Building a privacy program
Where to start, what can wait, and what you can hand to somebody else.
For businesses in Alberta, British Columbia, and anywhere in Canada under the federal Act. 12 steps in four phases.
On this page
Three kinds of work
The question under “where do I start” is usually “how much of this is mine”. Every step below is marked with one of these.
A product does this, not a decision you have to make. Some of it you already pay for and have not switched on. If somebody looks after your computers, this is the part to give them.
What arrives is a draft built from your own answers, with gaps left where only you know the detail. You read it, complete it, and adopt it. Every step marked this way comes from the Compliance Readiness assessment.
These depend on how your business actually works, so no product or template can settle them. Several take under an hour. The one that does not is getting the right clause into your service provider contracts.
On the word “required”. Where a step is marked Required, the provision named under it says so. Steps without the marker are practices regulators look for rather than provisions that demand them. Neither is a judgement about your own situation, and nothing here is legal advice.
What applies to you, and what you hold
None of this is published, and everything after it depends on it. The third step is the largest piece of work on the page, and five later steps read from it.
Work out which Acts cover you
Only you can decideUnder an hourIt depends on your province, what your business does, and whether you are federally regulated. Most businesses are covered by more than one Act, and the answer changes what every later step has to say.
Name one person as responsible, and tell your staff who it is
Only you can decideUnder an hourRequiredThe Act requires you to designate somebody accountable. It does not require a job title or a privacy qualification, and in a small business it is usually whoever already handles the awkward questions.
PIPEDA Schedule 1, clause 4.1
Write down what personal information you hold, why, where it is, and who can reach it
We write itA day or moreRequiredThe Act requires you to document the purposes you collect for. No Act uses the words "data inventory", but the retention periods, the access requests, the breach assessment and the published policy all read from this one.
PIPEDA Schedule 1, clause 4.2.1
The ones with a deadline
Each of these starts a clock the day somebody contacts you. They are second because the cost of not having them is counted in days, and because you cannot build them while the clock is already running.
Give people a way to complain, and a way to get an answer
We write itHalf a dayRequiredA route to complain is the first duty and the one most businesses have. The second is less known: every complaint has to be investigated, and where one is justified the Act expects your policies to change because of it.
PIPEDA Schedule 1, clauses 4.10.2 and 4.10.4
Be able to answer an access request on time
We write itHalf a dayRequiredThe clocks are not the same. The federal Act and BC give you 30 days; Alberta gives 45. Missing the deadline is itself a refusal under all three, so the date matters more than the polish of the answer.
PIPEDA s.8(3) · Alberta PIPA s.28(1)(a) · BC PIPA s.29(1)
Be ready for an incident: decide, report, notify, and record every one
We write itHalf a dayRequiredThe duty is not to have a plan. It is to make the right call under time pressure, report it where the law requires, and keep a record of every incident including the ones you decided not to report.
PIPEDA s.10.1 and s.10.3 · Alberta PIPA s.34.1
If it has already happened, start with the breach playbooks instead. Come back to this page afterwards.
What you tell people
These are the parts the public sees, and they are third on purpose. A policy written before the inventory describes the business you remembered rather than the one you have.
Publish a privacy policy, and give your staff the internal one
We write itHalf a dayRequiredTwo documents, not one. What the public can read about your practices, and what your own staff are told they may and may not do. The second is a separate duty and the one usually missing.
PIPEDA Schedule 1, clause 4.8 · Alberta PIPA s.6 · BC PIPA s.5
Say what you are collecting and why at the point you collect it, and take only what you need
Only you can decideHalf a dayRequiredThis is a line on a form rather than a document. Alberta adds something the others do not: the notice must also name a person who can answer questions about the collection.
PIPEDA Schedule 1, clauses 4.2.3 and 4.4 · Alberta PIPA s.13(1)
The things that are always true
Nothing here has a deadline, which is why it is last and why it is the part that slips. Each one holds on an ordinary day or it does not hold at all.
