Skip to main content
Home/Readiness/PIPEDA Readiness
PIPEDA Compliance

PIPEDA Readiness

A defensible privacy programme mapped to the ten Fair Information Principles, with a breach response process that actually meets the 24-month record-keeping requirement.

Standard PIPEDA
Typical Timeline 1-3 weeks
Starting Price $6,500
Scope Delivery Calgary, Toronto & Remote
Assessment Scope

What This Engagement Covers

PIPEDA is not a certification - it is a principles-based law enforced by the Office of the Privacy Commissioner of Canada, and most organisations only find out where their programme falls short after a complaint or a breach forces the question. We run readiness against the ten Fair Information Principles in Schedule 1, so your consent language, retention practices, safeguards, and breach response process would hold up if the OPC ever asked to see them - and so you can answer a customer's privacy questionnaire with documentation instead of a promise.

Canadian Operations & Law

What This Means for Canadian Businesses

PIPEDA is the federal private-sector privacy law and applies to virtually every Canadian business that collects, uses, or discloses personal information in the course of commercial activity - but it is not the only law in play. Alberta and British Columbia have their own "substantially similar" private-sector statutes (Alberta's PIPA applies instead of PIPEDA to organisations' intra-provincial activity, which matters directly for our Calgary clients), while Ontario has no general private-sector law of its own and relies on PIPEDA directly - relevant for our Toronto clients - except where Ontario's PHIPA governs health information custodians specifically. Quebec's Law 25 sits on top of all of this for any organisation with Quebec customers or employees, and is materially stricter than PIPEDA: mandatory privacy impact assessments for certain transfers, a biometric database registration requirement, and a private right of action. We scope every readiness engagement against the actual mix of federal and provincial obligations that apply to where your business and customers actually are.

Calgary HubAlberta Operations
Toronto HubOntario Operations
Control Framework

Domains & Controls We Assess

We evaluate every technical, operational, and administrative requirement against authoritative criteria.

Accountability & Governance (Principle 1)

  • A designated individual is accountable for PIPEDA compliance and reachable by name
  • Privacy policies are developed, approved, and communicated to staff who handle personal information
  • Contracts with processors and service providers carry through equivalent privacy obligations
  • Staff receive privacy training proportionate to their access to personal information

Identifying Purposes & Consent (Principles 2-3)

  • Purpose for collecting personal information is identified before or at the time of collection
  • Consent obtained is meaningful and proportionate to the sensitivity of the information
  • Consent mechanisms are not bundled into unrelated terms and support withdrawal
  • Collection involving minors or automated decision-making is flagged for enhanced consent review

Limiting Collection, Use, Disclosure & Retention (Principles 4-5)

  • Collection is limited to what the identified purpose actually requires
  • Use and disclosure stay within the purposes consent was obtained for, subject to defined exceptions
  • A retention schedule exists and personal information is destroyed or anonymised once it is no longer needed
  • Third-party disclosures, including cross-border transfers, are documented and justified

Safeguards (Principle 7)

  • Physical, organisational, and technical safeguards are proportionate to the sensitivity of the data held
  • Access to personal information is restricted to those whose role requires it
  • Personal information is encrypted at rest and in transit where the sensitivity warrants it
  • Vendors and processors are assessed for adequate safeguards before information is shared

Breach Response (Breach of Security Safeguards Regulations)

  • A process exists to detect breaches and assess real risk of significant harm (RROSH)
  • Notification to the OPC and affected individuals happens "as soon as feasible" once RROSH is established
  • A breach record is maintained for a minimum of 24 months - including breaches never reported
  • Post-incident remediation feeds back into the safeguards and controls that failed

Individual Access & Openness (Principles 8-10)

  • Access requests are tracked and answered within the legislated response window
  • Policies describing how personal information is handled are readily available on request
  • A defined process exists for individuals to challenge compliance and escalate complaints
  • Provincial overlay (Alberta PIPA, Quebec Law 25, Ontario PHIPA) is assessed against actual operating footprint
What You Receive

Engagement Deliverables

Everything you need to prove control operating effectiveness to your auditors and enterprise clients.

PIPEDA Gap Assessment Mapped to the Ten Fair Information Principles

Privacy Policy and Public-Facing Notice Review

Breach Response Plan Aligned to the Breach of Security Safeguards Regulations

Personal Information Inventory and Retention Schedule

Cross-Border Transfer and Third-Party Processor Review

Prioritised Remediation Roadmap

Client Stories

Trusted by Growing Businesses

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
FAQ

Common Questions

Is PIPEDA compliance actually mandatory for our business? +

Yes, if you collect, use, or disclose personal information in the course of commercial activity in Canada. The exception is intra-provincial activity in a province with its own substantially similar law - Alberta and British Columbia both have one - where the provincial law applies instead. PIPEDA still governs any interprovincial or international handling of that data regardless of where you are incorporated.

Is there a PIPEDA certification we can get? +

No. The Office of the Privacy Commissioner does not certify organisations, and there is no official PIPEDA seal. What we deliver is a documented readiness assessment against the ten Fair Information Principles - the same evidence base you would need if the OPC opened an investigation or a customer's security questionnaire asked for proof of your privacy programme.

How is this different from Alberta's PIPA or Quebec's Law 25? +

Alberta and BC each have their own private-sector privacy statute that applies instead of PIPEDA to organisations' activity within that province - relevant if your Calgary operations are intra-provincial. Ontario has no general private-sector law of its own, so Toronto-based commercial activity falls under PIPEDA directly, though PHIPA governs health information custodians specifically. Quebec's Law 25 is the strictest of all of them - mandatory privacy impact assessments for certain transfers, biometric database registration, and a private right of action - and applies the moment you have Quebec customers or employees, regardless of where you are based. We scope the engagement to whichever combination actually applies to you.

What actually triggers mandatory breach reporting under PIPEDA? +

The "real risk of significant harm" (RROSH) test - a factual assessment of the sensitivity of the information involved and the probability it will be misused. If RROSH is met, you must notify the OPC and affected individuals as soon as feasible, and keep a record of every breach - reported or not - for at least 24 months. Most organisations we assess don't have a working process for making that RROSH call under time pressure, which is where readiness work usually finds the biggest gap.

Get Started

Ready for Your PIPEDA Readiness Assessment?

Speak directly with our senior Canadian compliance team. We establish your exact scope, quote a fixed flat-rate price, and deliver a definitive timeline.