SealDrop Book a demo

Guides

PIPEDA and collecting documents from clients: a plain-language checklist

Short answer: PIPEDA doesn't certify tools; it makes your organization accountable for personal information you collect, including what your vendors handle for you. In practice: collect only what you need, say why, get consent, protect it with safeguards that match its sensitivity, keep it only as long as needed, and make sure any service provider is bound by contract to protect it the same way.

Who PIPEDA applies to

PIPEDA covers personal information collected in the course of commercial activity by private-sector organizations in Canada. British Columbia, Alberta and Québec have their own private-sector laws that apply instead for activity inside those provinces (BC PIPA, Alberta PIPA and Québec's private-sector act, as amended by Law 25), and health information can also fall under provincial health privacy laws. The principles below are shared by all of them.

The checklist

PIPEDA principleWhat it means when you collect documents
AccountabilityName someone responsible for privacy. You stay responsible for information you hand to a vendor — use a contract (a data processing agreement) that requires comparable protection.
Identifying purposesTell people why you need each document before you collect it.
ConsentGet meaningful consent — a clear statement and a checkbox or signature on your intake form works well.
Limiting collectionAsk only for what you need. A checklist per service keeps requests tight.
Limiting use, disclosure and retentionUse documents only for the stated purpose and delete copies you no longer need — including copies in email and upload tools.
AccuracyMake sure documents are current and belong to the right person.
SafeguardsProtect information according to its sensitivity: encryption, access control, two-step sign-in, logs.
OpennessPublish a plain privacy policy.
Individual accessBe able to tell people what you hold and give them access.
Challenging complianceHave a way to receive and answer privacy complaints.

Breaches

Under PIPEDA, a breach of security safeguards that creates a real risk of significant harm must be reported to the Office of the Privacy Commissioner of Canada and to the affected people, and every breach must be recorded and the records kept for 24 months. Holding fewer documents for less time is the simplest way to reduce what a breach could expose.

What to ask any document-collection vendor

  • Will you sign a data processing agreement that makes you our service provider?
  • Where exactly is the data stored and processed? Which subprocessors do you use?
  • How and when is our data deleted — including backups?
  • Who on your team can see our clients' documents?
  • How fast will you tell us about a breach?
  • Can we export our audit log?
Be wary of vendors claiming a PIPEDA certification: no official certification exists for software. A good vendor explains its safeguards and signs an agreement instead.

General information for Canadian businesses, not legal advice. Laws and professional rules change — check the current version with your regulator or lawyer.

SealDrop sends your clients or patients a secure link to upload documents and fill in forms. Everything is stored in Canada and deleted once you have filed it. How SealDrop handles privacy →

Questions

Is there a PIPEDA certification for software?

No. No official certification exists. Vendors can describe their safeguards and sign a data processing agreement; your organization remains accountable.

Does PIPEDA require data to be stored in Canada?

PIPEDA does not prohibit storing data outside Canada, but you remain accountable and must be open about it. Many organizations prefer Canadian storage because it is simpler to explain to clients.