PIPEDA, the Personal Information Protection and Electronic Documents Act, is Canada's federal private sector privacy law. If your website collects personal information from Canadian residents, PIPEDA governs how you collect, use, and disclose it. Your hosting provider is part of that picture.
The ten principles and which ones touch hosting
PIPEDA's framework is built around ten fair information principles. Four of them directly implicate your hosting decisions. Accountability: you are responsible for personal information under your control, including information held by processors like hosting providers. Safeguards: personal information must be protected with security measures appropriate to its sensitivity. Openness: your privacy practices must be available to users in a generally understandable form. And individual access: individuals have a right to access personal information you hold about them and to challenge its accuracy. These four principles are not abstract. They translate into specific requirements for how you configure your server, choose your hosting provider, and document your data handling practices.
The third-party transfer obligation
When you send personal information to a hosting provider, you are transferring it to a third party. PIPEDA requires that you take reasonable steps to ensure comparable protection when you do this. The concept of comparable protection has been interpreted in guidance documents from the Office of the Privacy Commissioner as requiring that the third party provide a level of privacy protection that is generally equivalent to what PIPEDA requires of you. A hosting provider operating under Canadian law is straightforward to characterize as providing comparable protection. A US-based provider subject to the CLOUD Act is harder, because the CLOUD Act creates a mechanism for data disclosure that PIPEDA does not contemplate as consistent with its principles.
What your hosting agreement should say
PIPEDA does not specify exactly what must be in a hosting contract, but the accountability principle requires that you impose comparable protection obligations on third parties who handle personal information on your behalf. At minimum, your hosting agreement should: require the provider to protect personal information using appropriate security measures; restrict the provider to processing personal information only for the purposes you have specified; require the provider to notify you in the event of a security breach affecting your data; and address data retention and deletion when the relationship ends.
Most commodity US hosting terms of service do not include these provisions in any meaningful way. Canadian hosting providers operating under Canadian law are generally better positioned to include appropriate data processing terms. If your current provider cannot supply a data processing agreement, that gap is worth addressing before a privacy regulator asks about it.
PIPEDA vs Quebec's Law 25: understanding the differences
PIPEDA is the federal floor for private sector privacy in Canada. Quebec's Law 25 is more demanding in several ways: it requires mandatory Privacy Impact Assessments before deploying new technology that involves personal information, it requires breach notification to the Commission d'accès à l'information du Québec in addition to individuals, it gives individuals a right to data portability, and the penalties for violations are higher. For businesses operating only outside Quebec, PIPEDA is the primary applicable law. For businesses operating in Quebec, both laws apply and you must satisfy the more demanding of the two requirements in each area.
Alberta's Personal Information Protection Act (PIPA) and British Columbia's Personal Information Protection Act are deemed substantially similar to PIPEDA and substitute for it in those provinces for provincially regulated activities. Organizations operating nationally need to consider all three frameworks.
Practical steps for PIPEDA-aware hosting
Choose a hosting provider that is incorporated in Canada. Get a written data processing agreement that addresses the obligations above. Document where your data is physically stored and include that in your privacy policy. Map the personal information flowing through your website: contact forms, account data, e-commerce records, analytics, and log files. Understand which third parties receive that data. Update your privacy policy to accurately describe your hosting location and any third-party processors. Review your hosting arrangement annually, particularly if the provider changes ownership or moves infrastructure.
Gotekky
Need help deciding what to do next?
Tell us what you are seeing and what outcome you need. We will identify whether a managed service, scoped project or paid technical assessment is the right next step.