Data governance for Canadian organisations: what PIPEDA requires in practice
Most Canadian organisations subject to PIPEDA have taken the minimum steps: they have designated a privacy officer, they have a privacy policy on their website, and they have a process for responding to access requests. What fewer organisations have is the underlying infrastructure that makes those steps meaningful: a data inventory, documented retention schedules, access controls that are actually enforced, and a breach response procedure that has been tested.
The accountability principle in practice
PIPEDA's accountability principle requires organisations to implement policies and practices that give effect to the other principles in the legislation. In practice, this means having documented policies, not just a named individual. It means those policies are communicated to staff. It means there is a process for reviewing and updating them as the organisation's data practices change.
An audit of most organisations' actual data practices against their stated policies will reveal gaps. Data is retained beyond the periods described in the policy. Access controls have not been updated to reflect staff changes. The breach notification procedure exists as a document but has never been walked through.
Starting with a data inventory
A data governance programme that is built without a data inventory is built on guesswork. The inventory does not need to be exhaustive on the first pass. It needs to answer four questions: what categories of personal information does the organisation hold, where does that information live, who has access to it, and what is the basis for holding it.
For many organisations, the process of building the inventory surfaces information that nobody knew was being collected, or data that was collected for a specific purpose and never disposed of when that purpose ended. Both of those findings have compliance implications.
PHIPA and health information in Ontario
Organisations in Ontario that handle personal health information are subject to PHIPA in addition to PIPEDA. The definition of a health information custodian under PHIPA is specific, and not every organisation that handles health-related data with it. But the definition is broad enough that some organisations are subject to PHIPA without being aware of it.
The practical requirements under PHIPA include more specific consent obligations, stricter access controls, and a breach notification requirement with a shorter timeline than PIPEDA's. For organisations that are uncertain about their status, a legal opinion is the appropriate first step, and a data governance review is the appropriate second step.
Data governance work is not a one-time project. The inventory needs to be maintained, the policies need to be reviewed, and the access controls need to reflect the organisation as it actually exists, not as it existed when the programme was set up.