TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Articles/Corporate
№ 411 Corporate

Sharing Customer Data With Third-Party Vendors: What Ontario Businesses Must Do

Learn what Ontario businesses must do under PIPEDA before sharing customer data with a vendor, data processor, or other third-party service provider.

Corporate5 min readTSLBy the Treadstone Law team · OntarioUpdated 2026-07
All articles
Key takeaways
  • PIPEDA's accountability principle makes an organization responsible for personal information in its custody or control, even after that information is handed to a third party for processing.
  • Whether you need fresh consent to share data with a vendor depends on the nature of the relationship.

Almost every business shares customer data with someone else eventually — a payment processor, an email marketing platform, a cloud storage provider, a bookkeeper. Handing data to a vendor does not hand off your legal responsibility for it.

This article explains what an Ontario business actually has to do, under Canada's federal privacy law PIPEDA, before and while sharing customer data with a third-party vendor.

Sharing Data Does Not Transfer Your Responsibility

PIPEDA's accountability principle makes an organization responsible for personal information in its custody or control, even after that information is handed to a third party for processing. If your vendor mishandles the data, PIPEDA generally still treats it as your problem to answer for — which is exactly why the contract you sign with a vendor, and the diligence you do before signing it, matters as much as your own internal practices.

Consent: What You Need Before You Share

Whether you need fresh consent to share data with a vendor depends on the nature of the relationship. Sharing data with a vendor that simply processes it on your behalf, for the purpose the customer already agreed to, is generally treated differently than disclosing data to an independent third party that will use it for its own purposes — the latter is far more likely to require new, meaningful consent. Being transparent in your privacy policy about the categories of vendors you use, and why, is good practice either way.

What a Vendor Contract Should Address

Contract elementWhy it matters
Purpose limitationRestricts the vendor to using the data only for the services you hired it for
Security safeguardsSets a minimum standard for how the vendor protects the data technically and physically
Breach notificationRequires the vendor to tell you promptly if something goes wrong, so you can meet your own obligations
Subcontractor flow-downEnsures any further vendor the first vendor uses is bound by the same standards
Deletion or return of dataAddresses what happens to your customer data when the relationship ends
Audit or verification rightsGives you a way to confirm the vendor is actually doing what the contract says

Cross-Border Considerations

Many common vendors — cloud hosting, payment processing, email platforms — store or process data outside Canada. PIPEDA does not prohibit this, but it does require you to be transparent about it and to use contractual or other means to try to secure comparable protection while the data is elsewhere. This is a common area for privacy-policy gaps: businesses adopt a foreign-hosted tool and never update their public disclosures to reflect it.

Red Flags in a Vendor's Data Practices

Frequently asked questions

Do I need a separate agreement for every vendor, even a small one?

In principle, yes. Even a small vendor handling customer data should have some written terms addressing purpose, security, and breach notification, though the depth of that agreement can scale with the sensitivity of the data and the size of the relationship.

Is it enough if the vendor says they are "PIPEDA compliant"?

That claim alone is not a substitute for your own diligence. You remain accountable for the data, so understanding what the vendor actually does — not just what it claims — is worth the time it takes.

What if my vendor has a data breach, not me?

You can still have notification obligations to affected individuals and, depending on the risk, to the federal Privacy Commissioner. A vendor's breach does not relieve you of your own responsibilities for the data you handed it.

Does this apply to something as simple as using a cloud email provider?

Yes, in principle. Any vendor that stores or processes customer personal information on your behalf is a vendor for these purposes, regardless of how ordinary or "off the shelf" the service feels.

Who is actually responsible if a vendor loses our customer data?

Both of you can end up with obligations, but your own accountability under PIPEDA does not disappear just because the vendor was the one that mishandled the information. A well-drafted vendor agreement is what lets you show, after the fact, that you took reasonable steps before the incident happened.

This article is general information, not legal advice. Reading it does not create a lawyer-client relationship. Ontario laws, tax rates, and government programs change, and how the law applies depends on your specific facts. For advice about your situation, speak with a licensed Ontario lawyer. Treadstone Law is licensed by the Law Society of Ontario — reach us at 1-844-900-1070 or start a file online.

This is a corporate question

Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.

ContactStart a File →