TRUST CENTRE · ASSURANCE STANDARD

Security Incident & Breach Notification Standard

PUBLIC ASSURANCELast updated: September 2026PCL OneVersion 1.0
Scope: PCL One-managed cloud services and support operations
Baseline Commitment

Confirmed breach affecting customer data: initial customer notification within 12 hours of confirmation. Material customer-impacting incidents are notified without undue delay; initial notice is not held back while every fact is investigated.

Purpose

This standard defines how PCL One escalates, communicates and follows through on security incidents that materially affect a customer’s data or contracted service. It separates the operational incident process from any statutory notification duty the customer may have as controller or public body.

Notification commitment

Notification commitment table
EventBaseline initial noticeHow it is applied
Confirmed security breach affecting customer dataWithin 12 hours of confirmationPreliminary notice may be issued before the full forensic picture is known.
Material incident affecting customer data or serviceWithout undue delay; target within 24 hours of confirmation of material customer impactUsed where impact is confirmed but breach classification or full scope is still being established.
Personal-data breach subject to a contractual/statutory maximumThe shorter of the applicable legal/contractual timeline or the timeline aboveAny stricter customer or regulator requirement prevails.

What the initial notice contains

  • Known nature of the incident and when it was detected or confirmed.
  • Affected service, environment and categories of customer data known at the time.
  • Known or reasonably suspected scope and customer impact.
  • Containment and recovery actions already taken or underway.
  • Any immediate action requested from the customer.
  • The next planned update point and the agreed customer contact channel.

Incident lifecycle

Incident lifecycle table
StageControl
Detect & triageValidate the alert, classify severity, preserve evidence and assign accountable incident ownership.
ContainLimit further exposure or service impact using proportionate technical and access controls.
InvestigateDetermine affected systems, data categories, timeline, root cause indicators and whether the event is reportable.
NotifyContact designated customer contacts using the baseline above. Do not wait for perfect information.
RecoverRestore safe service, validate integrity and monitor for recurrence.
Close & improveProvide post-incident findings when available, including corrective and preventive actions and tracked remediation.

Customer coordination

  • Customer notification is sent to the designated security, privacy and service contacts recorded for the engagement.
  • PCL One provides information reasonably available to support the customer’s own regulator, data-subject, insurance or executive reporting obligations.
  • Where an underlying hosting or subprocessor incident is involved, PCL One coordinates the provider response and remains the customer-facing escalation point for the contracted service.

Assurance records

  • Incident timeline and ticket record
  • Customer notification copies and status updates
  • Relevant access/audit logs and evidence-preservation record
  • Root-cause and corrective-action report for material incidents
  • Incident-response exercise or test records, where appropriate and subject to confidentiality

Applicability

This document states PCL One’s public assurance baseline. A customer agreement, service schedule, applicable law or regulator requirement may set additional or stricter obligations; those terms take precedence for the applicable service. Service-specific architecture, residency and retention settings are documented in the relevant service schedule.

Explore more assurance standards

Related customer-facing commitments

VENDOR ACCESS MODEL

Privileged Support & Break-Glass Access

How elevated support access is approved, constrained, logged and reviewed.

BUSINESS CONTINUITY & DISASTER RECOVERY

Service Resilience & Recovery

Availability, backup, disaster recovery and recovery-objective commitments.

SUPPLY-CHAIN TRANSPARENCY

Subprocessors & Third-Party Services

How service providers are governed and how relevant third-party involvement is disclosed.

Canadian Municipal Expertise|
ERP Implementation Capability|
PSAB-Aware Delivery|
Canadian Data Residency
Utility Billing · Property Tax · Permitting · Licensing · Asset Management · Work Orders