With the rise in the collection, use and disclosure of personal information and personal health information across organizations, the prevalence of privacy breaches, and the recognition of common law privacy torts in Ontario, organizations increasingly face legal, financial and reputational consequences from personal information handling practices. This article considers how this evolving area of law may inform an organization’s internal risk management program.