Canadian privacy readiness

Something has usually already happened. A customer’s procurement pack asks which privacy law you comply with. A funder asks for a privacy impact assessment by a date. Somebody forwarded an article about mandatory breach notification in British Columbia and nobody in the building can say whether it applies. The work below starts by answering that question properly, because every other decision hangs off it.

The short version: which instrument reaches you decides almost everything else

Working out which instrument reaches you is the first piece of work rather than a preliminary to it, because the answer changes the breach duty, the consent model and the regulator you would be dealing with. Canada has no single national privacy rule the way it has a single criminal code. It has several instruments with different triggers, and a programme built against the wrong one produces documents that answer questions nobody will ask while the real duty goes unmet.

So the sequence is fixed: establish applicability, inventory what you actually hold, assess the things that need assessing, fix consent and retention, and write a breach process that knows where it stops. Each step depends on the one before it.

Working out which law applies

Four instruments account for most organizations here, and the trigger for each is different in kind — one turns on the activity, one on the province and the sector, one on being a public body, and one on a province with its own comprehensive regime. The two British Columbia Acts are the pair most often confused with each other. PIPA binds private-sector organizations and non-profits in British Columbia, while FIPPA binds BC public bodies and reaches their suppliers through the contract rather than directly.

The federal private-sector Act

The Personal Information Protection and Electronic Documents Act applies to organizations collecting, using or disclosing personal information in the course of commercial activity, and to federal works, undertakings and businesses — banking, telecommunications, interprovincial transport, broadcasting — including in respect of their employees.

The British Columbia private-sector Act

The Personal Information Protection Act binds private-sector organizations and non-profits in the province. Section 4(3) requires an organization to designate one or more individuals responsible for compliance, and section 4(5) requires it to make that position’s title and contact information public — two of the few duties on this page that can be discharged in an afternoon and are very often simply undone.

The Act for BC public bodies

The Freedom of Information and Protection of Privacy Act binds public bodies. If you are a supplier rather than a public body it usually reaches you through a contract schedule, which is a different problem with the same content.

Quebec

Quebec’s Law 25 is named here as a driver of programme work rather than analyzed, and where Quebec personal information is in scope the detail is settled with your counsel at engagement. It is a real driver of programme work — organizations with Quebec customers or employees are asked about it — but the site does not assert obligations it has not verified against the province’s own sources, and this page will not be the first to do so.

The instruments are set out side by side, with their triggers, in which Canadian privacy law applies. More than one can reach the same organization at once, which is normal rather than a sign that something has gone wrong.

Data inventory and flow mapping

This is the artifact everything else depends on, and it is the step organizations most want to skip. Until there is a record of what personal information you hold, where it came from, what it is used for, who it is disclosed to, where it physically sits and how long it stays, every downstream answer is a guess dressed as a policy.

The inventory is built from the systems rather than from interviews alone: the application databases, the file shares, the ticketing system, the analytics platform, the mailboxes, the spreadsheet somebody keeps for a report that nobody has asked for since 2019. The last category is where most of the unnecessary risk turns out to live, and it is also the cheapest to remove.

What comes out of it is a register you can hand to a customer, a flow map per significant processing activity, and a list of the holdings nobody could justify — which is the input to the retention work below.

Privacy impact assessments: when one is expected

A privacy impact assessment is an assessment of whether a system, project or programme meets the privacy requirements that apply to it, written down before the thing is built rather than after. Where it is a statutory duty, the statute says what it is for. FIPPA section 69(1) defines a privacy impact assessment as an assessment conducted by a public body to determine whether a current or proposed enactment, system, project, programme or activity meets the requirements of Part 3 of that Act, and section 69(5) puts the duty to conduct one, in accordance with the responsible minister’s directions, on the head of a ministry.

That is narrower than the way the requirement is usually described in the market, and the difference matters when you are deciding how much to spend. Many organizations that are asked for a privacy impact assessment are not under the statutory duty at all — they are under a contractual one, imposed by a public-sector customer passing its own obligations down the chain, or a funder’s condition. The assessment is still worth doing and the document still has to satisfy the person who asked; what changes is who sets the standard it is measured against, and that is worth establishing in writing before the work starts. How we write the assessment itself is set out on privacy impact assessments.

How much detail belongs in one

Enough that a reader who was not there can follow the reasoning: what the system does, what personal information it touches, the authority for collecting it, who it flows to, what could go wrong, and what was changed as a result. An assessment that records no change to the design is usually an assessment that was run too late to affect anything, and the fix is procedural rather than editorial — it gets triggered at design, not at launch.

Consent, purpose and retention

Consent work is mostly a purpose problem. Organizations collect for a stated purpose, then quietly accumulate secondary uses — a new analytics integration, a model trained on support transcripts, a marketing segment built from transaction history — without going back to the basis on which the information was collected. The readiness work is to write the purposes down, test the actual uses against them, and identify where a new basis is needed.

