TerraLex Cross-Border Guide to Global Crisis Management Regulatory Guide

Welcome to the TerraLex global crisis management regulatory guide

When a crisis hits your organisation, you need to take action quickly. What practical steps can you and your team take to minimize the impact on your business? What are your reporting requirements in the relevant jurisdiction(s)? What legislation applies there?

Our guide provides you with the answers to these questions in relation to key jurisdictions and it supports your understanding of the relevant local legal framework. It also provides high level practical guidance for those crucial first 72 hours, together with contact details of the local TerraLex firm for when you need specialist advice.

A crisis, by its nature, is both serious and unexpected and your response and actions within the first 72 hours will most likely define its impact on your organisation.

It is therefore important to have in place robust procedures that, if followed, will help minimize the adverse consequences.

The crisis checklist below includes next steps which are common across all jurisdictions. Please refer to the chapter for the relevant jurisdiction for more detailed guidance on your obligations in that country.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Canada Global Crisis Management Regulatory Guide Guide

Date posted:
22/04/2026
Last update:
16/07/2025

Data breach

On discovering a data breach, which regulators or other government agencies should be notified?

  • An organization that is federally regulated or that processes personal information in the course of a commercial activity (except in Alberta, British Columbia or Quebec) must notify the federal Privacy Commissioner of a breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual. The organization must also notify affected individuals and organizations or government institutions that may be able to reduce or mitigate the risk of harm.
  • An organization that is subject to Alberta's private sector privacy legislation must notify the Alberta Privacy Commissioner of any incident involving the loss of or unauthorized access to or disclosure of personal information under the organization's control where a reasonable person would consider that there exists a real risk of significant harm to an individual as a result of the incident. The Privacy Commissioner may require the organization to notify affected individuals.
  • An organization that is subject to Quebec's private sector privacy legislation must notify the Commission d’accès à l’information of any confidentiality incident involving personal information the organization holds that presents a risk of serious injury. A "confidentiality incident" includes any (i) access, use or communication of personal information that is not authorized by law, (ii) loss of personal information, or (iii) other breach of the protection of personal information. The organization must also notify any person whose personal information is concerned by the incident, and may notify any person or body that could reduce the risk of serious injury.
  • The respective private sector privacy legislation in British Columbia does not contain similar notification obligations.
  • Some jurisdictions also have public sector and industry-specific legislation that require breach notification in certain circumstances. Certain regulatory bodies, such as the Office of the Superintendent of Financial Institutions, have also issued guidance about reporting certain data breaches or security incidents.

What legislation, relating to both criminal offences and civil wrongs, covers such a breach?

The breach reporting and notification obligations referenced above arise from the following legislation:

  • the federal Personal Information Protection and Electronic Documents Act;
  • Alberta's Personal Information Protection Act; and
  • Quebec's Act respecting the protection of personal information in the private sector.

As noted above, additional applicable public sector and industry-specific legislation or guidance may require notification in certain circumstances.

The provinces of British Columbia, Saskatchewan, Manitoba and Newfoundland have also adopted a statutory tort of invasion of privacy.

Additionally, Canada’s Criminal Code contains various provisions relevant to data protection and cyber security, though generally these offences apply to the perpetrator of certain breaches (such as hacking, mischief or fraud).

"Dawn" raids

What agencies have the power to conduct dawn raids on private sector companies? What legislation gives those agencies the power to undertake those inspections?

Numerous agencies have the power to conduct dawn raids on private sector companies, depending on the enforcement regime. These agencies include: provincial and federal police; the Competition Bureau; the Canada Border Services Agency; environmental protection, labor, securities commissions, and tax authorities. In almost all situations, except by reason of exigent circumstances (which include the risk that relevant records could be lost or destroyed), the agency must obtain a search warrant from a court.

  • The search and seizure powers of the federal Criminal Code can be used regarding all offenses violating federal laws (e.g. bribery, fraud, forgery, money laundering, customs violations, export/import controls, trade sanctions, etc.).
  • The federal Competition Act allows for search warrants to be granted pursuant to both civil and criminal investigations (including for hard core cartel conduct, abuse of dominant position and misleading advertising).
  • As well, a number of federal and provincial statutes have regulatory inspection powers. These include legislation relating to securities, environmental protection, occupational health and safety and tax. There is also sector-specific legislation that provide search and/or inspection powers (including legislation regarding financial services, food and beverage, pharmaceuticals, energy and transportation).

On what bases, including privilege and/or confidentiality, may organisations refuse to permit the seizure of documents?

List: - Provided the authority conducting the search complies with the scope of the warrant, there is rarely any basis pursuant to which confidentiality could prevent the seizure and review of documents.

