Canada operations
PIPEDA safeguards: what a Canada MSSP still has to prove.
Canada’s private-sector privacy law does not require a SOC logo. It requires safeguards equal to the sensitivity of the data, a real-risk decision after every incident, and a record you can hand the Commissioner. Most mid-market buyers in the GTA are buying the first and hoping the second never arrives.
Published August 17, 2026 · Cyberuptive Team · Toronto
The direct answer
If your organization collects, uses, or discloses personal information in the course of a commercial activity in Canada, PIPEDA is the federal ground rule. Principle 7, Safeguards, says you must protect that information against loss, theft, and unauthorized access, in a way that matches how sensitive it is. The law does not name your EDR, your SIEM, or your MSSP. The Office of the Privacy Commissioner of Canada is explicit: PIPEDA does not specify particular security safeguards.
That is the opposite of a free pass. It means a Toronto professional-services firm, a federally regulated lender, or a GTA healthcare vendor selling across provinces cannot point at a certificate and sit down. You have to show that the measures, physical, organizational, and technological, still fit the risk.
Who is actually in scope
The OPC’s short brief is clearer than most vendor one-pagers:
- Private-sector organizations across Canada that handle personal information in a commercial activity.
- Federally regulated organizations that conduct business in Canada, including banks, telecommunications companies, airlines, and inter-provincial transportation: and their employees’ personal information.
- Any business that handles personal information crossing a provincial or national border in the course of commercial activities, even if it sits in a province with its own private-sector law.
Alberta, British Columbia, and Quebec have private-sector laws the federal government has deemed substantially similar. Intra-provincial activity there is generally exempt from PIPEDA. That exemption does not follow the data out of the province. If a Calgary firm sends customer files to a Toronto processor, or a Montreal retailer runs its CRM in a U.S. region, PIPEDA is back in the conversation.
Ontario does not have a general private-sector privacy statute that replaces PIPEDA. For most commercial activity in the GTA, the federal Act is the one that applies.
Principle 7 is an operations problem
The Safeguards page tells organizations to protect all personal information, however it is stored, against loss, theft, or unauthorized access, disclosure, copying, use, or modification. The examples are deliberately ordinary: locked cabinets and alarm systems; passwords, encryption, firewalls, and patches; security clearances, least privilege, training, and contracts.
Sensitivity drives the bar. Health and financial information, uniquely identifying biometrics, and other data the OPC lists as generally sensitive need more than a shared mailbox and a consumer antivirus. The same page tells you to review safeguards as technologies and risks change. A 2022 SOC-2 report is not a 2026 safeguard.
That is why “we have an MSSP” is not an answer. The question is whether the MSSP can show, on a Tuesday, that MFA is on, logs are retained, an unused admin was removed, and last month’s critical patch is not still open on the finance laptop.
The breach duty is RROSH, plus a file for everything
Since November 1, 2018, the Breach of Security Safeguards Regulations (SOR/2018-64) have sat on top of Division 1.1 of PIPEDA. The OPC’s mandatory-reporting guidance reduces it to three obligations for organizations subject to the Act:
- Report to the Privacy Commissioner of Canada any breach of security safeguards that poses a real risk of significant harm to individuals.
- Notify those individuals, and any other organization that can reduce the harm.
- Keep a record of all breaches of security safeguards, not only the ones that cross the reporting line.
Real risk of significant harm is a judgment, not a ticket priority. The statute and the regulations tell you to weigh the sensitivity of the information and the probability it will be misused. A stolen encrypted laptop with a working passphrase is a different file than an open S3 bucket of customer SINs. Small businesses are in scope. The OPC says so in plain language.
The record-keeping rule is the one mid-market teams skip. If you only write things down when you decide to notify, you have already lost the argument about how you made the RROSH call.
Hiring a processor does not hire away the report
The OPC is direct: the organization in control of the personal information reports the breach. Accountability stays with the principal when information is transferred to a third party for processing. You need contracts that let you meet reporting, notification, and record-keeping. If the processor starts using that information for its own purposes, it is no longer just a processor: it is in control too.
Translate that into an MSSP statement of work. You are not buying “24/7 eyes.” You are buying a party that can, inside your notification window:
- 1. Tell you what personal information was involved, and what was not. A generic “possible intrusion” email is not a RROSH input.
- 2. Produce a timeline you can attach to an OPC report. First detection, containment, systems touched, data classes, and who was told.
- 3. Isolate an identity or endpoint under written authority without waiting for your IT manager to land at Pearson.
- 4. Keep a breach file even when you decide the harm threshold was not met. That file is the control. The non-report is the decision.
If those four items are missing, you do not have a safeguard. You have a reseller of alerts. The acronyms are unpacked in our 2026 MDR vs MSSP vs SIEM buyer’s guide. The Canada-specific cut is who writes the Commissioner narrative.
Five questions for any SOC that wants Canada business
- 1. Where is personal information processed, and who can see it? Cross-border handling is still PIPEDA. Get the region list and the access list, not a trust-center screenshot.
- 2. Who is the accountable person on our side, and who is theirs? Principle 1 requires someone named. An anonymous SOC queue is not that person.
- 3. What does the first four hours of a suspected breach look like in the SOW? If the answer is “we open a ticket,” you will miss the as-soon-as-feasible clock.
- 4. Can they distinguish employee business-contact data from customer personal information? PIPEDA’s exceptions are narrow. Treating everything as “corporate telemetry” is how you mis-scope a report.
- 5. Will they help draft the record for incidents you do not notify? If they only engage when you already plan to call the OPC, they are a crisis vendor, not a safeguard.
How Cyberuptive runs this from Toronto
We are a managed security firm with a Toronto office and a Canada delivery page that is built around PIPEDA-aligned operations, not a transplanted U.S. pitch. MDR is the containment layer. SOC-as-a-Service is the 24/7 watch. The compliance problem is evidence: can we show least privilege, encryption where it is warranted, and an incident file a counsel can stand on.
We will tell a buyer when a full MSSP is more than they need. A 25-person studio with a customer list and Microsoft 365 often needs identity hardening, logging, and a written breach procedure: not a 20-source SIEM. A federally regulated firm with employee and customer data in the same tenant usually needs the heavier stack. The law is the same. The sensitivity is not.
What to do this week
Name the accountable person. Write down where personal information actually lives, M365, the CRM, the payroll vendor, the backup. Open the MSSP or IT contract and highlight the breach section. If that section does not mention records, notification support, or a timeline, you have a gap before anyone is breached.
If you want that inventory reviewed, scoped, not a six-month RFP, start with a 30-minute call. Bring the data-map sketch and the current EDR / identity stack. We will tell you whether PIPEDA’s safeguard duty is already covered, or whether you are one unrecorded incident away from explaining the gap to the Commissioner.
References
- OPC, PIPEDA requirements in brief (scope, 10 principles, substantially similar provinces)
- OPC: PIPEDA fair information principles
- OPC: Principle 7, Safeguards
- OPC, Mandatory reporting of breaches of security safeguards
- Canada Gazette, Breach of Security Safeguards Regulations, SOR/2018-64 (in force November 1, 2018)