Being notified about a privacy breach

As of 2022, Manitoba public bodies and trustees are required to report privacy breaches to Manitoba Ombudsman when the public body or trustee determines there is a real risk of significant harm to an individual because of the breach. They are also required to notify affected individuals.

A privacy breach occurs when there is theft or loss, or unauthorized access, use, disclosure, destruction or alteration of personal information or personal health information.

The laws that outline requirements of notice and action relating to privacy breaches are The Personal Health Information Act (PHIA) for personal health information and The Freedom of Information and Protection of Privacy Act (FIPPA) for personal information.

The criteria for determining if a breach could create a risk of harm is defined under FIPPA regulation and PHIA regulation.

What happens when a public body or trustee reports a breach to Manitoba Ombudsman?

The privacy breach will be reviewed by our office whether we receive individual complaints or not. Typically, after receiving a privacy breach report, our team would conduct a privacy breach review.

  • We determine if the public body or trustee took all reasonable steps to respond to the breach.
  • We assess the public body or trustee’s compliance with legislation and regulation for determining if there was a real risk of significant harm, and we review how affected individuals were notified.
  • We may identify gaps in the response and ask the public body or trustee to address them. We may also give guidance for appropriate action to improve privacy protection and prevent similar breaches from happening again in the future.

The Ombudsman can also decide to open an investigation into a privacy breach reported to our office by the public body.

All investigations done by the Ombudsman are done in private. We do not confirm publicly that investigations have been initiated or are ongoing.

Will I get a copy of the privacy breach review if my information is involved but I did not make a complaint?

Our privacy breach reviews are provided directly to the public body or trustee who reported the breach to us. The body/trustee is asked to make any necessary improvements to prevent harm or additional breaches. If the Ombudsman has opened and completed an investigation into a reported privacy breach, the Ombudsman may publish the report on our website, but not all investigations are published.

What if I am affected by the breach?

If your information has been affected, the public body or health information trustee is required to notify you and provide detailed information about the breach including:

  • Timelines
  • The personal information affected
  • What they have or will be doing to reduce risk of harm and future breaches
  • Advice to you on what you can do to reduce your risk of harm
  • If our office has been notified as required by legislation
  • Where you can direct your questions to
  • And any other information they feel is relevant

If the body/trustee is not able to contact you directly, it may post relevant information through publicly accessible platforms such as websites or social media, or by posting physical posters in relevant places or doing a news release.

The body/trustee involved is your main source of ongoing information and updates about the breach and any measures, supports and services it may be offering to you as a result.

We encourage you to read that information carefully to learn about what occurred and what next steps are available to you.

Can I still make a complaint?

You have the right to make a complaint to the Ombudsman about how a public body or trustee handled your personal information or personal health information, including instances where information was disclosed/shared in a way that is not authorized by law.

If a breach report has been made to the Ombudsman by the body/trustee, the complaint may be handled at the same time as the breach review because information gathered during our review may inform the complaint investigation.

What are my privacy rights?

Manitoba public bodies and trustees should only collect, use, store or disclose your personal information or personal health information as authorized under FIPPA and PHIA. You have the right to:

  • privacy of your personal or personal health information, which should only be collected, used and disclosed for purposes allowed by FIPPA and PHIA
  • protection of your personal or personal health information through physical, administrative and technical security safeguards
  • access your personal or personal health information, and ask that any errors be corrected
  • be notified by a public body or trustee of a privacy breach when required
  • have someone else exercise your rights, including making a complaint on your behalf
  • make a complaint to the Ombudsman about how a public body or trustee handled your personal or personal health information or the body’s response to your request to access/correct that information

Learn more about: