- PIPEDA's accountability principle makes an organization responsible for personal information in its custody or control, even after that information is handed to a third party for processing.
- Whether you need fresh consent to share data with a vendor depends on the nature of the relationship.
Almost every business shares customer data with someone else eventually — a payment processor, an email marketing platform, a cloud storage provider, a bookkeeper. Handing data to a vendor does not hand off your legal responsibility for it.
This article explains what an Ontario business actually has to do, under Canada's federal privacy law PIPEDA, before and while sharing customer data with a third-party vendor.
Sharing Data Does Not Transfer Your Responsibility
PIPEDA's accountability principle makes an organization responsible for personal information in its custody or control, even after that information is handed to a third party for processing. If your vendor mishandles the data, PIPEDA generally still treats it as your problem to answer for — which is exactly why the contract you sign with a vendor, and the diligence you do before signing it, matters as much as your own internal practices.
Consent: What You Need Before You Share
Whether you need fresh consent to share data with a vendor depends on the nature of the relationship. Sharing data with a vendor that simply processes it on your behalf, for the purpose the customer already agreed to, is generally treated differently than disclosing data to an independent third party that will use it for its own purposes — the latter is far more likely to require new, meaningful consent. Being transparent in your privacy policy about the categories of vendors you use, and why, is good practice either way.
What a Vendor Contract Should Address
| Contract element | Why it matters |
|---|---|
| Purpose limitation | Restricts the vendor to using the data only for the services you hired it for |
| Security safeguards | Sets a minimum standard for how the vendor protects the data technically and physically |
| Breach notification | Requires the vendor to tell you promptly if something goes wrong, so you can meet your own obligations |
| Subcontractor flow-down | Ensures any further vendor the first vendor uses is bound by the same standards |
| Deletion or return of data | Addresses what happens to your customer data when the relationship ends |
| Audit or verification rights | Gives you a way to confirm the vendor is actually doing what the contract says |
Cross-Border Considerations
Many common vendors — cloud hosting, payment processing, email platforms — store or process data outside Canada. PIPEDA does not prohibit this, but it does require you to be transparent about it and to use contractual or other means to try to secure comparable protection while the data is elsewhere. This is a common area for privacy-policy gaps: businesses adopt a foreign-hosted tool and never update their public disclosures to reflect it.
Red Flags in a Vendor's Data Practices
- No written data processing agreement at all — just a general terms of service.
- Vague or missing language about subcontractors and where data is actually stored.
- No stated breach-notification obligation running back to you.
- Reluctance to answer basic questions about the vendor's own security practices.
- Broad rights, buried in the vendor's terms, to use "aggregated" or "anonymized" versions of your customer data for its own purposes, without clarity about how that anonymization actually works.
Frequently asked questions
Do I need a separate agreement for every vendor, even a small one?
In principle, yes. Even a small vendor handling customer data should have some written terms addressing purpose, security, and breach notification, though the depth of that agreement can scale with the sensitivity of the data and the size of the relationship.
Is it enough if the vendor says they are "PIPEDA compliant"?
That claim alone is not a substitute for your own diligence. You remain accountable for the data, so understanding what the vendor actually does — not just what it claims — is worth the time it takes.
What if my vendor has a data breach, not me?
You can still have notification obligations to affected individuals and, depending on the risk, to the federal Privacy Commissioner. A vendor's breach does not relieve you of your own responsibilities for the data you handed it.
Does this apply to something as simple as using a cloud email provider?
Yes, in principle. Any vendor that stores or processes customer personal information on your behalf is a vendor for these purposes, regardless of how ordinary or "off the shelf" the service feels.
Who is actually responsible if a vendor loses our customer data?
Both of you can end up with obligations, but your own accountability under PIPEDA does not disappear just because the vendor was the one that mishandled the information. A well-drafted vendor agreement is what lets you show, after the fact, that you took reasonable steps before the incident happened.
This is a corporate question
Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.