Simple, transparent pricing
Know your breach obligations. Build your compliance program. All in one subscription.
Covers PIPEDA, Alberta PIPA, and BC PIPA. Quebec Law 25 is outside our scope.
What the Business plan buys, on a real assessment
Alberta PIPA requires the organization to assess the risk of harm itself, and PIPEDA says the same. ACME Retail had one incident affecting 18,400 people, with customers in Alberta, British Columbia, Ontario and Quebec. Here is what that assessment returned, under every framework that reaches them:
Alberta PIPA
Reporting required
BC PIPA
Voluntary report recommended
PIPEDA
Reporting required
Same facts, three different answers, because BC PIPA has no mandatory breach-notification trigger. 6 documents came out of it, a completed report for each of the three regulators among them.
This assessment in full →A compliance assessment →A completed PIA →Walk a breach assessment →Walk a compliance assessment →
Business Plan
Privacy Compliance
$799/year CADplus applicable taxes
For small businesses and professional practices
Breach management
- ✓ 3 breach assessments per year
- ✓ A determination under each framework that applies to you, with the reasoning
- ✓ The obligations each one triggers, and who they are owed to
- ✓ Up to 6 documents generated automatically
- ✓ Every assessment kept, with its outcome and its documents
Annual compliance assessment
- ✓ Ten areas scored separately, against the duties your province and sector impose
- ✓ An overall status, shown against all three so you can place it
- ✓ Every gap with the provision behind it, so a finding can be checked rather than trusted
7 documents generated from your answers
- ✓ Gap remediation roadmap
- ✓ Incident response plan
- ✓ Privacy management programme
- ✓ Personal information inventory
- ✓ Privacy records and registers
- ✓ Internal privacy policy
- ✓ Complaint handling procedure
Ongoing compliance
- ✓ A dated document set each year, with what changed since last time
- ✓ What is due, on your portal →
- ✓ Public privacy policy template, where you need one
30-day money-back guarantee, so long as you have not downloaded any documents. Downloads are recorded: that a document was taken and when, never the document itself. Payments processed by Stripe.
MSP Plans
From $1,645/year CADplus applicable taxes
For IT service providers, minimum 5 clients. There is no platform fee: $1,645 is five clients at the Starter rate. What MSPs get →
Per-client annual fee
MSP Starter
5–10 clients
MSP Growth
11–50 clients
MSP Scale
51+ clients
All rates are plus applicable taxes. Rates are by band and apply to every client, so crossing into the next band lowers your whole bill, so eleven clients costs less than ten. A block bought mid-term is charged at the rate in force, and the better rate applies from renewal.
Each client receives
- ✓ Everything in the Business plan
- ✓ Unlimited PIAs
- ✓ Multi-client management dashboard
30-day money-back guarantee, so long as no document has been downloaded for any client organization under the account. The same rule as the Business plan.
Privacy Impact Assessment
Bought one at a time, by anyone. No subscription.
A structured assessment for a new project, system or data use. Each movement of information is placed under the Act that governs it, the duties you have not met are listed against the provision behind each, and you receive a completed PIA document.
- ✓Paid before you start, so nobody finishes one and then meets a payment screen.
- ✓No subscription is created and nothing renews.
- ✓Your account and its records stay with you afterwards.
- ✓Included in every MSP plan, at no additional cost per client.
Not sure what you get? See a sample assessment verdict →
Or see a complete annual compliance assessment →
Privacy by design
Breach details are processed entirely within your browser and never transmitted to our servers.
Canadian data residency
Production infrastructure hosted in Canada. Your data stays in Canada.
Grounded in Canadian law
Assessment logic built on the text of PIPEDA, Alberta PIPA and BC PIPA and on published OPC and OIPC guidance, not a generic privacy checklist.