Why a PIPEDA gap assessment is its own piece of work
Most Canadian companies meet PIPEDA through a customer questionnaire. A form asks whether you comply with the Personal Information Protection and Electronic Documents Act, somebody ticks yes because the company has a privacy policy and encrypts its database, and the question goes away for a year. Then a larger buyer asks for your privacy officer's name, your retention schedule, your sub-processor list and your process for answering an access request within thirty days, and the yes stops holding up.
PIPEDA is not a control framework in the sense that SOC 2 or ISO 27001 are. It is a federal statute applying to organizations that collect, use or disclose personal information in the course of commercial activity, and its substantive obligations live in Schedule 1, the ten Fair Information Principles. The principles are short and plainly written, and that brevity is what makes them hard. The statute names the outcome and leaves the mechanism to you, so the only way to know whether you comply is to compare what each principle asks against what your organization actually does, system by system.
That comparison is the gap assessment. It is Phase 1, and it has to come first, because remediation cannot be honestly scoped or priced until somebody has looked. A firm quoting a fixed remediation price before assessing your environment is pricing a guess. Our PIPEDA readiness engagement starts from $2,500 and is a gap assessment; remediation is scoped and priced from the findings it produces.
The ten Fair Information Principles, and what each one asks for in practice
1. Accountability. You must name an individual accountable for compliance, and that name has to be available to anyone who asks. The assessment looks for a designated privacy officer with the role written into a job description, not a title borrowed for a questionnaire, plus the surrounding machinery: internal privacy policies rather than a website page, contractual privacy protections flowed down to every third party handling personal information on your behalf, and staff training with attendance records. Accountability follows information transferred to processors. You remain responsible for it.
2. Identifying purposes. Purposes must be identified at or before the moment of collection. The practical test is whether you can state, for every field you collect, why you collect it, in language a customer would recognize. Assessments routinely find fields that predate anyone's memory of why they exist, and analytics or enrichment uses that were never declared.
3. Consent. Knowledge and consent are required for collection, use and disclosure, with narrow exceptions. The Office of the Privacy Commissioner's guidelines for meaningful consent set out what that looks like operationally: emphasize four key elements, being what is collected, who it is shared with, the purposes, and the risk of harm; give a genuine choice at the point of decision; make the form of consent proportionate to sensitivity, with express consent for sensitive information; allow withdrawal; and design for the device it appears on. The work is auditing signup flows, cookie and tracking behaviour and pre-checked boxes, then checking whether a withdrawal reaches downstream systems or just sets a flag nobody reads.
4. Limiting collection. Collection is limited to what is necessary for the identified purposes, by fair and lawful means. This is where over-collection surfaces: full dates of birth where a year would do, a mandatory phone number on a form nobody calls, a third-party script pulling more than the page needs.
5. Limiting use, disclosure and retention. Personal information may be used or disclosed only for the purposes for which it was collected, except with consent or as law requires, and retained only as long as necessary to fulfil those purposes. Two gaps dominate. The first is secondary use, typically product analytics, model training, or a marketing tool wired into the production database. The second is retention: most organizations have no retention schedule, no deletion capability in their backups, and no evidence anything has ever been destroyed. The principle requires procedures governing destruction, and requires that information used to make a decision about someone be kept long enough for them to contest it.
6. Accuracy. Information must be as accurate, complete and up to date as the purposes require. The practical question is whether a customer can correct their record, whether corrections propagate to anyone you disclosed to, and whether stale records are reviewed rather than left to accumulate.
7. Safeguards. Protection appropriate to sensitivity, through physical, organizational and technical measures, covering loss, theft, unauthorized access, disclosure, copying, use and modification. This is the principle that looks most like a security framework and the one most companies are furthest along on. Sensitivity drives the level, so health or financial data in scope raises the bar.
8. Openness. Specific information about your policies and practices must be readily available in an understandable form: the title and contact address of the accountable person, how to gain access to your information, the types of personal information held with a general account of their use, and what is made available to related organizations. A one-paragraph privacy notice does not satisfy this.
