Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

GDPR for Canadian Companies: When It Applies, Article 27, and Why Adequacy Is Not an Exemption

Direct answer: The GDPR applies to a Canadian company with no EU office when it offers goods or services to people in the EU, or monitors their behaviour there. If it applies, you usually also need an EU representative under Article 27, a person established in the EU who acts as your contact point for regulators and individuals. Canada's adequacy decision does not change any of that. Adequacy makes it easier for EU organizations to send personal data to Canadian companies covered by PIPEDA; it does not exempt you from the GDPR when you are directly in its scope.

When the GDPR applies to a Canadian company

Article 3 sets the territorial scope. There are two routes that matter for a company based in Canada.

You have an establishment in the EU

An office, a branch or in some cases even a small stable presence in an EU member state brings the processing carried out in the context of that establishment into scope, wherever the processing physically happens. If you have one, the GDPR applies through Article 3(1), and Article 27 does not, because you are already established there.

You target or monitor people in the EU

Without any EU establishment, Article 3(2) applies the GDPR when you process personal data of people who are in the EU and the processing relates to either:

  • Offering goods or services to them, paid or free. The test is whether you envisage serving people in the EU. A site that merely can be reached from Europe is not enough. Signals that you are targeting include pricing in euros, an EU language version you would not otherwise have, shipping to EU countries, EU customer references, or marketing aimed at EU markets.
  • Monitoring their behaviour in the EU. Tracking users across sites, behavioural advertising, profiling, and detailed analytics tied to individuals can all count.

For a Canadian SaaS company the usual trigger is simple: EU businesses sign up, and their employees become your users. If you sell to EU customers and process their staff's personal data, assume you are in scope and work out in what role.

Controller or processor

Your obligations depend on your role. For the data your customers put into your product, you are usually a processor acting on their instructions, and the obligations centre on the data processing agreement, security, sub-processors and assisting your customer. For your own marketing lists, website analytics and account data, you are the controller, with the full set of obligations including lawful basis, notices and individual rights.

Not sure which privacy laws apply to you? Answer a few questions about where your customers and users are, and see which regimes come into play. Privacy law finder

The Article 27 representative

A controller or processor caught by Article 3(2) must designate in writing a representative in the EU. The representative must be established in one of the member states where the people whose data you process are located. They act as a contact point for supervisory authorities and for individuals, and under Article 30 they keep the record of processing activities alongside you.

There is a narrow exemption. You do not need a representative if your processing is occasional, does not include large-scale processing of special categories of data or criminal convictions data, and is unlikely to result in a risk to people's rights and freedoms, taking into account its nature, context, scope and purposes. A SaaS product that EU users rely on every day is rarely "occasional". Assume you need one unless you have analysed the exemption and written down why it applies.

Three points that get confused:

  • A representative is not a data protection officer. The DPO under Articles 37 to 39 is an internal advisory role, mandatory only in specific cases such as large-scale regular monitoring or large-scale processing of special category data. The representative is your local contact point. You may need one, both or neither.
  • Appointing a representative does not move your liability. It is without prejudice to legal action against the controller or processor itself.
  • The representative must be in the EU. A Canadian privacy officer, however capable, cannot fill the role. The United Kingdom has its own equivalent requirement under the UK GDPR, and a UK representative is a separate appointment.

Name the representative in your privacy notice, with contact details, so individuals and authorities can find them.

Why adequacy does not exempt you

The European Commission recognized Canada as providing adequate protection in 2001, for recipients subject to PIPEDA, and kept that decision in place after its review published in January 2024. Adequacy is a Chapter V concept: it governs transfers of personal data out of the EU. It means an EU company can send personal data to a Canadian company covered by PIPEDA without additional transfer safeguards such as standard contractual clauses.

It does not mean Canadian law replaces the GDPR for Canadian companies. If you are in scope under Article 3(2), the GDPR applies to you directly, and adequacy says nothing about your lawful basis, your notices, the rights you owe individuals, your records, your breach obligations or your representative. The adequacy decision is useful to you and your EU customers. It is not an exemption.

Check, too, that the decision covers your situation. It applies to organizations subject to PIPEDA. Onward transfers from you to your own sub-processors in other countries still need their own basis.

Free weekly email

Get The Compliance Brief every Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

What GDPR readiness involves

  • Records of processing. What personal data you hold, about whom, for what purpose, on what lawful basis, where it goes and how long you keep it. Processors keep their own simpler record.
  • Lawful basis per activity. Consent is one of six bases and often not the right one. Contract and legitimate interests carry most B2B SaaS processing, with a documented assessment for legitimate interests.
  • Data processing agreements with customers, and with your own sub-processors, covering what Article 28 requires.
  • Transfer mechanisms for any onward transfers outside the EU and Canada.
  • Individual rights. Access, rectification, erasure, portability and objection, answered without undue delay and within one month, extendable by two further months for complex or numerous requests if you tell the person within the first month.
  • Breach handling. Under the GDPR, a controller notifies the supervisory authority within 72 hours of becoming aware of a breach unless it is unlikely to result in a risk, and tells affected people without undue delay when the risk is high. Processors tell their controller without undue delay.
  • Security of processing appropriate to the risk, which is where SOC 2 or ISO 27001 work overlaps heavily.
  • Privacy notices that say all of this in plain language, and name your representative.

Running GDPR, PIPEDA and Law 25 together

A Canadian company with EU customers is usually also subject to PIPEDA, and often to Quebec Law 25. The regimes differ in detail, including breach thresholds and timelines, request deadlines and the role of the privacy officer, but most of the work is shared: one data inventory, one set of vendor contracts, one incident register designed to meet the strictest record-keeping rule, one request log that tracks each law's clock. Building three separate programmes is how small companies end up maintaining none of them. Our PIPEDA vs GDPR comparison covers the differences in more detail.

The stakes

The most serious GDPR infringements can be fined up to 20 million euros or 4% of total worldwide annual turnover for the preceding financial year, whichever is higher. Failing to appoint a representative falls in the lower tier, up to 10 million euros or 2%. Enforcement against non-EU companies is harder than against EU ones, but the more common consequence is commercial: an EU customer's procurement team asks for your DPA, your records of processing and your representative, and the deal waits until you have them.

Our GDPR readiness Phase 1 gap analysis is from $3,000. It establishes whether and how the GDPR applies to you, maps your processing, and produces a ranked list of gaps. We cannot act as your Article 27 representative, because that role must be established in the EU, and we will tell you if you need one.

Frequently asked questions

Does the GDPR apply if we only have a few EU users?

Possibly. The test is whether you offer goods or services to people in the EU or monitor their behaviour, not how many there are. Volume matters more to the Article 27 exemption, which requires processing to be occasional and low risk.

Is a Canadian company with EU customers exempt because of adequacy?

No. Adequacy governs transfers of personal data from the EU to Canada. If the GDPR applies to you directly under Article 3(2), adequacy does not remove those obligations.

Can our privacy officer be our EU representative?

Only if they are established in the EU, in a member state where the people whose data you process are located. A privacy officer in Canada cannot fill the role.

Do we need a data protection officer?

Only in specific cases, such as core activities that involve large-scale regular and systematic monitoring or large-scale processing of special category data. Many Canadian SaaS companies do not, but a representative is a separate question.

EU customers asking for your GDPR position? We work out how the GDPR applies to you, map your processing and give you a ranked list of what to fix.

GDPR readinessOr find which laws apply

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on privacy law. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.