Do I need customer consent before sharing their information with a third-party service provider?
It depends on what the third party is doing with the information. Under PIPEDA, sharing personal information with a service provider who is processing it on your business's behalf, for the same purpose it was originally collected for, such as a payment processor, a shipping company, or an IT provider hosting your customer database, generally doesn't require separate fresh consent beyond what was already obtained for the original purpose, as long as your business remains accountable for how that provider handles the information and has appropriate contractual safeguards in place.
Sharing information with a genuinely separate third party for a different purpose, such as selling customer data to an unrelated company for its own marketing use, is a different matter entirely and generally does require new, specific consent, since that goes beyond what the customer originally agreed to when the information was collected.
The practical distinction is between a service provider acting as an extension of your own business operations versus an outside party using the information for its own separate purposes. Reviewing your contracts with vendors who handle customer data, and making sure they include appropriate confidentiality and security commitments, is worth doing even where fresh consent isn't strictly required for the sharing itself.
Key takeaways
- Sharing with a service provider processing data on your behalf for the same purpose generally doesn't need fresh consent.
- Your business remains accountable for how that provider handles the information.
- Sharing with an unrelated third party for its own separate purpose generally requires new consent.
- Put proper confidentiality and security terms in vendor contracts even when fresh consent isn't required.