9. Individual access. On written request, an individual is entitled to be told of the existence, use and disclosure of their personal information, to be given access to it, and to challenge its accuracy and completeness. Response is required within thirty days, with a limited extension where notice is provided, generally at minimal or no cost. You must also account for third parties to whom the information has been disclosed. This is the obligation that breaks operationally, because answering it means knowing every system holding one person's data. Without a data map you cannot answer on time.
10. Challenging compliance. An individual must be able to address a challenge to the accountable person, and complaint procedures must be simple, easy to use and publicized. Every complaint has to be investigated, and justified complaints have to result in amended practices. The assessment looks for the intake channel, the investigation record and evidence that something changed.
What a PIPEDA gap assessment actually produces
A privacy gap assessment that ends in a maturity score has told you little. Four deliverables matter.
A scoped inventory of personal information. Every category the organization holds, the systems it lives in, its purpose, its sensitivity, who internally can reach it, and the consent mechanism behind it. Built from interviews with the teams who touch the data, not a questionnaire to department heads.
A data map, covering cross-border flows and sub-processors. Where personal information enters, moves, rests and leaves. PIPEDA does not prohibit transfers outside Canada, but treats a transfer to a processor as a use, which keeps you accountable and requires transparency plus contractual means to secure a comparable level of protection. That makes the sub-processor list a compliance artefact, not a procurement detail. The map should name every processor, what it holds, where it stores it, and which contract governs it.
A findings register. Each gap stated against the principle it fails, with the evidence observed, the exposure created and the remediation required. This is the artefact a buyer, an auditor or a regulator can be shown, and the input to scoping and pricing remediation.
A prioritized remediation roadmap. Sequenced by risk and dependency, because privacy fixes have a required order. Retention rules cannot be written before the inventory exists, and access request procedures cannot be tested before the data map is complete. The roadmap should say who owns each item and what evidence closes it.
Where PIPEDA and SOC 2 overlap, and where they do not
SOC 2 reports against the Trust Services Criteria. Security is the common criteria and is mandatory. Availability, Processing Integrity, Confidentiality and Privacy are optional categories a company elects to include. The overlap with PIPEDA sits almost entirely in Principle 7, safeguards. Access control, change management, encryption, monitoring, incident response and vendor management done for SOC 2 Security largely satisfy the safeguards PIPEDA expects, and the evidence is reusable.
Everything else in PIPEDA sits outside the Security criteria completely. Consent has no analogue there. Neither does purpose limitation, retention limits, the right of access and correction, openness, or complaint handling. A company with a clean SOC 2 Type II covering Security only has demonstrated nothing about whether it collects more than it needs, whether its consent is meaningful, whether it can answer an access request in thirty days, or whether it has ever deleted anything.
The Privacy category narrows the distance but does not close it. Its criteria cover notice, choice and consent, collection, use and retention, access, disclosure, quality and monitoring, so the structural resemblance to PIPEDA is real. It is still not PIPEDA compliance. A SOC 2 report attests that the controls management described were suitably designed and, in a Type II, operated effectively over a period. It does not attest that those controls satisfy a Canadian federal statute. The thirty day access response, the breach reporting threshold, the record-keeping requirement and the Commissioner's jurisdiction are not what the auditor opined on.
The planning consequence: run the security work once and use it for both, then treat the privacy obligations as a separate stream with its own assessment, findings and owner. Companies that fold PIPEDA into a SOC 2 project as a checkbox end up with good safeguards and nothing else.
Breach of security safeguards: reporting, notification, and the record you must keep regardless
Since November 2018, PIPEDA has required mandatory breach reporting, and the assessment must test it. A breach of security safeguards means loss of, unauthorized access to, or unauthorized disclosure of personal information resulting from a failure of an organization's security safeguards or from those safeguards not being established.
The trigger is real risk of significant harm to an individual. Significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunity, financial loss, identity theft, effects on the credit record, and loss of property. Assessing whether the risk is real means weighing the sensitivity of the information and the probability it has been, is being, or will be misused.
