ClearBreach

← Guides

PIPEDAAB PIPABC PIPAManaged service providers

Onboarding a Client: The Privacy Questions Worth Asking in Week One

By Yong DuPublished Reviewed

Six questions that decide what a managed services provider is taking on, and what the client is still accountable for after you arrive.

On this page

What you are actually taking on

A managed services provider does not take on a client's accountability. PIPEDA Schedule 1 clause 4.1.3 keeps the organization responsible for personal information it transfers to a third party for processing, and requires it to use contractual or other means to provide a comparable level of protection while the information is with that third party.

Read from the other side of the table, that clause is about you. Your client is measured on whether their arrangement with you is good enough. The six questions below are the ones that decide whether it is, and every one of them is easier to ask in week one than in the week after something happens.

The six questions

1. Where does this client actually do business?

Not where they are registered. Where the activity happens. An organization operating only within Alberta is under Alberta PIPA for that activity. One that sells across a provincial border picks up PIPEDA as well. British Columbia has its own Act, and BC PIPA imposes no mandatory breach-notification duty on private-sector organizations at all, which changes what a breach at that client obliges them to do.

If you manage clients in several provinces you are managing organizations under different Acts simultaneously. That is a fact about your practice, not about any one client.

2. What personal information is in the systems we are taking over?

Health information, financial and banking details, government identifiers, employment records. You do not need an inventory in week one, but you need to know which of those are present, because they decide how a breach is assessed and which obligations it triggers.

3. Who is their privacy officer, and do they know it?

PIPEDA Schedule 1 Principle 4.1, Alberta PIPA s.5(3) and BC PIPA s.4(3) all require an individual to be designated. In a small organization it is usually the owner or the office manager, and that is fine. What is not fine is a designation nobody told the designated person about.

This matters to you operationally: when something happens, that is the person you call.

4. Is there anything written down?

A written privacy policy staff can find and read is a duty under PIPEDA clause 4.1.4(d), AB PIPA s.6(1) and s.6(3), and BC PIPA s.5(a). Most small organizations have a published policy for customers and nothing internal for staff. Knowing which of the two exists tells you what you are inheriting.

5. Has anything already happened?

Ask directly whether they have had a privacy incident, including ones they decided not to report. PIPEDA s.10.3(1) requires a record of every breach of security safeguards regardless of whether it was reportable, and s.10.3(2) requires it produced to the Commissioner on request. If no such record exists, that gap predates you, and it is much easier to say so now than after your first year.

6. What does the contract say about a breach on either side?

Both directions. What you tell them, how fast, and what they tell you. The clause is cheap to write at signature and expensive to argue about during an incident.

The one that catches providers out

Question five has a mirror image, and it is the one nobody asks: you are the vendor.

The same clause that makes your client responsible for choosing you makes you the arrangement they are being measured on. When a compliance assessment runs at that client and comes back with a finding about service provider management, the finding is about you. Being able to answer it, in writing, in advance, is worth more to the relationship than anything else on this list.

Common mistakes

Assuming their law is your law. A provider in Alberta managing a client in BC is managing a BC PIPA organization. The obligations follow the client.

Taking "we have a privacy policy" at face value. Ask whether it is the public one or the internal one. They are different duties and most organizations have only the first.

Treating the contract as a formality. It is the artefact your client will be asked about.

Waiting for an incident to learn the escalation path. The first time you need the privacy officer's mobile number should not be the day you need it.

Frequently asked questions

Does taking on a client make us accountable for their privacy compliance?

No. Under PIPEDA Schedule 1 clause 4.1.3 the client remains accountable for personal information transferred to a service provider for processing. You become the third party in that clause, which means your client is measured on whether their arrangement with you provides comparable protection. Your obligations are contractual and operational; their accountability does not move to you.

Which privacy law applies to a client we onboard?

It depends on where the client does business, not where you do. An organization operating only within Alberta is under Alberta PIPA for that activity; one selling across a provincial border picks up PIPEDA as well; British Columbia has its own PIPA. A provider with clients in several provinces is managing organizations under different Acts at the same time, which is why the question belongs in week one rather than after an incident.

What should be in the contract before we start?

Two things at minimum, because you will only negotiate it once: comparable protection of the personal information you will handle, and a requirement that each side tells the other promptly about a breach. PIPEDA clause 4.1.3 requires contractual or other means to provide a comparable level of protection, and it is the client's obligation to obtain that from you.

Do we need to know what personal information a client holds?

You need to know enough to protect it and to assess a breach if one happens. Whether the client holds health information, financial details or government identifiers changes how a breach is assessed and what obligations it triggers. A provider who does not know what is in the systems they manage cannot answer the first question a regulator asks.

This guide is educational and does not constitute legal advice. It is grounded in the text of PIPEDA, Alberta PIPA, and BC PIPA and published guidance from the OPC, OIPC Alberta, and OIPC BC. If your situation involves regulatory investigation, litigation risk, or circumstances not addressed here, engage a qualified privacy lawyer.

See what a compliance assessment finds

A real assessment for a small clinic: every area scored, every gap against the provision behind it, and the documents that close them.

See a complete assessment →

Get early access →