PIPEDA Compliance Checklist for Canadian Companies (2026)

PIPEDA Compliance Checklist for Canadian Companies (2026)

By Krikor Tengerian · Co-founder, SecuritAI Technologies Ltd. · September 2026 · 10 min read

A customer asks where their personal information is stored, who inside your company can open it, and what happens if it leaks. The honest answer is that nobody has written it down. That is the moment most Canadian teams go looking for a PIPEDA compliance checklist, and it is almost never a regulator that sends them.

It usually arrives through a procurement questionnaire, an enterprise buyer's security review, or a near miss that made somebody ask a question the team could not answer on paper. You are not behind. That is how nearly every business meets this law.

Here is the part people get wrong

There is no PIPEDA certificate. No auditor issues one, no body accredits you, and no logo goes on your website when you are finished. The Personal Information Protection and Electronic Documents Act is a set of obligations you have to meet continuously, and the only test of whether you met them comes after something goes wrong, when the Office of the Privacy Commissioner of Canada asks you to show your work.

That changes what a checklist is for. You are not collecting points toward a badge. You are building the file you would hand over on the day somebody asks.

The Act applies to private sector organizations across Canada that collect, use or disclose personal information in the course of a commercial activity, and the OPC's own summary defines commercial activity broadly enough to include the selling, bartering or leasing of donor, membership or other fundraising lists. The same OPC page notes that Alberta, British Columbia and Quebec have their own private sector privacy laws deemed substantially similar, and that federally regulated organizations are covered no matter which province they operate in. If you are a Toronto company selling to a Montreal customer, you are usually looking at both.

The checklist, built on the ten principles

PIPEDA's operative requirements sit in Schedule 1 of the Act as ten fair information principles. The OPC lists them as accountability, identifying purposes, consent, limiting collection, limiting use disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Work them in that order, because the first one carries the rest.

Score yourself as you go. There are eleven lines to mark: the ten principles below, plus the breach record covered in the next section. Mark each one implemented, partial or not started, and beside it write the name of the document or record you would hand the Commissioner to prove it. If you cannot name the record, mark it not started, however good the practice behind it is. The count of lines you could not back with a file is your real starting point.

1. Accountability. Name a person. The OPC's privacy management program guidance states plainly that organizations are required to appoint someone to oversee the development, implementation and maintenance of their privacy program. This is one line in a document and it is the single most common gap. Write the name, the role, and what they are accountable for.

2. Identifying purposes. For every category of personal information you hold, record why you collect it, before or at the time of collection. If your only answer is "the form has always had that field", delete the field.

3. Consent. Record how consent was obtained for each purpose, and how someone withdraws it. Screenshots of your signup flow and your cookie banner belong in the file, with the date they were taken.

4. Limiting collection. Compare what you actually collect against the purposes you wrote down in step two. Anything with no matching purpose comes out of the form and out of the database.

5. Limiting use, disclosure and retention. This is where a retention schedule lives. Say how long each category is kept and what happens at the end. Then check whether the deletion actually runs, because a policy that says ninety days over a table that has never been pruned is worse than no policy at all.

6. Accuracy. Show how a record gets corrected when it is wrong, and who is allowed to correct it.

7. Safeguards. Access control, encryption, logging, backups, and a way to prove each one is on. The Canadian Centre for Cyber Security publishes its Baseline Cyber Security Controls for Small and Medium Organizations, which is a reasonable Canadian floor to measure yourself against and easier to defend than a control set you invented.

8. Openness. Your privacy policy has to describe your actual practices in plain language and say who to contact. Read it against step two. On most sites they disagree.

9. Individual access. Someone writes in and asks for their data. Who receives that request, how do you verify it is really them, where do you search, and what is your turnaround. Write the runbook before you need it.

10. Challenging compliance. A documented complaint path, and a record of complaints received and what you did about each one.

The breach obligations most checklists get wrong

This is the part that is written into the statute rather than the principles, and it is where the file either exists or it does not.

Under section 10.1 of PIPEDA, an organization must report to the Commissioner any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe the breach creates a real risk of significant harm to an individual, and must notify the affected individual on the same test. The Act defines significant harm to include bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. The two factors the Act names for judging real risk are the sensitivity of the information and the probability that it has been, is being, or will be misused.

Then there is the obligation almost nobody has covered. Section 10.3 requires an organization to keep and maintain a record of every breach of security safeguards involving personal information under its control. The OPC's guidance on mandatory breach reporting says this plainly: you keep records of all breaches whether there is a real risk of significant harm or not, the law requires you to keep them for two years, and the OPC can request access to them or a copy of them. The Breach of Security Safeguards Regulations set the retention at 24 months after the day on which the organization determines the breach occurred.

