You collect customer data. PIPEDA applies. There's no policy.
Email lists, billing addresses, support tickets, payment history. Canada's private-sector privacy law covers all of it for any business that uses customer data commercially. The question isn't whether the rule applies. It's whether you can show you've thought about it.
PIPEDA readiness means a Canadian business is set up to comply with the Personal Information Protection and Electronic Documents Act: a written privacy policy, a consent flow on data-collection forms, a documented deletion process, and vendor data agreements. PIPEDA applies to any business that uses personal information for commercial activity in Canada.
- We have customer data. We don't have a privacy policy
- Our cyber insurer is starting to ask for documentation
- Someone asked us to delete their record. We don't know how to do it
- I have no idea what PIPEDA actually covers
- We collect emails for marketing. Nobody set up consent properly
- If a regulator audited us tomorrow, we have nothing to show them
PIPEDA isn't a binder. It's a set of habits.
PIPEDA isn't a one-time policy you write and forget. It's a privacy posture that shifts every time you sign a new vendor, hire someone, or change how you bill. It starts with a scoped readiness project: what you collect, who has access, the policy, consent flow, and deletion process, priced before anything starts. Keep me on after to hold it current as your stack moves, only if you want to. Scoped to your situation and quoted after a free Tech Health Check. See common projects. Advisory from $750/mo.
Technology Partner
A scoped readiness project, then privacy that stays current if you want it. Scoped to your situation and quoted after a free Tech Health Check. See common projects.
See how Technology Partner worksFind out, or
Talk it through.
An hour with me, across the five stages of your business. You get a written report within 24 hours with what to fix first. Or scan it yourself first in 13 minutes if that's faster.