The events of the last few months, which I think most of the honourable members would have followed, suggest very strongly that this would be an important addition to the law, so that there is no hesitation on the part of companies and organizations holding personal information on behalf of Canadians that when this happens, they do have to take positive steps to notify them and to make them aware and to take action to prevent identity theft.
There was a reputable study done in the United States about the link between data breach and identity theft, because that's always the question: how do we know that data breaches are linked eventually to some harm, because many of them aren't? The study suggested that 5% of those people whose personal information has been obtained because of a data breach would be subject to identity theft. I find that very interesting. If people say that a data breach does not necessarily mean that something is going to happen to you, it would seem from this study that it will happen to 5% of the people. So if you have a breach of the personal information of 100,000 Canadians, then this would suggest that 5,000 of them are going to have serious issues with fraud, identity theft, or the same.
That's a very recent study and that finding is significant. That's why I'm asking this committee to move to make this mandatory, so that we'll have increased attention on the part of organizations to the security in which they keep personal information and then to their duty to act swiftly and appropriately to help people take the right steps to monitor their personal information and their credit cards and even in some cases their mortgages, their land holdings, so that they'll at least be aware. If you don't know that you've been a victim of a data breach, you may not be paying special attention. How many of us have time to read all our credit card statements in detail and so on? I think that's true of many Canadians in their busy lives.
I think this is an important public measure. I have more suggestions for the contents of data breach notification, given our research, and I'd be very happy to help the committee if you were to decide to move in this direction.