Secure what you hold: a login on everything, encryption, updates, locked drawers
Buy and configureHalf a dayRequiredThe duty is to make reasonable security arrangements, and no Act names a method. That cuts both ways: nothing specific is demanded of you, and nothing specific protects you if what you chose was not reasonable.
PIPEDA Schedule 1, clause 4.7 · Alberta PIPA s.34 · BC PIPA s.34
If you send marketing email: consent you can show, identification in every message, a working unsubscribe
Buy and configureUnder an hourRequiredYour email platform does most of this once it is configured. The part it cannot do is prove how somebody came to be on the list, and implied consent from a purchase expires two years after it.
CASL s.6 and s.10 · SOR/2012-36
Set how long you keep each kind of record, and destroy it securely when that ends
Only you can decideHalf a dayRequiredIn BC there is a floor as well as a ceiling. Information used to make a decision about somebody must be kept at least a year after the decision, and the Act says so despite the duty to destroy. Alberta’s rule of the same number runs the other way.
Alberta PIPA s.35(2) · BC PIPA s.35(1) and s.35(2)
Make your service providers accountable in writing
Only you can decideA day or moreRequiredYou stay responsible for personal information a provider handles for you, so the protection has to be in the contract. This is the one step on the page that needs a conversation with the other side rather than an afternoon.
PIPEDA Schedule 1, clause 4.1.3
Keeping it going
A program is not finished, it is maintained, and the maintenance is smaller than the build. Read the inventory once a year beside the list of software you pay for. Update the row the same week anything changes. Re-read the published policy when the business changes rather than when the calendar says so.
The law moves too. Alberta and British Columbia both have reform under way, and the federal Act is being replaced. None of that changes the twelve steps above, which is the reason they are worth doing now rather than waiting to see.
When to get a lawyer
Most of a program is yours to build, and this page is written so that you can. Four situations are worth a lawyer rather than a search engine.
- When it is genuinely unclear which Act covers you, such as a business working across provinces or a non-profit in Alberta.
- When you are drafting the clause that binds a service provider.
- When a breach is near the line, or a reporting deadline is running.
- When a regulator or a complainant has already been in touch.
What you produce here is a useful thing to bring to any of those conversations.
Finding where you are
This page is the order. It does not tell you which of the twelve you have already done, and for most businesses the honest answer is some of each.
The Compliance Readiness assessment answers that, and produces the documents for the steps marked “we write it”. You can also see what it generates before deciding anything.
Frequently asked questions
Do I have to do these twelve things in this order?
No, and the order is not arbitrary either. Several steps read from earlier ones: you cannot set a retention period for information you have not listed, and you cannot write an accurate privacy policy before you know what you collect. The phases reflect those dependencies. Within a phase the order matters much less, so if one step is easy for you and another is hard, take the easy one first.
Which of these does the law actually require?
Nine of the twelve carry a Required marker, and each names the provision underneath it. The other three are practices regulators look for rather than duties any Act imposes. The distinction matters because the two compete for the same budget and the same afternoon. Anything described online as a Canadian privacy requirement without a section number beside it is worth checking.
How long does the whole thing take?
Each step carries its own estimate and most are under a day. The two that are not are writing down what personal information you hold, which is the largest single piece of work on the page, and getting privacy terms into your service provider contracts, which is the only step that needs somebody else to agree. A small business doing this deliberately rather than all at once usually spreads it over a few weeks.
What if I have already done some of it?
Most organizations have. The visible things tend to be done, a published policy and somebody named as responsible, and the unglamorous ones tend not to be, retention, service provider terms and incident readiness. This page is the order rather than an assessment, so it does not tell you which of the twelve you have. The Compliance Readiness assessment answers that and produces the documents for the steps marked "we write it".
Does this cover Quebec?
No. This page covers the federal Act, Alberta PIPA and BC PIPA, plus CASL for marketing email. Quebec's Law 25 imposes duties these three do not, including a privacy officer by default and specific rules on automated decisions, and a page that quietly folded it in would be wrong in the direction that matters. If you operate in Quebec, treat this as the floor rather than the whole.