VibeCoded

What if my app leaks data in Canada?

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Contain it first: close the hole, rotate exposed keys and preserve logs. Then assess whether the breach creates a real risk of significant harm (PIPEDA) or risk of serious injury (Law 25). If it does, report to the regulator and notify the affected people as soon as feasible. Record every breach either way; PIPEDA requires keeping records for 24 months. General information, not legal advice.

The first days

  1. Close the hole: turn on row level security, revoke the key, disable the endpoint.
  2. Preserve evidence: logs, database audit trails, provider usage logs.
  3. Work out what was exposed, whose, and for how long.
  4. Assess harm: sensitivity of the data and likelihood of misuse.
  5. Report and notify where the threshold is met.
  6. Tell business customers per their contracts.
  7. Fix the cause and have it tested.

Prevent the next one

Most leaks from AI-built apps come from the same few holes. See common holes and the checklist.

What the breach record contains

Under PIPEDA's breach record-keeping requirement, keep a record of every breach of security safeguards involving personal information, reportable or not, for 24 months. A useful record includes: the date of the breach and the date you discovered it; how it happened; what personal information was involved and roughly how many people; your assessment of the risk of significant harm and the reasoning; whether you reported to the Privacy Commissioner and notified individuals, and when; and what you changed to stop it happening again.

The Commissioner can ask to see these records. Writing the record as you investigate, rather than afterwards, also forces the questions that decide whether you must report. Law 25 requires a similar register of confidentiality incidents for Quebec.

Getting it checked

TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.

Get a scope for your app

Tell us what you built, what it stores and who is about to use it.

Get matched

Common questions

Do I have to report every leak?

Report when the risk threshold is met. Record every one regardless.

Can I just fix it quietly?

Fixing is required. Whether you must report depends on the risk of harm, not on whether anyone noticed.