Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Canada’s Privacy Commissioner Sets New Expectations for Third-Party Privacy Due Diligence

Canada’s Privacy Commissioner Sets New Expectations for Third-Party Privacy Due Diligence

By
Key Takeaways
  • Responsibility Stays With the Organization: Businesses subject to PIPEDA remain responsible for personal information under their control when it is collected, used, disclosed, or processed by third-party providers.
  • Due Diligence Should Come Before the Contract: The OPC recommends assessing a prospective provider’s privacy practices before using its services or entering into an agreement.
  • Assessments Should Follow the Data: Organizations should understand what personal information is involved, map data flows, examine subcontractors and cross-border transfers, and determine how providers intend to use the information.
  • AI Introduces Additional Questions: When technology relies on training data, organizations should examine where that data came from, how it was collected, and whether its sourcing complies with applicable privacy requirements.
  • Oversight Continues After Procurement: The guidance calls for attention to security, breach responsibilities, data retention and disposal, vendor lock-in and lock-out, and mechanisms for ongoing monitoring of provider compliance.
Deep Dive

Privacy Commissioner of Canada, Philippe Dufresne, released new guidance for organizations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), laying out how businesses should assess the privacy practices of prospective third-party service providers. The guidance applies when an outside product, service, or technology will involve the collection, use, or disclosure of personal information, whether the provider is processing information directly, supplying technology that handles it, or working somewhere further down the chain.

The Office of the Privacy Commissioner of Canada (OPC) is accepting comments on the guidance until Dec. 4, after which it will consider whether changes are needed.

Under PIPEDA, organizations remain responsible for personal information under their control, including information collected on their behalf or transferred to another organization for processing. They are also required to use contractual or other means to ensure that information receives comparable protection while a third party is processing it.

“It is essential for organizations to comply with privacy law – and to ensure that third-party partners are doing the same – in order to protect individuals’ privacy and personal information,” Dufresne said in announcing the guidance. He added that doing so can help organizations earn Canadians’ trust, making investment in privacy protection a potential competitive advantage.

That responsibility is why the OPC places the assessment before procurement rather than after implementation. Organizations should examine a provider’s privacy practices before using its services or entering into an agreement, with the review conducted by people who have the training and expertise to understand what they are looking at. Where that expertise does not exist internally, the regulator says outside legal or technical specialists may be necessary.

The point is not merely to produce another vendor questionnaire. A sufficiently rigorous assessment can expose privacy and compliance risks while there is still time to do something about them, influence contractual terms, inform the decision to use a provider in the first place, and give an organization evidence of its accountability if an oversight body later comes asking questions.

Following the Information

The OPC begins with what sounds like the simplest question: what personal information is actually involved? In practice, the answer can become complicated quickly.

Organizations are advised to account for information they process themselves as well as information a provider collects or processes on their behalf, including anything shared with the provider. Sensitive information requires closer scrutiny, with the OPC pointing to health and financial data, racial and ethnic origins, political opinions, genetic and neural data, uniquely identifying biometric information, information about a person’s sex life or sexual orientation, and religious or philosophical beliefs.

The regulator also cautions businesses against treating information as harmless simply because it is publicly accessible or has supposedly been anonymized. PIPEDA can still apply to personal information available in public spaces, including information posted online, while data stripped of direct identifiers may remain capable of being re-identified. Where a provider claims information has been anonymized, the OPC recommends asking specifically how that was done and how the techniques satisfy applicable legal thresholds.

From there, the inquiry follows the information itself. Organizations should map how personal information moves among the business, its clients and other individuals, the provider, subcontractors, and any additional parties involved in delivering the service. That map should reach all the way to where the information is stored, including cloud databases controlled by the provider or another third party.

It should also capture why the information is moving. The OPC says organizations should establish each purpose for which a provider will collect, use, or disclose personal information on their behalf. If the provider wants to use that information for its own purposes, including training an algorithm or improving internal processes, the organization should determine whether consent is required and whether the proposed use is consistent with PIPEDA and other applicable privacy laws.

That last point brings the guidance squarely into the questions businesses now face when evaluating AI products. Where a provider’s technology depends on training data, the OPC says organizations should ask where that data came from and how it was collected, then consider whether its sourcing complies with PIPEDA or the laws of the jurisdictions where it was obtained.

The assessment should reach into the technology itself as well. Organizations are advised to understand how a provider treats personal information and examine known risks in the technology’s operation, including systemic bias, security vulnerabilities, inaccuracy, or discriminatory treatment. They should determine which functions are actually necessary for their purposes and whether unnecessary capabilities can be switched off. Where the technology is difficult to understand, the OPC recommends requesting additional materials and considering independent external sources that can shed light on its performance.

The Provider Behind the Provider

A contract with one company can conceal a much longer chain of organizations handling the same information. The OPC’s guidance asks businesses to look through that chain rather than stop at the name on the agreement.

If subcontractors will handle personal information, organizations should establish their identities in writing and confirm that they will be held to the same privacy standards as the primary provider. The roles of the organization, provider, and subcontractors should be defined, including responsibility for responding when individuals seek access to their personal information. Those responsibilities should ultimately make their way into the contract.

The same scrutiny applies when the chain crosses national borders. Organizations should identify the jurisdictions in which providers and subcontractors will collect, use, or disclose personal information and understand the PIPEDA obligations attached to information handled elsewhere. They should also assess risks to the integrity, security, and confidentiality of information transferred to service providers operating outside Canada.

Security is part of that inquiry, but the OPC frames it in practical terms. Businesses should confirm what cybersecurity, physical access, and workplace controls a provider uses, understand the security features built into its technology, and know who is responsible for configuring them. They should also settle the question of a breach before one happens, including what the organization, provider, and any subcontractors will each be expected to do.

Planning for the Relationship to End

The guidance does not assume that a successful vendor relationship lasts forever. In fact, some of its more consequential recommendations concern what happens when it does not.

The OPC tells organizations to assess the possibility of “vendor lock-in,” where dependence on proprietary technology or data formats can make changing providers difficult and reduce the organization’s control over personal information processing. Contractual guarantees around data portability are among the possible safeguards. Businesses should also consider “vendor lock-out,” the less familiar but equally practical risk that a provider ceases operations and leaves its customers with questions about how to access or recover the personal information it holds.

Retention and disposal therefore belong in the assessment from the beginning. Organizations should understand how a provider destroys personal information at the end of its lifecycle, including copies residing on cloud servers, in backups, or with subcontractors. They should also establish what will happen to information when services are terminated: how it will be returned, how remaining copies will be deleted, and how disposal will be carried out.

Even then, the work is not finished. Once a provider is operating, organizations should consider how its technology can be monitored through measures such as access logs, reporting tools, regular testing, and independent audits. The OPC likewise recommends ongoing mechanisms for checking whether providers continue to meet their privacy obligations, including inspections or independent audits.

The guidance is not presented as an exhaustive statement of everything PIPEDA requires when businesses use third parties, and the OPC acknowledges that the appropriate assessment will vary from one relationship to another. Its best practices are meant to provide a foundation rather than a universal checklist.
But the responsibility underneath them is considerably less flexible. An organization can outsource the processing, buy the technology, rely on subcontractors, move information across borders, and entrust the mechanics of handling that information to companies it may never see. What it cannot outsource under PIPEDA is its responsibility for ensuring that its use of those products and services complies with the privacy requirements that still belong to it.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong