
Use this OPC-aligned ten-principle checklist to find compliance gaps and prioritise three fixes your organisation should make today: name a privacy officer, publish a clear privacy policy and set up a working complaint procedure. Those three items are what the Office of the Privacy Commissioner checks first in almost any investigation. Everything else in this guide builds on top of them.
TL;DR:
- Most compliance issues are flagged early by having a named privacy officer, publishing a clear privacy policy, and establishing a complaint procedure.
- Critical gaps often include lacking a designated privacy owner, vague purpose disclosures, and no formal process for handling complaints or breaches.
- Encryption, MFA, and retention policies are vital but generally come after ensuring accountability, openness, and an effective complaint log are in place.
- Vendors must be contractually required to meet privacy standards, especially when processing data across borders or using cloud services outside Canada.
- Regular review, documentation, and building a strong paper trail are essential for maintaining PIPEDA compliance and demonstrating efforts during investigations.
PIPEDA applies to private-sector organizations in Canada that collect, use, or disclose personal information in the course of commercial activity, including selling or leasing membership and donor lists to another party. That scope catches far more small and mid-sized businesses than most owners assume, from a Kitchener dental clinic tracking patient contact details to a Toronto e-commerce shop storing customer addresses in Shopify.
The checklist below follows the ten fair information principles from Schedule 1 of PIPEDA. Translating each principle into a plain yes/no question is the fastest way to expose the gaps an investigator would flag, and it’s the same approach privacy management guides recommend for organizations that don’t have a dedicated legal team.
For each principle, note what evidence you’d need to prove a “yes,” who owns the fix on a “no,” and how urgent it is.
A surprisingly common failure here is naming a committee instead of a single accountable person. The OPC expects someone specific and contactable, not a shared inbox. If the answer to the first question is “no,” this is a same-week fix owned by an owner or executive, not IT.
If your intake forms or website say nothing about why a phone number or email is being collected, that’s a gap. The fix is usually a short line of text at the collection point, reviewed by whoever owns your privacy policy.
Meaningful consent isn’t a checkbox buried in a 40-page terms document. If your only consent mechanism is a pre-checked box or a link nobody clicks, treat that as a “no” and rework the flow with legal input if the data involved is sensitive (health, financial, biometric).
This is the principle most organizations fail quietly. Marketing teams especially tend to add “just in case” fields to forms. An IT manager or privacy officer should audit every collection point twice a year and remove anything that isn’t tied to a documented purpose.
If your answer to the retention question is “we’ve never actually deleted anything,” that’s a medium-severity gap that IT and legal should close together, generally within a quarter.
This principle is often the easiest “yes” once a correction request process exists for Principle 9 (Individual Access), since the two overlap in practice.
This is the principle with the most moving parts, and it’s covered in depth in the safeguards section below. Any “no” involving encryption or MFA is high severity and should go to IT leadership immediately, not sit on a backlog.
Openness is one of the three principles the OPC checks first in almost any complaint or investigation, alongside accountability and challenging compliance. A missing or vague privacy policy is the single most common finding in small business reviews.
This is the third principle the OPC checks first. A complaint procedure that exists only in someone’s head, with no log and no published contact point, is treated the same as having none at all.
Pro Tip: Build a simple spreadsheet with one row per principle, columns for “yes/no,” “evidence,” “owner,” and “target date.” That single document is often the first thing an OPC investigator asks to see, and it takes an afternoon to build.
The OPC’s own self-assessment tool is designed to walk an organization through its practices against the ten principles and generate an action plan for whatever gaps show up. Running it properly takes a few hours, not days, and it’s the fastest way to validate the checklist above against an official source.
Pro Tip: Run the self-assessment again after 90 days of remediation work, not after every individual fix. Comparing two snapshots gives you a defensible before-and-after record if the OPC ever asks how you got compliant.
Document the assessment date, who ran it, and the resulting action items in one file. That record becomes your evidence trail. If a complaint or breach ever triggers an OPC inquiry, being able to show “we assessed ourselves on this date and closed these gaps by this date” carries real weight.
Three principles account for most of what the OPC checks first in any review: accountability, openness, and challenging compliance. Fix these before anything else.
Designate a real privacy officer. This needs to be one named individual, not a title shared across three managers or a generic “privacy@” inbox with no owner behind them. Publish their name or role, and a way to contact them, on your website’s privacy policy page. Internally, document the appointment in writing (an email, a board resolution, an HR record) with a date, so you can prove when accountability started.
Publish a short, honest privacy policy. It doesn’t need to be long. It needs to cover:
If your organization uses U.S.-based cloud infrastructure or a vendor with servers outside Canada, disclose that plainly. Vague language like “we may share data with partners” invites scrutiny; specific, accurate language builds the kind of trust the OPC frames as a competitive advantage rather than a legal burden.
Set up a minimal complaint process. This can be as simple as a dedicated email address, a logbook (physical or digital) recording the date, the complainant, the issue, and the resolution, and a stated timeline for responding. What matters to an investigator is that the log exists and is dated, not that the process is elaborate.
Pro Tip: During an OPC investigation, the fastest remediations are the ones with paper trails: a published policy with a visible last-updated date, a signed training record, a vendor contract clause, and a logged complaint. Build the paper trail as you go, not after the fact.
