ClearBreach

← Guides·All compliance guides →

PIPEDAAB PIPABC PIPAAll sectors

Security Safeguards: What Canadian Regulators Have Treated as Not Enough

By Yong DuPublished

No Canadian privacy Act names a single security method. What regulators have actually found inadequate, and why.

On this page

The law names no method, and that cuts both ways

Three Acts, one duty, and no shopping list.

PIPEDA clause 4.7: personal information shall be protected by security safeguards appropriate to the sensitivity of the information. Clause 4.7.1: the safeguards shall protect against loss or theft, as well as unauthorized access, disclosure, copying, use, or modification.

Alberta PIPA s.34 and BC PIPA s.34 both require an organization to protect personal information by making reasonable security arrangements. Neither names a single method anywhere in the Act.

This is usually read as reassuring, and it should not be. Nothing specific is demanded of you, which also means nothing specific protects you. You cannot point at a certificate and say the law asked for that and I did it. The standard is whether what you chose was reasonable for what you hold, judged afterwards by somebody who knows what went wrong.

Clause 4.7.2 is the part that makes it workable. The safeguards vary with the sensitivity, the amount, the distribution, the format and the method of storage. A mailing list and a file of clinical records are not held to one standard.


What regulators have actually treated as not enough

This is a narrow section on purpose. It is not a security guide, and the internet has enough of those. It is the short list of things Canadian privacy regulators have published decisions about, which is a different and much smaller set than best practice.

A password instead of encryption, on a device that left the building. The Alberta Commissioner has treated this twice. In P2022-ND-068 a password-protected laptop with no encryption reported was found to pose a real risk of significant harm, making the breach reportable. In P2022-ND-066 the recommendation was to consider encryption on laptops instead of password protection.

The distinction is worth stating plainly because it is the one most often blurred. A password stops somebody using the running computer. Encryption stops somebody reading the disk after they take it out. For a device that leaves the premises, only the second one is doing anything.

Some records encrypted and some not. The tempting reading is that partial coverage is partial protection. It is not, because the question a regulator asks is whether a real risk of significant harm exists for an affected individual, and for everybody in the unencrypted part there is no protection at all. Averaging across the set is the wrong arithmetic.

Access wider than the job needs. Not a provision, and the BC Commissioner's guide to PIPA asks about it at page 10, question 9. It appears in published cases as the reason a small incident became a large one: one compromised account reached everything because every account did.


The one safeguard that rests on a provision

Worth separating from everything else on this page.

A login on anything holding personal information is the safeguard that sits directly on PIPEDA clause 4.7.1, which requires protection against unauthorized access, and on both provincial s.34s. It is not a recommendation.

Everything else in this guide is either a recommendation in Schedule 1, which s.5(2) says imposes no obligation, or a control named in regulator guidance. That does not make them unimportant. It makes them a different kind of thing, and knowing which is which is how you decide what to do first with a limited budget.


Named here as recommendations because a page that presented them as law would be wrong in the direction that costs you money.

Control Where it comes from Status
Encryption PIPEDA clause 4.7.3, in a "should" Recommended. The consequences on a lost device are real
Multi-factor authentication Nowhere in any of the three Acts Not required by any provision
Need-to-know access PIPEDA 4.7.3 "should"; BC OIPC guide p.10 Recommended
Keeping software updated Joint BC and Alberta security assessment, section 6 Recommended
Locked storage for paper and devices Joint assessment s.5.4 Recommended
Confidentiality agreements for staff Joint assessment s.4.13 Recommended
A clean desk Joint assessment Recommended
Privacy audits 2012 accountability guidance Recommended

Multi-factor is the one to be careful about, because it is the control most often described online as a privacy requirement in Canada. It is not in PIPEDA, it is not in Alberta PIPA, it is not in BC PIPA. The examples clause 4.7.3 gives are passwords and encryption.

None of this is an argument against doing them. It is an argument for knowing which things a regulator can hold you to.


Where to start with nothing

In this order, because it is the order the published decisions suggest rather than the order a security framework would give you.

  1. A login on everything holding personal information. The only item here resting on a provision.
  2. Encryption on anything that leaves the building. Laptops, phones, portable drives, backups in transit. This is where the Alberta decisions concentrate.
  3. Access limited to the people whose job needs it. The control that decides whether one compromised account is an incident or a catastrophe.
  4. Updates applied. Unglamorous, and it closes the holes somebody else already found.
  5. Paper and devices locked when unattended. The oldest control on the list and still the cause of real breaches.

Most small businesses have some of one and none of the rest, and the gap is usually not knowledge. It is that nobody owns it.


What this guide is not

It is not a security standard, and following it is not a defence. The duty is to make arrangements that are reasonable for what you hold, and only you know what you hold.

It is also not advice about a specific incident. If a device has gone missing, the question is no longer what you should have done; it is whether the breach is reportable and how long you have. That is a different page and a different clock.


Frequently asked questions

Does Canadian privacy law require encryption?

No Act requires it. PIPEDA clause 4.7.3 names encryption in a sentence that says safeguards 'should' include it, and s.5(2) of the Act says a 'should' in Schedule 1 is a recommendation that imposes no obligation. Alberta PIPA s.34 and BC PIPA s.34 require reasonable security arrangements and name no method at all. What has happened instead is that Alberta's regulator has repeatedly treated the absence of encryption on a lost device as a reason a breach poses a real risk of significant harm, which makes it reportable. That is a consequence rather than a duty, and for a lost laptop it is the consequence that matters.

Is multi-factor authentication required?

No. Multi-factor authentication appears nowhere in PIPEDA, Alberta PIPA or BC PIPA. PIPEDA clause 4.7.3 is a recommendation and the examples it gives are passwords and encryption. It is widely recommended, it is usually a good idea, and it is not a legal requirement. Any page telling you the law demands it is wrong, and that matters because it competes for budget with things the law does demand.

What does 'reasonable security arrangements' actually mean?

It is deliberately not defined, and it scales. PIPEDA clause 4.7.2 says the nature of the safeguards will vary with the sensitivity of the information, the amount, the distribution, the format and the method of storage, and that more sensitive information should be safeguarded by a higher level of protection. So the standard for a mailing list is not the standard for clinical records. The practical test is whether you could explain your choices to somebody afterwards.

Is a password the same as encryption?

No, and Alberta's regulator has said so twice. In P2022-ND-068 a password-protected laptop with no encryption reported was found to pose a real risk of significant harm. In P2022-ND-066 the recommendation was to consider encryption on laptops instead of password protection. A password keeps somebody out of the running system. Encryption keeps them out of the disk.

Where do I start if I have done nothing?

A login on everything that holds personal information, which is the one safeguard that rests on a provision rather than guidance, under PIPEDA clause 4.7.1. Then encryption on anything that leaves the building, because that is where the published decisions concentrate. Then access limited to the people whose job needs it. Those three cover most of what has gone wrong in the cases regulators have published.

This guide is educational and does not constitute legal advice. It is grounded in the text of PIPEDA, Alberta PIPA, and BC PIPA and published guidance from the OPC, OIPC Alberta, and OIPC BC. If your situation involves regulatory investigation, litigation risk, or circumstances not addressed here, engage a qualified privacy lawyer.

See what a compliance assessment finds

A real assessment for a small clinic: every area scored, every gap against the provision behind it, and the documents that close them.

See a complete assessment →

Get early access →