September 2, 2026 · 5 min read
A breach is something that happened to a company. A privacy case is about something the company did. The settlements look similar and the classes are built quite differently.
| Data breach | Privacy | |
|---|---|---|
| What happened | Information was taken or exposed | Information was collected, used or shared in a way the class disputes |
| Intent | Not alleged: the company was also a victim | The conduct was deliberate; the dispute is about consent and disclosure |
| The class | Whoever was in the affected system | Whoever used the product during the period |
| Proving harm | Exposure is the harm | Harder: often no money was lost |
Recognisable shapes: information gathered in the background of an app or device; data shared with advertising or analytics partners in a way the class says was not adequately disclosed; recordings or transcripts retained beyond what people expected; identifiers used to link activity across services.
The common thread is consent: not whether data was collected, but whether the collection was disclosed in a way a person could actually act on.
Because usually nothing was stolen and no money was lost, privacy settlements often pay a flat per-person amount from a fund, with no documented tier at all. They are also frequently pro rata: the fund is fixed and divided among claimants, so the per-person figure depends on how many people file.
What pro rata means for your share →
Canada regulates private-sector personal information federally through PIPEDA, alongside provincial regimes, and Quebec has its own. A regulator's finding is not the same thing as a class action, but a public finding often precedes one, because it establishes facts a class can build on.
That is also why privacy settlements frequently include non-monetary terms: commitments to change a practice, delete data, or alter a disclosure. Those terms are sometimes the more valuable half, and they are easy to miss while reading for the dollar figure.
People conflate these constantly, and they are separate machines that happen to run on the same facts.
| Privacy complaint | Class action | |
|---|---|---|
| Who decides | A privacy commissioner, federally or provincially | A court |
| What you get | An investigation and findings about the practice | A share of a settlement, where one is reached |
| Money | Not the mechanism. Findings are generally recommendations. | The whole point |
| Effect on the other | Findings can supply facts a class builds on | Does not resolve the regulatory question |
So a headline about a company being investigated, or found to have contravened privacy law, is not news that you are owed anything. It is often the event that makes a class action possible a year or two later, which is a different and slower thing.
Compare Canadian privacy settlements against American ones and the American figures usually win by a wide margin. That gap is mostly structural rather than a measure of how badly anyone behaved.
Several US states have privacy statutes that set a damages figure per violation in the statute itself, with Illinois biometric law the most cited example. When the number does not have to be proven person by person, the arithmetic of a large class produces a large fund quickly. Canada's regime is built differently, and harm generally has to be established rather than assumed from the statute.
The practical takeaway is not that Canadians are shortchanged. It is that a US settlement figure is a bad yardstick for what a Canadian proceeding on similar facts should be worth, and anyone quoting one at you as a comparison is comparing two different legal systems.
Privacy settlements carry terms that are not payments, and they are easy to skip past while looking for a dollar figure. The ones worth finding in the notice:
These bind the company but they do not put anything in your account, so a settlement that is mostly non-monetary can be a real result and a small cheque at the same time. Both statements are true and the notice states which one you are looking at.
Usually the test is simply whether you used the product during the class period. There is rarely anything to document, and the administrator can often confirm from account records.
Open settlements, including privacy →
How to check a class definition →
No. A breach concerns information taken or exposed; a privacy case concerns information the company collected or shared deliberately, with consent as the dispute.
These settlements generally do not require demonstrated financial harm: being in the class during the period is normally the test.
No. A regulatory finding is separate from a class action, though it often precedes one.
PayUpBro is not a law firm and never files a claim for you. This page explains publicly available information about how class action settlements work; it is not legal advice. Whether you qualify is decided by the court-appointed settlement administrator, not by us.