Principle 7 covers the technical, administrative, and physical controls protecting personal information, and it’s the principle most likely to trigger a serious incident if it fails. The right controls scale with how sensitive the data is, not with how big your organization is.
Technical controls, baseline to sensitive:
Administrative controls:
Physical controls:
Threat landscapes shift quickly enough that a review done once and forgotten stops being useful within a year. Ransomware attempts, phishing volume, and credential-stuffing attacks have all climbed against Canadian small businesses, which is part of why the OPC’s guidance pushes organizations toward ongoing risk analysis rather than a one-time setup.
Breach readiness checklist:
Retain your breach evidence for at least as long as your general retention schedule requires for the affected data category, and longer if litigation or regulatory inquiry is plausible. If sensitive data is involved (health records, financial account numbers, government IDs), the OPC’s own guidance calls for a proportionately stronger threat and risk analysis before you even collect it, not just after something goes wrong.
Most small and mid-sized Canadian businesses run at least part of their operations through cloud services with servers outside the country, and that fact alone doesn’t break PIPEDA. What breaks it is failing to disclose it or failing to contractually require the vendor to protect the data properly. Organizations handling personal information that crosses provincial or national borders in commercial activity stay under PIPEDA regardless of any provincial privacy law that might otherwise apply.
Vendor due-diligence checklist before signing:
Disclosing cross-border processing: if a vendor stores or processes Canadian customer data outside Canada, your privacy policy needs to say so in plain language, including which country and what safeguards apply. For sensitive categories of information, this may cross the line into needing express, meaningful consent rather than implied consent buried in a terms-of-service update.
Practical mitigations for common SaaS setups: where possible, configure cloud tools like Microsoft 365 to keep Canadian tenant data in Canadian data centres, review sharing permissions quarterly, and avoid free-tier tools that don’t publish a data processing agreement at all. Reviewing where your infrastructure actually lives is worth doing before, not after, a customer asks. Data sovereignty considerations for hosting are worth a read if you’re evaluating a new provider. It’s also worth periodically checking whether AI crawlers or third-party scripts on your own website can access customer data without your knowledge, which a website crawlability audit can surface quickly.
Compliance isn’t a one-time project. It’s a maintenance schedule with a few clear triggers.
A minimal viable compliance posture built around these review habits, an encrypted device policy, and a documented 30-day access request process is realistic for most small organizations to sustain without a full-time compliance department.
NetFusion Designs Inc is a managed IT provider working with small and mid-sized organizations across Ontario and Canada, and privacy compliance gaps are a common issue found during onboarding security reviews.
A typical pattern: a professional services firm with client contact and financial data spread across email, a shared drive, and a legacy database has no named privacy officer, no published privacy policy, and no MFA on half its accounts. Running the checklist above against that environment usually surfaces 15 to 20 gaps in a single afternoon. Over a 90-day window, the highest-severity items (MFA rollout, a named privacy officer, a published policy) typically close within the first two to three weeks, while vendor contract reviews and retention schedule cleanup take the full quarter.
Before hiring any managed IT or Managed Intelligence Provider to support this work, ask them directly:
Most PIPEDA guidance treats all ten principles as equally urgent, which is technically true and practically useless. In every OPC investigation pattern this research points to, three principles decide whether an organization looks compliant on day one: a named accountable person, an honest published policy, and a working complaint log. Everything else, encryption, retention schedules, vendor clauses, matters enormously, but it’s remediation work you do after those three are visible.
The other place conventional advice falls short is treating compliance as a document exercise. An investigator doesn’t want a policy that reads well. They want dated evidence: training records, contract clauses, a complaint log with real entries. Organizations that build the paper trail as they go, rather than reconstructing it under pressure, are the ones that come out of a review looking credible rather than scrambling.
If you do nothing else this month, name your privacy officer in writing and publish your policy. Everything downstream gets easier once those two things exist.
— Geeshan
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Verify every obligation against the primary sources rather than relying on any single guide, including this one. The PIPEDA requirements in brief page from the OPC covers applicability and cross-border scope. The Privacy guide for businesses expands each of the ten principles into documented expectations. Run the OPC self-assessment tool directly against your own practices, and read the Schedule 1 text of the Act itself for exact legal wording. For a practical, small-business-oriented template, ClearBreach’s compliance checklist is a solid companion resource.
Organizations must follow the ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use and retention, accuracy, safeguards, openness, individual access, and challenging compliance. In practice, this means a named privacy officer, a published privacy policy, documented consent practices, and a working complaint procedure.
The ten principles from Schedule 1 are accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. Each one translates into specific operational checks, covered in the checklist above.
Start by mapping each of the ten principles into concrete yes/no questions with an evidence requirement and an owner, then run the OPC self-assessment tool to validate your findings. Prioritise accountability, openness, and complaint handling first, since those are what the OPC checks earliest in most reviews.
PIPEDA doesn’t apply to personal information collected, used, or disclosed for purely personal or domestic purposes, or to employee information at federally unregulated organizations operating solely within a province that has its own substantially similar privacy law, such as Alberta, British Columbia, or Quebec. Cross-border and federally regulated activities remain under PIPEDA regardless of provincial law.