Yes, the Privacy Commissioner.... Parliamentary information research, which is always excellent, gave us something here. One of their points is that the Privacy Commissioner has noted an addition to adding a duty to notify, or as an alternative, a provision could be added to PIPEDA that would allow for an organization that has suffered a security breach to notify credit bureaus about the breach without the consent of the individuals affected. That's her recommendation.
The rationale is that it would allow credit bureaus to be more proactive in protecting consumers from identify theft and fraud. Having heard that, do you have any observations about it?
