Very well.
Bill S-4 could force private sector organizations to report any losses or breaches of personal information. However, unlike what is set out in Bill C-12, the test proposed for this mandatory reporting is subjective since it enables the organizations themselves to determine, and I quote:
if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to the individual.
In your view, is that test reasonable?