Skip to content

Evidence request lists

Canadian PIPEDA

Evidence request list. 31 controls, 31 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

PIPEDA: Breach of Security Safeguards (Division 1.1)

PIPEDA-10.1
Report of Breach to the Commissioner

s.10.1(1): an organization must report to the Privacy Commissioner any breach of security safeguards involving personal information where it is reasonable to believe the breach creates a real risk of significant harm.

Artefacts an auditor will ask for
  • breach assessment and report to the OPC
  • timeliness of reporting
Where this commonly fails
  • reportable breach not reported to the OPC
  • assessment of real risk of significant harm not performed
PIPEDA-10.1(6)
Real Risk of Significant Harm Assessment

s.10.1(7)-(8): factors relevant to assessing the real risk of significant harm, including sensitivity of the information and probability of misuse.

Artefacts an auditor will ask for
  • documented RROSH assessment considering sensitivity and probability of misuse
Where this commonly fails
  • no documented RROSH assessment
  • factors not considered
PIPEDA-10.1-ind
Notification of Breach to Individuals

s.10.1(3): an organization must notify affected individuals of a breach that creates a real risk of significant harm, unless otherwise prohibited by law.

Artefacts an auditor will ask for
  • notification to affected individuals containing prescribed content
  • timeliness of notification
Where this commonly fails
  • affected individuals not notified
  • notification lacks required information
PIPEDA-10.2
Notification to Other Organizations

s.10.2: an organization must notify other organizations or government institutions that may be able to reduce or mitigate the risk of harm from a breach.

Artefacts an auditor will ask for
  • records of notifying other organizations that can mitigate harm
Where this commonly fails
  • other organizations able to mitigate harm not notified
PIPEDA-10.3
Records of Breaches

s.10.3: an organization must keep and maintain a record of every breach of security safeguards involving personal information and provide it to the Commissioner on request.

Artefacts an auditor will ask for
  • register of all breaches (not only reportable ones)
  • records available to the OPC on request
Where this commonly fails
  • only reportable breaches logged
  • no breach register

PIPEDA: Complaints and Oversight

PIPEDA-11
Filing of Complaints with the Commissioner

s.11: an individual may file a written complaint with the Privacy Commissioner against an organization for contravening a Division 1 provision or failing to follow a Schedule 1 recommendation.

Artefacts an auditor will ask for
  • process for cooperating with OPC complaints and investigations
  • records of complaint responses
Where this commonly fails
  • no process to respond to an OPC complaint or investigation

PIPEDA: Consent and Use (Division 1)

PIPEDA-5(3)
Appropriate Purposes

s.5(3): an organization may collect, use or disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances.

Artefacts an auditor will ask for
  • reasonableness assessment of processing purposes
Where this commonly fails
  • purposes a reasonable person would not consider appropriate
PIPEDA-6.1
Valid Consent

s.6.1: consent is valid only if it is reasonable to expect that the individual understands the nature, purpose and consequences of the collection, use or disclosure.

Artefacts an auditor will ask for
  • evidence consent disclosures are understandable to the target audience
Where this commonly fails
  • consent buried in dense legalese
  • audience cannot reasonably understand
PIPEDA-7
Collection, Use and Disclosure Without Consent

s.7: limited circumstances in which personal information may be collected, used or disclosed without knowledge or consent (e.g. investigations, legal requirements, emergencies).

Artefacts an auditor will ask for
  • documentation of any reliance on a s.7 exception
  • legal basis for without-consent processing
Where this commonly fails
  • exception relied on without meeting its conditions
PIPEDA-7.3
Disclosure for Prospective Business Transaction

s.7.2/7.3: conditions for using and disclosing personal information in the course of a prospective or completed business transaction.

Artefacts an auditor will ask for
  • agreement restricting use of personal information in a transaction to the transaction
  • safeguards and return/destruction if the transaction does not proceed
Where this commonly fails
  • personal data used beyond the transaction
  • no agreement governing the data

PIPEDA: Schedule 1 Fair Information Principles

PIPEDA-4.1
Principle 1 - Accountability

Schedule 1, 4.1: an organization is responsible for personal information under its control and must designate an individual(s) accountable for compliance.

Artefacts an auditor will ask for
  • designation of an accountable individual (privacy officer)
  • documented accountability for personal information under control
Where this commonly fails
  • no designated accountable person
  • accountability not documented
PIPEDA-4.1.3
Accountability for Transfers to Third Parties

Schedule 1, 4.1.3: an organization is responsible for personal information transferred to a third party for processing and must use contractual or other means to provide comparable protection.

Artefacts an auditor will ask for
  • contracts requiring comparable protection by processors
  • due diligence over third-party processors
Where this commonly fails
  • transfers without contractual protection
  • no oversight of processors
PIPEDA-4.1.4
Policies and Practices (Privacy Management Program)

Schedule 1, 4.1.4: implement policies and practices to give effect to the principles - procedures, complaint handling, training, and explanatory materials.

Artefacts an auditor will ask for
  • documented privacy policies and procedures
  • staff training and explanatory materials
Where this commonly fails
  • no privacy management program
  • policies not implemented in practice
PIPEDA-4.10
Principle 10 - Challenging Compliance

Schedule 1, 4.10: an individual must be able to address a challenge concerning compliance to the designated accountable individual; complaints must be investigated.

Artefacts an auditor will ask for
  • complaint-handling procedure
  • records of complaints investigated and resolved
Where this commonly fails
  • no complaint mechanism
  • complaints not investigated
PIPEDA-4.2
Principle 2 - Identifying Purposes

Schedule 1, 4.2: the purposes for which personal information is collected must be identified at or before the time of collection.

