Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Do You Actually Need PIPEDA?

If you collect, use, or disclose personal information in the course of commercial activity in Canada, PIPEDA already applies to you by default, whether you have a program for it or not. The real question isn't whether the law applies. It's whether you need to invest in a formal compliance program, and for a lot of companies asking us this, the honest answer is no, not yet.

What PIPEDA Actually Requires (and Doesn't)

The Personal Information Protection and Electronic Documents Act is Canada's federal private-sector privacy law. It sets out ten fair information principles: things like getting meaningful consent, limiting collection to what you need, being transparent about how data is used, and giving people a way to access or correct their own information. Unlike SOC 2, there's no auditor, no certificate, and no logo you get to put on your website. There's no "PIPEDA certified." What exists is a legal obligation to handle personal information a certain way, and the ability to demonstrate that if the Office of the Privacy Commissioner ever comes asking.

That distinction matters because a lot of the "PIPEDA compliance" marketed to small businesses is really privacy program hygiene dressed up as a compliance product. You don't need to buy a framework to write a privacy policy or appoint someone accountable for privacy. You need to actually do those things.

Who Genuinely Needs a Formal PIPEDA Program

  • You handle sensitive personal data at volume. Health information, financial data, biometric data, or anything involving vulnerable populations raises the bar on consent and safeguards considerably.
  • You're selling to enterprise or government buyers. Procurement teams and legal departments increasingly ask for a documented privacy program as part of vendor due diligence, separate from a SOC 2 report.
  • You've had, or are worried about, a breach. PIPEDA has mandatory breach notification requirements with real teeth. If a breach involving personal information creates a "real risk of significant harm," you must notify the affected individuals and the Privacy Commissioner. Not having a documented process for this before an incident happens is how a bad day becomes a legal problem.
  • You operate across provinces with their own privacy statutes, or you have any Quebec customers, which pulls Law 25 into the picture alongside PIPEDA.
  • You're already pursuing SOC 2 and want your privacy documentation to satisfy both frameworks instead of building it twice.
Privacy obligations piling up? Law 25 and PIPEDA readiness, with a named privacy officer where the law asks for one. Privacy officer

Who Is Over-Buying PIPEDA Compliance

We see this a lot with early-stage SaaS companies in Toronto and Waterloo: a founder gets a sales email about "PIPEDA certification," panics, and is ready to sign a five-figure retainer before checking what they actually collect. If your product touches basic business contact information, you're pre-revenue, and no customer has asked for privacy documentation, a full third-party PIPEDA program is usually premature. What you need instead is a plain-language privacy policy that reflects what you actually do, a named point of contact for privacy inquiries, and a basic process for responding to access requests. That's a few hours of work, not a retainer.

The over-buying pattern is common enough that it's worth saying directly: PIPEDA doesn't require an external audit, a certification body, or ongoing managed compliance software in most cases. If a vendor is selling you an annual "PIPEDA compliance certificate," ask what body issues it and under what legal authority, because there isn't one.

Where PIPEDA Overlaps With SOC 2 and Quebec Law 25

This is where the real efficiency lives, and it's the reason we treat privacy and security programs together rather than as separate line items. SOC 2's Privacy trust services criteria and PIPEDA's fair information principles cover a lot of the same ground: notice, consent, collection limits, access, and disclosure controls. If you're already scoping PIPEDA readiness, most of that documentation, your data inventory, your retention schedule, your incident response plan, feeds directly into a SOC 2 audit and vice versa. Building them in sequence instead of together is the most common way we see companies pay twice for the same work.

Quebec's Law 25 adds a layer on top for anyone with Quebec residents as customers or employees: mandatory privacy impact assessments for certain data transfers, a stricter consent standard, and its own breach notification regime with its own regulator. A company in Montreal or Ottawa selling nationally needs to think about PIPEDA, Law 25, and (if serving US enterprise customers) SOC 2 as one connected privacy and security posture, not three separate checklists.

How to Tell Which Situation You're In

Ask three questions before spending anything:

  • Has a customer, investor, or regulator actually asked us for privacy documentation, or are we anticipating it?
  • Do we handle sensitive categories of personal information, or standard business contact data?
  • Are we already building a SOC 2 program where privacy documentation can be shared, or would this be a standalone effort?

If the answers point to "not yet," spend a day writing an honest privacy policy and naming an accountable owner. If they point to "yes," a proper PIPEDA readiness assessment mapped against whatever else you're pursuing, whether that's a SOC 2 report or the broader compliance posture our compliance practice covers, is worth doing properly and once.

Get an Honest Read on Your Privacy Obligations

We built our reputation in Canada's security and compliance market on saying no when a client doesn't need something, not just yes when they do. If you want a straight answer on whether PIPEDA, Law 25, or SOC 2 privacy criteria actually apply to your business, or how to build one program that satisfies all three, contact traztech and we'll tell you where you stand before we tell you what to buy.

