Data & Security
PIPEDA and Quebec Law 25: A Plain-Language Checklist
A PIPEDA compliance checklist for online ordering, plus what Quebec Law 25 adds: a named privacy lead, incident records, privacy policy and portability.
If you sell custom home products online in Canada, you collect personal information with every quote: names, addresses, phone numbers, sometimes photos of a customer's home. This PIPEDA compliance checklist covers the federal basics, then what Quebec's Law 25 adds if you serve customers there. It is general information, not legal advice: have a privacy lawyer review your own practices.
Which law applies to you
The Office of the Privacy Commissioner of Canada (OPC) explains that PIPEDA applies to private-sector organizations across Canada that collect, use or disclose personal information in the course of commercial activity.
Alberta, British Columbia and Quebec have their own private-sector privacy laws, described by the OPC as substantially similar. Organizations subject to those laws are generally exempt from PIPEDA for activity within that province. In Quebec, the provincial private-sector law was substantially amended by what is commonly called Law 25.
A manufacturer in one province selling across the country can deal with more than one regime. That is one reason to get advice specific to your business.
The 10 principles behind PIPEDA
The OPC summarizes PIPEDA's obligations as 10 fair information principles:
| Principle | What it means for an ordering business |
|---|---|
| Accountability | Name someone responsible for privacy |
| Identifying purposes | Say why you collect each piece of information |
| Consent | Get meaningful consent for what you collect and how you use it |
| Limiting collection | Collect only what the order needs |
| Limiting use, disclosure and retention | Use it for the stated purpose and keep it only as long as needed |
| Accuracy | Keep customer records correct |
| Safeguards | Protect the data with security suited to its sensitivity |
| Openness | Publish your privacy practices |
| Individual access | Let customers see the information you hold about them |
| Challenging compliance | Give customers a way to complain |
Breaches: report, notify and keep records
The OPC's guidance on mandatory breach reporting sets out three obligations under PIPEDA:
- Report to the Privacy Commissioner any breach of security safeguards involving personal information that poses a real risk of significant harm.
- Notify affected individuals about those breaches.
- Keep records of all breaches of security safeguards, whether or not they pose a real risk of significant harm, for two years.
The third point catches small businesses out. A misdirected email with a customer's address is a record you may need to keep, even if it never reaches the reporting threshold.
Software vendors: you stay accountable
Your ordering platform, email tool and hosting provider all process personal information for you. The OPC's guidelines for processing personal data across borders state that an organization is responsible for personal information in its custody, including information transferred to a third party for processing. Organizations should use contracts to provide a comparable level of protection and tell customers, in clear language, when their information may be processed in another country.
So the questions in who owns your customer list are privacy questions as well as business ones.
What Quebec Law 25 adds
The Commission d'accès à l'information du Québec (CAI) summarizes the main changes. Among them:
- A person in charge of privacy. By default it is the person with the highest authority in the business, such as the owner or CEO. The CAI's page on this role says it can be delegated in writing, and the title and contact details must be published on the company's website.
- Confidentiality incidents. Businesses must keep a register of incidents and notify the CAI and affected individuals when an incident presents a risk of serious injury. The CAI has a page on incidents and security measures.
- Privacy impact assessments before communicating personal information outside Quebec, proportionate to the sensitivity of the information.
- A published privacy policy in clear and simple terms when information is collected through technological means.
- Data portability. Since September 22, 2024, individuals can ask for their personal information in a structured, commonly used technological format.
The CAI notes administrative monetary penalties for private businesses can reach $10 million or 2% of worldwide turnover.
Your PIPEDA compliance checklist
Use this as a starting point for a review with your lawyer:
- Name a privacy lead and publish their title and contact details.
- List what your quote and order forms collect, and remove anything you do not need.
- Write a privacy policy in plain language and link it from your checkout.
- Separate order emails from marketing emails, and get consent for marketing.
- Set retention periods for abandoned quotes and old orders.
- Keep a breach and incident log, even if it stays empty.
- Put privacy terms in your contracts with software vendors, and know where each one hosts data.
- Make sure you can export a customer's records on request.
- If you serve Quebec, assess any transfer of personal information outside the province.
Security sits underneath all of this. See isolated customer data for one of the key questions to ask vendors.
How Inlay handles this
- Each company's orders live in a separate encrypted database (AES-256 at rest, TLS 1.2 or higher in transit).
- You choose Canadian or US hosting, which helps when you assess where data goes.
- You own your customer data and can export it any time by CSV or API, which makes access and portability requests easier to answer.
- Inlay never sells your data or markets to your customers, and deletes data within 30 days of cancellation.
This post is general information, not legal advice. Check with a privacy lawyer about your obligations in each province where you sell.
Book a 20-minute demo to walk through where customer data is stored and how exports work.