a breach when your IT provider caused it?

In short

Ask your provider in writing what happened, when, and which personal information was involved, then confirm who handles breach reporting and notification. The Office of the Privacy Commissioner of Canada states that organisations subject to PIPEDA are responsible for personal information under their control, including information transferred to a third party for processing.

If something has gone wrong on systems your IT provider manages, consider making the first request in writing so there is a dated record of what you asked. Ask for the incident timeline, the systems named, and the provider's statement of what personal information was involved.

Where responsibility sits under federal privacy law

The Office of the Privacy Commissioner of Canada, in its guidance on assessing third-party service providers dated September 10, 2026, states that organisations subject to PIPEDA are responsible for personal information under their control, including personal information collected by a third party on their behalf or transferred to a third party for processing. The same guidance states that organisations must ensure comparable protection for personal information collected, used or disclosed on their behalf by a third party, and that Principle 4.1.3 of PIPEDA requires contractual or other means to achieve that.

That guidance covers assessment of third parties and states that it does not cover all requirements that may apply under PIPEDA. It points organisations to the OPC's separate guidance on breach reporting for obligations in the event of a data breach, which we have not reproduced here. So your own reporting obligations are a question to put to privacy counsel, not something to infer from a provider's assurance that the matter is handled.

What to request in writing

On subcontractors and roles, the OPC guidance recommends establishing subcontractor identities in writing, identifying the roles and responsibilities of your organisation and the provider, and confirming how a data breach will be managed. These are recommended practices in that guidance, not a statement of what your contract currently says.

Keep the reply in three separate columns in your notes

Record what the provider states, such as a summary of cause or an assurance that access was closed. Record separately any document, export, screenshot or log you receive: the record reports its contents, and receiving it does not by itself establish that it is complete, accurate or that the event occurred as described. Record separately again anything you or an adviser actually compared, naming the two items and the narrow result.

Also write down what nobody answered, and whether the system involved was inside the services you agreed. If it sits outside that agreed scope, ask who is responsible for it rather than assuming either party was.

What the provider's answer can and cannot settle

A provider's written account can tell you what the provider reports and can identify the systems it names. It cannot establish what happened in systems it does not name, and it is not an independent confirmation of its own accuracy. Ask what independent confirmation is available, for example a report from a third party engaged after the incident, and who commissioned it.

A slow or partial reply is consistent with several explanations, including staff workload, an unclear request, or advice to say little while an insurer or counsel is involved. Those possibilities do not tell you the cause, so the useful next step is a dated follow-up asking specifically what is still outstanding and when it will arrive.

Deciding whether to keep, improve or replace the provider

One incident, on its own, does not settle whether the arrangement works. Gather the written record as well: whether roles for breach handling were agreed before the incident, whether the account you received matches the documents supplied, and whether questions you asked remain unanswered. Take that record into the renewal discussion rather than a general impression.

The OPC guidance also suggests considering how the performance and security of a provider's technology can be monitored once it is implemented, listing access logs, reporting tools, regular testing and independent audits, and separately suggests considering how the provider's compliance with privacy obligations can be monitored on an ongoing basis, through inspections or independent audits. Whether any of those apply to your arrangement is a question for the provider and for whoever agreed your current contract.

For the wider comparison of agreed services, documents and unresolved issues, see how to evaluate the managed IT provider you already have. If you want that assessment done independently, the actually. review is the relevant service.

actually. offers an independent review of evidence about your existing IT provider.

The review is a paid service.

Sources

This is one question. An independent review answers the rest, with evidence.

Request an Independent Review