We've been talking quite a bit about companies and individuals not wanting to report, for different reasons. Companies want to seem like trusted institutions or organizations, and individuals feel ashamed. Maybe that's similar in both cases.
Last November, the government created a mandatory requirement for federal organizations that are subject to PIPEDA. This requires them to notify the Privacy Commissioner, individuals who may be affected and third parties or government departments that may be able to help in the situation. I think a test is required to really assess whether the breach is harmful enough that they would be required to report it. There are fines of up to $100,000.
Do you think this step, this measure that was taken, would now help get the information out there to people in the right amount of time? How do you view this?