The Breach Record Nobody Knows They Owe

Most people who read PIPEDA's breach provisions come away with one takeaway: notify if there is a real risk of significant harm. They miss the obligation sitting beside it. You must keep a record of every breach of security safeguards involving personal information, including the ones you decided were not notifiable, and keep those records for 24 months. The Privacy Commissioner can ask for them, and the request tends to arrive after something else has gone wrong.

This is the cheapest item on the PIPEDA list and the one we most often find missing. A lost laptop, a misdirected customer list, a support agent pasting a spreadsheet into the wrong Slack channel: all breaches of safeguards, none necessarily notifiable, all needing a dated entry. With no log, you have no evidence you ever ran the assessment, and the regulator's default reading is that you did not.

What "real risk of significant harm" turns on. The statute points at sensitivity and probability of misuse. In practice the assessment is short. Was the data identifiable or reasonably re-identifiable. Did it include financial details, health information, or government identifiers. Who received it, and can you confirm deletion. Was it encrypted, and did the key travel with it. A one-page template with those questions, filled in the same afternoon, beats any policy document you can buy.

Access Requests, and the 30 Days That Start Without Warning

An individual can ask what personal information you hold, how it is used, and to whom it has been disclosed. You have 30 days to respond, with a limited extension if you notify them inside the first 30, and you cannot charge a fee without giving an estimate up front and a chance to withdraw the request.

The failure mode is not refusal. It is that nobody can answer the question. A modern SaaS stack scatters personal information across the production database, the warehouse, the support tool, the CRM, the email platform, backups, and whatever your observability vendor retains. The first access request usually consumes several engineering days, because it is the moment the data inventory finally gets built. Doing that inventory beforehand turns the next request into a query.

Where Consent Quietly Breaks in a SaaS Product

Session replay and product analytics. Tools that record sessions capture whatever is on screen, which in a B2B product includes your customer's customers. Meaningful consent has to cover a purpose the user would reasonably expect, and full-session recording of a workflow holding third-party personal information sits outside that expectation unless masking is configured properly.

Secondary use for model training. If customer data flows into training or fine-tuning, that is a new purpose. Burying it in a terms update is the pattern that draws complaints. The clean answer is a contractual commitment not to train on customer content, plus a technical control that backs it up, plus documentation of both.

Cross-border storage. PIPEDA does not prohibit sending personal information outside Canada. It makes you accountable through contractual means and expects transparency that it happens and that foreign law may apply. The obligation is disclosure and comparable protection, not data residency. Buyers confuse the two constantly, and a founder who knows the difference can answer a residency demand without agreeing to build a Canadian region.

What Actually Happens if Someone Complains

The Office of the Privacy Commissioner is an ombudsman-style regulator. A complaint leads to an investigation and a published findings report, and the Commissioner recommends rather than orders in most circumstances. Repeated legislative effort to add order-making powers and monetary penalties federally has not produced a law in force, so anyone selling a program on the basis of imminent federal fines is describing a PIPEDA that does not exist. What bites is commercial: a published finding is exactly what a buyer's procurement team surfaces during diligence. Quebec's Law 25 is the regime with real financial teeth today, which is why a company with Quebec customers should treat that as the binding constraint.

What Enterprise Buyers Actually Ask About PIPEDA

Security questionnaires rarely ask "are you PIPEDA compliant," because the asker knows there is nothing to certify. The questions that show up instead are answerable in an afternoon if you have done the work and impossible to fake if you have not. Who is your designated individual accountable for privacy, by name. Where is personal information stored and processed, by country. What is your retention schedule by data category. What is your timeline for handling an access or deletion request. Have you had a breach in the last 24 months. Will you sign a DPA with breach notification inside a defined window.

Six answers. That is the practical shape of a PIPEDA position for most Canadian B2B SaaS companies, and it is why we often tell people the work is smaller than they were quoted. Those answers also feed the privacy criteria in a SOC 2 scope and the records Law 25 expects, so nothing is wasted if you later formalize it through our compliance practice.

When You Should Not Hire Us for This

If you are pre-revenue, handling business contact information only, and no customer has asked you anything, buy nothing. Write the policy, name an accountable person in writing, start the breach log, revisit in a year.

If your only real problem is a Quebec-specific privacy impact assessment for one transfer, scope that narrowly rather than commissioning a federal program around it. If you are already inside a SOC 2 or ISO 27001 project, ask that partner to extend the existing data inventory and retention schedule instead of starting a parallel privacy engagement. Two teams building two inventories from the same interviews is how money gets wasted here.

We earn our fee when privacy has become a deal blocker: a buyer's legal team is redlining your DPA, a breach has already happened, or you are trying to satisfy PIPEDA, Law 25, and a US customer's contract with one set of documents. If that is where you are, tell us what is on the table and we will scope the smallest version that clears it. The annual refresh belongs on a retainer, not a project.

Privacy obligations piling up? Law 25 and PIPEDA readiness, with a named privacy officer where the law asks for one.

Privacy officerOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on privacy law. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.