A data breach in Canada now costs CA$7.11 million on average, and takes 205 days to find and contain. Neither number is set by the attacker.
Both come from IBM's Cost of a Data Breach 2026 report for Canada, published 29 July 2026: a record CA$7.11 million average, an average of 28,500 compromised records per breach, and a lifecycle that grew 6% year over year to 205 days from compromise to containment.
Start with the good news
Canadian courts have actually been kind to breached companies.
In Setoguchi v. Uber B.V., Alberta's courts refused to certify a class action over a breach that exposed data on 57 million Uber drivers and riders. The data at the centre of the Alberta case was names, phone numbers and email addresses. Nobody proved it had ever been used against anyone, and the court found no basis in fact for real, compensable harm. Risk of future harm, it held, is not compensable.
Certification was denied at first instance in 2021 ABQB 18. The appeal was dismissed in 2023 ABCA 45. The Supreme Court of Canada refused leave to appeal in July 2023 (docket 40681).
Owners read that and hear "we're covered."
Now read what that ruling actually is
It isn't a shield around your company. It's a description of a fact pattern that happened to be true that day: data that wasn't sensitive, and no evidence of misuse.
Change either fact and the ruling stops helping you.
In Owsianik v. Equifax Canada Co., 2022 ONCA 813, the data included social insurance numbers, dates of birth and credit card numbers. Ontario's Court of Appeal closed the intrusion-upon-seclusion route against companies that fail to prevent a third party's intrusion — and it was explicit that the plaintiffs still had remedies. (Ontario law is persuasive in Alberta, not binding.)
What survived
Breach of contract. Negligence. Breach of statute. All three were left intact, subject to proving a loss the law will compensate.
Negligence asks one question: was your conduct reasonable?
That question isn't answered by the attack. It's answered by what you built, what you knew, and what you were able to do next — decisions all made long before the breach.
What cheap code actually takes
Cheap code rarely causes the breach by itself. It removes your ability to be diligent after one.
- •No logs → you can't say what was taken. Alberta's PIPA requires reporting to the Commissioner when a breach creates a real risk of significant harm (s. 34.1). You cannot run that test on data you can't enumerate.
- •Shared admin credentials → you can't say who did what.
- •No record of which systems hold personal information → every answer to a regulator starts with "we think."
Each of those is a sentence read aloud in a courtroom.
What changes on Monday
Here's the part nobody says out loud: the cheapness usually wasn't the developer's failure. It was the spec. Logging, access control and dependency upkeep weren't in the scope you paid for, so they weren't in the code you got.
That was a purchasing decision — which means it's still reversible.
It's also not rare. Veracode's 2026 State of Software Security, which analyzed 1.6 million unique applications, found 82% of organizations carrying security debt and 60% of those carrying debt rated critical. The difference between companies isn't whether they have it — it's whether they know where it is. (Veracode sells application security, and this is its own platform data; it's used here to describe how common the condition is, not to recommend a product.)
Three questions for whoever owns your code:
1.If someone got in last night, which log tells us what they touched — and how long do we keep it?
2.Which systems hold personal information, and who has standing access to each?
3.What's in our dependency list that hasn't been updated in a year?
If those answers take more than a week to produce, that is the answer.
You didn't buy code. You bought every consequence it makes possible.
Alberta's PIPA is under review: a legislative committee recommended 12 amendments in February 2025 and the province consulted publicly through February 2026. No amendment bill has been introduced.