Retention is where the statutes are unusually concrete, and where a schedule pays for itself. BC PIPA section 35(2) requires an organization to destroy documents containing personal information, or to sever the link to particular individuals, as soon as it is reasonable to assume that the purpose for which the information was collected is no longer served by keeping it and that retention is no longer necessary for legal or business purposes. Section 35(1) runs the other way for information used to make a decision about someone: it must be kept for at least a year so the individual has a reasonable opportunity to ask for it.

Those two pull in opposite directions on purpose, and a retention schedule is what resolves them per record type instead of per argument. It also converts the inventory into the only privacy control that reduces risk while reducing cost at the same time: holding less.

Service providers and cross-border transfer

Responsibility does not move with the data. BC PIPA section 4(2) makes an organization responsible for personal information under its control including information that is not in its custody, which is the provision that turns every processor you use into your problem. The practical work is a vendor list reconciled against the inventory, the security and privacy terms your contracts actually contain, and a clear answer to what happens to the information when a vendor is dismissed.

On residency, the question is narrower than the anxiety around it. Where your servers sit does not by itself decide which Act applies; what the organization is, where it operates and what it does with the information decide that. Residency is usually a contractual or public-sector procurement requirement rather than a statutory trigger for a private-sector organization, and it is worth knowing which of the two you are answering before redesigning a platform around it. Vendor assessment as a standing process is covered in third-party risk and cyber due diligence.

Breach response process, and where it hands off

It depends which Act binds you. BC PIPA requires reasonable security arrangements and imposes no mandatory privacy-breach notification duty, PIPEDA imposes one on the real-risk-of-significant-harm test, and FIPPA imposes one on BC public bodies. That is the whole of the position on this page; the argument behind it, including the widely repeated claim about BC that does not survive contact with the statute, is set out in reporting a breach in BC.

Two federal provisions shape the process for anyone under PIPEDA. Section 10.1 requires a report to the Commissioner, and notification to the individual, where it is reasonable to believe the breach creates a real risk of significant harm. Section 10.3(1) is the one that catches organizations out: it requires a record of every breach of security safeguards involving personal information under the organization’s control — not only the ones that met the reporting threshold — and the Commissioner may ask for those records.

So the process has to do two separable things: capture and assess every incident consistently enough that the record is defensible, and escalate the ones that may cross the threshold to the people entitled to decide. That determination rests with your counsel. Readiness work builds the process, the evidence and the decision record counsel relies on, and stops at the point where the call itself is made. What the process gives counsel is a documented assessment made on stated criteria at a recorded time, rather than a reconstruction weeks later.

The plan, the roles and the tabletop that exercises them are incident response readiness; what the first day looks like in practice is the first 24 hours of an incident.

What you receive

DeliverableWhat it settles
Applicability analysisWhich instruments reach the organization, for which activities, and what each one requires of it
Data inventory and flow mapsWhat is held, where it came from, where it goes and where it sits
Privacy impact assessmentsThe systems or programmes that need one, assessed, with the design changes recorded
Policy setThe policies and complaints process the Act requires, sized to the organization and written to be followed
Retention scheduleHow long each record type is kept, and what happens at the end of it
Breach response processAssessment criteria, the record the statute requires, and the escalation point to counsel

Each control asserted points at an artifact in your own systems rather than at a sentence in a binder. What that assembled record looks like to an outside reader is described in the evidence pack.

The instrument-to-control map, and how to use it

The provisions themselves, quoted from the official consolidations at BC Laws and Justice Laws with the control and the evidence beside each one, are in the instrument-to-control map. It is the working reference behind this service and it is public on purpose: a readiness engagement should not be the only way to find out what an Act actually says.

Use it in the other direction as well. When a customer questionnaire asserts a duty, the map is where you check whether the duty exists in the form claimed before you build anything to satisfy it.

Where privacy sits alongside a framework a contract imposes, that work is PCI DSS, HIPAA and CPCSC readiness; where a customer is asking for an independent report instead, it is SOC 2 and ISO 27001 readiness. Neither satisfies a privacy instrument on its own.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Do we have to report a privacy breach in BC?

The commercial pressure on a BC private-sector organization is usually contractual rather than statutory: customers, insurers and procurement ask for notification commitments the Act does not impose.

Does Quebec’s Law 25 apply to us?

If you hold personal information about people in Quebec, treat it as in scope and get the position confirmed rather than assumed.

What is the difference between PIPA and FIPPA?

They are different Acts with different subjects, and the most expensive mistakes on this page come from reading a duty in one as though it sat in the other.

What is a privacy impact assessment?

Whether you are under a statutory duty to conduct one, a contractual duty, or neither, is the question to settle before deciding how much the document needs to contain.

Can you tell us whether we have to notify?

Work runs alongside counsel, and the handoff point is written into the process rather than improvised during an incident.

Why does it matter which instrument applies?

It is also the cheapest question to answer, and answering it late is what makes a privacy programme expensive.

Start with the applicability question

Say what the organization does, which provinces its people and customers are in, and what prompted the question — a questionnaire, a funder, a contract clause or an incident. The reply says which instruments look relevant and what the first piece of work would be. More context is on compliance and privacy.

Discuss a scope