← Guides·All compliance guides →
Making Service Providers Accountable: What the Contract Has to Cover
By Yong DuPublished
You stay responsible for personal information your suppliers handle. What the contract has to say, and why.
On this page
The rule in one sentence
You can hand the work to somebody else. You cannot hand over the responsibility.
PIPEDA Schedule 1 clause 4.1.3 is the provision:
An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.
Alberta PIPA s.5(2) says the same thing in its own words. The phrase that does the work in both is comparable level of protection: whatever you owe the individual, the provider has to deliver on your behalf, and you have to have arranged that in a way you can show.
Note what the clause does not say. It does not require a particular form of agreement, a named document, or a list of your providers. "Contractual or other means" is deliberately broad, and a small business meeting it with an exchange of emails is meeting it.
Who counts as a service provider
More people than most businesses think, because the test is not whether the supplier is a technology company. It is whether they handle personal information for you.
The ones that are obvious: cloud software holding your customer records, a payroll provider, an email platform, a hosting company, an outsourced IT contractor.
The ones that get missed:
- The bookkeeper or accountant with access to your invoicing, which is customer names, addresses and what they bought.
- The shredding or document storage company. They never read the records, and they hold them.
- The answering service or virtual receptionist who takes names and reasons for calling.
- A marketing agency given the mailing list.
- A contractor's own subcontractor, which is the one nobody asks about. Your provider using a provider is still your personal information.
A useful first pass is to work down the list of everyone you pay. If a supplier could see a customer's name, they are in scope.
What the clause has to cover
Six things. These are the substance; the wording is for whoever drafts your contracts.
1. What they may do with it, and nothing else. The provider may use the personal information to deliver the service you bought, and for no other purpose. The clause that matters most in practice is the one forbidding use for their own purposes, including improving their own product or training a model on it.
2. A comparable level of protection. The provision's own phrase. In practice this means the security arrangements you would be expected to make yourself, applied by them.
3. They tell you about a breach, quickly, and in time for you to act. This is the most commonly missing term and the most expensive one to be without. Your reporting clock starts when you become aware of a breach, so a provider who tells you three weeks later has spent your deadline for you. Ask for a fixed period, in hours or days, not "promptly".
4. You can ask what they are doing. A right to ask for evidence that the protections exist. For a small supplier this is a question and an answer. For a large one it is usually a certification or an audit report they already publish.
5. Subcontracting is disclosed, and the same terms flow down. Otherwise the comparable protection stops one layer below the contract you read.
6. Return or destruction at the end. When the arrangement ends, the personal information comes back or is destroyed, and they tell you which. The practical failure here is not malice. It is a provider that simply keeps everything forever because nobody asked.
Where the obligation differs by province
Alberta adds a duty about your published policy. PIPA s.6(2) requires an organization using a service provider outside Canada to state, in its policies, the countries where the collection, use, disclosure or storage occurs or may occur, and the purposes the provider is authorized for. Neither the federal Act nor BC requires this of the policy. A US email platform or US hosting is enough to engage it.
The federal Commissioner asks for something no Act requires. The 2009 cross-border guidelines ask you to tell individuals that information held in another country may be reachable by that country's law enforcement and national security authorities, in clear language. That is guidance, not a provision, and this guide marks it as such because the difference matters when you are deciding what to spend time on.
What regulators look for, and what no Act requires
Worth separating, because a list that mixes them wastes your effort on the wrong things.
A duty: the comparable protection itself, under PIPEDA 4.1.3 and Alberta PIPA s.5(2).
Not a duty, and asked for anyway: a written list of your providers. The joint BC and Alberta security assessment asks for documented personal information assets and where they are held, at s.1.2, and the 2020 assessment asks for breach reporting terms at s.4.18 and return or destruction at ss.4.22 and 4.23. These are what a regulator looks for after something has gone wrong. None of them is a provision, and a guide that presented them as law would be wrong in the direction that costs you money.
The practical reading: the clause is the duty, the list is how you find out which contracts need it.
Why there is no template here
A contract clause is a legal document, and drafting one for your situation would be legal advice. ClearBreach produces the documents a legal conversation needs and does not have that conversation for you.
What that leaves you with is more useful than a template would be. You now know the six things the clause has to cover, which means you can brief whoever drafts your contracts in one email, or read what a provider has put in front of you and say which of the six is missing.
This is the step on the program roadmap that takes longest, because it is the only one that needs somebody else to agree. Start with the providers holding the most sensitive information rather than the easiest contract to change.
Related guides
- Building a privacy program: what to do first. Where this step sits, and what has to come before it
- Personal Information Inventory. The list that tells you which providers are in scope
- Cross-Border Privacy Impact Assessments. When the provider is outside Canada
- MSP Client Onboarding Privacy Questions. The same conversation from the provider's side
Frequently asked questions
If my software provider has a breach, is it my problem?
Yes, and that is the whole point of the rule. PIPEDA Schedule 1 clause 4.1.3 says an organization is responsible for personal information in its possession or custody, including information transferred to a third party for processing, and must use contractual or other means to provide a comparable level of protection. Alberta PIPA s.5(2) is to the same effect. Transferring the work does not transfer the accountability. In practice your customers will also come to you rather than to a supplier they have never heard of.
Does a vendor's standard terms of service count?
Sometimes, and you have to read them to find out. Many cloud providers publish a data processing addendum that covers most of what is needed, and accepting it is a reasonable way to meet the duty for a commodity service. What it will not usually cover is a provider small enough to have no such document, which in a small business is often the bookkeeper, the shredding company or the IT contractor. Those are the contracts to look at first.
What if the provider will not change their contract?
That is information, not a dead end. A large provider will not negotiate for a small customer, so the question becomes whether their standard terms are good enough, which is a judgement you can record. A small provider who refuses to commit to anything in writing is telling you something about how they handle information, and that is worth knowing before rather than after.
Do I need a contract with a provider outside Canada?
Yes, and in Alberta there is a second duty on top of it. Alberta PIPA s.6(2) requires your published policies to state the countries where a foreign service provider collects, uses, discloses or stores personal information, and the purposes it is authorized for. Neither PIPEDA nor BC PIPA requires that of the policy. The federal Commissioner separately asks you to tell people the information may be reachable by that country's authorities, which no Act requires.
Does ClearBreach provide a template clause?
No, and that is deliberate. A contract clause is advice about a legal document, and drafting one would be giving legal advice rather than producing the documents a legal conversation needs. What this guide does is set out what the clause has to cover, so that you can brief whoever drafts it, or read what a provider has offered and tell whether it is enough.
This guide is educational and does not constitute legal advice. It is grounded in the text of PIPEDA, Alberta PIPA, and BC PIPA and published guidance from the OPC, OIPC Alberta, and OIPC BC. If your situation involves regulatory investigation, litigation risk, or circumstances not addressed here, engage a qualified privacy lawyer.
See what a compliance assessment finds
A real assessment for a small clinic: every area scored, every gap against the provision behind it, and the documents that close them.
See a complete assessment →