Read that again. Not the serious ones. Every one. A laptop left in a taxi and recovered, an email sent to the wrong client, a misconfigured folder closed within the hour. Each is a record, each is kept for two years, and the Commissioner can ask for the file.

The stakes are in section 28 of the Act. Knowingly contravening section 10.1 or subsection 10.3(1) is an offense punishable on summary conviction by a fine not exceeding $10,000, or as an indictable offense by a fine not exceeding $100,000, per section 28 of PIPEDA on the Justice Laws website. Those are penalties for the failure to report and to keep records, separate from whatever the breach itself cost you.

Go back to your eleven lines. If the breach record is marked not started, or partial because incidents get handled but never written down, that is the gap with a fine attached, and it is the first thing we would show you. Book a walkthrough and our team will take you through the breach log, the risk of harm assessment and the notification record, and how the ten principles map to controls you can track.

Teams do not fail PIPEDA because they misread the statute. They fail it because eighteen months later they cannot produce the consent screenshot, the retention schedule, the access request they answered in March, or the breach log for an incident somebody handled well and never wrote down.

The OPC's own self assessment tool makes the same point from the regulator's side. It states that you cannot determine how compliant you are with PIPEDA until you have assessed the design of your privacy control mechanisms and how well the mechanism is actually operating in the business environment. Design and operation. A policy proves the first and nothing else.

If your company has anything AI facing in production, the same evidence question arrives with sharper edges, because PIPEDA does not care that the system is a model. It still asks whether the purpose is lawful, whether the safeguards match the sensitivity of the data, and whether you can explain a decision that affected a real person. Our sister company SecuritAI covers the testing side of that.

Being straight about our role

We are not an auditor, we do not certify anyone against PIPEDA, and no vendor can, because the certificate does not exist. What SecuritComply builds is the software that holds the evidence: the ten principles mapped to controls you can track, the consent and privacy policy records, the breach log with its risk of harm assessment and notification record, and a privacy impact assessment for each new system.

If you want the full picture of what the law requires and how it maps to a working program, our PIPEDA compliance page covers it. And if a European or UK buyer is in the mix, our post on PIPEDA and GDPR covers where the two diverge, while the Canadian data residency guide answers the storage question that usually follows.

If more than two of your eleven lines came back not started, book a walkthrough with our team and bring the list.

Frequently asked questions

Does PIPEDA apply to my company if I only have a handful of customers?

There is no revenue or headcount threshold in the Act. It applies to private sector organizations across Canada that collect, use or disclose personal information in the course of a commercial activity, per the OPC's summary of PIPEDA. Size changes what reasonable safeguards look like, not whether the law applies.

Can we get PIPEDA certified?

No. There is no PIPEDA certification and no accredited body issuing one. Any vendor offering to certify you against PIPEDA is describing something that does not exist. What you can do is document a privacy management program and hold the evidence, so that if the Commissioner asks, the answer is a file rather than a scramble.

Do we really have to log a breach that harmed nobody?

Yes. Section 10.3 of PIPEDA requires a record of every breach of security safeguards involving personal information under your control, and the OPC's breach reporting guidance states that this covers all breaches whether or not there is a real risk of significant harm. The Breach of Security Safeguards Regulations set the retention period at 24 months from the day you determine the breach occurred.

What is the difference between reporting to the Commissioner and notifying the individual?

Both are triggered by the same test, a real risk of significant harm, and both are required under section 10.1 of PIPEDA when that test is met. Reporting goes to the Office of the Privacy Commissioner. Notification goes to the affected person, and the regulations allow indirect notification through public communication where direct contact would cause further harm, create undue hardship, or where you do not have contact information.

We are in Ontario but our customers are in Quebec and BC. Which law applies?

Likely more than one. The OPC's summary of PIPEDA notes that Alberta, British Columbia and Quebec have private sector privacy laws deemed substantially similar to PIPEDA, and that federally regulated organizations are subject to PIPEDA regardless of province. The practical approach is to build one evidence set that satisfies the strictest obligation you are under, rather than running a separate program per jurisdiction.

References

All links verified live and read against the cited text on September 11, 2026.

Ready to get compliant?

SecuritComply makes it simple, 17 frameworks, Canadian data residency, 50 to 70% less than typical US quotes.

Start Free →