Breach Response Procedure

Last updated: September 25, 2026

This Breach Response Procedure outlines the steps Affordrive takes to detect, assess, contain, and notify affected parties in the event of a privacy breach involving personal information. This procedure supports our compliance with PIPEDA's breach notification requirements.

1. What constitutes a breach

A privacy breach is any unauthorized access to, collection, use, disclosure, or loss of personal information. Examples include:

  • Unauthorized access to the platform database or dealer portal
  • Accidental disclosure of consumer data to the wrong dealership
  • Loss or theft of a device containing stored consumer data
  • A dealership sharing data outside the terms of the Dealership Data-Sharing Agreement
  • A cyberattack, malware infection, or phishing incident affecting systems holding personal information

2. Detection and internal reporting

Any team member, dealership, or user who suspects a breach must report it immediately to info@affordrive.ca. Reports are treated as urgent and triaged within 2 hours of receipt. Automated monitoring and access logs are reviewed regularly to detect anomalies.

3. Breach assessment

Upon receiving a report, Affordrive's designated privacy officer conducts a risk assessment to determine:

  • The type and volume of personal information involved
  • The cause and scope of the breach
  • The likelihood of the information being misused
  • The potential harm to affected individuals (identity theft, financial loss, reputational damage)
  • Whether the breach meets the threshold for mandatory notification under PIPEDA

4. Containment

Immediately upon confirming a breach, Affordrive takes steps to limit further exposure:

  • Revoke compromised access credentials and reset affected dealer portal accounts
  • Isolate affected systems and apply security patches if the breach involves a technical vulnerability
  • Suspend data sharing with any dealership implicated in the breach
  • Preserve evidence and logs for investigation purposes

5. Notification

If the assessment determines that the breach poses a real risk of significant harm to affected individuals, Affordrive notifies the following parties as soon as feasible and no later than the timelines required by PIPEDA:

  • Affected consumers: notified by email with a description of the breach, the data involved, steps we are taking, and actions they can take to protect themselves
  • The Office of the Privacy Commissioner of Canada (OPC): a formal breach report is filed as required by PIPEDA
  • Affected dealerships: notified if their access or data was implicated, with instructions to review their local data handling

If the breach does not meet the real-risk-of-significant-harm threshold, it is documented internally and reviewed without external notification, unless otherwise required by law.

6. Remediation

Following containment and notification, Affordrive takes corrective actions to prevent recurrence:

  • Conduct a root-cause analysis to identify how the breach occurred
  • Implement technical or administrative fixes (access controls, staff training, policy updates)
  • Review and update this procedure and related policies, including the Privacy Policy and Dealership Data-Sharing Agreement
  • Monitor affected systems for signs of continued or related compromise

7. Post-incident review

Within 30 days of resolving the breach, Affordrive conducts a post-incident review to evaluate the effectiveness of the response, document lessons learned, and implement improvements. The review is retained as part of our compliance records.

8. Record-keeping

All breach incidents — whether or not they trigger notification — are documented with the date of detection, assessment findings, actions taken, and resolution. Records are retained for a minimum of 24 months after the breach, or longer if required by law, in accordance with our Data Retention Policy.

9. Dealer responsibilities

Dealerships must report any suspected breach involving consumer data received through Affordrive within 24 hours of discovery, as required by the Dealership Data-Sharing Agreement. Failure to report may result in immediate suspension of platform access.

    base44
    Edit with Base44