  • Claims of solicitor-client or other types of legal privilege over documents may be asserted during the search and seizure process. Documents will be collected without being examined and sealed until a judge can assess the privilege claim. Review of these documents by the authorities conducting the search will only be undertaken once issues of privilege have been resolved.

Whistleblowing

What are the circumstances under which an employee is entitled to protection when reporting an alleged wrongdoing?

List: - Most notably, the Criminal Code protects employees who have provided information to the enforcement authorities in relation to federal or provincial criminal offenses that they believe have or are being committed. As a result, the Criminal Code’s protections of whistleblowers extend beyond offenses listed in the Criminal Code. As well, certain other legislation, such as the Competition Act, some provincial securities legislation and some public sector legislation, provide whistleblowers with additional protections.

  • However, in many circumstances, employees who are considering whistleblowing have a duty to their employer that requires the employee to raise the potential issue to the appropriate manager or supervisor within the organization.

  • Outside of the concept of reprisal under provincial employment standards, human rights and occupational health and safety legislation, the principles of whistleblower protection generally do not apply to non-criminal offences as well as issues with respect to following human resources or other internal policies.

What legislative protection does that employee enjoy?

  • Under the Criminal Code, no employer or person acting on behalf of an employer or in a position of authority over an employee shall take a disciplinary measure against, terminate or otherwise adversely affect the employment of a whistleblower or of a potential whistleblower (as a threat against whistleblowing), when such whistleblowing involves reporting a criminal offense to the enforcement authorities.

  • As noted above, other legislation may include additional protections. For example, a whistleblower’s identity will be kept strictly confidential under the Competition Act. As well, the Competition Act protects an employee who refuses to take any action based on a good faith belief that doing so would constitute an offence under the Competition Act. Also under the Competition Act, an employer cannot dismiss, suspend, demote, discipline, harass, or take any other reprisal action against an employee for whistleblowing or cooperating with the Competition Bureau in good faith, if the employee believes the information is true. There are significant penalties available if a whistleblower is subject to a reprisal action under the Competition Act.

  • Another example is the Ontario Securities Act, which protects whistleblowers and persons that cooperate with the Ontario Securities Commission. There is also a remedial process in place whereby an employee can receive compensation if their employer retaliated against them for whistleblowing. A number of additional whistleblowing protections also apply to public sector employees.

Anti-bribery and corruption

What are the main anti-corruption laws and regulations in your jurisdiction?

Canada’s Criminal Code includes domestic offences for bribery, fraud, corruption, influence-peddling, and breach of trust, among other offenses . These offenses apply to both private parties and public officials. Bribery of foreign public officials has been criminalized in the Corruption of Foreign Public Officials Act. Quebec’s Anti-Corruption Act is the only sub-federal anti-corruption legislation in Canada.

Does the legislation have extra-territorial effect?

List: - The Corruption of Foreign Public Officials Act provides for jurisdiction based on nationality. Offenses under the Act are deemed to have been committed in Canada, regardless of where the offense actually occurred, when a Canadian citizen, permanent resident, or corporation commits the offense (or conspires or attempts to commit, or being an accessory after the fact, or counselling in relation to that offense).

  • Canada’s criminal law is based on territorial jurisdiction, which precludes convictions for offenses committed outside Canada unless explicitly stated by Parliament. However, the activities constituting an offense need only have a “real and substantial connection” to Canada to be subject to the jurisdiction of Canadian courts.

What are the main enforcement bodies?

Federal, provincial and major municipal police services enforce the Criminal Code. Only the RCMP, Canada’s national police force, has authority to enforce the Corruption of Foreign Public Officials Act.

Unlike other jurisdictions, there is no civil or administrative enforcement of anti-bribery and anti-corruption laws in Canada.

Internal investigations

Is there any duty to report the issue, for example to a regulator?

In most cases, there is no duty to report. However, some cases where an internal investigation yields an issue will require reporting.

This includes provincial securities legislation that require public companies to disclose material changes and provincial environmental legislation that requires the reporting of certain environmental contamination events.

Certain federal and provincial legislation concerning food safety and consumer protection may require reporting incidents to the relevant regulators where there are risks of harm.

What is the protection from disclosure for documents generated as part of the investigation (for example, privilege)?

Documents generated for the purpose of obtaining or providing legal advice are privileged as pertaining to legal advice and are protected from disclosure. As well, documents created for the purpose of anticipated litigation are privileged and protected from disclosure until such litigation is concluded.

Is the advice given by an in-house lawyer in relation to the investigation privileged and/or confidential?

Advice provided by in-house counsel in relation to an investigation is privileged (and confidential) if it meets the general requirements for solicitor-client privilege or litigation privilege as described above.

Other communications which contain non-legal advice or are not prepared for the purposes of litigation will not be privileged.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.