Trust centers and PIPEDA
PIPEDA does not require a trust centre. It does make you accountable for personal information your suppliers handle, and that is exactly what buyers want the trust centre to show.
PIPEDA, Canada's federal private-sector privacy law, does not require a trust centre, but it shapes what a Canadian buyer expects to find on one. Under the accountability principle an organization stays responsible for personal information it transfers to a third party for processing, and must use contractual or other means to protect it. So when a Canadian company buys your service, its reviewer needs to see your safeguards, your subprocessors and where data goes. A trust centre is where you show them once.
Which PIPEDA obligations does a trust centre support?
| PIPEDA principle | What your buyer must show | What your trust centre publishes |
|---|---|---|
| Accountability (principle 1) | Comparable protection when a processor handles personal information | Controls summary, subprocessor list, DPA terms |
| Safeguards (principle 7) | Security appropriate to the sensitivity of the information | Encryption, access control, logging, report or certificate |
| Openness (principle 8) | Readily available information about policies and practices | Privacy policy, privacy contact |
| Breach of security safeguards | Reporting to the Privacy Commissioner and notifying individuals where there is a real risk of significant harm, and keeping records of every breach | Your incident notification commitment to customers |
What should a Canadian trust centre say about privacy?
- Where personal information is stored and whether it leaves Canada. See data residency.
- Every subprocessor that touches personal information, with its location. See subprocessor lists.
- How and when you notify customers of a breach affecting their data.
- Your privacy officer or privacy contact.
- Your data processing agreement, gated or public.
Where do provincial laws apply instead?
Quebec, Alberta and British Columbia have their own private-sector privacy laws that apply in place of PIPEDA for most activity within those provinces, and health information has its own statutes such as Ontario's PHIPA. Quebec's Law 25 adds publishing and transfer requirements covered on the Law 25 page. Bill C-36 would replace Part 1 of PIPEDA if passed; see Bill C-36 and trust centres.
Common questions
Does PIPEDA require us to store data in Canada?
No. PIPEDA does not prohibit transferring personal information outside Canada, but it keeps you accountable for it and expects transparency about it. Some buyers, contracts and provincial public sector rules require Canadian storage separately.
Is a trust centre enough to meet PIPEDA's openness principle?
It helps, but your privacy policy and your practices are what the principle addresses. The trust centre is where you make them easy to find for business customers.
Get Canadian privacy content right
Providers who know PIPEDA and the provincial laws can write this section.
Get matched