TrustCenter

Trust centers and PIPEDA

PIPEDA does not require a trust centre. It does make you accountable for personal information your suppliers handle, and that is exactly what buyers want the trust centre to show.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

PIPEDA, Canada's federal private-sector privacy law, does not require a trust centre, but it shapes what a Canadian buyer expects to find on one. Under the accountability principle an organization stays responsible for personal information it transfers to a third party for processing, and must use contractual or other means to protect it. So when a Canadian company buys your service, its reviewer needs to see your safeguards, your subprocessors and where data goes. A trust centre is where you show them once.

Which PIPEDA obligations does a trust centre support?

PIPEDA principles and the trust centre content that supports them
PIPEDA principleWhat your buyer must showWhat your trust centre publishes
Accountability (principle 1)Comparable protection when a processor handles personal informationControls summary, subprocessor list, DPA terms
Safeguards (principle 7)Security appropriate to the sensitivity of the informationEncryption, access control, logging, report or certificate
Openness (principle 8)Readily available information about policies and practicesPrivacy policy, privacy contact
Breach of security safeguardsReporting to the Privacy Commissioner and notifying individuals where there is a real risk of significant harm, and keeping records of every breachYour incident notification commitment to customers

What should a Canadian trust centre say about privacy?

  • Where personal information is stored and whether it leaves Canada. See data residency.
  • Every subprocessor that touches personal information, with its location. See subprocessor lists.
  • How and when you notify customers of a breach affecting their data.
  • Your privacy officer or privacy contact.
  • Your data processing agreement, gated or public.

Where do provincial laws apply instead?

Quebec, Alberta and British Columbia have their own private-sector privacy laws that apply in place of PIPEDA for most activity within those provinces, and health information has its own statutes such as Ontario's PHIPA. Quebec's Law 25 adds publishing and transfer requirements covered on the Law 25 page. Bill C-36 would replace Part 1 of PIPEDA if passed; see Bill C-36 and trust centres.

Common questions

Does PIPEDA require us to store data in Canada?

No. PIPEDA does not prohibit transferring personal information outside Canada, but it keeps you accountable for it and expects transparency about it. Some buyers, contracts and provincial public sector rules require Canadian storage separately.

Is a trust centre enough to meet PIPEDA's openness principle?

It helps, but your privacy policy and your practices are what the principle addresses. The trust centre is where you make them easy to find for business customers.

Get Canadian privacy content right

Providers who know PIPEDA and the provincial laws can write this section.

Get matched