Back to Research

WHEN, NOT IF // 03

When, Not IfAug 18, 20264 min

The cheapest developer you ever hired

Canadian courts have been kind to breached companies — but Setoguchi describes a fact pattern, not a shield, and Owsianik left negligence, contract and statutory claims alive. Negligence asks whether your conduct was reasonable, and that is the one question cheap code makes unanswerable: no logs, no record of what you hold, no way to run the test PIPA s. 34.1 requires.

A data breach in Canada now costs CA$7.11 million on average, and takes 205 days to find and contain. Neither number is set by the attacker.

Both come from IBM's Cost of a Data Breach 2026 report for Canada, published 29 July 2026: a record CA$7.11 million average, an average of 28,500 compromised records per breach, and a lifecycle that grew 6% year over year to 205 days from compromise to containment.

Start with the good news

Canadian courts have actually been kind to breached companies.

In Setoguchi v. Uber B.V., Alberta's courts refused to certify a class action over a breach that exposed data on 57 million Uber drivers and riders. The data at the centre of the Alberta case was names, phone numbers and email addresses. Nobody proved it had ever been used against anyone, and the court found no basis in fact for real, compensable harm. Risk of future harm, it held, is not compensable.

Certification was denied at first instance in 2021 ABQB 18. The appeal was dismissed in 2023 ABCA 45. The Supreme Court of Canada refused leave to appeal in July 2023 (docket 40681).

Owners read that and hear "we're covered."

Now read what that ruling actually is

It isn't a shield around your company. It's a description of a fact pattern that happened to be true that day: data that wasn't sensitive, and no evidence of misuse.

Change either fact and the ruling stops helping you.

In Owsianik v. Equifax Canada Co., 2022 ONCA 813, the data included social insurance numbers, dates of birth and credit card numbers. Ontario's Court of Appeal closed the intrusion-upon-seclusion route against companies that fail to prevent a third party's intrusion — and it was explicit that the plaintiffs still had remedies. (Ontario law is persuasive in Alberta, not binding.)

What survived

Breach of contract. Negligence. Breach of statute. All three were left intact, subject to proving a loss the law will compensate.

Negligence asks one question: was your conduct reasonable?

That question isn't answered by the attack. It's answered by what you built, what you knew, and what you were able to do next — decisions all made long before the breach.

What cheap code actually takes

Cheap code rarely causes the breach by itself. It removes your ability to be diligent after one.

  • No logs → you can't say what was taken. Alberta's PIPA requires reporting to the Commissioner when a breach creates a real risk of significant harm (s. 34.1). You cannot run that test on data you can't enumerate.
  • Shared admin credentials → you can't say who did what.
  • No record of which systems hold personal information → every answer to a regulator starts with "we think."

Each of those is a sentence read aloud in a courtroom.

What changes on Monday

Here's the part nobody says out loud: the cheapness usually wasn't the developer's failure. It was the spec. Logging, access control and dependency upkeep weren't in the scope you paid for, so they weren't in the code you got.

That was a purchasing decision — which means it's still reversible.

It's also not rare. Veracode's 2026 State of Software Security, which analyzed 1.6 million unique applications, found 82% of organizations carrying security debt and 60% of those carrying debt rated critical. The difference between companies isn't whether they have it — it's whether they know where it is. (Veracode sells application security, and this is its own platform data; it's used here to describe how common the condition is, not to recommend a product.)

Three questions for whoever owns your code:

1.If someone got in last night, which log tells us what they touched — and how long do we keep it?

2.Which systems hold personal information, and who has standing access to each?

3.What's in our dependency list that hasn't been updated in a year?

If those answers take more than a week to produce, that is the answer.

You didn't buy code. You bought every consequence it makes possible.


Alberta's PIPA is under review: a legislative committee recommended 12 amendments in February 2025 and the province consulted publicly through February 2026. No amendment bill has been introduced.

Written by Levon Azevedo

Get the next one by email.

Subscribe

Want to know where your company actually stands? Eva will walk you through it — 15 minutes, no account, nothing stored: blackicelabs.ca/readiness

This is not legal advice. Breach obligations depend on your jurisdiction, sector and facts — get counsel.