Where that threshold is met, three obligations follow. Report to the Office of the Privacy Commissioner in the prescribed form, as soon as feasible after determining the breach occurred. Notify affected individuals, also as soon as feasible, with enough information to understand the significance of the breach and reduce the risk of harm. Notify any other organization or government institution able to reduce the risk or mitigate the harm.
The obligation most often missed is the fourth, which has no threshold at all. You must keep a record of every breach of security safeguards involving personal information under your control, whether or not it creates a real risk of significant harm, and provide those records to the Commissioner on request. Regulations set the retention period at twenty-four months from the day the organization determines the breach occurred. In practice that means a breach log with an entry for every incident, including ones you assessed and decided not to report, showing the reasoning. Knowingly contravening the reporting duty in section 10.1 or the record-keeping duty in section 10.3 is an offence under section 28: a fine up to $10,000 on summary conviction, or up to $100,000 on indictment.
A readiness assessment should test three things: whether a documented procedure applies the real risk of significant harm test, whether anyone has been trained to run it under time pressure, and whether the breach log exists and is populated. A tabletop exercise is the cheapest way to find out. Ours starts from $3,000 for a day.
Where provincial law displaces or sits beside PIPEDA
PIPEDA applies to commercial activity across Canada and to personal information crossing provincial or national borders, but it is not the only statute in play.
Quebec Law 25 applies to enterprises operating in Quebec regardless of where they are headquartered, and is materially stricter than PIPEDA. Its provisions phased in through 22 September 2024, enforced by the Commission d'accès à l'information, with penalties reaching $25M CAD or 4% of worldwide turnover. It adds requirements PIPEDA does not have: a mandatory privacy officer defaulting to the person exercising the highest authority, privacy impact assessments, obligations around automated decision making, and data portability. Selling into Quebec means a separate assessment. Our Law 25 readiness sprint runs four weeks from $6,000.
Alberta PIPA and BC PIPA have been declared substantially similar to PIPEDA, so within those provinces they apply in its place for intraprovincial commercial activity. PIPEDA still covers federal works and undertakings and information crossing a border. Both carry their own breach and access provisions, so an Alberta or British Columbia footprint means reading the provincial act rather than assuming equivalence.
Ontario PHIPA governs personal health information held by health information custodians in Ontario and has also been declared substantially similar for that information. A digital health vendor is usually not a custodian but an agent or electronic service provider acting for one, which carries its own obligations. If your product touches Ontario clinical data, PHIPA governs, and the contract with the custodian is where most of the obligations arrive.
The scoping point is simple: the assessment must establish which statutes apply before assessing against them, and the answer is often more than one.
What to ask a readiness partner about privacy work specifically
Security and privacy readiness are different disciplines. Ask directly:
- Is remediation priced before or after the gap assessment? If a fixed price arrives before anyone has examined your data flows, ask what it is based on.
- Will the engagement produce a data inventory and a data map naming cross-border flows and sub-processors, or only a findings summary? Ask to see the structure of both, redacted, from prior work.
- Which statutes will be assessed against, and who made that determination? A company selling nationally usually has PIPEDA plus at least one provincial act in scope.
- Who does the privacy work? Ask for Canadian engagements the firm can point to, and for the practitioner's credentials beyond a baseline certificate.
- How is the breach response obligation tested? Reading the policy is not a test.
- Which entity signs the contract, and under which province's law? Where does your engagement data live during the work, and what happens to it afterwards?
- Who signs your audit, and can they be referenced? A readiness partner should never be your auditor. Audits are performed by licensed CPA firms and certifications by accredited certification bodies.
Next step
If customers are asking about PIPEDA and you have no inventory, data map or retention schedule, the gap assessment is the work. It sets scope, produces the findings register, and makes remediation something that can be priced honestly instead of guessed at.
TrazTech is a Canadian readiness practice run by a published security researcher with five CVEs on the public record, including CVE-2024-45163 at CVSS 9.1. PIPEDA readiness starts from $2,500. If Quebec or SOC 2 is also in scope, say so at the outset, because the assessments are cheaper run together. Reach us through traztech.ca to book a scoping call.