41 / 63PIPEDA Compliance

PIPEDA compliance, built for the law that's coming as well as the one in force

PIPEDA compliance for Canadian organisations, built to still hold when Bill C-36 replaces the Act.

  • CCIE Security-led safeguards work
  • Canadian data residency
  • Reading Bill C-36 since first reading
THE WORK

PIPEDA compliance, three pillars, one operator.

One Canadian team maps the data, fixes the consent, and proves the safeguards. Personal information protection and consent management sit with the same engineers, so nothing falls between the person who writes the policy and the person who owns the system.

  1. 1

    Data and consent

    What personal information you hold, why you hold it, and what people actually agreed to. Consent management starts by matching the language at the collection point to what the systems really do with the data afterwards.

  2. 2

    Safeguards you can show

    The security controls the safeguards principle asks for, evidenced rather than described in a policy. Bill C-36 was tabled 2026-06-15, and the work it would require is the work PIPEDA already asks for, so nothing here is wasted if the Act changes.

  3. 3

    A breach process that holds

    PIPEDA breach reporting decisions, notice to affected individuals, and a record of every breach, not just the reportable ones. The law makes you keep those records for two years whether a breach met the real risk of significant harm test or not (Office of the Privacy Commissioner of Canada).

THE PROOF

Built to last. Evidence over promises.

The Privacy Commissioner cannot fine you or order a change today. Bill C-36 would alter both, which is the honest reason to start privacy compliance work in Canada now rather than after royal assent.

IN PRODUCTION

Privacy a Canadian complaint would survive.

We thought we were fine because we had a privacy policy. SMEnode asked to see the list of systems holding customer data and we couldn't produce one. That was the finding. Eleven weeks later we had the inventory, the consent language matched what we actually do, and the breach log existed.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

PIPEDA compliance in Canada, made real.

Written by the engineer who runs this work, not by a product team. Most organisations have a privacy policy and no privacy programme, so the policy describes a company that doesn't exist.

A privacy policy isn't a privacy programme.

Good PIPEDA work starts with an inventory, not a document. You can't honour a purpose limit, a retention limit, or an access request without knowing which systems hold personal information and why each one has it. A privacy policy audit on its own tells you what you claim. The inventory tells you what you do, and the gap between the two is the finding. That inventory is the boring half nobody funds, and it's the half every complaint tests. The ten principles then stop being an abstract list: accountability means a named person, consent means language matching what you actually do, and safeguards mean controls somebody verified.

Where the risk actually sits.

We work from the systems outward, which is the reverse of how a template does it. The risk sits in three places. A privacy policy written by a lawyer who never saw the database. Consent collected once, years ago, for purposes that have since expanded, which is why consent management is a running job rather than a launch task. And a breach process that exists on paper but has never been run, so the first real incident becomes a decision made in a panic by whoever is awake. Personal information protection fails at those three seams far more often than it fails at the firewall.

What enforcement looks like today, and what Bill C-36 would change.

The enforcement picture as of 2026-09-02, stated precisely because most pages get it wrong. The Commissioner can investigate, audit under section 18 where reasonable grounds exist, publish findings, and sign a compliance agreement under section 17.1. It cannot order you to change a practice, award damages, or fine you. Binding remedies come from a Federal Court application, which can award damages. Knowingly failing to report a breach or keep the records is a separate offence carrying fines. Bill C-36, the Protecting Privacy and Consumer Data Act, was tabled 2026-06-15 and sits at first reading. It would replace Part 1 of PIPEDA, create a Digital Safety and Data Protection Commission with binding order power, and carry penalties up to the greater of 10 million dollars or 3 percent of gross global revenue (Gowling WLG, 2026-06-24; McCarthy Tetrault, 2026-06-16).

Control checklist
THE METHOD

How our privacy compliance and consent management work runs.

Four steps, and step 01 is the one that changes the conversation. We ask for a list of every system holding personal information about customers or staff, and almost nobody can produce it. That isn't a criticism, it's the normal starting point, and it's why privacy work that begins with policy language fails. The inventory decides the scope of everything after it, including how much you actually need.

  1. Step 01

    Inventory the data

    Every system holding personal information, what it holds, why, who can reach it, how long it keeps it, and whether it leaves Canada. We write down what nobody has written down.

  2. Step 02

    Fix the consent

    We compare what you tell people at collection against what the systems actually do, then rewrite the language and the collection points so the two match. That is consent management with the plumbing attached, not a banner.

  3. Step 03

    Evidence the safeguards

    The safeguards principle needs controls that work, not controls described. We verify them and keep the proof where a reviewer can find it.

  4. Step 04

    Rehearse the breach

    The reporting decision, the notice to individuals, and the log of every breach. Then we run a tabletop, because an untested process is a document.

QUESTIONS

PIPEDA compliance questions, answered straight.

Answers first, including the one where we say you don't need us yet. An architect takes the call, not a salesperson.

Usually both, in different places. PIPEDA covers private-sector organisations handling personal information in commercial activity across Canada. Alberta, British Columbia and Quebec have their own private-sector laws that displace it for activity inside those provinces, while PIPEDA still governs data crossing a provincial or national border. Federally regulated sectors like banks, telecoms and airlines stay under PIPEDA wherever they operate. We work out which applies before quoting anything.

Not the way most pages imply, and you should know the real answer. The Commissioner investigates, audits, publishes findings and can sign a compliance agreement, but it cannot fine you, order you to change, or award damages. Binding orders and damages come from the Federal Court. The one clear penalty is for knowingly failing to report a breach or keep breach records. None of this is legal advice, and your counsel should confirm it.

Not because it's law, because it isn't. It was tabled 2026-06-15 and sits at first reading, so it still needs second reading, committee, third reading, the Senate and royal assent. What makes it worth knowing now is that the work it would require is the same work PIPEDA already asks for, and it takes longer to build than a bill takes to pass. Inventory and consent don't change if the Act does.

No, and that's a common and expensive assumption. SOC 2 is a US framework you meet through customer contracts, and even with the privacy criterion in scope it evidences controls to an auditor rather than satisfying a Canadian statute. The overlap is real on the safeguards side, so we reuse that evidence rather than duplicating it. The consent, purpose, retention and access obligations have no SOC 2 equivalent.

When you don't yet know what personal information you hold, since the inventory is cheaper as a standalone piece of work and might be all you need. When the real trigger is one customer questionnaire, which is usually faster to answer directly. And when a system migration is underway, because mapping data that's about to move twice wastes the mapping. We say so.

A data inventory naming every system that holds personal information, consent language that matches what those systems do, safeguard evidence a reviewer can follow, a breach log with a tested reporting decision behind it, and one named accountable person. All of it is written for your own team to keep current, and it stays yours if we never speak again.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.