Artefacts an auditor will ask for
  • documented purposes at point of collection
  • collection notices stating purposes
Where this commonly fails
  • purposes not identified before collection
  • vague or overbroad purposes
PIPEDA-4.2.4
New Purpose Requires New Consent

Schedule 1, 4.2.4: identifying a new purpose after collection requires the consent of the individual before use.

Artefacts an auditor will ask for
  • process to obtain fresh consent for new purposes
Where this commonly fails
  • secondary use without new consent
PIPEDA-4.3
Principle 3 - Consent

Schedule 1, 4.3: the knowledge and consent of the individual are required for the collection, use or disclosure of personal information, except where inappropriate.

Artefacts an auditor will ask for
  • records of knowledge and consent
  • consent obtained at/ before collection
Where this commonly fails
  • collection/use/disclosure without consent
  • consent not meaningful
PIPEDA-4.3.4
Form of Consent Calibrated to Sensitivity

Schedule 1, 4.3.4-4.3.6: the form of consent (express vs implied, opt-in vs opt-out) depends on the sensitivity of the information and reasonable expectations.

Artefacts an auditor will ask for
  • express consent for sensitive information
  • consent form proportionate to sensitivity
Where this commonly fails
  • implied consent used for sensitive data
  • opt-out used where express consent required
PIPEDA-4.3.8
Withdrawal of Consent

Schedule 1, 4.3.8: an individual may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.

Artefacts an auditor will ask for
  • mechanism to withdraw consent
  • process to action withdrawal and inform individual of consequences
Where this commonly fails
  • no withdrawal mechanism
  • withdrawal not honoured
PIPEDA-4.4
Principle 4 - Limiting Collection

Schedule 1, 4.4: collection must be limited to what is necessary for the identified purposes and collected by fair and lawful means.

Artefacts an auditor will ask for
  • data inventory showing collection limited to purpose
  • fair and lawful collection methods
Where this commonly fails
  • over-collection
  • collection by deception
PIPEDA-4.5
Principle 5 - Limiting Use, Disclosure and Retention

Schedule 1, 4.5: personal information must not be used or disclosed for purposes other than those for which it was collected, except with consent or as required by law, and retained only as long as necessary.

Artefacts an auditor will ask for
  • retention schedule
  • controls preventing secondary use/disclosure
Where this commonly fails
  • use beyond purpose
  • indefinite retention
PIPEDA-4.5.3
Secure Destruction and Retention

Schedule 1, 4.5.3: information no longer required must be destroyed, erased or made anonymous; guidelines and procedures governing destruction are required.

Artefacts an auditor will ask for
  • secure destruction/anonymisation procedures and records
  • retention then disposal evidence
Where this commonly fails
  • data retained past need
  • insecure disposal
PIPEDA-4.6
Principle 6 - Accuracy

Schedule 1, 4.6: personal information must be as accurate, complete and up-to-date as necessary for the purposes for which it is to be used.

Artefacts an auditor will ask for
  • data quality processes
  • update mechanisms
Where this commonly fails
  • inaccurate data used for decisions
PIPEDA-4.7
Principle 7 - Safeguards

Schedule 1, 4.7: personal information must be protected by security safeguards appropriate to the sensitivity of the information.

Artefacts an auditor will ask for
  • security safeguards proportionate to sensitivity
  • risk-based protection of personal data
Where this commonly fails
  • safeguards not proportionate to sensitivity
  • sensitive data inadequately protected
PIPEDA-4.7.3
Categories of Safeguards

Schedule 1, 4.7.3: safeguards must include physical, organizational and technological measures.

Artefacts an auditor will ask for
  • physical, organizational and technological controls
  • access controls and encryption where appropriate
Where this commonly fails
  • only one category of safeguard implemented
PIPEDA-4.7.4
Employee Awareness of Safeguards

Schedule 1, 4.7.4: organizations must make employees aware of the importance of maintaining the confidentiality of personal information.

Artefacts an auditor will ask for
  • privacy/security awareness training records
Where this commonly fails
  • staff handling personal data untrained
PIPEDA-4.8
Principle 8 - Openness

Schedule 1, 4.8: an organization must make readily available specific information about its policies and practices relating to the management of personal information.

Artefacts an auditor will ask for
  • publicly available privacy policy
  • contact for privacy questions
Where this commonly fails
  • policies not publicly available
PIPEDA-4.8.2
Required Openness Information

Schedule 1, 4.8.2: the information made available must include the accountable person contact, access procedures, a description of the type of information held, and what is made available to related organizations.

Artefacts an auditor will ask for
  • privacy policy covering the 4.8.2 required elements
Where this commonly fails
  • privacy policy missing required elements
PIPEDA-4.9
Principle 9 - Individual Access

Schedule 1, 4.9: upon request, an individual must be informed of the existence, use and disclosure of their personal information and be given access to it.

Artefacts an auditor will ask for
  • access-request handling process
  • records of access requests and responses
Where this commonly fails
  • access requests not honoured
  • no access process
PIPEDA-4.9.4
Access Response Timelines

Schedule 1, 4.9.4: requested information must be provided within a reasonable time and at minimal or no cost (generally 30 days under s.8).

Artefacts an auditor will ask for
  • SLA evidence access provided within ~30 days
  • cost limited to minimal
Where this commonly fails
  • access responses late
  • excessive fees charged
PIPEDA-4.9.5
Correction and Notation

Schedule 1, 4.9.5: an individual may challenge the accuracy and completeness of information and have it amended; unresolved challenges must be noted and conveyed to third parties where appropriate.

Artefacts an auditor will ask for
  • correction/amendment process
  • notation of unresolved challenges
Where this commonly fails
  • corrections not actioned
  • third parties not informed of corrections
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Canadian PIPEDA framework page.