Canadian PIPEDA
Evidence request list. 31 controls, 31 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
PIPEDA: Breach of Security Safeguards (Division 1.1)
s.10.1(1): an organization must report to the Privacy Commissioner any breach of security safeguards involving personal information where it is reasonable to believe the breach creates a real risk of significant harm.
- breach assessment and report to the OPC
- timeliness of reporting
- reportable breach not reported to the OPC
- assessment of real risk of significant harm not performed
s.10.1(7)-(8): factors relevant to assessing the real risk of significant harm, including sensitivity of the information and probability of misuse.
- documented RROSH assessment considering sensitivity and probability of misuse
- no documented RROSH assessment
- factors not considered
s.10.1(3): an organization must notify affected individuals of a breach that creates a real risk of significant harm, unless otherwise prohibited by law.
- notification to affected individuals containing prescribed content
- timeliness of notification
- affected individuals not notified
- notification lacks required information
s.10.2: an organization must notify other organizations or government institutions that may be able to reduce or mitigate the risk of harm from a breach.
- records of notifying other organizations that can mitigate harm
- other organizations able to mitigate harm not notified
s.10.3: an organization must keep and maintain a record of every breach of security safeguards involving personal information and provide it to the Commissioner on request.
- register of all breaches (not only reportable ones)
- records available to the OPC on request
- only reportable breaches logged
- no breach register
PIPEDA: Complaints and Oversight
s.11: an individual may file a written complaint with the Privacy Commissioner against an organization for contravening a Division 1 provision or failing to follow a Schedule 1 recommendation.
- process for cooperating with OPC complaints and investigations
- records of complaint responses
- no process to respond to an OPC complaint or investigation
PIPEDA: Consent and Use (Division 1)
s.5(3): an organization may collect, use or disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances.
- reasonableness assessment of processing purposes
- purposes a reasonable person would not consider appropriate
s.6.1: consent is valid only if it is reasonable to expect that the individual understands the nature, purpose and consequences of the collection, use or disclosure.
- evidence consent disclosures are understandable to the target audience
- consent buried in dense legalese
- audience cannot reasonably understand
s.7: limited circumstances in which personal information may be collected, used or disclosed without knowledge or consent (e.g. investigations, legal requirements, emergencies).
- documentation of any reliance on a s.7 exception
- legal basis for without-consent processing
- exception relied on without meeting its conditions
s.7.2/7.3: conditions for using and disclosing personal information in the course of a prospective or completed business transaction.
- agreement restricting use of personal information in a transaction to the transaction
- safeguards and return/destruction if the transaction does not proceed
- personal data used beyond the transaction
- no agreement governing the data
PIPEDA: Schedule 1 Fair Information Principles
Schedule 1, 4.1: an organization is responsible for personal information under its control and must designate an individual(s) accountable for compliance.
- designation of an accountable individual (privacy officer)
- documented accountability for personal information under control
- no designated accountable person
- accountability not documented
Schedule 1, 4.1.3: an organization is responsible for personal information transferred to a third party for processing and must use contractual or other means to provide comparable protection.
- contracts requiring comparable protection by processors
- due diligence over third-party processors
- transfers without contractual protection
- no oversight of processors
Schedule 1, 4.1.4: implement policies and practices to give effect to the principles - procedures, complaint handling, training, and explanatory materials.
- documented privacy policies and procedures
- staff training and explanatory materials
- no privacy management program
- policies not implemented in practice
Schedule 1, 4.10: an individual must be able to address a challenge concerning compliance to the designated accountable individual; complaints must be investigated.
- complaint-handling procedure
- records of complaints investigated and resolved
- no complaint mechanism
- complaints not investigated
Schedule 1, 4.2: the purposes for which personal information is collected must be identified at or before the time of collection.
- documented purposes at point of collection
- collection notices stating purposes
- purposes not identified before collection
- vague or overbroad purposes
Schedule 1, 4.2.4: identifying a new purpose after collection requires the consent of the individual before use.
- process to obtain fresh consent for new purposes
- secondary use without new consent
Schedule 1, 4.3: the knowledge and consent of the individual are required for the collection, use or disclosure of personal information, except where inappropriate.
- records of knowledge and consent
- consent obtained at/ before collection
- collection/use/disclosure without consent
- consent not meaningful
Schedule 1, 4.3.4-4.3.6: the form of consent (express vs implied, opt-in vs opt-out) depends on the sensitivity of the information and reasonable expectations.
- express consent for sensitive information
- consent form proportionate to sensitivity
- implied consent used for sensitive data
- opt-out used where express consent required
Schedule 1, 4.3.8: an individual may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.
- mechanism to withdraw consent
- process to action withdrawal and inform individual of consequences
- no withdrawal mechanism
- withdrawal not honoured
Schedule 1, 4.4: collection must be limited to what is necessary for the identified purposes and collected by fair and lawful means.
- data inventory showing collection limited to purpose
- fair and lawful collection methods
- over-collection
- collection by deception
Schedule 1, 4.5: personal information must not be used or disclosed for purposes other than those for which it was collected, except with consent or as required by law, and retained only as long as necessary.
- retention schedule
- controls preventing secondary use/disclosure
- use beyond purpose
- indefinite retention
Schedule 1, 4.5.3: information no longer required must be destroyed, erased or made anonymous; guidelines and procedures governing destruction are required.
- secure destruction/anonymisation procedures and records
- retention then disposal evidence
- data retained past need
- insecure disposal
Schedule 1, 4.6: personal information must be as accurate, complete and up-to-date as necessary for the purposes for which it is to be used.
- data quality processes
- update mechanisms
- inaccurate data used for decisions
Schedule 1, 4.7: personal information must be protected by security safeguards appropriate to the sensitivity of the information.
- security safeguards proportionate to sensitivity
- risk-based protection of personal data
- safeguards not proportionate to sensitivity
- sensitive data inadequately protected
Schedule 1, 4.7.3: safeguards must include physical, organizational and technological measures.
- physical, organizational and technological controls
- access controls and encryption where appropriate
- only one category of safeguard implemented
Schedule 1, 4.7.4: organizations must make employees aware of the importance of maintaining the confidentiality of personal information.
- privacy/security awareness training records
- staff handling personal data untrained
Schedule 1, 4.8: an organization must make readily available specific information about its policies and practices relating to the management of personal information.
- publicly available privacy policy
- contact for privacy questions
- policies not publicly available
Schedule 1, 4.8.2: the information made available must include the accountable person contact, access procedures, a description of the type of information held, and what is made available to related organizations.
- privacy policy covering the 4.8.2 required elements
- privacy policy missing required elements
Schedule 1, 4.9: upon request, an individual must be informed of the existence, use and disclosure of their personal information and be given access to it.
- access-request handling process
- records of access requests and responses
- access requests not honoured
- no access process
Schedule 1, 4.9.4: requested information must be provided within a reasonable time and at minimal or no cost (generally 30 days under s.8).
- SLA evidence access provided within ~30 days
- cost limited to minimal
- access responses late
- excessive fees charged
Schedule 1, 4.9.5: an individual may challenge the accuracy and completeness of information and have it amended; unresolved challenges must be noted and conveyed to third parties where appropriate.
- correction/amendment process
- notation of unresolved challenges
- corrections not actioned
- third parties not informed of corrections
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Canadian PIPEDA framework page.