The 60-second summary
On 10 September 2026, the Office of the Privacy Commissioner of Canada published guidance for organisations subject to PIPEDA that are assessing third-party service providers. It reinforces accountability for personal information under organisational control and the need for contractual or other means to ensure comparable protection. Recommended diligence covers sensitive information, data flows, provider purposes, technology performance, subprocessors, access rights, international processing, AI training-data sources, safeguards, breach roles, vendor lock-in, provider failure, retention, deletion and ongoing monitoring. The guidance is open for comments until 4 December 2026 and may then be updated. It is guidance supporting existing duties, not a new law.
Timeline that matters
10 September 2026
Guidance published
The OPC released the guidance and opened it for comments.
4 December 2026
Comment deadline
Comments are accepted until this date; the OPC will then evaluate possible amendments.
11 December 2026
Next review
Check for a revised document and summary of edits after consultation.
What changed
The OPC has translated accountability into a detailed pre-contract assessment model. Notably, it brings AI training-data sources, claimed anonymisation, optional functionality, subprocessor identities, vendor lock-in, provider failure, backup deletion and ongoing monitoring into the vendor privacy review.
Who should pay attention?
Procurement and vendor-risk teams
Use the guidance to structure pre-contract diligence, approval and reassessment.
Privacy and legal teams
Validate accountability, purposes, transfers, contracts and individual-rights arrangements.
AI and product teams
Investigate training-data sources, optional features, performance and provider secondary use.
Security teams
Assess safeguards, configuration ownership, breach response, monitoring and evidence.
Business owners
Own the necessity, residual risk, service dependency and exit decision.
What the guidance clarifies
- Accountability stays with the organisation
- PIPEDA Principle 4.1.3 applies to information under organisational control, including information processed by a third party.
- Assessment should precede contracting
- The OPC recommends assessing privacy practices before using or agreeing to obtain the service.
- Comparable protection needs more than a questionnaire
- Contractual or other means must support comparable protection, while monitoring and evidence demonstrate accountability.
- AI procurement needs data-provenance review
- The guidance specifically recommends checking whether technology uses training data and how that data was sourced.
- Exit risk is a privacy risk
- The guidance addresses lock-in, provider failure, portability, return and deletion across backups and subprocessors.
- The document may change
- The OPC is accepting comments until 4 December 2026 and may amend the guidance afterward.
Vendor diligence must follow the data, the technology and the full service lifecycle
Why this matters for global organisations
A reusable vendor-assessment programme should test actual data flows, secondary purposes, AI data provenance, subprocessor chains, safeguards and exit mechanics. Contracts matter, but defensible accountability also requires competent review, operational monitoring and retained evidence.
- Map processing before approving a provider.
- Investigate provider secondary use and training-data claims.
- Treat portability, deletion and service failure as privacy controls.
- Reassess vendors when technology, scope or risk changes.
15 actions to start now
- Define the proposed service, business purpose and personal-information scope before procurement.
- Identify sensitive information and apply proportionate scrutiny.
- Map data flows across the organisation, provider, subprocessors and data sources.
- Confirm every provider purpose, including product improvement and algorithm training.
- Test functionality, performance, accuracy, bias and security claims using independent evidence where appropriate.
- Document controller, provider and subprocessor roles and individual-rights responsibilities.
- Identify all subprocessors in writing and require equivalent protections.
- Assess collection, storage, access and transfer locations and related legal risks.
- Verify the source and lawful collection of training and testing data.
- Assess cybersecurity, physical security, workplace controls and configurable security settings.
- Contract for breach escalation, audit evidence, deletion, return, portability and subprocessor control.
- Evaluate vendor lock-in, business failure and service-exit scenarios.
- Confirm deletion across production systems, cloud storage, backups and subprocessors.
- Monitor performance, security and compliance through logs, tests, reporting and independent audits.
- Schedule reassessment when processing, technology, locations, ownership or risk changes.
Suggested next steps
- Select one high-risk provider and run the guidance end to end: verify data flows, purposes, training-data use, subprocessors, locations, security settings, breach duties, deletion and exit evidence; record gaps and owners before renewal or expansion.
Evidence worth retaining
- Approved business purpose and necessity statement.
- Personal and sensitive information inventory.
- End-to-end data-flow and transfer map.
- Provider and subprocessor identity register.
- Purpose and secondary-use assessment.
- AI training and testing data provenance evidence.
- Functional, accuracy, bias and security test results.
- Security architecture, certifications and configuration records.
- Role and individual-rights responsibility matrix.
- Signed contract, data-protection terms and breach clauses.
- Transfer and location risk assessment.
- Retention, deletion, backup and exit plan.
- Lock-in and business-continuity assessment.
- Ongoing monitoring, audit and reassessment records.
- Risk acceptance and accountable approval.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- What personal information is genuinely necessary for the service?
- Does the provider use customer data for its own purposes or model improvement?
- Can the provider substantiate anonymisation claims against the applicable legal threshold?
- Which subprocessors and collection or storage locations are involved?
- How were AI training and testing datasets sourced?
- Who configures optional privacy and security controls?
- Can the organisation fulfil access, correction and deletion requests across the service?
- What evidence will be available after a breach or control failure?
- Can data be exported in a usable format and deleted from backups at exit?
- What happens if the provider fails, is acquired or changes material terms?
- How often will the assessment be refreshed?
- Which other privacy, sectoral, cybersecurity or AI rules apply?
Official sources
- OPC — Privacy Commissioner releases guidance for businesses working with third-party service providers, 10 September 2026
- OPC — Guidance on assessing third-party service providers
- Justice Laws Website — Personal Information Protection and Electronic Documents Act
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.