The PIPEDA compliance checklist, 32 points you can finish this afternoon
By James Frost, Founder, WARDORX
Last reviewed
9 min read
A privacy compliance checklist for Canadian businesses, built from the ten principles in the Act rather than from somebody's blog post. Tick it here, or have the PDF emailed to you.
Most PIPEDA checklists you will find are twelve vague items long and end in a contact form. This one has 32, every item names the principle it comes from, and the whole thing is on this page - you can work through it right now without giving anyone your email.
It is written for the Canadian small business with no privacy officer, no legal department and no budget for either: a clinic, a trades company, an online shop, an agency. If you handle personal information in the course of doing business in Canada, the Personal Information Protection and Electronic Documents Act applies to you, and there is no small-business exemption to fall back on.
Work through it honestly. Anything you cannot tick is not a failure, it is a decision nobody has made yet, and most of them take an afternoon rather than a project.
32 points
Grouped into six obligations
10 principles
Every item names the one it comes from
No paywall
The whole list is on this page
The 32-point privacy compliance checklist
Tick what is true today, not what you intend to do. Progress saves in this browser only and is sent nowhere, which is the least we can do on a checklist about collecting less.
0/32
Saved in this browser only. Nothing is sent anywhere.
Accountability and governance
0/6Who is responsible, and can you prove it on a Tuesday afternoon with no notice.
Knowing what you hold
0/5You cannot limit, secure or delete data you have never inventoried.
Consent and notice
0/6The part that gets small businesses caught, because the defaults are wrong.
Safeguards
0/7Proportionate to sensitivity - which means a clinic and a landscaper differ.
Individual rights
0/4Thirty days is shorter than it sounds when nobody is watching the inbox.
Breach readiness
0/4The obligations here are the only part of PIPEDA carrying an offence provision.
- What is a PIPEDA compliance checklist?
- A working list of the things Canadian privacy law requires you to have in place, expressed as statements you can confirm or not. A good one maps every item to a specific obligation rather than to general good practice, which is why each of the 32 items here names the principle in Schedule 1 of the Act that it comes from. It is a self-assessment tool, not a certification - nobody issues a PIPEDA certificate, and any vendor offering you one is selling something else.
- Is this PIPEDA checklist free?
- Yes, and it is on this page in full. There is nothing hidden behind an email address. If you want it as a PDF to work through away from the screen or to hand to whoever administers your systems, we will email that to you, and we ask for express consent before ever sending you anything else.
- How many items should a privacy compliance checklist have?
- Enough to cover all ten principles and no more than you will actually complete. Ours is 32, grouped into accountability, knowing what you hold, consent and notice, safeguards, individual rights and breach readiness. Anything much shorter is skipping a principle; anything much longer is usually a consultant's scoping document rather than a checklist.
- Does PIPEDA apply to my small business in Canada?
- Almost certainly. PIPEDA applies to organizations that collect, use or disclose personal information in the course of commercial activity, with no exemption based on revenue, headcount or being a sole proprietor. If you are in Alberta, British Columbia or Quebec, the provincial private-sector statute may govern your activity inside the province, while PIPEDA continues to cover anything crossing a provincial or national border.
- What happens if I fail a PIPEDA audit?
- There is no PIPEDA audit in the sense of a scheduled inspection you pass or fail. The Privacy Commissioner investigates complaints and can publish findings, but cannot levy fines. The exposure that actually costs Canadian businesses money is civil - class actions after a breach - plus CASL penalties from the CRTC, which are real and collected. That is the argument for the retention and safeguards items on this list rather than for panic.
- How often should I run through this checklist?
- Once now, then whenever something changes that touches personal information: a new tool in the stack, a new form on the site, a staff change, a new market. An annual re-run is a reasonable floor, and the accountability items are worth checking whenever the person responsible changes.
Every item traces to the Act.
The 32 points above are not a list somebody invented to look thorough. Each one carries the number of the principle in Schedule 1 of the Personal Information Protection and Electronic Documents Act that it comes from, and the full guide walks through all ten in plain English - along with templates for a privacy policy, a cookie policy and a breach response plan, and how PIPEDA compares to Quebec's Law 25, California's CCPA and the GDPR.
Read the full PIPEDA compliance guideThis is a practical guide written by a Calgary web agency that builds compliant sites, not legal advice. For anything consequential, take advice from a Canadian privacy lawyer.
Stop paying $5K/month for nothing.
Get a site that ships. Fourteen days, fixed fee, and a number you can hold us to from month one.
Book a call - 30 min
live availabilityTimes shown in your local zone. You'll get the audit doc before the call, not after.