On September 10, 2026, the Privacy Commissioner of Canada (the Commissioner) released new guidance (the Guidance) to help businesses subject to the Personal Information Protection and Electronic Documents Act (“PIPEDA”) assess third-party service providers’ privacy practices before engaging them.

The Guidance is specifically directed towards organizations subject to PIPEDA that are considering working with a third-party service provider to implement a product, service, or technology involving the collection, use, or disclosure of personal information.

The Guidance outlines 11 best practices to help organizations meet their accountability obligations under Principle 4.1.3 of PIPEDA:

  1. Know what personal information is involved:  Identify the personal information involved and assess its sensitivity and associated risks.
  2. Map data flows: Understand how personal information will move between the organization, provider, subcontractors, and other relevant parties.
  3. Confirm how data will be used: Confirm how the provider will collect, use, and disclose personal information, including for secondary purposes.
  4. Understand functionality and performance: Be aware of how the technology functions and ensure functionalities can be disabled if needed.
  5. Confirm roles and responsibilities: Clearly establish the privacy responsibilities of the organization, provider and subcontractors.
  6. Assess out-of-country collection and transfers: Determine the jurisdiction in which personal information will be collected, used or disclosed and assess related risks.
  7. Identify the source of training data: Determine the source of data used to train AI or tests its functioning and whether its sourcing is consistent with legal requirements.
  8. Verify security practices and administrative controls: Assess the provider’s security policies and breach response practices.
  9. Assess the risk of vendor lock-in and lock-out: Consider risks associated with dependence on the provider’s technology, including loss of access to personal information or services.
  10. Confirm data retention and end of contract procedures: Confirm what happens to personal information when the relationship ends.
  11. Identify monitoring mechanisms: Confirm processes to monitor the provider’s ongoing privacy and contractual compliance.

The Guidance emphasizes that organizations should assess a third party’s privacy practices before using or entering into an agreement to obtain a prospective provider’s services.

For more information, see the full Guidance available here.

Summary By: Victoria Di Felice

 

E-TIPS® ISSUE

26 10 07

Disclaimer: This Newsletter is intended to provide readers with general information on legal developments in the areas of e-commerce, information technology and intellectual property. It is not intended to be a complete statement of the law, nor is it intended to provide legal advice. No person should act or rely upon the information contained in this newsletter without seeking legal advice.

E-TIPS is a registered trade-mark of Deeth Williams Wall LLP.