🍁 PIPEDA Compliance

PIPEDA — Canada's private sector privacy law.Is your business compliant?

The Personal Information Protection and Electronic Documents Act (PIPEDA) applies to virtually every Canadian small business. Most SMBs are not fully compliant — and most do not know it until after a breach.

Check your PIPEDA compliance free

What PIPEDA requires from your business

1

Accountability

Designate a privacy officer responsible for compliance. This can be the business owner in a small business.

2

Identifying purposes

Identify why you are collecting personal information before or at the time of collection.

3

Consent

Obtain meaningful consent before collecting, using, or disclosing personal information.

4

Limiting collection

Collect only the information necessary for the identified purposes.

5

Limiting use and disclosure

Use personal information only for the purposes for which it was collected.

6

Accuracy

Keep personal information as accurate, complete, and up to date as necessary.

7

Safeguards

Protect personal information with security safeguards appropriate to the sensitivity of the information.

8

Openness

Make your privacy policies and practices readily available — typically through a published privacy policy.

9

Individual access

Upon request, inform individuals about the existence, use, and disclosure of their personal information.

10

Challenging compliance

Allow individuals to challenge your compliance with PIPEDA through a designated privacy officer.

PIPEDA breach notification requirements

What you must do within 72 hours of discovering a breach

Immediately

Assess the breach

Determine what data was affected, who is impacted, and whether there is a real risk of significant harm to individuals.

Within 72 hours

Notify the Privacy Commissioner

Report the breach to the Office of the Privacy Commissioner of Canada as soon as feasible. Include what happened, what data was involved, and what steps you are taking.

As soon as feasible

Notify affected individuals

Notify individuals whose personal information was involved if there is a real risk of significant harm. Include what happened and what they can do to protect themselves.

How Guardlyne tracks your PIPEDA compliance

Guardlyne's Canadian Compliance assessment module evaluates your business against all 10 PIPEDA principles — and shows you exactly what is missing.

Privacy policy published and accessible
Consent processes for data collection
Breach notification process documented
Data subject request handling procedure
Privacy officer designated
Data retention and deletion policy
Security safeguards appropriate to data sensitivity
Check your PIPEDA compliance free →

PIPEDA questions answered

Does PIPEDA apply to my small business?
+
What counts as personal information under PIPEDA?
+
What are the penalties for PIPEDA non-compliance?
+
Do I need a privacy policy?
+
What do I need to do if there is a breach?
+
How does Guardlyne help with PIPEDA compliance?
+