PIPEDA and collecting documents from clients: a plain-language checklist
Who PIPEDA applies to
PIPEDA covers personal information collected in the course of commercial activity by private-sector organizations in Canada. British Columbia, Alberta and Québec have their own private-sector laws that apply instead for activity inside those provinces (BC PIPA, Alberta PIPA and Québec's private-sector act, as amended by Law 25), and health information can also fall under provincial health privacy laws. The principles below are shared by all of them.
The checklist
| PIPEDA principle | What it means when you collect documents |
|---|---|
| Accountability | Name someone responsible for privacy. You stay responsible for information you hand to a vendor — use a contract (a data processing agreement) that requires comparable protection. |
| Identifying purposes | Tell people why you need each document before you collect it. |
| Consent | Get meaningful consent — a clear statement and a checkbox or signature on your intake form works well. |
| Limiting collection | Ask only for what you need. A checklist per service keeps requests tight. |
| Limiting use, disclosure and retention | Use documents only for the stated purpose and delete copies you no longer need — including copies in email and upload tools. |
| Accuracy | Make sure documents are current and belong to the right person. |
| Safeguards | Protect information according to its sensitivity: encryption, access control, two-step sign-in, logs. |
| Openness | Publish a plain privacy policy. |
| Individual access | Be able to tell people what you hold and give them access. |
| Challenging compliance | Have a way to receive and answer privacy complaints. |
Breaches
Under PIPEDA, a breach of security safeguards that creates a real risk of significant harm must be reported to the Office of the Privacy Commissioner of Canada and to the affected people, and every breach must be recorded and the records kept for 24 months. Holding fewer documents for less time is the simplest way to reduce what a breach could expose.
What to ask any document-collection vendor
- Will you sign a data processing agreement that makes you our service provider?
- Where exactly is the data stored and processed? Which subprocessors do you use?
- How and when is our data deleted — including backups?
- Who on your team can see our clients' documents?
- How fast will you tell us about a breach?
- Can we export our audit log?
General information for Canadian businesses, not legal advice. Laws and professional rules change — check the current version with your regulator or lawyer.
Questions
Is there a PIPEDA certification for software?
No. No official certification exists. Vendors can describe their safeguards and sign a data processing agreement; your organization remains accountable.
Does PIPEDA require data to be stored in Canada?
PIPEDA does not prohibit storing data outside Canada, but you remain accountable and must be open about it. Many organizations prefer Canadian storage because it is simpler to explain to clients.